Privacy policy

Last updated:

Sutrah is a prayer-scheduling app. It reads when you are busy so it can place prayer blocks in the gaps, and writes those blocks to your calendar. This policy explains exactly what data it receives, what it does with it, who else sees it, and how it is protected.

How we use Google user data

Signing in with Google grants two scopes. We request nothing else, and we never request access to Gmail, Drive, contacts or any other Google service.

Email, name, profile picture
From the openid email profile scopes. Used to create your account, identify you at sign-in, and send the weekly summary email if you leave it enabled. Your name and picture are only ever shown back to you.
Calendar events
From the https://www.googleapis.com/auth/calendar.events.owned scope on Google, which covers events on calendars you own, or Calendars.ReadWrite on Outlook, which covers events in your own calendars. Neither permission is limited to events Sutrah created; our code is, and it works on your primary calendar only. Used for three things and nothing else: reading the start and end times of your existing events so prayer blocks avoid them; creating, updating and deleting the prayer events Sutrah itself put on your calendar; and, only if you switch travel mode on, scanning event titles for airline codes and airport codes so prayer times can follow you to a destination.

What we keep. We do not store your other events. Their times are held in memory during a sync to work out where the gaps are, then discarded. We store only the prayer blocks we created, as a time, a status, and the identifier of the event we wrote. Travel detection stores a destination label such as “Dubai (DXB)”, never the meeting title it came from.

What we never do. We do not read your email, build advertising or marketing profiles, sell your data, or use your calendar content to train machine-learning models.

Limited Use

Sutrah’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use Microsoft user data

Signing in with Microsoft uses openid email profile offline_access Calendars.ReadWrite. It is used for exactly the same three purposes as the Google calendar scope above, with the same retention: your other events are read to find free time and are not stored.

The Meeting Guard browser extension

The extension is optional. It shows today's prayer times inside Google Calendar and warns you before you book a meeting over one. It talks only to the Sutrah deployment you point it at; there is no separate service, no third party, and no analytics inside the extension.

Stored in your browser
Your app URL, your feed token, and whether the on-page pill is shown. Nothing else. Chrome and Firefox sync extension settings between your own signed-in profiles, so these travel with your browser profile.
Sent to Sutrah
Your feed token, to identify your account, and, when you are drafting a meeting, the start and end time of that draft, so it can be checked against your prayer windows.
Read on the page, never sent
To find the time you are drafting, the extension reads the text of Google Calendar's event dialog. That text is parsed in your browser and only the start and end times leave it. Meeting titles, guest lists, descriptions and attachments are never transmitted, stored or logged.
Not collected at all
No browsing history, no page content outside calendar.google.com, no clicks, no identifiers, and no telemetry of any kind.

The feed token is the same credential as your calendar subscription URL. Anyone holding it can read your prayer schedule, so treat it like a password. Resetting the feed URL in Settings revokes it immediately, and the extension will ask for the new one.

Removing the extension deletes everything it stored. It holds no data on our side, so nothing else needs to be cleaned up.

Who we share, transfer or disclose data to

We do not sell your data, and we do not transfer it to anyone for advertising, analytics profiling, credit assessment, or model training. Google user data is shared only with the infrastructure providers below, only to operate the service, and only to the extent each one needs.

We do measure how many people reach each page, using Vercel Web Analytics. It is cookieless, sets no cross-site identifier, and does not fingerprint your device or build a profile of you. It records the page visited, the referring site and coarse device information. It never sees your calendar, your prayer times, your location or your email address, and none of it is linked to your account.

Only the path of a page is measured. Anything after the ? in the address is removed in your browser before the measurement is sent, so the coordinates in a shared timetable link, and the token in an unsubscribe link, stay on your device. If a page address cannot be reduced to a plain path, the measurement is dropped instead of sent.

Vercel (hosting)
Runs the application. Data passes through memory while a request is served. United States and global edge network.
Vercel Web Analytics
Aggregate page views and referrers. Cookieless, with no cross-site identifier and no profile. It never receives calendar content, prayer times, your location or your email.
Neon (database)
Stores your account, settings, prayer blocks and encrypted calendar tokens.
Upstash QStash (job queue)
Optional. Receives only your internal user identifier so a re-sync can be queued. It never receives calendar content.
Resend (email)
Optional. Receives your email address and the summary figures when weekly emails are enabled. No calendar content is included.
Slack
Optional and only if you connect it. Receives the status text and emoji you choose, while a prayer block is running. It never receives your other events.

A current list, with the data each one handles, is on the sub-processors page. We may also disclose data if legally required to, or to protect the safety and integrity of the service.

City search and reverse geocoding use OpenStreetMap Nominatim. Those requests are made by your browser and contain the place name or coordinates you look up. They contain no Google user data.

How we protect your data

Tokens encrypted at rest
Google and Microsoft OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written to the database, using a 32-byte key held only in the server environment. The database never holds a usable token on its own.
Plaintext copies removed
As soon as an account is linked, the plaintext access, refresh and identity tokens that the auth library writes are overwritten with null, so the encrypted copy is the only one that remains.
Encrypted in transit
All traffic is HTTPS, with HTTP Strict Transport Security enabled. Calls to Google and Microsoft are TLS.
Access control
Every read and write is scoped to the signed-in account. Sessions are signed cookies. Background jobs and scheduled tasks require a shared secret.
Minimised requests
Calendar reads request only the fields needed to find free time and to recognise our own blocks, rather than whole event records.
Subscription feed token
Your webcal address contains a secret token. Anyone holding that URL can read your prayer schedule, so treat it like a password. It grants no access to your Google account.

Retention, export and deletion

Data is kept for as long as your account exists. You can download everything we hold as a JSON file, and delete your account outright, from Settings. Deleting also removes the prayer events Sutrah wrote to your calendar, so you are not left tidying them up by hand, and deletes your encrypted tokens.

You can revoke Sutrah’s access at any time from your Google account permissions page, independently of anything you do here.

Children

Sutrah is not directed at children under 13, and we do not knowingly collect their data.

Changes and contact

If this policy changes materially we will update the date above and, where the change affects how Google user data is handled, notify signed-in users. Questions, requests or complaints: privacy@sutrah.app. Workplace administrators reviewing this app can use the IT access guide.

← Back home