Dayroz Privacy Policy
Effective 26 August 2026 · applies to the Dayroz mobile app and Dayroz Web
The short version
Dayroz works as a guest — no account, no personal data required, for prayer times, rates, weather, calculators and the other reference tools. An account is needed only for the personal tools that have to survive a lost phone, and then we store your email plus what you save in those tools so it syncs across your devices. We don't sell your data, and we don't collect anything the feature you're using doesn't need.
What we collect
- Nothing, as a guest. Reference tools work without an account. Your preferences — language, city, currency, theme, notification and prayer settings — stay on your device.
- Your account: your email address and password (handled by our authentication provider, Supabase — we never see your password), and, if you add them, a display name, profile photo and home city.
- What you save in the personal tools: to-dos, notes, grocery lists, expenses and budgets, udhaar and installments, committee, habits, water, reminders, occasions, documents, learning, recipes, meal plans and the rest. It is stored so it syncs between your devices and is not lost with your phone.
- Health and medical entries, if you use those tools: cycle and pregnancy logs, symptoms and notes, fasting and prayer logs, medications and doses, and Treatment Journey records — appointments, diagnoses, prescriptions, test results and the costs you attach to them. This is sensitive, we treat it that way: it is stored under your account only, never used for advertising, never shared with anyone unless you share it yourself, and it goes when your account goes.
- Files you attach: ID and document scans, medical reports and photos you add to a Treatment Journey, and your profile photo are uploaded to private storage buckets scoped to your account — nobody else's account can read them. (Your profile photo is served from a public URL so it can render in the app; the other buckets are private.) Photos you take for the passport-photo tool, the document scanner and the QR scanner are processed on your device and are uploaded only if you choose to attach them.
- Sharing a Treatment Journey: if you invite someone to view your records, we store the email address you invite and the read-only invite itself, and that person can then read what you shared until you revoke it.
- Push notifications: if you enable them, a device push token (Firebase Cloud Messaging) is stored so we can deliver alerts you asked for — fuel-price changes, or a new electricity bill for a connection you saved.
- Bill lookups: reference numbers you check are sent through our server to the official PITC portal to fetch that bill, and are not used for anything else.
- Links you paste into the media saver: the link is sent to our server, which resolves the direct media URL and hands it back to your device to download. We keep the file only in transit. The WhatsApp status saver is different — it reads the status folder on your own phone through a folder access grant you give, and nothing there leaves your device.
- Help chat: what you type into the in-app help assistant is sent to our help-bot server and on to the AI model that answers, so it can reply. No account identifier goes with it. Don't paste passwords or personal records into it.
- Location, only when you ask: choosing your city is manual by default. If you tap "Use my location" in the city picker, the app reads your approximate location once (coarse, never precise GPS) and sends those coordinates to OpenStreetMap to look up the city name. We store the city; we do not store the coordinates and we keep no location history. You can refuse and search for your city by name instead.
- Diagnostics: our server keeps ordinary web logs (IP address, request time, error traces) for security and debugging, kept short-term.
What we do NOT do
- We do not sell or rent your personal data to anyone.
- We do not read your personal tool content — health entries included — for advertising or to train models.
- We do not track your location in the background, and we never ask for precise GPS.
- We do not read your contacts, call logs, SMS, or scan your file system.
Permissions the app asks for
- Camera — QR scanning, document scanning, passport photos. Only while you're on those screens.
- Approximate location — the one-tap city lookup described above, foreground only.
- Notifications and alarms — reminders, prayer times, medication doses and alarms you set. Exact alarms are asked for, not taken silently; without them reminders still fire, less precisely.
- Biometrics — to unlock the Documents vault if you turn that on. The check happens on your device.
- Folder access (Android) — only if you use the WhatsApp status saver, and only for that folder.
Ads
The mobile app shows ads through Google AdMob — full-screen ads between actions, and rewarded videos you choose to watch (for example, to restore a streak). There are no banner ads. AdMob may use an advertising identifier; in Europe and the UK you are asked for consent first and can change that answer any time in Settings → Ad privacy, and on iOS the system tracking prompt applies. AdMob's own policies govern what happens during an ad.
Services we rely on
- Supabase — account authentication, database, and the private storage buckets your attachments live in.
- Railway — hosts our backend API.
- Google Firebase Cloud Messaging — push notification delivery.
- Google AdMob — advertising, as described above.
- OpenStreetMap — city search and reverse geocoding (Nominatim), map tiles, and mosque search (Overpass). Only the search text or the coordinates are sent; no account or device identifier goes with them.
- Cloudflare — the servers the internet speed test measures against.
- AlQuran.cloud and islamic.network — Quran text and recitation audio.
- Our help-bot server (Vercel) — answers help-chat questions.
- Sites opened inside the app — the arcade games, vehicle verification and e-challan portals are third-party websites shown in a web view. What you do there is covered by their own policies, not this one.
Data retention & deleting your account
Your data is kept while your account exists. You can delete your account at any time, which permanently removes your account, all synced tool data, and your uploaded files:
- In the app: Settings → Account → Delete account.
- By email: write to support@dayroz.com from your account email and we'll delete it within 7 days.
Export what you want to keep first — deletion cannot be undone.
Children
Dayroz is a general-audience utility app and is not directed at children under 13. We do not knowingly collect data from children.
Changes
If this policy changes materially, we'll update this page and note the new effective date above.
Contact
Dayroz Technologies, Islamabad, Pakistan · info@dayroz.com · see also the Dayroz Terms of Service.