Privacy Policy
Tilawa is a platform for live, one-to-one Qur'an lessons between students and verified teachers. We take your privacy seriously because it is part of our ethical duty as Muslims, not because regulation requires it. This policy explains what we collect, why we collect it, what we never collect, and what rights you have over your data.
1. Who we are
Tilawa is operated by an individual based in Ghana. For any privacy questions, requests, or complaints, contact info@tilawaapp.com.
2. What we collect
2.1 Account information
When you sign up, we collect:
- Your name, as you choose to display it
- Your phone number (used for OTP sign-in and account security)
- Your gender (required for our gender-segregated matching, immutable after signup)
If you apply to teach, we also collect the information you submit about your city or town, languages, teaching specialties, Qur'an proficiency, teaching experience, and availability so we can review your application. If you apply through our website, you may optionally provide an email address so we can contact you about the application.
2.2 Session metadata
When you request and join a lesson, we store metadata about the session: who the participants were, when it happened, how long it lasted, and whether it completed successfully. We do not store the content of any lesson.
If you submit a session rating or written review, we store it with the session and the accounts involved so we can maintain quality and respond to safety concerns.
2.3 Bundles and payments
Students begin with a 10-minute welcome trial. To continue learning they may purchase a minute bundle. Payment is by Ghana Mobile Money and is handled by our payment processor, Cheqam. You approve each charge on your own handset. Tilawa passes Cheqam the mobile money number to charge and the amount, and receives back only a transaction reference and a confirmation that the payment occurred. Your mobile money PIN and wallet credentials never reach us.
2.4 Device and technical data
To run reliably we use account and device identifiers, push-notification tokens, app-interaction analytics, and diagnostic information such as the type of phone, operating-system version, app version, crash reports, and performance traces. This helps deliver calls and notifications, prevent abuse, and improve reliability. You can opt out of product analytics in the app; essential operational and security data is still processed.
3. What we do NOT collect
Some things we have explicitly designed out of the system. These are not promises in a marketing page; they are commitments enforced in our code and architecture:
- We never record your lessons. Audio is encrypted and sent in real time using WebRTC, directly between participants where network conditions allow or through a temporary relay when necessary. It is not recorded, transcribed, or retained by Tilawa.
- We do not read your messages. We do not run text analysis or content scanning over any communication in the app.
- We do not sell your data. Not to advertisers, not to data brokers, not to anyone. Ever.
- We do not show third-party ads. The app contains no advertising of any kind.
- We do not track you across other apps or websites.
4. How we use your data
We use the data we do collect only for:
- Letting you sign in and use the app
- Matching you with teachers (or students) of your own gender
- Connecting live sessions and sending service notifications
- Processing bundle payments
- Investigating fraud, abuse, or safety reports
- Fixing bugs and improving performance
- Sending important service notices (e.g. terms updates)
5. Who we share data with
To run the service, we use a small number of trusted third parties. Each is bound by their own privacy commitments and we share only what they need.
- Supabase: database, authentication, and signalling infrastructure. Hosts your account data and session metadata.
- Cheqam: processes minute bundle purchases and voluntary donations by Ghana Mobile Money, and sends account SMS. Receives the mobile money number being charged and holds payment information directly under their own privacy policy.
- Firebase Cloud Messaging: delivers push notifications to your device. Receives an anonymous device token.
- Sentry: collects anonymized crash reports so we can fix bugs. We strip personal information from crash logs.
- PostHog: processes product-interaction analytics to help us understand whether app features work as intended. Users can opt out of this analytics collection in the app.
- Cloudflare: provides temporary TURN relay connectivity for encrypted live audio when a direct WebRTC connection is unavailable.
We do not share your data with anyone else, except where required by law (for example, a court order issued by a Ghanaian court of competent jurisdiction). In such cases we will inform you unless legally prohibited.
6. Where your data is stored
Your account and session metadata are stored on Supabase infrastructure. Supabase runs on cloud providers with data centres in multiple regions. We choose the region closest to our users where available.
7. How long we keep your data
- Account data: kept while your account is active. Deleted within 30 days of account deletion.
- Session metadata: kept for as long as your account is active so you can see your learning history. Anonymised after deletion.
- Payment and donation records: kept for 7 years to comply with Ghanaian tax, accounting, and financial regulations. When the account is permanently deleted, the direct link to the user's profile is removed.
- Audio: never stored at all. There is nothing to keep or to delete.
8. Your rights
At any time, you may:
- Access the data we hold about you
- Correct data that is inaccurate
- Delete your account and associated data, subject to the limited retention described above
- Export your data in a portable format
- Object to specific uses (e.g. marketing notices)
Account deletion is available directly inside the app under Profile → Danger zone → Delete account. For anything you cannot do yourself, email info@tilawaapp.com and we will respond within 14 days.
9. Children
Tilawa is open to learners of all ages, including children. Children under 13 must have parental consent to use the platform. Parents may contact us at any time to review, export, or delete their child's data.
10. Security
We protect your data using industry-standard practices: encrypted connections (HTTPS / TLS), encrypted storage at rest, Row Level Security policies in our database, and minimum-privilege access for the small number of people who maintain the system. No system is perfectly secure. If we ever detect a breach affecting your data, we will notify you within 72 hours along with what happened and what to do.
11. Changes to this policy
We will update this policy as the service grows. Material changes will be announced inside the app and by email at least 14 days before they take effect. The "last updated" date at the top of this page always reflects the current version.
12. Contact
For any question, concern, or request related to this policy or your data:
- Email: info@tilawaapp.com
- Developer contact: kausara@tilawaapp.com
Delete your Tilawa account
You can request deletion either in the Tilawa app or by email if you no longer have access to the app.
- In the app: open Profile, scroll to Danger zone, tap Delete account, and confirm.
- Outside the app: email info@tilawaapp.com with the subject “Tilawa account deletion request.” Include the name on the account and the email address or phone number you use to sign in. We may ask you to verify account ownership before processing the request.
Your profile is hidden and access to the account is disabled as soon as the request is processed. You then have 30 days to cancel the request by signing back in and restoring the account. After 30 days, the account and associated personal data are permanently deleted or anonymised.
Profile information, authentication data, device tokens, lesson records, reports, blocks, favourites, and other data tied only to the account are deleted or anonymised. We retain transaction and other records only when required for tax, accounting, fraud prevention, safety, dispute resolution, or other legal obligations. Where retained, the account link is removed where possible, access is restricted, and the records are kept only for the period stated in Section 7 or as otherwise required by law. Lesson audio is never recorded or stored.