Privacy policy
Last updated:
Sutrah is a prayer-scheduling app. It reads when you are busy so it can place prayer blocks in the gaps, and writes those blocks to your calendar. This policy explains exactly what data it receives, what it does with it, who else sees it, and how it is protected.
How we use Google user data
Signing in with Google grants two scopes. We request nothing else, and we never request access to Gmail, Drive, contacts or any other Google service.
- Email, name, profile picture
- From the
openid email profilescopes. Used to create your account, identify you at sign-in, and send the weekly summary email if you leave it enabled. Your name and picture are only ever shown back to you. - Calendar events
- From the
https://www.googleapis.com/auth/calendar.events.ownedscope on Google, which covers events on calendars you own, orCalendars.ReadWriteon Outlook, which covers events in your own calendars. Neither permission is limited to events Sutrah created; our code is, and it works on your primary calendar only. Used for three things and nothing else: reading the start and end times of your existing events so prayer blocks avoid them; creating, updating and deleting the prayer events Sutrah itself put on your calendar; and, only if you switch travel mode on, scanning event titles for airline codes and airport codes so prayer times can follow you to a destination.
What we keep. We do not store your other events. Their times are held in memory during a sync to work out where the gaps are, then discarded. We store only the prayer blocks we created, as a time, a status, and the identifier of the event we wrote. Travel detection stores a destination label such as “Dubai (DXB)”, never the meeting title it came from.
What we never do. We do not read your email, build advertising or marketing profiles, sell your data, or use your calendar content to train machine-learning models.
Limited Use
Sutrah’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we use Microsoft user data
Signing in with Microsoft uses openid email profile offline_access Calendars.ReadWrite. It is used for exactly the same three purposes as the Google calendar scope above, with the same retention: your other events are read to find free time and are not stored.
The Meeting Guard browser extension
The extension is optional. It shows today's prayer times inside Google Calendar and warns you before you book a meeting over one. It talks only to the Sutrah deployment you point it at; there is no separate service, no third party, and no analytics inside the extension.
- Stored in your browser
- Your app URL, your feed token, and whether the on-page pill is shown. Nothing else. Chrome and Firefox sync extension settings between your own signed-in profiles, so these travel with your browser profile.
- Sent to Sutrah
- Your feed token, to identify your account, and, when you are drafting a meeting, the start and end time of that draft, so it can be checked against your prayer windows.
- Read on the page, never sent
- To find the time you are drafting, the extension reads the text of Google Calendar's event dialog. That text is parsed in your browser and only the start and end times leave it. Meeting titles, guest lists, descriptions and attachments are never transmitted, stored or logged.
- Not collected at all
- No browsing history, no page content outside calendar.google.com, no clicks, no identifiers, and no telemetry of any kind.
The feed token is the same credential as your calendar subscription URL. Anyone holding it can read your prayer schedule, so treat it like a password. Resetting the feed URL in Settings revokes it immediately, and the extension will ask for the new one.
Removing the extension deletes everything it stored. It holds no data on our side, so nothing else needs to be cleaned up.
How we protect your data
- Tokens encrypted at rest
- Google and Microsoft OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written to the database, using a 32-byte key held only in the server environment. The database never holds a usable token on its own.
- Plaintext copies removed
- As soon as an account is linked, the plaintext access, refresh and identity tokens that the auth library writes are overwritten with null, so the encrypted copy is the only one that remains.
- Encrypted in transit
- All traffic is HTTPS, with HTTP Strict Transport Security enabled. Calls to Google and Microsoft are TLS.
- Access control
- Every read and write is scoped to the signed-in account. Sessions are signed cookies. Background jobs and scheduled tasks require a shared secret.
- Minimised requests
- Calendar reads request only the fields needed to find free time and to recognise our own blocks, rather than whole event records.
- Subscription feed token
- Your webcal address contains a secret token. Anyone holding that URL can read your prayer schedule, so treat it like a password. It grants no access to your Google account.
Retention, export and deletion
Data is kept for as long as your account exists. You can download everything we hold as a JSON file, and delete your account outright, from Settings. Deleting also removes the prayer events Sutrah wrote to your calendar, so you are not left tidying them up by hand, and deletes your encrypted tokens.
You can revoke Sutrah’s access at any time from your Google account permissions page, independently of anything you do here.
Children
Sutrah is not directed at children under 13, and we do not knowingly collect their data.
Changes and contact
If this policy changes materially we will update the date above and, where the change affects how Google user data is handled, notify signed-in users. Questions, requests or complaints: privacy@sutrah.app. Workplace administrators reviewing this app can use the IT access guide.