Anchor · Fajr Alarm

Privacy Policy

Last updated: March 8, 2026 · Effective: March 8, 2026

Our commitment: We treat your data — especially anything related to your faith — as a trust (amanah). We will never sell it, share it with data brokers, or use it for advertising.

01

Who We Are

Anchor: Fajr Alarm ("Anchor", "we", "us", or "our") is a mobile application designed to help users build and maintain a consistent Fajr prayer morning routine.

For any privacy-related matter, contact us at contact@mvpmatter.com.

02

A Note on Religious Data

GDPR Special Category Data (Article 9)

By using a Fajr prayer app, you may be implicitly revealing information about your religious beliefs. Under EU law, this is classified as Special Category data and requires heightened protection and your explicit consent.

We acknowledge this responsibility. We process data that may reflect your religious practice only on the basis of your explicit consent, provided when you create an account. You may withdraw this consent at any time by deleting your account.

03

Data We Collect

Account Data

When you sign in via Apple or Google:

  • Your name and email address (or an Apple relay address)
  • A unique identifier from Apple or Google
  • Authentication tokens

Location Data

We request your precise GPS location only to calculate accurate Fajr prayer times for your area. Your coordinates are stored locally and, if signed in, synced to our servers. Location is never shared with advertisers.

Onboarding Responses

We ask questions during onboarding to personalize your experience (motivation, relationship with Fajr, wake-up style). Your answers are stored locally and, if signed in, synced to our servers. They may reflect personal values and religious practice.

Daily Check-In Data

  • Date of each check-in
  • Your response (yes / not today)
  • Streak count and longest streak
  • Human Mode usage

Camera & Photo Data

If you enable the Photo Wake Challenge, your camera captures a wake-up photo. Only a non-reversible hash of your reference photo is stored — the actual image is never uploaded to our servers.

Analytics Data (Mixpanel)

Mixpanel collects automatically:

  • Device type, OS version, app version
  • App events (e.g., onboarding screen viewed, setup completed)
  • Approximate location (city/country — not precise GPS)
  • Session duration and frequency
  • A pseudonymous device identifier

Analytics data is processed in the EU via Mixpanel's EU infrastructure. We do not send prayer-specific events linked to your identity.

Payment Data

Payments are processed by Stripe. We do not collect or store your payment card details — Stripe handles this securely. We only receive your subscription status (active, expired, trial).

04

Why We Use Your Data

PurposeData UsedLegal Basis (GDPR)
Provide the app serviceAccount data, settings, check-insContract performance
Calculate prayer timesLocation coordinatesContract performance
Maintain streak & progressDaily check-ins, streak dataContract performance
Sync data across devicesAll account-linked dataContract performance
Photo wake verificationCamera, photo hashExplicit consent
Improve app experienceAnalytics (Mixpanel)Legitimate interests
Process subscriptionPayment data (Stripe)Contract performance
Legal obligationsAccount data, transaction recordsLegal obligation
Religious practice supportOnboarding responses, check-insExplicit consent (Art. 9 GDPR)

05

Third-Party Services

ServicePurposePrivacy Policy
SupabaseAuthentication & databasesupabase.com/privacy
MixpanelApp usage analyticsmixpanel.com/legal
StripeSubscription managementstripe.com/privacy
Apple Sign-InAuthenticationapple.com/legal/privacy
Google Sign-InAuthenticationpolicies.google.com

We have executed Data Processing Agreements (DPAs) with Supabase and Mixpanel.

06

Data Sharing

✕ No data sold✕ No data brokers✕ No advertisers

We share your data only in limited circumstances:

  • With service providers listed above, solely to deliver the service
  • When required by law (valid legal process, court order, or government request)
  • To protect the rights, property, or safety of users or the public
  • In a business transfer (merger or acquisition) — we would notify you in advance

07

Data Retention

Data TypeRetention Period
Account dataUntil deletion, or 2 years after last active use
Daily check-ins & streaksUntil account deletion
Onboarding responsesUntil account deletion
Location coordinatesUntil account deletion
Photo hashUntil photo challenge is disabled
Analytics data (Mixpanel)Up to 5 years, pseudonymous
Payment records7 years (legal/accounting obligation)

After account deletion, personal data is permanently erased within 30 days.

08

Your Rights

GDPR Rights (EU / UK Users)

Access
Request a copy of your personal data
Rectification
Correct inaccurate data we hold
Erasure
Request deletion of your data
Restriction
Limit how we process your data
Portability
Receive your data in a portable format
Object
Object to processing based on legitimate interests
Withdraw Consent
Especially for religious data and analytics
Complain
Lodge a complaint with your local DPA (e.g., CNIL)

CCPA / CPRA Rights (California Users)

  • Right to know — what data we collect, use, and disclose
  • Right to delete — request deletion of your personal information
  • Right to correct — request correction of inaccurate information
  • Right to opt-out — we do not sell or share data for advertising
  • Right of non-discrimination — we will not penalize you for exercising your rights

To exercise any right, email contact@mvpmatter.com. We respond within 30 days.

09

Account Deletion

You can delete your account at any time from within the app:

Settings → Account → Delete Account

All personal data is permanently removed from our servers within 30 days. Local data is cleared immediately. For help, email contact@mvpmatter.com.

10

Children's Privacy

Anchor is not directed at children under 13 (or 16 in the EU/UK). We do not knowingly collect data from children. If you believe we have done so inadvertently, contact us and we will delete it immediately.

11

Security

  • Encryption in transit (TLS/HTTPS) for all data sent to servers
  • Row-Level Security (RLS) — your data is only accessible to you
  • Secure authentication via Apple Sign-In and Google Sign-In (OAuth 2.0)
  • No storage of raw payment card data
  • Strict access controls on employee access to personal data

12

Changes to This Policy

When we make material changes, we will update the "Last updated" date and notify you within the app or by email. Continued use after the effective date constitutes acceptance of the updated policy.


13

Contact Us

Privacy questions, requests, or concerns

contact@mvpmatter.com

We respond within 5 business days · Data requests fulfilled within 30 days