Privacy Policy — Mutaba
Last Updated: July 13, 2026
1. Introduction
Welcome to Mutaba ("we," "our," or "us"). Mutaba is a mobile and web application designed to help Muslims track their daily ibadah (worship), read and listen to the Quran, follow prayer times, find Qibla direction, count tasbih, read doa and dzikir, track Ramadan progress, and enhance their spiritual journey.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Mutaba application on Android (Google Play Store), iOS (App Store), or the web version. Please read this policy carefully. By using Mutaba, you agree to the practices described in this policy.
This policy is written for end users of the Mutaba app. It does not cover separate internal operational tools used to manage public content, release notes, notifications, or app operations.
2. Information We Collect
2.1 Information You Provide
- Preferences & Settings: Language preferences, prayer time calculation method, adzan notification settings (per-prayer toggles, muazin voice selection, sound mode), notification preferences, display preferences (dark/light/system mode), Quran reading settings (script type, font size, reading mode, transliteration/translation toggles, word-by-word mode), and tasbih counter settings (vibration, sound, default target).
- Ibadah (Worship) Data: Daily prayer tracking records (5 obligatory prayers + sunnah practices like Rawatib, Dhuha, Tahajjud, and Witir), custom ibadah items you create, prayer completion reasons, and fasting logs.
- Quran Reading Data: Last-read position (surah, ayat, and Mushaf page number), bookmarks (surah + ayat references), khatam (completion) targets and progress, surah read marks, reading sessions (duration and surah), reading targets (minutes per day), and Quran search queries you submit.
- Tasbih Data: Dzikir counter session history including preset name, count, and target for each session.
- Personal Notes: Any notes you create within the app, including title and content.
- Ramadan Data: Daily Ramadan checklist data (sahur, puasa, tilawah, sedekah, tarawih, witir, qiyamul lail, doa, dhuha, dzikir) and custom Ramadan items.
- Notification History: Notifications received by the app may be saved locally so you can review them in the notification screen.
- Doa Sharing Outputs: When you copy, share, download, or save a doa story image, the selected doa text and generated image are handled on your device and by the share destination you choose.
2.2 Information Collected Automatically
- Location Data: With your explicit permission, we access your device's GPS coordinates to provide accurate prayer times, Hijri calendar dates, and Qibla direction. Location data is cached locally on your device (refreshed every 6 hours) and sent to third-party APIs (AlAdhan for prayer times, BigDataCloud for city name resolution) but is not stored on our servers. If location permission is denied, the app defaults to Jakarta coordinates.
- Device Information: Device type, device model name, device name when available, operating system, and app version may be used to operate the app, troubleshoot issues, deliver updates, and register push notifications.
- Push Notification Token: When you grant notification permission, your Expo Push Token (or Web Push subscription on browser) and device model/name are sent to and stored on our backend server to deliver push notifications and in-app announcements.
- Request Metadata: When the app requests content from our API, our server processes ordinary HTTP metadata such as method, path, status code, response timing, and cache status for operational monitoring. We do not include worship records, notes, bookmarks, or tracker history in those content requests.
- Usage Analytics: Anonymous usage patterns (screen navigation events with screen name and route segments) to improve the app. We use Aptabase (self-hosted at aptbase.awans.id), a privacy-first analytics platform. No personal data, location, or worship records are included in analytics events.
- Compass & Motion Sensors: The Qibla compass feature accesses your device's magnetometer (compass) and heading sensors. This data is processed entirely on-device in real-time and is never transmitted or stored.
2.3 Information We Do NOT Collect
- We do not collect your name, email address, or phone number.
- We do not require account registration or login.
- We do not collect payment information.
- We do not store zakat calculator inputs on our servers.
- We do not track your browsing history outside the app.
- We do not sell your data to third parties.
- We do not use advertising SDKs or ad trackers.
- We do not record audio from your microphone.
- We do not read your clipboard or photo library in the background.
3. How We Use Your Information
We use the collected information to:
- Provide accurate prayer times based on your location and selected calculation method.
- Display Qibla direction using your GPS coordinates and compass heading.
- Calculate and display Hijri calendar dates.
- Store your ibadah tracking data, Quran bookmarks, reading progress, tasbih history, notes, Ramadan data, notification history, and preferences locally on your device.
- Schedule local adzan reminders on your device and deliver optional remote push notifications or in-app announcements.
- Fetch and display Quran text, tafsir, word-by-word data, doa/dzikir content, changelog entries, release information, and Islamic articles.
- Stream Quran recitations, murottal, Haramain recordings, and adzan preview audio.
- Let you copy Quran or doa text, use the system share sheet, download doa story images on web, or save doa story images to your photo library on mobile when you choose that action.
- Deliver haptic feedback for tasbih counting, Qibla alignment, and UI interactions.
- Personalize your app experience (theme, language, Quran font, reading preferences, prayer method, adzan settings).
- Deliver over-the-air (OTA) app updates via Expo Updates to fix bugs and add features without requiring a store update.
- Improve app reliability through anonymous screen-view analytics.
4. Data Storage & Security
4.1 Local Storage (On-Device)
All personal data — including ibadah records, Quran reading progress, bookmarks, reading sessions, khatam progress, tasbih history, notes, Ramadan checklist, notification history, location cache, adzan settings, and preferences — is stored locally on your device using two storage mechanisms:
- SQLite Database (
mutaba.db) — the primary storage for all user data on native platforms (Android/iOS). Uses WAL (Write-Ahead Logging) mode for performance. - AsyncStorage — secondary/backup storage and primary storage for the web version. Also used for API response caching.
We do not maintain central servers that store your personal worship data. Your data lives entirely on your device.
4.2 Server-Side Storage
For end-user app use, our backend server stores the following information:
- Push notification tokens — your Expo Push Token or Web Push subscription and device model/name, used solely to deliver notifications to your device.
- Public app content and metadata — Quran text, tafsir, doa/dzikir content, murottal metadata, Haramain recordings metadata, in-app notifications, changelog entries, and APK release metadata. This is content served to app users, not your personal worship data.
- Operational request logs — method, path, status, response timing, response size, and cache status used to monitor reliability and performance.
Your personal worship records, notes, bookmarks, reading progress, tasbih history, Ramadan checklist, and zakat calculator inputs are not uploaded to our backend server.
4.3 API Calls & Data Flow
The app makes requests to the following APIs:
Our Backend API (api.mutaba.net)
- Push notification token registration (your token + device model)
- In-app notification delivery (announcements, updates, promotions)
- Changelog and release information
- Quran text, tafsir, word-by-word data, search, juz, and Mushaf page data
- Doa/dzikir categories and items
- Murottal reciter and surah listings
- Haramain recording categories and audio listings
The app authenticates these content requests in the background. You do not need an account, and no personal worship data is sent to our server with these content requests.
Third-Party APIs (Direct)
- AlAdhan API (aladhan.com) — prayer times, Hijri calendar conversion, and Qibla direction. Only your latitude/longitude coordinates are sent.
- BigDataCloud API (bigdatacloud.com) — reverse geocoding (converting GPS coordinates to city/province names). Only coordinates are sent.
- Rumaysho.com (WordPress REST API) — Islamic article content. No personal information is sent.
- Islamic Network CDN (cdn.islamic.network) — Quran recitation audio playback. No personal worship data is sent.
- IslamCan.com — adzan audio previews. No personal information is sent.
- Archive.org — murottal (Quran recitation) audio streaming. No personal information is sent.
- Haramain.info — Haramain recording audio sources and metadata. No personal worship data is sent.
- Aptabase (aptbase.awans.id) — anonymous screen navigation analytics only.
4.4 Caching
To improve performance and enable offline access, the app caches various content locally:
- Prayer times and Hijri dates — cached for 24 hours
- City name (reverse geocoding) — cached for 24 hours
- Location coordinates — cached for 6 hours
- Quran text (surah, mushaf pages, tafsir) — cached in SQLite indefinitely until manually cleared
- Doa/dzikir content — cached for 24 hours
- Islamic articles — cached for 6 hours
- In-app notifications, changelog, and release metadata — cached briefly for performance
You can clear Quran text cache from the app settings. All other caches expire automatically.
4.5 Security Measures
- Data encryption in transit (HTTPS/TLS for all API calls).
- Backend content APIs use app-level API key authentication to reduce unauthorized automated access.
- Local storage uses platform-provided app storage (SQLite on native, AsyncStorage on web).
- No transmission of personal worship data to external servers.
- Self-hosted analytics platform (Aptabase) — data not shared with third-party analytics companies.
5. Device Permissions
Mutaba may request the following device permissions:
- Location (GPS): For prayer times, Qibla direction, and city name display. Required for core features, but the app falls back to Jakarta if denied.
- Notifications: For adzan (prayer time) reminders, remote push notifications, in-app announcements, and app updates. Optional — the app works without notification permission, but reminders and push messages will be limited.
- Compass / Magnetometer: For the Qibla compass feature. Used only on the Qibla screen, processed on-device only.
- Haptics / Vibration: For tasbih counting feedback, Qibla alignment confirmation, and UI interactions. Can be disabled in tasbih settings.
- Audio Playback: For murottal (Quran recitation), Haramain recordings, adzan previews, and adzan notification sounds. No microphone access is requested.
- Photo / Media Library: Only when you choose to save generated doa story images to your photo library on mobile. We do not read your existing photos.
- Clipboard: Only when you explicitly tap the copy button to copy Quran ayah text, doa text, or app/debug values shown in Settings. We never read your clipboard automatically.
- Internet: For fetching content, prayer times, and delivering notifications. Many features work offline after initial data load.
6. Third-Party Services
Mutaba uses the following third-party services:
- Google Play Store / Apple App Store — for app distribution (their respective privacy policies apply).
- Expo / EAS Updates / Expo Push Notifications — app runtime, update delivery, and mobile push notification delivery (see Expo's privacy policy).
- Aptabase — self-hosted, privacy-first analytics. Only anonymous screen navigation events are tracked. No personal data is shared.
- AlAdhan.com — Islamic prayer times and Qibla direction API (see their privacy policy).
- BigDataCloud — reverse geocoding API (see their privacy policy).
- Quran.com — Quran verse data API (see their privacy policy).
- equran.id / Quran Foundation data — Quran text, translation, tafsir, script, and structural Quran metadata used by our backend content APIs.
- Rumaysho.com — Islamic articles via WordPress REST API.
- Islamic Network CDN — Quran recitation audio used inside the Quran reader.
- Archive.org — Quran recitation (murottal) audio hosting.
- Haramain.info — Haramain recording source content.
- IslamCan.com — adzan audio previews.
7. Data Handling by Feature
The following table details what data each feature uses, where it is stored, and what is transmitted:
| Feature | Data Collected | Storage | Transmitted To |
|---|---|---|---|
| Prayer Times | GPS coordinates | Local (cached 24h) | AlAdhan API (coords only) |
| Qibla Compass | GPS coordinates, compass heading | Local location cache; compass heading real-time only | AlAdhan API (coords for Qibla angle); BigDataCloud if city lookup is needed |
| Quran Reader | Bookmarks, last read position, reading sessions, khatam progress, search queries | Local SQLite + AsyncStorage | Mutaba backend for content/search; Islamic Network CDN for recitation audio |
| Mushaf View | Page cache, reading position | Local SQLite | Mutaba backend (page data fetch) |
| Ibadah Tracker | Daily prayer records, sunnah records, custom items | Local SQLite + AsyncStorage | None |
| Tasbih Counter | Session history (preset, count, target) | Local SQLite + AsyncStorage | None |
| Notes | Note titles and content | Local SQLite + AsyncStorage | None |
| Ramadan Tracker | Daily checklist (10 built-in + custom items) | Local SQLite + AsyncStorage | None |
| Doa & Dzikir | Selected content, copy/share actions | Local cache (24h) | Mutaba backend (content API); system share destinations when you choose to share |
| Doa Story Images | Selected doa text and generated image | Temporary file, photo library, or web download when requested | None by Mutaba; share destinations you choose may receive the image |
| Murottal | Selected reciter/surah playback request | Not stored as personal data | Mutaba backend + Archive.org audio |
| Haramain Audio | Selected recording playback request | Not stored as personal data | Mutaba backend + Haramain.info audio sources |
| Adzan Notifications | Per-prayer toggle, muazin selection, sound mode | Local SQLite + AsyncStorage | None for local scheduling; IslamCan only when previewing adzan audio |
| Push Notifications | Expo Push Token or Web Push subscription, device model/name | Our server | Mutaba backend; Expo or browser push service for delivery |
| Islamic Articles | Article browsing/search within article content | Local cache (6h) | Rumaysho.com for online articles; bundled local articles require no network |
| In-App Notifications & Changelog | None (content only) | Short local/API cache | Mutaba backend |
| Hijri Calendar | GPS coordinates | Local cache (24h) | AlAdhan API (coords only) |
| Zakat Calculator | Financial values entered | Not stored (in-memory only) | None |
| Analytics | Screen name, route segments | Not stored locally | Aptabase (self-hosted, anonymous) |
8. Children's Privacy
Mutaba is suitable for users of all ages. We do not knowingly collect personal information from children under 13 (or applicable age in your jurisdiction). The app does not require registration and stores personal worship data on the device. Push notification tokens may be treated as personal data in some jurisdictions, and they are used only to deliver notifications.
9. Your Rights
You have the following rights regarding your data:
- Access: All your worship data is stored on your device and is accessible to you at all times.
- Deletion: You can delete all app data by clearing the
app's storage through your device settings or uninstalling the app.
You can also clear specific data in supported feature screens:
- Clear Quran cache from Settings → Reading Settings
- Clear tasbih history from the Tasbih screen
- Delete individual notes from the Notes screen
- Portability: Your data is stored locally and can be managed through your device's settings.
- Opt-out of Location: You can revoke location permissions at any time through your device settings. The app will default to Jakarta coordinates for prayer times.
- Opt-out of Notifications: You can disable push notifications through your device settings, or disable adzan notifications individually per prayer within the app's Adzan Settings.
- Analytics Choice: Aptabase respects Do Not Track (DNT) browser settings. On mobile, analytics are limited to anonymous screen-view events.
10. Data Retention
- Local data: Retained on your device until you delete it in the app where supported, clear app storage through your device settings, or uninstall the app. Reading sessions are pruned after 90 days, and tasbih history is limited to the latest 100 sessions.
- Push tokens: Stored on our server until the token becomes invalid, cleanup occurs after failed delivery, or you ask us to remove it.
- Analytics: Anonymous screen view events are retained on our self-hosted Aptabase instance according to Aptabase's default retention policy.
- API caches: Local app caches automatically expire for most online content (typically 5 minutes to 24 hours depending on the data type), while Quran content caches may remain until manually cleared for offline reading.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Last Updated" date at the top of this page. Significant changes may be communicated via in-app notifications. We encourage you to review this Privacy Policy periodically. Continued use of the app after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or Mutaba's data practices, please contact us at:
- Email: privacy@mutaba.net
- Website: https://mutaba.net
- Telegram: t.me/mutabanet
13. Governing Law
This Privacy Policy is governed by the laws of the Republic of Indonesia. Any disputes arising from this policy shall be resolved in the courts of Indonesia.