Privacy Policy
Last updated: June 18, 2026
Courtesy translation. This privacy notice is prepared under Turkish law — the Personal Data Protection Law No. 6698 (KVKK) — and this English version is provided for your convenience. In the event of any conflict or legal dispute, the Turkish text is the authoritative version.
If you have questions about this policy, write to rafiqaapp@gmail.com.
Important Note: This text is a privacy notice prepared under Law No. 6698 on the Protection of Personal Data (KVKK). By using the Rafiqa app, you accept this policy. For questions, you can write to rafiqaapp@gmail.com.
1. Data Controller
Your personal data is processed by Rafiqa as the data controller within the scope of Law No. 6698 on the Protection of Personal Data (“KVKK”).
2. Personal Data Collected
The following categories of personal data are processed within the Rafiqa app:
Identity and Contact Data
- •Full name (optional)
- •Email address (via Google account or direct registration)
- •Profile photo (imported from Google account)
Location Data
Special Category- •The parent user’s GPS coordinates (latitude/longitude)
- •Last location update time
- •Safe zone (geofence) settings
Health and Activity Data
Special Category- •Daily routine reminder name, optional note and schedule (free text entered by the user)
- •Reminder completion status (marked/not marked)
- •Blood pressure, weight, temperature, pulse, blood sugar (if entered by the user)
- •If Health Connect permission is granted: step count, pulse and sleep duration — written to the server as a single daily summary record per day (raw measurement history is not collected)
- •Fall detection events
Data Kept on the Device (Not Sent to the Server)
- •Contact names and phone numbers from the address book — shown and cached only on the device
- •Contact entries added/edited with app permission — written to the phone’s own contacts
- •A local “frequently called” list made up of numbers you have called through Rafiqa
- •Camera image (Magnifier and Flashlight) — not recorded, not transmitted
- •The name and icon of the app shortcuts you add to the home screen
App Usage Data
- •Alarm settings
- •Dhikr and Quran-reading progress data
- •Prayer time notification preferences
- •Language and font size preferences
- •Module visibility and ordering preferences
Payment and Subscription Data
- •Subscription plan and status
- •Google Play purchase reference (purchaseToken) — card and billing details remain with Google and are not transmitted to Rafiqa’s servers
- •Trial period and subscription end date
Technical Data
- •Firebase Authentication user ID (UID)
- •Expo push notification token
- •Device type and operating system version (anonymous)
3. Purposes of Processing and Legal Bases
| Purpose | Legal Basis |
|---|---|
| Providing the app and ensuring service quality | Performance of a contract (KVKK Art. 5/2-c) |
| Location tracking and safe zone notifications | Explicit consent (KVKK Art. 5/1) |
| Daily routine reminders and health journal management | Explicit consent (KVKK Art. 5/1, Art. 6/2) |
| Fall detection and emergency notifications | Legitimate interest / Vital interest (KVKK Art. 5/2-f, e) |
| Sending push notifications | Performance of a contract / Explicit consent |
| Subscription and payment management | Performance of a contract (KVKK Art. 5/2-c) |
| Technical support and customer service | Legitimate interest (KVKK Art. 5/2-f) |
| Fulfilling legal obligations | Legal obligation (KVKK Art. 5/2-ç) |
4. Transfer of Personal Data
Your personal data may be shared with the following third parties:
Google Firebase (Auth + Firestore)
Authentication and database service
Location: USA / Europe
Google Play Billing
Subscription purchase and renewal (card details are not transmitted to Rafiqa)
Location: USA / Europe
Expo (Push Notifications)
Push notification infrastructure
Location: USA
Cross-border transfers are carried out within the scope of Article 9 of the KVKK, either to countries with an adequate level of protection as determined by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), or on the basis of your explicit consent.
Health Connect data
The app reads step count, pulse and sleep duration through Health Connect, and only when the parent user has granted permission. This data is saved to your account once a day as a single daily summary record, and appears only on the Health Tracking screen, which only users linked to the same family can see.
- Health Connect data is not used for advertising purposes.
- Health Connect data is not sold and is not shared with third parties for marketing purposes.
- Health Connect permission can always be revoked from the phone’s Health Connect settings; once permission is withdrawn, no new data is read.
- Records can be deleted individually from the Health Tracking screen; all of them are deleted when the account is deleted.
Rafiqa is not a medical device. Entered or read values are not interpreted, not evaluated, and no threshold or alert is generated from them; the app does not diagnose, does not recommend treatment and does not give medical advice. For health-related decisions, consult your physician.
5. Retention Periods
| Data Category | Retention Period |
|---|---|
| Profile and identity information | Until account deletion + 30 days |
| Location data | 90 days (only the last location is retained) |
| Health records | For as long as the account is active |
| Reminder and alarm data | For as long as the account is active |
| Payment and subscription records | 10 years (under tax legislation) |
| Push token | Until invalid or until account deletion |
| Fall detection events | 1 year |
If you delete your account, your data is permanently deleted once the retention periods above have elapsed. Where legal obligations require it, the stated retention periods may be extended.
Parent accounts and plan downgrades: the family subscription is managed by the child (administrator) account. If the plan is downgraded from Pro (2 parents) to Standard (1 parent), the administrator chooses which parent account remains. The account that is not selected is closed and, after the notice period stated in the app (7 days by default), it is permanently deleted together with all of its data. During this period the parent is warned inside the app and by push notification, and the deletion is cancelled automatically if the Pro plan is purchased again.
6. Data Security
The following technical and organisational measures are taken to protect your personal data:
- All data is stored encrypted in Firebase Firestore (AES-256)
- Firebase Authentication is used for identity verification; passwords are never stored in plain text
- Data communication with the API takes place over TLS/HTTPS
- Firestore Security Rules ensure that each user can only access their own data
- Payments are processed through Google Play Billing; card details are never transmitted to Rafiqa’s servers
- Sensitive data (tokens, keys) is never embedded in the frontend bundle; it is kept server-side or in environment variables
- Access logs are audited on a regular basis
7. User Rights (KVKK Article 11)
Under Article 11 of the KVKK, you have the following rights:
Right to be informed
Learn whether your personal data is being processed
Right of access
Access your processed data and request a copy
Right to rectification
Request the correction of inaccurate or incomplete data
Right to erasure
Request deletion of your data once the conditions for processing no longer apply
Right to object
Object to processing based on legitimate interest
Right to restriction
Request that processing be restricted under certain conditions
Right to data portability
Receive your data in a structured format
Right to complain
Apply to the Personal Data Protection Board (KVK Kurulu) in the event of non-compliance with the KVKK
To exercise your rights, you can write to rafiqaapp@gmail.com. Requests are answered within 30 days at the latest, as required by Article 13 of the KVKK. For identity verification purposes, it is sufficient to state your email address in your request.
8. Cookies and Analytics
The Rafiqa mobile app does not use cookies. This website (refiq-73ba9.web.app) uses only strictly necessary technical cookies.
Firebase Crashlytics is used for in-app performance monitoring. This tool contains crash reports and error logs; it does not contain personally identifiable information.
9. Children’s Privacy
Rafiqa is not designed for individuals under the age of 18. Users of the app are assumed to be at least 18 years old. The data of elderly individuals for whom a parent profile is created is managed by the parent/child user, and the KVKK rights of these individuals can be exercised through a written application to the data controller.
10. Policy Changes
This policy may be updated from time to time. Material changes will be announced via an in-app notification or a notification to your registered email address. The effective date of the updated policy is indicated on this page. Continuing to use the app after changes are published means you accept the new policy.
11. Contact
You can contact us with questions about our privacy policy, to exercise your rights under the KVKK, or to report a data breach:
Email: rafiqaapp@gmail.com
Web: refiq-73ba9.web.app
Response time: 30 days at the latest (KVKK Art. 13)
Application to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu): kvkk.gov.tr
