Privacy Policy

Effective date: May 1, 2026

1. Introduction

Ayaat ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you use the Ayaat platform, including our website at ayaatapp.com and our iOS application.

2. Information We Collect

We collect the following categories of information:

  • Account information — your email address, username, and display name when you register. If you sign in with Apple or Google, we receive your email address (and, where you choose to share it, your name) from that provider.
  • Profile information — optional details such as a bio, profile photo, and city.
  • Uploaded content — audio files and metadata (surah, reciter name, recording date) you choose to upload.
  • Usage data — pages visited, tracks played, searches performed, and interactions with the platform.
  • Verification documents — if you apply for reciter verification, documents you submit for identity verification. These are stored securely and accessed only by administrators.
  • Connected YouTube account — if you connect your YouTube channel as a reciter, we receive your channel ID, handle, title, and avatar, and a list of your own uploaded videos. See Section 12 for full details.
  • Push notification tokens — if you use our iOS app and grant notification permission, we store an Apple Push Notification service (APNs) device token so we can send you transactional alerts (e.g. verification status updates).

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service.
  • Personalise your experience (e.g. recommendations, listening history).
  • Process reciter verification applications.
  • Send transactional communications (account confirmations, password resets).
  • Detect and prevent abuse, fraud, and violations of our Terms of Service.
  • Comply with legal obligations.

4. Data Sharing

We do not sell your personal data. We may share data with:

  • Service providers — such as Supabase (database, authentication, file storage for verification documents), Cloudflare R2 (audio file storage and delivery), and Apple Push Notification service (iOS push delivery). These providers process data on our behalf under data processing agreements.
  • Identity providers — when you sign in with Apple or Google, those providers receive a sign-in request from us and return your verified email address to us. We do not share other data with them.
  • Law enforcement — where required by applicable law or legal process.

Public profile information (username, bio, uploaded recitations) is visible to all users of the Service.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g. resolving disputes).

6. Cookies & Local Storage

We use session cookies necessary for authentication. We also store certain preferences (such as playback settings and sidebar state) in your browser's local storage. We do not use advertising or tracking cookies.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Object to or restrict certain processing.
  • Export your data in a portable format.

To exercise any of these rights, contact us at support@ayaatapp.com.

8. Security

We implement industry-standard security measures including encrypted connections (TLS), row-level security on our database, and restricted access to sensitive data. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

9. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. YouTube & Google API Data

Ayaat uses YouTube API Services. By connecting your YouTube account, you also agree to the YouTube Terms of Service and the Google Privacy Policy.

We request the youtube.readonly scope only when you, as a reciter, choose to connect your YouTube channel. With this scope we:

  • read your channel ID, handle, title, and avatar to display your connected channel on your dashboard and verify ownership;
  • list your own uploaded videos so you can pick which ones to import as audio tracks on Ayaat;
  • read public metadata (title, duration, thumbnail) for each video you choose to import.

We store only your channel ID, handle, title, avatar URL, and an encrypted OAuth refresh token. We do not download your videos, access analytics or viewer data, post or modify content on your channel, share your YouTube data with third parties, or use it for advertising.

You can disconnect your YouTube account at any time from your Ayaat dashboard, which deletes the stored channel data and refresh token. You can also revoke Ayaat's access directly via Google Security Settings.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us at support@ayaatapp.com.

Terms of Service·Back to Ayaat