Privacy Policy
Version 2026-10-01 · Last updated: October 1, 2026
This policy explains in plain words what data Itqan114 collects about you, why, who can see it, where it is stored, how long it is kept, and what your rights are. Everything in it describes what the app does today. You agree to it when you create your account, and we ask for your agreement again whenever it changes.
Information we collect
When you create an account: your name, email address, password (we store an encrypted hash of it, never the password itself), country, account type, your phone number if you enter one, and the time you agreed to this policy along with its version number.
While you use the app: your memorization progress; your recitation sessions, with their surahs and ayahs, their results, the words you got right or wrong, and their duration; your plans and assignments; your competition and position-test results; your support requests; your reminders and notifications; your consents to the camera, recording and retention period; and a log of who played, downloaded or deleted your recordings. During a session we also note how many times you left its page or switched to another window, and for how long.
We do not ask for your date of birth, and we do not locate you: your country is whatever you choose.
The microphone and your recitation audio
The microphone is used only when you recite — including the position test and competitions — from the moment a session starts until it ends. It stays off while you read or listen.
During a session your voice is sent to OpenAI to be turned into text, which we use to follow your words and score your recitation (details under “Who turns your voice into text”).
We keep the audio of every recitation session saved in “Sessions”, and nothing from the position test or competitions (see “Your saved recordings and who can hear them”).
Who turns your voice into text
On the live site, your voice travels along three paths at once during a session, all of them to OpenAI:
- Live stream: your browser connects directly to OpenAI and sends your microphone audio as you speak, so your words come back while you are still reciting.
- Second ear: a second live stream of the same audio to a different model, which confirms what the first one heard.
- Short clips: about every two and a half seconds, the last eight seconds of your audio are sent to our server, and from there to OpenAI.
When you end the session, its full recording is sent to our server, and from there to OpenAI for the final scoring. Our server lets go of the audio as soon as the text arrives, keeps the text in its memory for ten minutes at most, and stores audio only as described under “Your saved recordings and who can hear them”.
OpenAI does not receive your name or your email. With each of the two live streams it receives a coded identifier of your account with us, from which neither can be read, and which it asks for in order to detect abuse; and its servers see your device’s IP address because your browser connects to them directly. The short clips and the full recording are sent by our server with nothing that identifies you.
According to OpenAI’s published policy for its API (https://developers.openai.com/api/docs/guides/your-data): by default this data is not used to train its models, clips and recordings are not kept once they have been transcribed, and live-stream logs are kept for up to 30 days to detect abuse, unless the law requires OpenAI to keep them longer.
If the live stream is unavailable in your browser (a service outage, or a browser that does not support it), the app uses your browser’s built-in speech recognition, and your browser may then send your voice to the company that makes it (for example Google, in Chrome) under that company’s own policy.
Your saved recordings and who can hear them
Our server, on Google Cloud, keeps the audio of every recitation session saved in “Sessions”, automatically and with no switch. The audio is uploaded after the report appears; if the upload fails, “Your recitation audio could not be saved” appears, and your score and report stay saved.
- Who can hear it: you, your teacher in a circle you belong to, the owner and supervisors of the institution you belong to, your guardian, and the platform administrator. A supervised account is no different: joining the circle, which its guardian approved, is the permission, so no separate consent is asked for its audio.
- A teacher you have a follow with sees your sessions, their results, your recurring mistakes and your plans, but never hears your voice and never sees video.
- Video is kept only with consent to “recording for review” with the camera; for a supervised account, only the guardian’s consent counts. For as long as the consent stands, it can be seen by you, your guardian, the platform administrator, your teacher in a circle and your institution’s supervisors.
- Recordings kept before audio keeping became automatic, with the “Keep an audio recording of my recitation” switch, stay as they were: heard by you, your guardian and the platform administrator — not by your teacher or your institution.
No recording is ever kept from the position test or from competitions.
This keeping cannot be switched off; if you don’t want a recording to stay, delete it whenever you like from “My recordings” in “Profile” (your guardian can too, if your account is supervised), or shorten the retention period. Every play, download or deletion of a recording is written to a log that you and your guardian can see.
Optional camera
The camera is optional and off by default. We ask you about it when you start reciting, and remember your answer for this visit only. When you turn it on, gaze detection runs on your device alone, and all it sends to our server are counts: how many times your gaze moved away, and for how long.
Video is uploaded and stored only with consent to recording. The face-detection model is downloaded to your device from Google and jsDelivr servers.
How we use your data
To follow and correct your recitation and save your progress; to run circles, follows, families, competitions and leaderboards; to send service email (welcome messages, password codes, invitations, and the reminders you ask for); and to answer support requests.
We do not sell your data, we show no advertising, and we use no analytics or tracking tools.
Who can see your sessions
Your sessions, their results and reports, your recurring mistakes and your plans can be seen by: you, your guardian, your teacher in a circle, the supervisors of the institution you belong to, a teacher you have a follow with, and the platform administrator. Your recordings have their own rule, set out under “Your saved recordings and who can hear them”.
A follow starts only once the person invited accepts it, and for a supervised account only with the guardian’s consent; either of you, or the guardian, can end it at any time. A following teacher sees: your name, email and join date, your number of sessions and their average accuracy, your last ten sessions, your recurring mistakes, your session reports, and your plans (without being able to change them); they do not hear your voice or see video.
On your institution’s or circle’s leaderboard, your name and results are shown to your classmates and teachers, even if your profile is private.
What everyone can see
Your public profile is visible by default to any visitor, without signing in, and you can make it private at any time from “Profile”. It shows your name, country and join date, the ayahs and surahs you have memorized, the latest surahs you are memorizing, and your number of sessions and their average accuracy.
The leaderboard on the home page is public: it shows the top ten public accounts that have at least three sessions each, with their name, country, number of sessions and average accuracy. Private profiles do not appear on it.
On competition leaderboards every participant appears with their rank, country and score; their name is hidden if their profile is private.
The profile of a supervised account is always private, and its owner cannot make it public.
Children and guardians
An account is “supervised” when it is linked to a guardian: the guardian creates their child’s account and agrees to this policy on the child’s behalf; or links an existing account using its password; or a teacher or institution suggests the guardian’s email, the student agrees, and the guardian then accepts the invitation.
Only the guardian consents for their child to the camera, recording and the retention period, and to every follow or institution membership before it starts. The child’s session audio is kept like anyone else’s: the guardian’s approval of the child’s circle is the permission for its teacher and institution to hear it, so no separate consent is asked for the audio. A supervised account can switch off what its guardian allowed or shorten the period, but never extend it.
The guardian sees their child’s sessions, progress and recordings, and the child is told when they are linked to the person who has become their guardian. We do not ask for a date of birth: supervision is known from the link alone.
A teacher or institution can create a student account; the student then receives a code by email to set their password.
Your phone number and who sees it
A phone number is optional when you register. It does not appear on your public profile or on leaderboards, and neither your classmates nor the people who follow you can see it.
The support team sees it when you send a help request: it arrives with your request in the support inbox and on the administrator’s dashboard. If you are a teacher, or an institution owner or supervisor looking after a student who has no teacher, your student sees your name, email and phone on the contact card so they can reach you.
When a teacher adds a student, they may enter the name, email and phone of the student’s guardian, which are then stored with the invitation. If the guardian accepts it and their account has no phone number, this number is added to it.
To correct or delete your number, write to us at supportitqan114@gmail.com.
The emails we send, and what reaches other people
We send email from noreply@itqan114.com through the Resend service, and a reply to any of these messages goes to the support inbox, supportitqan114@gmail.com.
To your own inbox: a welcome message after you register, password-reset codes, reminders if you chose email for them, and invitations addressed to you.
To other people, when you or someone who teaches you asks for it:
- Follow invitation: when you invite someone by email, they receive a message with your name, and an invitation to register if they have no account. No more than one email is sent per invitation per week, and no more than ten invitation emails per account per day.
- Guardian invitation: if a teacher or institution suggests your guardian’s email, we show you the address first, and nothing is sent to it until you agree. The guardian then receives an email with your name and a link valid for fourteen days.
- Institutions: when an institution creates a student account, the student receives a code to set their password, along with their teacher’s name; when it invites a student or a teacher, they receive the institution’s name and the name of the person who invited them.
- Support requests: these reach the support inbox as described under “Email support”.
No inbox receives more than 3 unrequested emails a day from us (welcome messages and invitations), whoever asks for them.
Email support
You send your request from the “Help” page, or from the “Contact support” button next to any error: its type, subject and text. It is saved in your account, and a notice of it is sent through Resend to the support inbox, supportitqan114@gmail.com, which is a Gmail mailbox, together with what we need to answer you: your name, email, phone number if we have it, country, account type, registration date, your number of sessions, their average accuracy and your last session, what you have memorized, how many requests you have sent, and your account ID. The platform administrator also sees it on their dashboard.
When you come from an error message, the start of the request says where the error happened and what it said, the page, and the app’s version number; you see all of this and can edit it before sending.
The reply comes to your email from supportitqan114@gmail.com; there are no replies inside the app. Each account can send five requests a day.
If you are not signed in, or if the “Help” page itself fails to open, the button opens your email app with a message to supportitqan114@gmail.com containing the page, the context, the version number and the time, and nothing is sent until you send it yourself.
When you delete your account, your requests are deleted from the app, but the messages that already reached the support inbox stay there.
Reminders and notifications
You create reminders yourself from “Profile”: their type, time and days, your time zone, and, if you set them, quiet hours during which we do not remind you. A reminder always reaches you as a notification inside the app, and by email too if you choose it; we send no notifications to your device outside the app. You can create up to 20 reminders.
In-app notifications tell you about things that concern you, such as invitations, assignments and consents, and they are deleted with your account.
Services that process your data
We give each service only what it needs to do its job:
- Google Cloud: the server the app runs on, where your data and recordings are stored.
- OpenAI: turning recitation audio into text.
- Resend: sending email from noreply@itqan114.com.
- Gmail, by Google: the support mailbox that receives your requests and from which replies are written.
- Quran.com: tafsir and translations. Our server requests them, so nothing about you reaches it.
- mp3quran.net: recitations and their ayah timings for listening.
- Google Fonts, jsDelivr and Google Storage: fonts, the Mushaf font, and the face-detection model.
- flagcdn.com: language flags on the language selection screen.
Whatever your browser requests from these sites directly lets them see your device’s IP address, as with any visit on the internet.
When you share a session report yourself (on WhatsApp, through your device’s share menu, or by copying it), its text goes only where you send it, and nothing leaves before you send it.
Where your data is stored
Itqan114 runs on a server we rent from Google Cloud, which also holds the database, and recordings are stored on its disk. The app image it is deployed from is stored in Google Artifact Registry and contains none of your data.
Your browser connects to the site over an encrypted connection (HTTPS).
Your IP address and server logs
When you try to sign in or request a reset code, we count the attempts for each email and each device address (IP), to stop password guessing and floods of messages; a device that has signed in before is counted on its own (see “What is stored in your browser”). In the same way we count, for each account and each address, the live streams it opens and the minutes of audio it sends to be turned into text (240 minutes per account a day, far more than a day of reciting), and the welcome and invitation emails it causes and each inbox receives, so that no script can run up the service or flood anyone’s inbox.
These counts live only in the server’s memory, as scrambled codes (hashes) rather than the email or the address itself: sign-in attempts stop counting after a quarter of an hour, and the rest after a day at most. They are never written to the database, and they are forgotten entirely if the server restarts. The reset code itself is valid for a quarter of an hour, and we store its hash, not the code.
Our app keeps no log of your requests or your IP address. Its logs hold errors and short technical lines, such as a session’s ID, duration, number of words and score, never your name; if an error mentions an email address, it is shown masked (like a***@g***.com). They are kept in a few files of limited size, and the oldest lines are erased as new ones are written.
There are no diagnostics on the live site: the tools that record and trace sessions to improve the engine are switched off there. The server opens none of their routes, and the app your browser downloads does not include them; they run only on the developer’s machine.
Data retention
Your saved recordings are kept for 90 days unless you choose otherwise; you or your guardian can choose 7, 30, 180 or 365 days from “Profile” or the “Family” page. When the period ends, the server deletes them on its own; it checks for this every six hours.
A supervised account can shorten the period its guardian chose, but not lengthen it. Keeping session audio cannot itself be switched off; if you don’t want a recording to stay, delete it from “My recordings” or shorten the period.
Your account data, progress, sessions and results are kept as long as your account exists, and they are all deleted, together with your recordings, when you delete it.
Your rights
From “Profile” you can: edit your name and country; make your profile public or private; change your password; turn the camera and recording for review on or off; change the retention period; view and delete your recordings and see who played them; manage your reminders; and delete your account permanently with your password.
When an account is deleted, its data, sessions and recordings are deleted from our server. If it belongs to a guardian, their children are unlinked and told about it. An institution owner removes its members first, or writes to support for help.
There is no button in the app for downloading a copy of your data. To request one, or to correct what you cannot edit yourself (such as your email or phone), write to us at supportitqan114@gmail.com.
What is stored in your browser
We use no cookies and no tracking tools of any kind. The app stores only the following, in your browser:
- Your sign-in token: it lasts 30 days if you choose “Remember me on this device”; otherwise it is erased when you close the window. It is also erased when you sign out.
- A device mark: after you sign in successfully, a signed code that proves this device has signed in before, so that wrong attempts by others on the same network do not hold up your sign-in. It holds a random device number and a scrambled form (hash) of your email, never the address itself, and it lasts 180 days.
- Your language, theme, reading preferences, what you last listened to, and the ayah timings of recitations you have listened to.
- For this visit only: your camera answer, your place in reading, the fact that you have seen the welcome screen, and small technical marks (a surah you have finished reading, or a reload after an update).
Of all this, only the sign-in token reaches us, with each request, and the device mark, when you sign in; clearing the site’s data in your browser erases all of it.
The installed app
You can install Itqan114 on your device with the “Install the app” button. It is the same site and asks for the same permissions: the microphone for reciting, and the camera if you turn it on.
A small worker in your browser (a Service Worker) stores only the app’s static files, so that it opens faster and can show a page telling you that you are offline if the network drops. It never stores server responses, your data, audio or recitations; the microphone never passes through it; and pages always come from the network.
Its old files are erased with each new version, and clearing the site’s data in your browser erases all of them.
Changes to this policy
If we change it, we raise its version number and update its date at the top of this page, and ask for your agreement on your next visit before you continue.
Contact us
For any question or request about your privacy: supportitqan114@gmail.com. The reply will come from the same address.