1. Who We Are
This privacy policy ("Policy") describes how Alphabet Technologies ("Sokoun", "we", "us", "our"), the publisher of the Sokoun mobile and Wear OS applications (the "App"), collects, uses, discloses, and protects information about you.
- Legal entity: Alphabet Technologies, United Arab Emirates.
- Contact email: Sokoun-app@alphabetechnologies.ae
- Website: www.alphabetechnologies.ae
- Data Protection Officer: Not appointed — privacy requests are handled by the contact above (see Section 11).
If any of the above changes, we will update this Policy and increment the Last Updated date.
2. Scope
This Policy applies to:
- The Sokoun phone application available on the Google Play Store.
- The Sokoun watch application that runs on Wear OS devices paired with a supported phone.
- Any website, support channel, or marketing surface that links to this Policy.
It does not apply to third-party services, websites, or operating-system components that may be integrated with or invoked by the App (Google Maps, system notifications, Health Services, the device sensor stack, etc.). Their own privacy policies govern their handling of your data.
3. Summary at a Glance
For a quick orientation; the binding text is in the sections that follow.
| Category | What we do |
|---|---|
| Where your data lives | On your device. Sokoun is designed to work offline. We do not operate cloud servers that store your prayer logs, biometric recordings, or profile. |
| What we collect | The minimum information needed to compute prayer times, deliver notifications, and generate the in-app insights you see (heart-rate, accelerometer, gyroscope readings during a prayer session). |
| Who we share it with | No one, unless one of the narrow situations in Section 8 applies (e.g. you export data, you request support, or we're legally compelled). |
| Selling or sharing for ads | We do not sell your personal information, share it for cross-context behavioural advertising, or use it for profiling that produces legal or similarly significant effects. |
| Children | The App is not directed at children under 13. See Section 10. |
| Your rights | Access, correction, deletion, portability, restriction, objection, withdrawal of consent — see Section 11. |
4. Information We Collect
We collect the following categories of information. Where data stays on your device only, we say so explicitly.
4.1 Location data
What: Approximate or precise geographic coordinates (latitude, longitude), and optionally a derived city/region label.
Why: To compute Islamic prayer times for your location, to determine the direction to the Qiblah, and to display correct sunrise/sunset reference points in the schedule. Prayer times are inherently location-dependent; the App cannot perform its core function without this.
How: Through the device's native location services (Android LocationManager) after you grant location permission. You can also enter a location manually.
Where it lives: Stored locally in app preferences on your device, and mirrored to the paired Wear OS watch over the Wear OS Data Layer so the watch can compute prayer times and the Qiblah bearing without an active phone link.
What we do NOT do: We do not transmit your coordinates to our servers, advertising networks, or analytics providers. We do not build a movement history or "location trail."
4.2 Health and sensor data
What: During a prayer session you initiate (manually or via auto-detect), the App records, on the watch:
- Accelerometer samples (3-axis acceleration, ~50 Hz) for the duration of the prayer.
- Gyroscope samples (3-axis angular velocity, ~50 Hz) for the duration of the prayer.
- Heart-rate samples (BPM, on a best-effort sub-second cadence) when the watch hardware supports it and the relevant permission is granted (
android.permission.health.READ_HEART_RATEon Wear OS).
Why: To compute the per-prayer biomechanics shown on the "Holistic Mindfulness" screen — stillness index, Tam'anina (estimated longest sustained still window), heart-rate trend, respiration waveform proxy, consistency radar, posture / movement-flow swimlane, and rakaat estimate. None of these analyses is possible without the underlying sensor data.
Where it lives: On the watch as plain-text CSV files in the App's private storage; transferred to the paired phone over the Wear OS Data Layer once the session ends; stored on the phone in the App's private application-support directory. The data is never uploaded to a Sokoun server, third-party analytics service, or advertising network.
Sensitivity classification:
- Under GDPR Article 9, biometric data processed to derive health-related insights is "special category data." Our lawful basis is your explicit consent (Art. 9(2)(a)), given by enabling the relevant feature and granting the OS-level permission. You can withdraw consent at any time by disabling the feature, revoking the permission, or deleting the recordings (see Section 11).
- Under California law it is "sensitive personal information" under Cal. Civ. Code § 1798.140(ae) and is subject to the additional rights described in Section 11.4.
What we do NOT do: We do not infer medical diagnoses; we do not share health data with insurers, employers, advertisers, or any third party; we do not retain raw sensor data beyond the per-prayer files described above.
4.3 Prayer log
What: A record of which prayers you marked as completed, the timestamp at which you marked them, and (when relevant) a tombstone if you unmarked a prayer.
Why: To power streak counts, "missed prayer" alerts, the calendar / history view, the Insights tab, and the cross-device sync between your phone and watch.
Where it lives: Locally in shared preferences on both phone and watch. The two devices exchange logs over the Wear OS Data Layer so that recording a prayer on either device produces a single, consistent record.
What we do NOT do: We do not back this data up to a Sokoun cloud account, because no such cloud account exists.
4.4 Profile information
What: Optional, user-supplied fields: display name, profile photo, date of birth, gender, tagline, calculation-method preference, language preference, theme preference (if applicable), and similar personalisations. Date of birth and gender are optional and self-reported; we use them only to personalise the in-app experience and, like every profile field, they are stored only on your device and never transmitted to us.
Why: To personalise the in-app experience.
Where it lives: Locally on your device.
What we do NOT do: We do not require you to create an account. We do not collect your email address, phone number, social-network identifiers, or government IDs.
4.5 Technical information collected by the platform
When the App runs, the operating system itself may collect data — crash logs, performance traces, app launch metrics, etc. — and route some of that data to Google (Play Console crash reports). This information is collected and processed by Google under its privacy policy, which we incorporate by reference here: Google Privacy Policy.
We receive only aggregated, anonymised reports of crashes and adoption metrics from the Play Console. We do not receive identifiers that allow us to single you out.
4.6 Information we do NOT collect
For the avoidance of doubt and to keep this Policy honest:
- We do not collect your contacts, photos (beyond the optional profile photo you actively pick), SMS messages, call logs, calendar entries, microphone audio, or camera video.
- We do not read or write to any external storage outside the App's own sandbox.
- We do not assign you a persistent advertising identifier or collect the device's advertising ID for marketing purposes.
- We do not fingerprint your device.
- We do not integrate any third-party analytics SDK, crash-reporting SDK other than the OS-built-in console, advertising SDK, attribution SDK, or social-login SDK.
If any of the above changes in a future release, we will update this Policy before the change ships and obtain consent where required.
5. How We Use Information
We use the information described in Section 4 for the following purposes only:
- To deliver the App's core features — computing prayer times, generating notifications, drawing the Qiblah bearing, recording prayer logs, computing biomechanics insights, syncing state across your phone and watch.
- To respond to your support requests if you contact us at the email in Section 1 and you voluntarily share information with us in the course of that request.
- To comply with legal obligations that bind us, such as responding to a lawful, properly-served court order or government request.
- To enforce our Terms of Service, prevent fraud or abuse of the App, and protect the rights and safety of users.
We do not use your information for:
- Behavioural advertising (cross-context or otherwise).
- Building or selling profiles of you.
- Training machine-learning models on your personal data.
- Any "automated decision-making, including profiling" within the meaning of Article 22 GDPR that produces legal or similarly significant effects on you.
6. Legal Bases for Processing (GDPR / UK GDPR)
For users in the EEA, the United Kingdom, or any jurisdiction with a similar regime, our lawful bases under GDPR Article 6 (and, for health data, Article 9) are:
| Processing | Lawful basis |
|---|---|
| Computing prayer times from your location | Performance of a contract (Art. 6(1)(b)) — you ask the App to deliver prayer times and we do. |
| Recording prayer logs | Performance of a contract (Art. 6(1)(b)). |
| Recording sensor data and generating biomechanics insights | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)). You consent by enabling the auto-detect / manual-start feature and granting the OS-level body-sensor permission. Withdrawing consent is described in Section 11. |
| Sending notifications | Performance of a contract (Art. 6(1)(b)) for prayer-time reminders the user has explicitly enabled. |
| Crash and performance reporting via Play Console | Legitimate interests (Art. 6(1)(f)) in maintaining a stable, secure product, balanced against your reasonable expectations as captured in this Policy. |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)). |
7. Permissions Requested
Below is the complete list of operating-system permissions the App may request, the feature each one enables, and what happens if you decline.
| Permission | Required for | If you decline |
|---|---|---|
| Location (foreground) | Computing prayer times and the Qiblah bearing. | You can enter a location manually instead; otherwise prayer-time features are unavailable. |
| Camera | Optionally taking a profile photo with the camera. | Pick a photo from the gallery instead, or skip the profile photo entirely. |
Body sensors / Heart rate (android.permission.BODY_SENSORS, android.permission.health.READ_HEART_RATE) | Recording heart-rate during prayer for the Holistic Mindfulness insights. | Heart-rate insights are skipped; accelerometer and gyroscope insights still work. |
Physical activity (android.permission.ACTIVITY_RECOGNITION) | Letting the watch auto-detect the start of a prayer from your movement. | Auto-detect is unavailable; you can still start a prayer manually. |
| Foreground service health | Allows the watch to keep recording sensor data for the duration of a prayer when the screen is off. Required by Wear OS 6 / Android 14+. | Long sessions may stop recording when the screen turns off. |
Notifications (POST_NOTIFICATIONS on Android 13+) | Sending the prayer-time and pre-adhan alerts you opt into. | Those alerts won't fire. |
Alarms & reminders (SCHEDULE_EXACT_ALARM / USE_EXACT_ALARM) | Delivering prayer-time and pre-adhan notifications at the exact computed time. | Reminders may arrive a little less precisely. |
| Notification Policy Access (Do Not Disturb) | Automatically silencing the phone during a prayer session and restoring it when finished. | The phone won't auto-silence; you can use the system Do Not Disturb manually. |
| Internet | Reverse-geocoding the city name from your coordinates and downloading prayer-method updates. | A previously-cached location and method still work; geocoding fails silently. |
| Wear OS Data Layer | Syncing prayer logs and sensor recordings between your phone and watch. | The two devices behave as independent instances. |
If a future feature requires a new permission, we will request it at the moment you enable that feature, not at app launch.
8. When We Share Information
We share information only in the narrow, specifically-enumerated situations below.
- With the operating system and the device's own components. The App calls into the OS for location, sensors, notifications, and inter-device data transfer. That data is handled by the OS under its own terms.
- With Google, in its console capacity. Crash reports and aggregated performance metrics flow to the Play Console under Google's privacy policy (Section 4.5).
- With you, on your own request. If you use an export feature (now or in the future), the resulting file goes wherever you direct it.
- In response to lawful legal process. If we are served with a subpoena, court order, or equivalent binding legal demand, we will comply to the extent required by law. Because we do not operate servers that hold user data, our ability to respond is necessarily limited to whatever we hold (typically: nothing personal to you).
- In connection with a corporate transaction. If the Sokoun product is ever acquired, merged, or restructured, the acquirer would take on this Policy as binding on it. We would notify you in-app and via the Last Updated mechanism before any change in practice took effect.
We do not sell personal information. We do not "share" it for cross-context behavioural advertising. We do not disclose it to data brokers.
9. Data Retention and Deletion
- Prayer logs, profile fields, and preferences are retained on your device for as long as you keep the App installed. When you uninstall the App, your operating system deletes its private data directory.
- Sensor recordings (per-prayer CSV files) are retained on the watch until they're shipped to the phone and then deleted on the watch; on the phone they live in the App's private storage until you unrecord the associated prayer (which removes the linked sensor files) or until you uninstall.
- Crash reports in the Play Console are retained per Google's respective retention policies.
- Support correspondence you send to our contact email is retained for as long as needed to respond and for a reasonable archival period (typically up to 24 months) for audit purposes, and then deleted.
You can delete all locally-stored data immediately by uninstalling the App.
10. Children's Privacy
The App is not directed to children under the age of 13 (or under 16 in jurisdictions where that is the operative threshold under GDPR Art. 8). We do not knowingly collect personal information from children below those ages. If you are a parent or guardian and believe a child has provided us with personal information, please contact us at the email in Section 1 and we will take reasonable steps to delete it.
The App does not contain features designed to attract children (no in-app purchases targeted at minors, no social features, no user-generated content shared with other users, no advertising).
11. Your Rights
11.1 Rights under GDPR / UK GDPR (EEA / UK residents)
You have the right to:
- Access the personal data we hold about you (Art. 15). Because we hold almost nothing centrally, exercising this right typically means we tell you exactly that.
- Rectify inaccurate data (Art. 16). For locally-stored data, you can do this directly in the App.
- Erase ("right to be forgotten") your personal data (Art. 17). Uninstalling the App erases all data we hold about you on your device.
- Restrict processing (Art. 18) in the limited circumstances Art. 18 permits.
- Port your data (Art. 20) — request a structured, commonly-used, machine-readable copy. Where the data is already on your device in a portable format (CSV for sensor recordings, JSON for prayer logs), the App can produce it; otherwise contact us.
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time (Art. 7(3)) for processing based on consent, such as health-data processing. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Lodge a complaint with your supervisory authority. In the EEA, that is your national Data Protection Authority; in the UK, the Information Commissioner's Office at ico.org.uk.
To exercise any of these rights, contact us at the email in Section 1. We will respond within 30 days, extendable by a further 60 days for complex requests under Art. 12(3).
11.2 Rights under CCPA / CPRA (California residents)
If you are a California resident you have the right to:
- Know what categories of personal information we collect, the sources, the purposes, and the categories of third parties to which it is disclosed. This Policy is that disclosure.
- Access the specific pieces of personal information collected.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Limit the use and disclosure of sensitive personal information to what is necessary to provide the requested service.
- Opt out of any sale or "sharing" of personal information for cross-context behavioural advertising. We do not sell or share personal information in those senses, so there is no opt-out to exercise — but the right exists regardless.
- Non-discrimination — we will not deny you service, charge a different price, or provide a lesser quality of service because you exercised any of these rights.
Submit requests to the email in Section 1. We may need to verify your identity by asking you to confirm details that match what is on your device, before we act on a deletion or access request.
11.3 Authorised agents
You may use an authorised agent to submit a rights request on your behalf if (a) you provide signed written authorisation to that agent, and (b) we are able to verify your identity directly or through the agent.
11.4 Sensitive personal information
The heart-rate, accelerometer, and gyroscope data described in Section 4.2 is "sensitive personal information" under the CPRA. We use it solely to provide the in-app Holistic Mindfulness insights you have asked for, and we do not use, disclose, or retain it for any other purpose. You do not need to exercise the right to limit (CCPA § 1798.121) because we already restrict use to the specified purpose.
11.5 Rights under other jurisdictions
Residents of jurisdictions including the United Arab Emirates (PDPL), Saudi Arabia (PDPL), Brazil (LGPD), Canada (PIPEDA / Quebec Law 25), Japan (APPI), Australia (Privacy Act 1988), and South Korea (PIPA) have analogous rights. We will honour requests on equivalent terms.
12. International Data Transfers
Because the App is engineered to keep your data on your device, there are no routine international transfers of your personal data by Sokoun. The Play Console data described in Section 4.5 is transferred to Google under that company's own transfer mechanisms (Standard Contractual Clauses, the EU-U.S. Data Privacy Framework, etc.), which they describe in their privacy policy.
If you contact us by email, the email message will be transferred to and stored on the servers of our email provider, which may be located outside your home jurisdiction. We use Standard Contractual Clauses or other transfer mechanisms recognised by the European Commission for that transfer, where applicable.
13. Security
We take the following measures to protect your personal information:
- Data minimisation. We collect only what the feature requires (Section 4).
- Local-only storage. Because we do not operate a backend that holds your personal data, there is no server-side breach surface for a third party to attack.
- Sandbox isolation. All on-device data is stored in the App's private storage area, which the operating system isolates from other apps.
- Wear OS Data Layer. Cross-device sync travels over the encrypted Bluetooth / Wi-Fi channel provided by Wear OS, which Google operates under its own security standards.
- No third-party analytics SDKs. Eliminates a common third-party-leak vector.
No system is perfectly secure. If we ever become aware of a personal-data breach that creates a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Art. 33) and notify affected users without undue delay where the breach is likely to result in a high risk (Art. 34).
14. Third-Party Services
The App does not integrate any third-party SDKs for analytics, advertising, attribution, social login, A/B testing, or marketing automation as of the effective date of this Policy.
The App does rely on the following third-party platforms, whose own privacy policies govern their handling of any data they receive:
- Google LLC — operating system, Wear OS Data Layer, Play Store distribution. policies.google.com/privacy.
- Open-source libraries. The App uses open-source Flutter / Dart packages (e.g. the
adhanlibrary for prayer-time calculation,shared_preferencesfor on-device storage,vibration,intl,google_fonts). These packages execute on your device and do not transmit personal data to their authors. A current list of all bundled open-source packages is reproduced under "Open-source notices" within the App.
15. Notifications and Communications
Notifications you receive from the App (prayer-time reminders, pre-adhan alerts, missed-prayer alerts, spiritual reminders, etc.) are generated locally on your device. We do not send push notifications from a remote server.
We do not have a marketing mailing list. We do not send promotional emails. The only email we will ever send you is a direct, individual reply to a support enquiry you have initiated.
16. Changes to This Policy
We may update this Policy from time to time. When we do, we will:
- Increment the Last Updated date at the top.
- Maintain a prior version of this Policy on request (we keep a versioned copy in our repository).
- For changes that materially expand the kinds of data we process or the purposes for which it is processed, give you in-app notice before the change takes effect, and where required by law, request fresh consent.
Continuing to use the App after a non-material change takes effect constitutes acceptance of the updated Policy.
17. Contact
If you have any question, complaint, or request relating to this Policy or your personal data, contact us at:
- Email: Sokoun-app@alphabetechnologies.ae
- Publisher: Alphabet Technologies, United Arab Emirates.
For privacy-specific matters, please put "Privacy Request" in the subject line so we can route it appropriately.
18. Effective Date and Version History
| Version | Date | Summary of change |
|---|---|---|
| 1.0 | 1 June 2026 | Initial publication. |
This Policy is published in English. Translations into other languages are provided for convenience; the English text controls in the event of any discrepancy.