Welcome to Qurantology. We are committed to protecting your personal information and your right to privacy. This Privacy Policy describes how Qurantology ("we", "us", or "our") collects, uses, and shares information about you when you use our platform, available at qurantology.com and our mobile applications.
Please read this policy carefully. If you have any questions or concerns, contact us at privacy@qurantology.com. By continuing to use our platform, you agree to the collection and use of information in accordance with this policy.
Introduction § 01
Qurantology is an AI-powered Quranic vocabulary learning platform serving 28,394+ scholars across 75 countries. As a platform grounded in Islamic values of trust (amanah) and accountability, we take the protection of your data as a core responsibility.
This policy applies to all users of our web platform, mobile apps (iOS & Android), API services, and any other products or services that link to this Privacy Policy. It does not apply to third-party websites or services that we may link to, which are governed by their own privacy policies.
This policy is written in plain language intentionally. If any section is unclear, please reach out — we are happy to explain in more detail.
Information We Collect § 02
We collect different types of information depending on how you use our platform. Below is a transparent breakdown of every category of data we may collect.
| Data Type | Examples | Purpose | Required? |
|---|---|---|---|
| Account Info | Name, email, password (hashed), country | Authentication & profile | Required |
| Learning Data | Vocabulary scores, quiz history, study time, accuracy rates | AI personalization | Required |
| Device Info | Browser, OS, device model, screen resolution | Compatibility & debugging | Automatic |
| Usage Analytics | Pages visited, features used, click patterns, session duration | Platform improvement | Automatic |
| Payment Info | Billing address, last 4 digits (full card data held by Stripe) | Subscription processing | If subscribed |
| Competition Data | Scores, rankings, participation history, prize eligibility | Leaderboards & rewards | If participating |
| Communications | Support messages, feedback, survey responses | Customer support | Optional |
We do not collect sensitive information such as racial or ethnic origin, political opinions, religious beliefs beyond what you voluntarily share, biometric data, or financial account details beyond what is required for payment processing.
How We Use Your Data § 03
Every piece of data we collect has a specific, documented purpose. We do not use your data in ways you would not reasonably expect.
- To provide and personalize our AI-powered Quranic vocabulary learning experience, including spaced repetition scheduling and progress tracking.
- To operate competitions, verify eligibility, calculate scores, distribute prizes, and maintain fair leaderboards.
- To process payments securely through our PCI-DSS compliant payment processor (Stripe) and manage your subscription.
- To communicate important platform updates, security notices, and service announcements. Marketing emails require your opt-in consent.
- To improve our AI models and platform features using aggregated, anonymized analytics — never individual user profiling for advertising.
- To detect and prevent fraud, abuse, unauthorized access, and other illegal activities that could harm our community of scholars.
- To comply with applicable legal obligations, enforce our Terms of Service, and protect the rights and safety of our users.
We rely on legitimate interest, contractual necessity, and explicit consent as our legal bases for processing. You can withdraw consent at any time from your account settings.
Cookies & Tracking § 04
We use cookies and similar tracking technologies to keep you logged in, remember your preferences, and understand how the platform is being used. We do not use advertising cookies or sell cookie data to third parties.
| Cookie Type | Description | Duration | Can Disable? |
|---|---|---|---|
| Essential | Session management, authentication, security CSRF tokens | Session | No |
| Preference | Language, theme settings, study mode preferences | 1 year | Yes |
| Analytics | Page views, feature usage (via self-hosted Plausible Analytics) | 90 days | Yes |
| Performance | Error logging, load time monitoring via Sentry | 30 days | Yes |
You can manage your cookie preferences at any time via the Cookie Settings panel in your account, or through your browser settings. Note that disabling essential cookies will affect your ability to log in and use the platform.
Data Sharing § 05
We do not sell, rent, or trade your personal data to any third party — ever. We only share data with trusted service providers who are contractually bound to protect it, and only to the extent necessary to deliver our service.
- Stripe — Secure payment processing. They receive billing information necessary to process subscriptions. Governed by Stripe's Privacy Policy.
- AWS (Amazon Web Services) — Cloud infrastructure hosting our platform. Data is encrypted at rest and in transit.
- Resend — Transactional email delivery (password resets, notifications). No marketing access.
- Sentry — Error monitoring for crash reports and debugging. Personal identifiers are scrubbed from logs.
- Legal Authorities — Only when required by a valid court order, subpoena, or applicable law. We will notify you when legally permitted to do so.
All third-party service providers are bound by Data Processing Agreements (DPAs) and are prohibited from using your data for their own purposes or sharing it further.
Data Security § 06
We implement industry-standard security measures to protect your data from unauthorized access, alteration, disclosure, or destruction. Our security practices include:
- All data is transmitted over HTTPS using TLS 1.3 encryption.
- Passwords are hashed using bcrypt with a minimum cost factor of 12 — we never store plaintext passwords.
- Databases are encrypted at rest using AES-256 and accessible only via private networks.
- Two-factor authentication (2FA) is available and recommended for all accounts.
- Regular third-party security audits and penetration testing are conducted annually.
- Access to user data is restricted to authorized personnel on a strict need-to-know basis with full audit logging.
In the event of a data breach that poses a risk to your rights, we will notify affected users and relevant authorities within 72 hours as required by GDPR Article 33.
Your Rights § 07
Depending on your location, you have the following rights regarding your personal data. You can exercise most of these directly from your account settings, or by contacting us.
Right to Access
Request a copy of all personal data we hold about you, including learning history and account details.
Right to Rectification
Correct any inaccurate or incomplete personal information in your profile at any time.
Right to Erasure
Request deletion of your account and all associated personal data ("right to be forgotten").
Right to Restrict
Request that we limit processing of your data while a dispute is being resolved.
Right to Portability
Export your learning data in a machine-readable format (JSON or CSV) from account settings.
Right to Object
Object to processing based on legitimate interest, including opt-out from marketing communications.
To exercise any of these rights, visit your Account Settings → Privacy or email privacy@qurantology.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
Children's Privacy § 08
Qurantology is designed for users of all ages, including students and young learners. We take additional care when our service is used by children.
- Users under 13 years old require verifiable parental consent before creating an account, in compliance with COPPA (USA) and equivalent laws.
- Users aged 13–17 have restricted data processing — their data is not used for analytics beyond core service delivery.
- Parents and guardians may request access to, correction of, or deletion of their child's data at any time by contacting us.
- We do not knowingly display targeted content, competitions with cash prizes, or advertising to users under 18 without explicit parental consent.
If you believe a child has provided us with personal information without appropriate consent, please contact us immediately at privacy@qurantology.com and we will take prompt action.
International Transfers § 09
Qurantology serves users in 75 countries. Your data may be processed in countries outside your own, including the United States and European Union, where our infrastructure is hosted.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure all cross-border data transfers are protected by one of the following safeguards: EU Standard Contractual Clauses (SCCs), adequacy decisions by the European Commission, or binding corporate rules where applicable.
For users in other regions, including Pakistan, the Middle East, and Southeast Asia, we apply equivalent data protection standards regardless of local requirements, as a commitment to our global community of scholars.
Policy Changes § 10
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last updated" date at the top of this page.
- Send an email notification to all registered users for material changes that affect your rights.
- Display a prominent in-app notice for significant changes with a 30-day review period before they take effect.
- Maintain an archive of previous versions of this policy, accessible upon request.
Your continued use of the platform after policy changes come into effect constitutes your acceptance of the updated policy. If you do not agree with the changes, you may delete your account before the effective date.
Contact & DPO § 11
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a privacy concern, please contact our Data Protection Officer (DPO):
| Data Protection Officer | Qurantology Privacy Team |
| privacy@qurantology.com | |
| Response Time | Within 30 days (typically 5–7 business days) |
| Postal Address | Qurantology Technologies, Islamabad, Pakistan |
| Supervisory Authority | PDPC Pakistan / Your local Data Protection Authority |
Still have questions?
Our privacy team is happy to walk you through anything in this policy.