Privacy Policy
Last updated: October 3, 2026
Courtesy translation. This privacy notice is prepared under Turkish law — the Personal Data Protection Law No. 6698 (KVKK) — and this English version is provided for your convenience. In the event of any conflict or legal dispute, the Turkish text is the authoritative version.
If you have questions about this policy, write to rafiqa@masync.co.
Important Note: This text is a privacy notice prepared under Law No. 6698 on the Protection of Personal Data (KVKK). By using the Rafiqa app, you accept this policy. For questions, you can write to rafiqa@masync.co.
1. Data Controller
Your personal data is processed by Rafiqa as the data controller within the scope of Law No. 6698 on the Protection of Personal Data (“KVKK”).
2. Personal Data Collected
The following categories of personal data are processed within the Rafiqa app:
Identity and Contact Data
- •Full name (optional)
- •Email address (via Google account or direct registration)
- •Profile photo (imported from Google account)
Location Data
Special Category- •The parent user’s GPS coordinates (latitude/longitude)
- •Last location update time and the location history of the last 7 days
- •Safe zone (geofence) settings
Health and Measurement Data
Special Category- •Pulse, weight and measurements you name yourself (if entered by the user). Entries created in earlier app versions are kept exactly as the user recorded them.
- •If Health Connect permission is granted: step count, pulse and sleep duration — written to the server as a single daily summary record per day (raw measurement history is not collected)
- •Fall detection events
Data Kept on the Device (Not Sent to the Server)
- •Contact names and phone numbers from the address book — shown and cached only on the device
- •Contact entries added/edited with app permission — written to the phone’s own contacts
- •A local “frequently called” list made up of numbers you have called through Rafiqa
- •Camera image (Magnifier and Flashlight) — not recorded, not transmitted
- •The name and icon of the app shortcuts you add to the home screen
App Usage Data
- •Alarm settings
- •Dhikr and Quran-reading progress data
- •Prayer time notification preferences
- •Language and font size preferences
- •Module visibility and ordering preferences
- •Daily routine reminder name, optional note and schedule (free text entered by the user)
- •Reminder completion status (marked/not marked)
Payment and Subscription Data
- •Subscription plan and status
- •Google Play purchase reference (purchaseToken) — card and billing details remain with Google and are not transmitted to Rafiqa’s servers
- •Trial period and subscription end date
Technical Data
- •Firebase Authentication user ID (UID)
- •Expo push notification token
- •Device type and operating system version (anonymous)
- •Device identifier: a device-specific identifier derived from the Android system ID by a one-way hash; the raw ID never leaves the device. It is stored in a record linked to your account together with last-seen time, platform (Android), app version and role. It is not an advertising ID and is not used for advertising or marketing; it contains no device model, IP address, location or other personal data.
3. Purposes of Processing and Legal Bases
| Purpose | Legal Basis |
|---|---|
| Providing the app and ensuring service quality | Performance of a contract (KVKK Art. 5/2-c) |
| Location tracking and safe zone notifications | Explicit consent (KVKK Art. 5/1) |
| Daily routine reminders and measurement journal management | Explicit consent (KVKK Art. 5/1, Art. 6/2) |
| Fall detection and emergency notifications | Legitimate interest / Vital interest (KVKK Art. 5/2-f, e) |
| Sending push notifications | Performance of a contract / Explicit consent |
| Account and setup information emails (welcome, how to connect your parent, a reminder if setup is unfinished). They contain no advertising; reply "stop" to any of them to opt out. | Performance of a contract (KVKK Art. 5/2-c) / Legitimate interest |
| Subscription and payment management | Performance of a contract (KVKK Art. 5/2-c) |
| Technical support and customer service | Legitimate interest (KVKK Art. 5/2-f) |
| Measuring how many devices an account is used on, and preventing account sharing and abuse; uninstalling and reinstalling the app does not make the same device count as a new one (this measurement currently places no restriction on you) | Legitimate interest (KVKK Art. 5/2-f) |
| Fulfilling legal obligations | Legal obligation (KVKK Art. 5/2-ç) |
4. Transfer of Personal Data
Your personal data may be shared with the following third parties:
Google Firebase (Auth + Firestore)
Authentication and database service
Location: USA / Europe
Google Play Billing
Subscription purchase and renewal (card details are not transmitted to Rafiqa)
Location: USA / Europe
Expo (Push Notifications)
Push notification infrastructure
Location: USA
Cross-border transfers are carried out within the scope of Article 9 of the KVKK, either to countries with an adequate level of protection as determined by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), or on the basis of your explicit consent.
Health Connect data
The app reads step count, pulse and sleep duration through Health Connect, and only when the parent user has granted permission. This data is saved to your account once a day as a single daily summary record, and appears only on the My Measurements screen, which only users linked to the same family can see.
- Health Connect data is not used for advertising purposes.
- Health Connect data is not sold and is not shared with third parties for marketing purposes.
- Health Connect permission can always be revoked from the phone’s Health Connect settings; once permission is withdrawn, no new data is read.
- Records can be deleted individually from the My Measurements screen; all of them are deleted when the account is deleted.
Rafiqa is not a medical device. Entered or read values are not interpreted, not evaluated, and no threshold or alert is generated from them; the app does not diagnose, does not recommend treatment and does not give medical advice. For health-related decisions, consult your physician.
5. Retention Periods
| Data Category | Retention Period |
|---|---|
| Profile and identity information | Until account deletion + 30 days |
| Location data | Latest location: same as profile data; location history: 7 days, then deleted automatically |
| Measurement records | For as long as the account is active |
| Reminder and alarm data | For as long as the account is active |
| Payment and subscription records | 10 years (under tax legislation) |
| Push token | Until invalid or until account deletion |
| Device identifier and device record | Until account deletion |
| Fall detection events | 1 year |
If you delete your account, your data is permanently deleted once the retention periods above have elapsed. Where legal obligations require it, the stated retention periods may be extended.
Parent accounts and plan downgrades: the family subscription is managed by the child (administrator) account. If the plan is downgraded from Pro (2 parents) to Standard (1 parent), the administrator chooses which parent account remains. The account that is not selected is closed and, after the notice period stated in the app (7 days by default), it is permanently deleted together with all of its data. During this period the parent is warned inside the app and by push notification, and the deletion is cancelled automatically if the Pro plan is purchased again.
6. Data Security
The following technical and organisational measures are taken to protect your personal data:
- All data is stored encrypted in Firebase Firestore (AES-256)
- Firebase Authentication is used for identity verification; passwords are never stored in plain text
- Data communication with the API takes place over TLS/HTTPS
- Firestore Security Rules ensure that each user can only access their own data
- Payments are processed through Google Play Billing; card details are never transmitted to Rafiqa’s servers
- Sensitive data (tokens, keys) is never embedded in the frontend bundle; it is kept server-side or in environment variables
- Access logs are audited on a regular basis
7. User Rights (KVKK Article 11)
Under Article 11 of the KVKK, you have the following rights:
Right to be informed
Learn whether your personal data is being processed
Right of access
Access your processed data and request a copy
Right to rectification
Request the correction of inaccurate or incomplete data
Right to erasure
Request deletion of your data once the conditions for processing no longer apply
Right to object
Object to processing based on legitimate interest
Right to restriction
Request that processing be restricted under certain conditions
Right to data portability
Receive your data in a structured format
Right to complain
Apply to the Personal Data Protection Board (KVK Kurulu) in the event of non-compliance with the KVKK
To exercise your rights, you can write to rafiqa@masync.co. Requests are answered within 30 days at the latest, as required by Article 13 of the KVKK. For identity verification purposes, it is sufficient to state your email address in your request.
8. Cookies and Analytics
The Rafiqa mobile app does not use cookies. The app includes Google Firebase Analytics, which measures only a small number of setup steps: language selection, completing the introduction, sign-up/sign-in, role selection, family code linking, finishing setup, trial start, opening the purchase screen and purchase; only non-identifying details such as role, language and subscription plan are sent with these events. This website (rafiqa.masync.co) separately uses strictly necessary technical cookies, and Google Analytics (via Firebase) to measure how visitors use the site — this is a separate data stream from the in-app measurement.
Your measurements, the step/heart-rate/sleep data read from Health Connect, and your location are NOT sent to Analytics; neither are messages, contacts or address-book content. No Advertising ID is collected, and the data is not used for advertising and is not sold. Anonymous crash and non-response statistics about app stability are collected by Google Play at the operating-system level and reach us only as de-identified aggregate counts.
Google Analytics on the website records anonymized usage data such as pages viewed, sections scrolled to, and buttons clicked (for example, the Google Play button), together with an approximate location derived from IP address. It does not collect your name, email address or other directly identifying information through this site. You can read Google’s own privacy practices at policies.google.com/privacy.
9. Children’s Privacy
Rafiqa is not designed for individuals under the age of 18. Users of the app are assumed to be at least 18 years old. The data of elderly individuals for whom a parent profile is created is managed by the parent/child user, and the KVKK rights of these individuals can be exercised through a written application to the data controller.
10. Policy Changes
This policy may be updated from time to time. Material changes will be announced via an in-app notification or a notification to your registered email address. The effective date of the updated policy is indicated on this page. Continuing to use the app after changes are published means you accept the new policy.
11. Contact
You can contact us with questions about our privacy policy, to exercise your rights under the KVKK, or to report a data breach:
Application to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu): kvkk.gov.tr