Privacy
What leaves your phone, where it goes, and what happens to it there.
Mawiza has no account and no Mawiza server. Nearly everything the app does happens on your device. This page names the exceptions precisely, including the parts that are outside our control once they leave.
Mawiza is operated from Toronto and available internationally, so this page is written to meet Canada's PIPEDA and, for readers in the EU and UK, the GDPR and UK GDPR. Your rights and how to complain are set out in full below rather than buried at the bottom.
The short version
- No backend. There is no Mawiza server anywhere. Nothing syncs.
- No account. You are never asked to register or sign in.
- No analytics or crash-reporting SDKs. None are linked into the app.
- No advertising and no tracking. No ad networks, no identifiers for advertisers, no third-party trackers.
- No push server. Every reminder is scheduled locally by your device.
- One optional network feature: weather, which is off until you turn it on.
- Nothing sold, ever. There is no mechanism by which it could be: nothing reaches us to sell.
- You already hold your data, so access, correction and erasure are things you do yourself, in the app, without asking us.
What can leave your device
Prayer times, Qibla bearings and Hijri dates are calculated on your device. Two service paths can transmit your coordinates. Neither involves a Mawiza server, and both are described below exactly as the app behaves.
| Path | What is sent | When |
|---|---|---|
| Weather api.open-meteo.com |
Your full latitude and longitude, and the weather fields requested. Mawiza attaches no account ID, API key or tracking identifier. As with any web request, the service also receives ordinary connection information such as your IP address. | Only while Weather moments is on and a device location is available, when a screen using weather is open. |
| Background weather api.open-meteo.com |
The home coordinates you explicitly saved. Not a fresh background GPS reading: the app has no background location permission. | Only when Weather moments and Ambient weather are both on, a home location is saved, and the operating system grants a background opportunity. The task checks your quiet hours before fetching. |
| City name your OS geocoder |
Coordinates handed to your phone’s own geocoding service to turn into a city label. That service may transmit them to its provider under that provider’s policy, not ours. | After a location fix you have permitted. |
Weather is off on a fresh install. Turning it off in Settings stops future weather requests. It cannot retract a request already sent.
What Open-Meteo says it keeps
We are not going to tell you a request disappears when we cannot see what happens to it. Open-Meteo’s published privacy policy states that its free API may retain IP addresses and troubleshooting logs that can contain coordinates, and that those logs are deleted after 90 days.
Treat a weather request as potentially retained by that provider for up to 90 days, not as an ephemeral lookup. This is their published policy quoted as such, not an independent audit we have performed. If that is not a trade you want to make, leave weather off; nothing else in the app depends on it.
What stays on your device
Your favourites, reading progress, saved home coordinates, settings and optional usage counters are stored in your phone’s app storage. Application code does not send them anywhere. They are included in your device or iCloud backup only if your own system backup settings include app data.
Usage counters exist to keep reminders within their cap, are never shown as a report, and can be switched off under Settings → Privacy. Turning them off suppresses future counting.
How it is kept safe, and for how long
The strongest safeguard here is structural rather than technical: there is no Mawiza server, so there is no Mawiza database to breach, no backup of yours to leak and no employee who could look you up. We cannot lose what we never hold.
- On your phone, app data sits in the storage sandbox iOS and Android give each app, protected by your device passcode and the OS. No other app can read it.
- The one request that leaves goes over HTTPS. The site you are reading is served over HTTPS only, sets no cookies and runs no scripts.
- Retention on your device is until you remove it. Nothing expires on a timer. Deleting the app removes all of it; clearing the app's data does the same without uninstalling.
- Retention off your device is not ours to set. Open-Meteo's own policy is quoted above: up to 90 days for logs that can contain coordinates.
Permissions
| Permission | Why | If you decline |
|---|---|---|
| Location while using the app |
Local prayer times, Qibla direction, the city label, and optional weather. Requested from an action that explains itself first, never on launch. The app ships with no always-on or background location permission. | Prayer times fall back to a chosen city; on-device Qibla guidance waits for a fix. Reading works fully without it. |
| Notifications | The specific reminders you switch on, and nothing else. | Everything except reminders continues to work. |
The App Store privacy label declares Precise Location for app functionality, not linked to you and not used for tracking.
On iOS the app declares a motion-usage string. This is a compatibility declaration: the location library Mawiza depends on contains motion-activity APIs, and Apple requires the string to be present. Mawiza does not access or use motion activity data. Qibla uses the compass heading, which does not require motion access.
Reminders
Reminders are scheduled on your device by the operating system. Nothing about them is sent anywhere, and there is no push server that could know what you enabled or whether you opened it.
When reminders are on and a location is available, the app prepares a short horizon of upcoming local dates and tops it up when you reopen the app. There is no guaranteed wake-up while the app is closed. Reopen after travelling or a timezone change so the schedule can be recalculated. Delivery also depends on your own notification, Focus and battery settings.
Why we are allowed to do this
Under the GDPR and UK GDPR a controller has to name its lawful basis rather than assume one. For nearly all of Mawiza the honest answer is that no basis is needed, because no processing by us takes place: the data never leaves your phone and we never receive it.
| What | Lawful basis |
|---|---|
| Favourites, progress, settings, counters | No basis required. Stored by the app on your device; we neither receive nor access it. |
| Prayer times, Qibla, Hijri dates | No basis required. Calculated on your device from a location we never see. |
| Weather | Your consent (Art. 6(1)(a)). Off until you switch it on; withdrawing it is turning Weather moments off, which is as easy as turning it on and costs you nothing else in the app. |
| City label | Your consent, given as the location permission. The geocoding is performed by your operating system, whose provider is the controller for anything it transmits. |
A weather request goes to Open-Meteo, whose servers are outside Canada, so enabling weather transfers your coordinates internationally. Their privacy policy governs what happens next. If you would rather no coordinates crossed a border, leaving weather off is a complete answer.
Mawiza does not and will not sell or share your personal information, as those terms are used in California law and elsewhere. There is no mechanism by which it could: nothing reaches us to sell.
One thing worth knowing that no law made us tell you
This is an app for Muslims. That means a request it sends is, in principle, capable of suggesting something about the person who sent it — not because the request contains anything religious, but because of which app made it. A weather lookup carries coordinates and ordinary connection information, and a service receiving it could in theory infer an interest in a Muslim app from the traffic pattern.
We think the real risk here is low: the request goes to a weather service with no reason to care, it carries no name, account or identifier, it is off until you turn it on, and nothing about the request names a dua, a prayer or this app’s purpose. But religious belief is exactly the kind of thing people are entitled to be careful about, and telling you only the parts that are legally mandatory would not be in the spirit of this page.
If this matters to you, leaving weather off removes it entirely. Prayer times, Qibla, the whole corpus and every reminder work with no network access at all.
Your rights
Canadian privacy law (PIPEDA) gives you a right of access to and correction of personal information an organisation holds about you. The GDPR and UK GDPR add rights to erasure, restriction, portability and objection. Those rights apply to Mawiza, and the answer to most of them is unusual: you already hold everything, so you can exercise them yourself, immediately, without asking us.
| Right | How to exercise it |
|---|---|
| Access | Open the app. Your favourites, progress and settings are shown in the interface that created them. There is no additional copy held by us to request. |
| Correction | Change or remove any of it in the app at any time. |
| Erasure | Clear the app's data, or delete the app. Both remove everything from your device. We hold no copy that could survive it. |
| Withdraw consent | Turn off Weather moments, or revoke location in your system settings. Neither disables the rest of the app. |
| Portability | Your data is already in your possession and included in your own device backup if your backup settings cover app data. |
| Objection and restriction | Write to us. In practice these bite on processing a company performs, and we perform none — but if you think we have that wrong, say so and we will answer rather than point at this sentence. |
One limit worth stating plainly: a request already sent to Open-Meteo is theirs, not ours. We cannot delete it on your behalf. Their policy is linked above, and their retention is what governs it.
Sharing, children, and changes
Sharing a dua
Sharing uses your system share sheet. You choose the destination, and that app or service then applies its own rules. Mawiza is not involved once the sheet hands it over.
Children
Mawiza collects no personal information from anyone, of any age. It has no account, no profile and no content you can post.
Changes to this page
Any change to permissions, services or transmitted data updates this page and the disclosure inside the app together. Adding a backend would be a product decision, not a quiet update, and this page would say so before it shipped.
Asking, and complaining
Questions about what the app sends, a request under any right above, or a claim on this page you think is wrong, all go to the same place: support@mawiza.ca. A correction to this page is as welcome as a bug report. Expect a reply from a person within 30 days, which is the limit Canadian law sets for an access request and a reasonable promise for everything else.
If that answer does not satisfy you, you can escalate, and you should know how. Nothing here asks you to take our word as final.
- In Canada: the Office of the Privacy Commissioner of Canada takes complaints about organisations under PIPEDA.
- In the EU or UK: you have the right to lodge a complaint with your national data protection authority — in the UK, the Information Commissioner's Office — and you can do so without going through us first.
- Elsewhere: your local regulator, if your country has one. Writing to us is never a precondition.
Last updated 19 September 2026. Describes Mawiza 2.0.1 and its App Store privacy
declarations.
Controller: Sabbir Hossain, Toronto, Ontario, Canada, reachable at
support@mawiza.ca. Mawiza is operated by
one individual, not a company, and has no employees, contractors or processors
with access to user data, because no user data reaches it.