DhikrFlow — Privacy Policy
Everything works offline, everything you count is stored on your device, and nothing about it leaves the device unless you sign in and ask for backup.
Last updated: 18 August 2026 · Version 1.0.0
Who this is about
DhikrFlow is a Tasbeeh, Adhkar and daily Dhikr counter. This policy
covers the DhikrFlow mobile app for Android and iOS
(com.zenski.dhikrflow) and nothing else.
What is stored on your device
A database on the phone holds your Dhikr, counting sessions, guided sequences, routines, goals, Adhkar progress, reminders and settings. It is the source of truth: the app never asks the network a question it can answer locally, and every feature works with no connection at all.
The database is not separately encrypted beyond the platform's own full-disk encryption. It is an app-private file that no other app can read. Deleting the app deletes it.
Nothing that could authenticate anyone is written by the app. No password, token or secret is stored in its settings or database; if you sign in, the sign-in session is kept by the platform's own secure store.
What leaves your device
Only if you sign in
Signing in is optional and the app never requires it. If you sign in with Google or Apple, your credential is handled by that provider's own SDK, and an account is created with Firebase Authentication.
Cloud backup writes to Cloud Firestore under your own account
(users/{your id}) and nowhere else: custom Dhikr, sessions,
routines, goals and preferences. Built-in content is not uploaded — it
ships with the app and is not your data. Cloud backup is
currently switched off for everyone, and if it is turned on in a
later release it will be something you enable rather than a default.
Usage and crash reporting
The app sends anonymous usage events to Firebase Analytics and crash reports to Firebase Crashlytics. What they may record is that something happened, how many, and which of a fixed set of choices was picked:
| Event | What it carries |
|---|---|
app_opened | nothing |
onboarding_finished | whether it was skipped |
session_completed | a count, and whether a target was set |
sequence_completed | number of steps |
routine_completed | number of steps |
adhkar_completed | which category |
goal_reached | which period |
preference_changed | which preference, and which choice |
reminder_created | which kind of reminder |
What is never measured: anything you wrote or chose to read — Dhikr text, custom names, routine names, goal labels, reminder messages — and which Dhikr you counted. This is enforced by the way the events are built, not by a rule someone has to remember.
Crash reports carry the stack trace and a trail of which operations ran, drawn from a fixed list. They do not carry your content.
Everything the app talks to
| Service | When | What it receives |
|---|---|---|
| Firebase Authentication | Only if you sign in | Your Google or Apple credential |
| Cloud Firestore | Only if signed in and backup is on | Your own records, under your own account |
| Firebase Analytics | While the app is used | The events above, and nothing else |
| Firebase Crashlytics | On a crash | The crash, with the trail above |
| Firebase Remote Config | At launch | Nothing — the app reads settings, it does not send any |
| Firebase App Check | At launch | An attestation that the request came from a real build |
There is no advertising SDK, no attribution SDK, no advertising identifier, and no tracking across other apps or websites. There are no ads in DhikrFlow.
What the app deliberately does not ask for
- Location. Prayer times are calculated on the device from a city you name, using a catalogue that ships with the app. There is no location permission and no lookup.
- Contacts, photos, microphone, camera or the file system.
- Precise device identifiers. An install is identified to Analytics by Firebase's own app-instance id, which you can reset by reinstalling.
On Android the app asks for permission to post notifications and to re-register reminders after a restart. On iOS it asks only for the notification permission the system prompts for. Reminders are local: their text is scheduled by your own device and never sent anywhere.
Children
DhikrFlow is suitable for all ages and collects nothing that identifies a person. It is not directed at children under 13 in a way that would involve collecting personal information from them, because it collects none from anyone.
Your choices
- Use it without an account. Every feature works as a guest.
- Sign out. Nothing local is deleted; the app carries on exactly as before.
- Delete your account. In the app, or by email if you cannot open it — see Deleting your account and your data.
- Delete the app. Everything stored on the device goes with it.
Deleting your account and your data
DhikrFlow does not require an account. If you have never signed in, there is nothing of yours on our side to delete — everything lives on your phone, and removing the app removes it.
In the app
Open More → Account → Delete account. This erases your cloud documents first and the account afterwards. If erasing the data fails, the account is deliberately kept rather than leaving records nobody can reach, and you can try again. Your data on the device is left untouched; delete the app to remove that too.
If you cannot open the app
Email info.zenski@gmail.com from the address you signed in with, asking for your account to be deleted. We will confirm the request and delete it.
What is deleted, and what is kept
| Data | What happens |
|---|---|
| Your account (Firebase Authentication) | Deleted. Email address and display name go with it. |
| Cloud backup: custom Dhikr, your own Adhkar, sessions, routines, goals, preferences | Deleted, before the account is. |
| Data on your phone | Untouched, and yours. Deleting the app removes it; nothing else can. |
| Anonymous usage events and crash reports | Carry no account and no identifier, so there is nothing to delete per person. They expire under Firebase's own retention settings. You can switch usage measurement off at any time on the app's Privacy screen. |
Data retention
Local data stays until you delete it or remove the app. Cloud records, if you ever have any, stay under your account until you delete the account. Analytics and crash data are retained under Firebase's own retention settings for this project.
Changes
If what the app does changes, this page changes in the same release. The date at the top is when it was last revised.
Contact
Questions about this policy, or a request about your data: info.zenski@gmail.com.