Mushafak
A mushaf that knows its companion — runs on your device
Last updated: 6 September 2026 · Applies to the Android app “مصحفك | Mushafak” (com.mushafak.app)
In four sentences: Mushafak asks for no account, name, email or phone number. Reading, memorizing and recitation checking all run and are stored on your device. There are no ads, no analytics and no tracking. The only things that reach our server are what you choose to send with an explicit tap: a support message, a report or recording to a teacher you linked with, or a stage-completion certificate code.
You can see all of it in “What does the app know about me?”, export it, or erase it at any time.
Never collected: name, email, phone number, contacts, location, installed apps, advertising ID, or anything outside the app.
| Destination | What is downloaded | When |
|---|---|---|
Cloudflare R2 (pub-…r2.dev) | Recitations, mushaf page images, timing indexes, tafsir shards, the recognition model | On request or “download all” |
| Firebase Storage (Google) | Backup mirror of the same files | Only if the first destination fails |
These are anonymous downloads: no account, no cookies, no identifier we add. As with any internet connection, the host sees your IP address at the time of the request in its ordinary operational logs. After the first download, reading, memorizing and recitation checking work offline.
Mushafak has a small server (mushafak-api on Cloudflare) that does not know who you are. It works with a random device identifier generated the first time you use one of the features below; it contains nothing about you and cannot be linked to a person. Nothing is sent automatically; everything below starts with your tap:
| Feature | What is sent | Why | Retention |
|---|---|---|---|
| Support | Your message, its type, app version, and your general settings if you choose to attach them | So you get a reply inside the app | Until you ask for deletion, or one year after the last message in the ticket |
| Linking with a teacher (code or QR) | Your device identifier and the teacher’s | So only your teacher sees your reports | Until either side unlinks |
| Report to teacher | Summary of a recitation result (ayahs and words), no audio | Memorization follow-up | Until unlinked |
| “Send to my teacher” after reciting | Your audio for that recitation (compressed m4a) with the engine’s verdict | So the teacher can listen and judge | Deleted 90 days after review, or on unlink |
| Stage certificate | Certificate code, stage number, ayah count and date — no name | So whoever you show the certificate can verify it by its code | Kept unless you ask for deletion |
| “Would you want this feature?” (optional) | Yes/no and your role (teacher/student) | To learn whether a feature is worth building | Aggregated without identifier after 30 days |
A teacher sees only what you sent them — never your device identifier or anything else. Mushafak does not sell or share any of this data with third parties; hosting is on Cloudflare under a standard data-processing agreement.
The app contains no ad SDK, no Google or Firebase Analytics, no crash reporter, no tracking pixel, and no data sharing with social networks.
The daily reminder, if you enable it, is scheduled and shown on your device by Android; no server sends notifications. “Do not disturb” in focus mode asks for a system permission and works locally only.
The app is suitable for all ages and collects no personal data from any user. The only content between users is the teacher link, created by the teacher and accepted by the student.
Quran text is from the King Fahd Complex; classical tafsirs come from public-domain sources; recitations come from sources permitting use with attribution. Sources and licenses are shown inside the app and with every tafsir shard.
Any change is published on this page with an updated date, and any new feature that uploads data is described here before it is enabled.
Inside the app: “Support”. Or by email: cloudenarymarwano@gmail.com