Privacy Policy

Last updated: June 18, 2026

Courtesy translation. This privacy notice is prepared under Turkish law — the Personal Data Protection Law No. 6698 (KVKK) — and this English version is provided for your convenience. In the event of any conflict or legal dispute, the Turkish text is the authoritative version.

If you have questions about this policy, write to rafiqaapp@gmail.com.

Important Note: This text is a privacy notice prepared under Law No. 6698 on the Protection of Personal Data (KVKK). By using the Rafiqa app, you accept this policy. For questions, you can write to rafiqaapp@gmail.com.

1. Data Controller

Your personal data is processed by Rafiqa as the data controller within the scope of Law No. 6698 on the Protection of Personal Data (“KVKK”).

Trade Name: Rafiqa

Website: refiq-73ba9.web.app

Email: rafiqaapp@gmail.com

2. Personal Data Collected

The following categories of personal data are processed within the Rafiqa app:

Identity and Contact Data

  • Full name (optional)
  • Email address (via Google account or direct registration)
  • Profile photo (imported from Google account)

Location Data

Special Category
  • The parent user’s GPS coordinates (latitude/longitude)
  • Last location update time
  • Safe zone (geofence) settings

Health and Activity Data

Special Category
  • Daily routine reminder name, optional note and schedule (free text entered by the user)
  • Reminder completion status (marked/not marked)
  • Blood pressure, weight, temperature, pulse, blood sugar (if entered by the user)
  • If Health Connect permission is granted: step count, pulse and sleep duration — written to the server as a single daily summary record per day (raw measurement history is not collected)
  • Fall detection events

Data Kept on the Device (Not Sent to the Server)

  • Contact names and phone numbers from the address book — shown and cached only on the device
  • Contact entries added/edited with app permission — written to the phone’s own contacts
  • A local “frequently called” list made up of numbers you have called through Rafiqa
  • Camera image (Magnifier and Flashlight) — not recorded, not transmitted
  • The name and icon of the app shortcuts you add to the home screen

App Usage Data

  • Alarm settings
  • Dhikr and Quran-reading progress data
  • Prayer time notification preferences
  • Language and font size preferences
  • Module visibility and ordering preferences

Payment and Subscription Data

  • Subscription plan and status
  • Google Play purchase reference (purchaseToken) — card and billing details remain with Google and are not transmitted to Rafiqa’s servers
  • Trial period and subscription end date

Technical Data

  • Firebase Authentication user ID (UID)
  • Expo push notification token
  • Device type and operating system version (anonymous)

3. Purposes of Processing and Legal Bases

PurposeLegal Basis
Providing the app and ensuring service qualityPerformance of a contract (KVKK Art. 5/2-c)
Location tracking and safe zone notificationsExplicit consent (KVKK Art. 5/1)
Daily routine reminders and health journal managementExplicit consent (KVKK Art. 5/1, Art. 6/2)
Fall detection and emergency notificationsLegitimate interest / Vital interest (KVKK Art. 5/2-f, e)
Sending push notificationsPerformance of a contract / Explicit consent
Subscription and payment managementPerformance of a contract (KVKK Art. 5/2-c)
Technical support and customer serviceLegitimate interest (KVKK Art. 5/2-f)
Fulfilling legal obligationsLegal obligation (KVKK Art. 5/2-ç)

4. Transfer of Personal Data

Your personal data may be shared with the following third parties:

Google Firebase (Auth + Firestore)

Authentication and database service

Location: USA / Europe

Privacy policy

Google Play Billing

Subscription purchase and renewal (card details are not transmitted to Rafiqa)

Location: USA / Europe

Privacy policy

Expo (Push Notifications)

Push notification infrastructure

Location: USA

Privacy policy

Cross-border transfers are carried out within the scope of Article 9 of the KVKK, either to countries with an adequate level of protection as determined by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), or on the basis of your explicit consent.

Health Connect data

The app reads step count, pulse and sleep duration through Health Connect, and only when the parent user has granted permission. This data is saved to your account once a day as a single daily summary record, and appears only on the Health Tracking screen, which only users linked to the same family can see.

  • Health Connect data is not used for advertising purposes.
  • Health Connect data is not sold and is not shared with third parties for marketing purposes.
  • Health Connect permission can always be revoked from the phone’s Health Connect settings; once permission is withdrawn, no new data is read.
  • Records can be deleted individually from the Health Tracking screen; all of them are deleted when the account is deleted.

Rafiqa is not a medical device. Entered or read values are not interpreted, not evaluated, and no threshold or alert is generated from them; the app does not diagnose, does not recommend treatment and does not give medical advice. For health-related decisions, consult your physician.

5. Retention Periods

Data CategoryRetention Period
Profile and identity informationUntil account deletion + 30 days
Location data90 days (only the last location is retained)
Health recordsFor as long as the account is active
Reminder and alarm dataFor as long as the account is active
Payment and subscription records10 years (under tax legislation)
Push tokenUntil invalid or until account deletion
Fall detection events1 year

If you delete your account, your data is permanently deleted once the retention periods above have elapsed. Where legal obligations require it, the stated retention periods may be extended.

Parent accounts and plan downgrades: the family subscription is managed by the child (administrator) account. If the plan is downgraded from Pro (2 parents) to Standard (1 parent), the administrator chooses which parent account remains. The account that is not selected is closed and, after the notice period stated in the app (7 days by default), it is permanently deleted together with all of its data. During this period the parent is warned inside the app and by push notification, and the deletion is cancelled automatically if the Pro plan is purchased again.

6. Data Security

The following technical and organisational measures are taken to protect your personal data:

  • All data is stored encrypted in Firebase Firestore (AES-256)
  • Firebase Authentication is used for identity verification; passwords are never stored in plain text
  • Data communication with the API takes place over TLS/HTTPS
  • Firestore Security Rules ensure that each user can only access their own data
  • Payments are processed through Google Play Billing; card details are never transmitted to Rafiqa’s servers
  • Sensitive data (tokens, keys) is never embedded in the frontend bundle; it is kept server-side or in environment variables
  • Access logs are audited on a regular basis

7. User Rights (KVKK Article 11)

Under Article 11 of the KVKK, you have the following rights:

Right to be informed

Learn whether your personal data is being processed

Right of access

Access your processed data and request a copy

Right to rectification

Request the correction of inaccurate or incomplete data

Right to erasure

Request deletion of your data once the conditions for processing no longer apply

Right to object

Object to processing based on legitimate interest

Right to restriction

Request that processing be restricted under certain conditions

Right to data portability

Receive your data in a structured format

Right to complain

Apply to the Personal Data Protection Board (KVK Kurulu) in the event of non-compliance with the KVKK

To exercise your rights, you can write to rafiqaapp@gmail.com. Requests are answered within 30 days at the latest, as required by Article 13 of the KVKK. For identity verification purposes, it is sufficient to state your email address in your request.

8. Cookies and Analytics

The Rafiqa mobile app does not use cookies. This website (refiq-73ba9.web.app) uses only strictly necessary technical cookies.

Firebase Crashlytics is used for in-app performance monitoring. This tool contains crash reports and error logs; it does not contain personally identifiable information.

9. Children’s Privacy

Rafiqa is not designed for individuals under the age of 18. Users of the app are assumed to be at least 18 years old. The data of elderly individuals for whom a parent profile is created is managed by the parent/child user, and the KVKK rights of these individuals can be exercised through a written application to the data controller.

10. Policy Changes

This policy may be updated from time to time. Material changes will be announced via an in-app notification or a notification to your registered email address. The effective date of the updated policy is indicated on this page. Continuing to use the app after changes are published means you accept the new policy.

11. Contact

You can contact us with questions about our privacy policy, to exercise your rights under the KVKK, or to report a data breach:

Email: rafiqaapp@gmail.com

Web: refiq-73ba9.web.app

Response time: 30 days at the latest (KVKK Art. 13)

Application to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu): kvkk.gov.tr