Privacy Policy

Last updated: October 3, 2026

Courtesy translation. This privacy notice is prepared under Turkish law — the Personal Data Protection Law No. 6698 (KVKK) — and this English version is provided for your convenience. In the event of any conflict or legal dispute, the Turkish text is the authoritative version.

If you have questions about this policy, write to rafiqa@masync.co.

Important Note: This text is a privacy notice prepared under Law No. 6698 on the Protection of Personal Data (KVKK). By using the Rafiqa app, you accept this policy. For questions, you can write to rafiqa@masync.co.

1. Data Controller

Your personal data is processed by Rafiqa as the data controller within the scope of Law No. 6698 on the Protection of Personal Data (“KVKK”).

Trade Name: Rafiqa

Website: rafiqa.masync.co

Email: rafiqa@masync.co

2. Personal Data Collected

The following categories of personal data are processed within the Rafiqa app:

Identity and Contact Data

  • •Full name (optional)
  • •Email address (via Google account or direct registration)
  • •Profile photo (imported from Google account)

Location Data

Special Category
  • •The parent user’s GPS coordinates (latitude/longitude)
  • •Last location update time and the location history of the last 7 days
  • •Safe zone (geofence) settings

Health and Measurement Data

Special Category
  • •Pulse, weight and measurements you name yourself (if entered by the user). Entries created in earlier app versions are kept exactly as the user recorded them.
  • •If Health Connect permission is granted: step count, pulse and sleep duration — written to the server as a single daily summary record per day (raw measurement history is not collected)
  • •Fall detection events

Data Kept on the Device (Not Sent to the Server)

  • •Contact names and phone numbers from the address book — shown and cached only on the device
  • •Contact entries added/edited with app permission — written to the phone’s own contacts
  • •A local “frequently called” list made up of numbers you have called through Rafiqa
  • •Camera image (Magnifier and Flashlight) — not recorded, not transmitted
  • •The name and icon of the app shortcuts you add to the home screen

App Usage Data

  • •Alarm settings
  • •Dhikr and Quran-reading progress data
  • •Prayer time notification preferences
  • •Language and font size preferences
  • •Module visibility and ordering preferences
  • •Daily routine reminder name, optional note and schedule (free text entered by the user)
  • •Reminder completion status (marked/not marked)

Payment and Subscription Data

  • •Subscription plan and status
  • •Google Play purchase reference (purchaseToken) — card and billing details remain with Google and are not transmitted to Rafiqa’s servers
  • •Trial period and subscription end date

Technical Data

  • •Firebase Authentication user ID (UID)
  • •Expo push notification token
  • •Device type and operating system version (anonymous)
  • •Device identifier: a device-specific identifier derived from the Android system ID by a one-way hash; the raw ID never leaves the device. It is stored in a record linked to your account together with last-seen time, platform (Android), app version and role. It is not an advertising ID and is not used for advertising or marketing; it contains no device model, IP address, location or other personal data.

3. Purposes of Processing and Legal Bases

PurposeLegal Basis
Providing the app and ensuring service qualityPerformance of a contract (KVKK Art. 5/2-c)
Location tracking and safe zone notificationsExplicit consent (KVKK Art. 5/1)
Daily routine reminders and measurement journal managementExplicit consent (KVKK Art. 5/1, Art. 6/2)
Fall detection and emergency notificationsLegitimate interest / Vital interest (KVKK Art. 5/2-f, e)
Sending push notificationsPerformance of a contract / Explicit consent
Account and setup information emails (welcome, how to connect your parent, a reminder if setup is unfinished). They contain no advertising; reply "stop" to any of them to opt out.Performance of a contract (KVKK Art. 5/2-c) / Legitimate interest
Subscription and payment managementPerformance of a contract (KVKK Art. 5/2-c)
Technical support and customer serviceLegitimate interest (KVKK Art. 5/2-f)
Measuring how many devices an account is used on, and preventing account sharing and abuse; uninstalling and reinstalling the app does not make the same device count as a new one (this measurement currently places no restriction on you)Legitimate interest (KVKK Art. 5/2-f)
Fulfilling legal obligationsLegal obligation (KVKK Art. 5/2-ç)

4. Transfer of Personal Data

Your personal data may be shared with the following third parties:

Google Firebase (Auth + Firestore)

Authentication and database service

Location: USA / Europe

Privacy policy

Google Play Billing

Subscription purchase and renewal (card details are not transmitted to Rafiqa)

Location: USA / Europe

Privacy policy

Expo (Push Notifications)

Push notification infrastructure

Location: USA

Privacy policy

Cross-border transfers are carried out within the scope of Article 9 of the KVKK, either to countries with an adequate level of protection as determined by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), or on the basis of your explicit consent.

Health Connect data

The app reads step count, pulse and sleep duration through Health Connect, and only when the parent user has granted permission. This data is saved to your account once a day as a single daily summary record, and appears only on the My Measurements screen, which only users linked to the same family can see.

  • Health Connect data is not used for advertising purposes.
  • Health Connect data is not sold and is not shared with third parties for marketing purposes.
  • Health Connect permission can always be revoked from the phone’s Health Connect settings; once permission is withdrawn, no new data is read.
  • Records can be deleted individually from the My Measurements screen; all of them are deleted when the account is deleted.

Rafiqa is not a medical device. Entered or read values are not interpreted, not evaluated, and no threshold or alert is generated from them; the app does not diagnose, does not recommend treatment and does not give medical advice. For health-related decisions, consult your physician.

5. Retention Periods

Data CategoryRetention Period
Profile and identity informationUntil account deletion + 30 days
Location dataLatest location: same as profile data; location history: 7 days, then deleted automatically
Measurement recordsFor as long as the account is active
Reminder and alarm dataFor as long as the account is active
Payment and subscription records10 years (under tax legislation)
Push tokenUntil invalid or until account deletion
Device identifier and device recordUntil account deletion
Fall detection events1 year

If you delete your account, your data is permanently deleted once the retention periods above have elapsed. Where legal obligations require it, the stated retention periods may be extended.

Parent accounts and plan downgrades: the family subscription is managed by the child (administrator) account. If the plan is downgraded from Pro (2 parents) to Standard (1 parent), the administrator chooses which parent account remains. The account that is not selected is closed and, after the notice period stated in the app (7 days by default), it is permanently deleted together with all of its data. During this period the parent is warned inside the app and by push notification, and the deletion is cancelled automatically if the Pro plan is purchased again.

6. Data Security

The following technical and organisational measures are taken to protect your personal data:

  • All data is stored encrypted in Firebase Firestore (AES-256)
  • Firebase Authentication is used for identity verification; passwords are never stored in plain text
  • Data communication with the API takes place over TLS/HTTPS
  • Firestore Security Rules ensure that each user can only access their own data
  • Payments are processed through Google Play Billing; card details are never transmitted to Rafiqa’s servers
  • Sensitive data (tokens, keys) is never embedded in the frontend bundle; it is kept server-side or in environment variables
  • Access logs are audited on a regular basis

7. User Rights (KVKK Article 11)

Under Article 11 of the KVKK, you have the following rights:

Right to be informed

Learn whether your personal data is being processed

Right of access

Access your processed data and request a copy

Right to rectification

Request the correction of inaccurate or incomplete data

Right to erasure

Request deletion of your data once the conditions for processing no longer apply

Right to object

Object to processing based on legitimate interest

Right to restriction

Request that processing be restricted under certain conditions

Right to data portability

Receive your data in a structured format

Right to complain

Apply to the Personal Data Protection Board (KVK Kurulu) in the event of non-compliance with the KVKK

To exercise your rights, you can write to rafiqa@masync.co. Requests are answered within 30 days at the latest, as required by Article 13 of the KVKK. For identity verification purposes, it is sufficient to state your email address in your request.

8. Cookies and Analytics

The Rafiqa mobile app does not use cookies. The app includes Google Firebase Analytics, which measures only a small number of setup steps: language selection, completing the introduction, sign-up/sign-in, role selection, family code linking, finishing setup, trial start, opening the purchase screen and purchase; only non-identifying details such as role, language and subscription plan are sent with these events. This website (rafiqa.masync.co) separately uses strictly necessary technical cookies, and Google Analytics (via Firebase) to measure how visitors use the site — this is a separate data stream from the in-app measurement.

Your measurements, the step/heart-rate/sleep data read from Health Connect, and your location are NOT sent to Analytics; neither are messages, contacts or address-book content. No Advertising ID is collected, and the data is not used for advertising and is not sold. Anonymous crash and non-response statistics about app stability are collected by Google Play at the operating-system level and reach us only as de-identified aggregate counts.

Google Analytics on the website records anonymized usage data such as pages viewed, sections scrolled to, and buttons clicked (for example, the Google Play button), together with an approximate location derived from IP address. It does not collect your name, email address or other directly identifying information through this site. You can read Google’s own privacy practices at policies.google.com/privacy.

9. Children’s Privacy

Rafiqa is not designed for individuals under the age of 18. Users of the app are assumed to be at least 18 years old. The data of elderly individuals for whom a parent profile is created is managed by the parent/child user, and the KVKK rights of these individuals can be exercised through a written application to the data controller.

10. Policy Changes

This policy may be updated from time to time. Material changes will be announced via an in-app notification or a notification to your registered email address. The effective date of the updated policy is indicated on this page. Continuing to use the app after changes are published means you accept the new policy.

11. Contact

You can contact us with questions about our privacy policy, to exercise your rights under the KVKK, or to report a data breach:

Email: rafiqa@masync.co

Web: rafiqa.masync.co

Response time: 30 days at the latest (KVKK Art. 13)

Application to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu): kvkk.gov.tr