Privacy Policy
Effective date: August 13, 2026 · Last updated: August 13, 2026
Maani ("Maani", "we", "us") is an app for Quran reflection (tadabbur) operated by Maani Technologies. This policy explains what data Maani accesses, how we use it, who we share it with, and the choices and rights you have. Maani uses the Quran Foundation APIs (Quran.com and QuranReflect) to provide Quran content and an optional community feature. Questions can be sent to contact.maani.tech@gmail.com.
1. Information we collect
We collect only what we need to run the app:
- Account details: your name, email address, and profile picture (if you sign in with Google).
- Your reflections and questions: the text of the reflections you write and the questions you ask Maani's AI, along with the ayah you are reflecting on.
- Your study data: bookmarks, private notes, reading progress, streaks, and goals.
- Subscription and billing data: your subscription tier and status, and the customer email or identifier held by our payment providers. We do not receive or store your full card number.
- Community data (only if you connect QuranReflect): the posts, comments, notes, and profile and follow information you choose to create or access through Quran.com.
- Basic technical data: limited device and usage information needed to operate, secure, and troubleshoot the service.
Quran content: Quran text, translations, word-by-word data, and related metadata are retrieved from the Quran.com API without collecting personal user data from that source.
2. How we use your information
We use your information only to:
- provide, maintain, and improve the Maani experience;
- generate your AI reflections and answers, grounded in classical tafsir;
- save your bookmarks, notes, progress, streaks, and goals, and sync them across your devices;
- manage your subscription and process payments;
- enable the optional community feature when you connect QuranReflect;
- respond to your support requests and send you service or account messages.
We do not use your data to build advertising profiles. We do not sell, mine, or repurpose your data beyond the features described here.
3. AI processing
Maani's reflection features are powered by Google Gemini. When you ask a question or write a reflection, the text you enter, the relevant ayah, and supporting tafsir context are sent to the AI provider to generate a response. Your personal reflections and questions are not used to train AI models without your prior, explicit consent.
4. Quran Foundation and Quran.com integration
- Quran text, translations, word-by-word data, and tajweed rules are retrieved from the Quran.com Content API (Quran Foundation).
- The community feature is optional. If you choose "Connect Quran.Foundation", Maani links your QuranReflect account through OAuth 2.0 so you can read and share reflections with the Quran.com community. This is opt-in and separate from creating a Maani account.
- The access and refresh tokens for that connection are encrypted at rest (AES-256-GCM) and stored on our servers. They are never returned to or stored on your device.
- You can disconnect at any time inside Maani, which deletes the stored tokens. You can also revoke Maani's access from your Quran.com / QuranReflect account settings.
5. Sensitive (religious) data
Reflection content and religious activity are sensitive personal information and receive stronger protection under applicable law. By choosing to use Maani's reflection, AI, and community features, you give clear, affirmative, and specific consent for us to process this content in order to provide those features. This consent is separate from your general agreement to our Terms of Service, and you can withdraw it at any time by deleting the relevant content, disconnecting the community feature, or closing your account.
6. Sharing and sub-processors
We do not sell your data and we do not share it to build advertising profiles. We share data only with the service providers ("sub-processors") that help us run Maani. Each is bound by a contract that requires them to protect your data and to respect Islamic content guidelines. The main sub-processors are:
| Sub-processor | Purpose | What is shared | Privacy policy |
|---|---|---|---|
| Appwrite | Core database and authentication (Singapore region) | Account data, reflections, notes, bookmarks, progress, subscriptions, encrypted connection tokens | appwrite.io/privacy |
| Google (Gemini AI, Cloud Text-to-Speech) | Generate AI reflections and text-to-speech audio | Your reflection or question text, the ayah, and tafsir context | policies.google.com/privacy |
| LemonSqueezy | Web billing | Email and subscription details | lemonsqueezy.com/privacy |
| RevenueCat | Mobile billing (Google Play and App Store) | Purchase and subscription identifiers | revenuecat.com/privacy |
| Resend | Service and product emails | Your email address | resend.com/legal/privacy-policy |
| Meta (Conversions API) | Measure sign-ups and purchases | A hashed (SHA-256) email and an internal identifier | facebook.com/privacy/policy |
| Quran Foundation / QuranReflect | Optional community feature | Only what you create or access when connected (posts, comments, notes, profile, follow) | quran.foundation |
We also use cloud hosting providers (Microsoft Azure, Render, and Vercel) as infrastructure processors.
7. Data security
We use industry-standard security practices, including:
- TLS for data in transit;
- encryption at rest, including AES-256-GCM encryption of your Quran.com connection tokens;
- access controls on a least-privilege basis;
- a defined secret-rotation cadence.
Our backend acts as a secure proxy, so API keys and sensitive tokens are not exposed to the client. In line with the Quran Foundation security requirements, we will report any confirmed security incident affecting Quran Foundation data to developers@quran.com within 24 hours.
8. Data retention and deletion
- We retain your data only while your account is active.
- You can delete your reflections, notes, and bookmarks in the app, and you can request full account deletion at maani.tech/delete-account or by emailing contact.maani.tech@gmail.com.
- On request, we hard-delete your personal data within 30 days and remove it from backups within 90 days.
- If you disconnect the community feature or delete your Quran.com account, we delete the associated connection tokens and community data we hold.
9. Your rights
You can:
- access and correct your information;
- export or delete your reflections, notes, and account;
- revoke the optional Quran.com connection at any time;
- withdraw your consent to sensitive-data processing.
To exercise any of these, use the in-app controls or email contact.maani.tech@gmail.com.
10. Children
Maani is not intended for children under the age of 13. We do not knowingly collect data from children under 13, and we will block or close an account if we learn it belongs to an underage user.
11. International data transfers
Your data may be processed outside your home country (for example, in Singapore for our database, and in the United States for AI and payment providers). Where required, we rely on recognized safeguards such as Standard Contractual Clauses (SCCs), and we comply with applicable local laws.
12. Changes to this policy
If we make material changes to this policy, we will notify you through an in-app notice or by email before the changes take effect. The "Last updated" date above always reflects the current version.
13. Contact
For any privacy question or request, contact us at contact.maani.tech@gmail.com. We aim to respond to inquiries within 30 days.