This Privacy Policy explains how Maqam AI Inc. ("we," "us," "our") collects, uses, discloses, and protects information through Maqam AI (the "App").
1. Information We Collect
1.1 Information You Provide: name, email, and profile information from your chosen sign-in method — Sign in with Apple, Google sign-in, or email sign-up; preferences you add; support communications.
1.2 Recitation and Usage Data: which surahs/ayahs you've practiced, session frequency, streaks, scores, and completion status; audio recordings you submit for practice and feedback ("Voice Data"); general feature usage and related progress metadata. If you separately opt in as described in Section 3.6, Voice Data may also include an optional product-improvement copy of a recitation recording and related metadata (such as account id, device, surah/ayah, qari, and practice mode).
1.3 Automatically Collected Information: device type, OS, device identifiers; IP address, access times, crash and diagnostic logs; approximate location derived from IP address, where applicable (we do not collect precise GPS location unless a specific feature requires it and you separately consent).
1.4 From Sign-In Providers: profile information (e.g., name, email) received from the sign-in provider you choose, as permitted by your settings with that provider.
1.5 The App will request microphone access to record your recitation for feedback purposes; you can manage this permission in your device settings at any time.
1.6 Optional product analytics: If you opt in, we also collect product-usage events so we can understand how the App is used and improve it. That may include screens and features you open, session metadata, and device or app-version details needed to interpret those events. When you agree, the App creates a random analytics pseudonym that is separate from its functional device identifier and your Supabase account identifier. It is not merged across devices. Maqam keeps a private account-to-pseudonym association only so we can honor deletion requests; that association is never sent to PostHog.
Product analytics does not include recitation audio, transcripts, Quran text, exact surah or ayah choices, reciter choices, pitch features, exact scores, names, email addresses, account identifiers, authentication data, URLs, receipts, transaction identifiers, advertising identifiers, arbitrary text, or raw errors. This collection uses PostHog as our analytics processor and is optional on iOS and Android. We ask in the App. You can turn it off or on later in Settings. We keep this analysis for Maqam's own product improvement; we do not sell it and do not use it for third-party advertising or cross-company tracking.
2. How We Use Information
We use information to:
- create and manage your account;
- operate and personalize the App, including tracking your recitation practice progress;
- process Voice Data on our servers and send derived measurements to AI providers (as described in Section 3) to generate style-comparison feedback and scoring (melody, pacing, pauses, ending, stability, and related signals — not tajweed certification);
- if you opt in (see Section 3.6), store recitation audio and related metadata in private cloud storage so we can improve Maqam AI's recitation products;
- if you opt in (see Section 3.7), analyze product-usage events through PostHog so we can improve the App; we keep that analysis for Maqam's own use;
- maintain, troubleshoot, and improve the App;
- send service-related communications and, where you've opted in, marketing;
- detect and prevent fraud, abuse, and security incidents;
- comply with legal obligations.
3. AI Processing and Voice Data
3.1 AI processing and third-party AI services. Recitation audio is uploaded to Maqam AI Inc. servers (api.maqamapp.com) to compare melody and timing with a licensed reference. For user-facing scores and coaching text, we send derived measurements (pitch contour, timing, pauses, and related diagnostics) — not the audio file, name, or email — to third-party AI providers, including OpenAI, Anthropic, Google (Gemini), xAI (Grok), and DeepSeek. We do not use Voice Data to create a biometric voiceprint. This sharing happens only after in-app permission (separate from agreeing to this Policy). You can withdraw in Settings → Scoring data sharing.
Speech recognition during live practice runs on your device. The App may send recognized words (transcripts, not audio) to Maqam servers (a Cloudflare Worker) so it can follow along as you recite. Those transcripts are processed to operate the App. They are not sold and are not used for advertising.
3.2 Where applicable law treats Voice Data as biometric or sensitive personal information, we rely on your consent — including the in-app permission described above — before processing it for that purpose. Withdrawing permission or contacting us to withdraw consent will limit your ability to use AI-based feedback features.
3.3 AI-Generated Feedback is produced by automated systems and may not always be accurate; see our Terms and Conditions for related disclaimers. Where you interact with an AI-powered feature, you are interacting with an automated system rather than a person.
3.4 We may use de-identified or aggregated data derived from App usage to improve our products. We do not use your raw, identifiable Voice Data to train AI models beyond providing your own feedback, unless we obtain your separate, explicit opt-in consent to do so. That opt-in is the in-app notice described in Section 3.6 (or Settings → Help improve Maqam). It is optional and separate from the in-app scoring permission and from agreeing to this Policy. Scoring still works if you decline.
3.5 Retention of Voice Data (scoring and on-device saves). Recordings submitted for scoring are processed to generate feedback and are then deleted from analysis systems after processing (typically within minutes). If you choose to save a recording on your device (for example in My recordings or milestone takes), that audio stays on your device and is not uploaded as a personal cloud library. Score and progress metadata may sync when you are signed in; My recordings audio does not sync across devices. If a processing failure occurs, temporary scoring files are discarded according to the same short retention window.
3.6 Cloud storage of your recitation audio. Separate from scoring, you may allow Maqam to keep a copy of your recitation recording plus related details (metadata such as account id, device id, surah/ayah, reciter practiced against, practice mode, and a background-noise assessment) so we can improve Maqam's recitation products. This is optional and off by default. We show an in-app notice ("Help improve Maqam") after you sign in if you have not answered yet. "Yes, I'll help Maqam" means we may store those copies in Maqam's private Cloudflare R2 bucket. "No" means we will not. We do not share this store with OpenAI, Anthropic, Google, xAI, DeepSeek, or other AI providers. You can turn it off anytime in Settings → Help improve Maqam. Turning it off stops new copies; it does not by itself erase copies already stored. Scoring still works if you say no. This is not a personal recordings library and does not replace My recordings on your device. We keep opted-in copies for up to 36 months, or until you delete your account, whichever is sooner. Account deletion removes this stored audio within 30 days.
3.7 Optional product analytics (PostHog). Separate from scoring and from optional recitation-audio storage, you may allow Maqam to collect product-usage events (for example, which screens and features you use, and related session or device metadata) so we can analyze how the App is used and improve it. This is optional and off until you agree. We show an in-app notice if you have not answered yet. Yes means we may send those events to PostHog, which processes them as our service provider. No means we will not. We keep this analysis for Maqam's own product improvement. We do not sell it, we do not use it for third-party advertising, and we do not share it with OpenAI, Anthropic, Google, xAI, DeepSeek, or other AI providers for their training. You can turn this off or on later in Settings. That control is separate from Scoring data sharing and from Help improve Maqam. Turning it off stops new events. The App still works if you decline. This is available on iOS and Android.
Events go first to Maqam's backend and a private Supabase outbox, then to PostHog's United States cloud service in Virginia. Request IP addresses, headers, and request bodies are not forwarded to PostHog, and GeoIP enrichment is disabled. Maqam does not use PostHog session replay, autocapture, screenshots, microphone capture, or network-body recording.
Analytics history is kept for no more than one year. Each analytics pseudonym expires after 365 days and its PostHog history is scheduled for deletion. PostHog deletion is asynchronous and may take up to 30 additional days to verify. If consent remains active, the App creates a new pseudonym that is not merged with the old one. Withdrawing consent stops new collection immediately, clears the local event queue, blocks pending delivery, and schedules deletion of the prior pseudonym's history. Logout, account switch, and account deletion also rotate or delete the current analytics identity.
4. Religious Data
Because the App is built around Quran recitation, your use of it may reveal or suggest information about your religious beliefs. We treat this with particular care: we do not use information suggestive of your religious beliefs for purposes unrelated to operating the App (such as advertising targeted by religious affiliation) without your explicit consent, and we do not sell it. Where applicable law (such as the EU/UK GDPR) classifies this as a special category of personal data, we process it on a legal basis permitted by that law, including consent you provide by creating an account and using the App's recitation features.
5. How We Share Information
AI providers (scoring only). We share derived recitation analysis data — not your name, email, or raw audio — with OpenAI, Anthropic, Google (Gemini), xAI (Grok), and DeepSeek, as described above, under their contractual data-protection terms. We do not sell personal information. We do not share Voice Data with those providers for their independent training, and we do not send optional product-improvement audio copies to them.
Cloud storage of recitation audio (first-party / processor-hosted). If you opt in under Section 3.6, product-improvement copies of recitation audio and related metadata are stored in a private Maqam Cloudflare R2 bucket. Cloudflare (Worker and private R2 object storage) acts as our processor/host for that store. Those copies are Maqam AI data hosted by a service provider; they are not shared for others' training.
Service providers. We use companies that process data only to help us run Maqam, under contractual confidentiality and data-protection terms:
- Cloudflare — storage and processing, including the optional recitation-audio archive and live-practice word matching;
- Supabase — accounts and app data;
- RevenueCat — purchases and subscription status;
- Apple and Google — Sign in with Apple and Google sign-in;
- OpenAI, Anthropic, Google (Gemini), xAI (Grok), and DeepSeek — scoring only, using derived recitation data, not name, email, or raw audio;
- PostHog — optional product analytics, only if you opt in as described in Section 3.7. PostHog processes events as our processor in its United States cloud region in Virginia. We keep the analysis for Maqam's own use; it is not sold and is not used for third-party advertising.
We may also share information with:
- Other service providers performing work on our behalf, including hosting and analytics, each under contractual confidentiality and data-protection obligations;
- Sign-in providers you choose, as needed to authenticate your account;
- Legal and safety recipients, to comply with law or protect rights, property, or safety;
- a successor in a merger, acquisition, or asset sale, under standard confidentiality terms;
- anyone else with your consent or at your direction.
6. Data Retention
We retain personal information, including Voice Data, only as long as needed to provide the App's features or as required by law, under a written data retention approach that sets the purpose, business need, and deletion timeline for each category of data we hold. Account, progress, and score metadata may be retained while your account is active. Voice Data submitted for scoring is deleted after processing as described in Section 3.5. Saved recordings remain on your device until you delete them.
If you opted in under Section 3.6, product-improvement copies and related metadata are kept for up to 36 months, or until you delete your account, whichever is sooner. Turning off Help improve Maqam in Settings stops new copies from being stored; it does not by itself erase copies already stored. If you request account deletion (see Section 8, Settings → Delete account, or maqamapp.com/delete-account), that request includes any such opted-in copies, and we complete deletion within 30 days. Some records may be retained where we are required to do so by law.
If you opted in under Section 3.7, product-analytics events are kept for no more than one year. Turning analytics off in Settings stops new events immediately, clears the local event queue, blocks pending delivery, and schedules deletion of the prior pseudonym's PostHog history. PostHog deletion may take up to 30 additional days to verify. A verified account-deletion request includes mapped analytics identities, pending events, analytics and diagnostic records held by Maqam, and applicable PostHog event history.
7. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. Keep your account credentials confidential.
8. Your Rights and Choices
Depending on your location, you may have the right to: access, correct, or update your information; request deletion; request a portable copy; object to or restrict certain processing; withdraw consent (including for AI or Voice Data processing) without affecting past lawful processing; opt out of marketing; and, where applicable (e.g., California and other U.S. states), opt out of "sale" or "sharing" of personal information, or lodge a complaint with a relevant regulator. Contact [email protected] to exercise these rights; we may need to verify your identity first. We will not discriminate against you for exercising them.
You can turn off scoring-related cloud analysis in Settings (Scoring data sharing), which stops new analysis audio from being sent. You can withdraw optional product-improvement storage in Settings → Help improve Maqam. That control is separate from Scoring data sharing. Withdrawal stops new copies; it does not by itself erase copies already stored. You can turn optional product analytics (PostHog) off or on later in Settings. That control is separate from Scoring data sharing and from Help improve Maqam. Turning analytics off stops new events. To delete stored copies, analytics records, and your account, use Settings → Delete account or maqamapp.com/delete-account. We complete account deletion, including Cloudflare audio and identifiable PostHog analytics we hold, within 30 days. You can also email [email protected].
9. Children's Privacy
The App is not directed at children under 13 for an independently held account. A child under 13 may use the App only through an account created and supervised by a parent or legal guardian, who must provide verifiable consent before we collect any personal information — including Voice Data, which we treat as biometric information for children — from that child. We do not knowingly collect personal information from a child under 13 without such consent, and we do not disclose a child's personal information to external parties beyond what is integral to providing the App's core features without separate verifiable parental consent. We retain children's personal information only as long as necessary for the purpose it was collected and delete it thereafter. Parents/guardians may contact [email protected] to review, request deletion of, or refuse further collection of their child's information.
10. International Data Transfers
Your information, including Voice Data, may be processed and stored outside your country of residence, in countries with different data protection laws. Where required, we use appropriate safeguards (such as standard contractual clauses) for these transfers.
11. Third-Party Links and Services
The App may link to or integrate with external services, including sign-in and AI processing. This Policy does not apply to them; their own privacy practices govern their handling of your information.
12. Do Not Track
The App does not currently respond to "Do Not Track" signals, as no uniform standard exists.
13. Changes to This Privacy Policy
We may update this Policy at any time, in our sole discretion. We will post the revised Policy in the App and/or on our website and update the "Last Updated" date. Notifying you beyond this is a courtesy; except where applicable law requires more specific or advance notice — for example, for a material change in how we use previously collected data — we retain discretion over the method and timing of notice. Continued use of the App after a revised Policy takes effect constitutes acceptance of it.
14. Contact Us
Questions about privacy? Email [email protected].