Privacy Policy
Last updated: 29 August 2026
This policy describes which personal data are processed when you visit this website, its mosque pages, the TV display and the accompanying mobile app — and on what legal basis.
In short: you can use everything without an account and without providing personal data. No analytics, tracking or advertising services are used, no usage profiles are created and no data is sold. What is processed is what the operation technically requires — and what you expressly trigger, such as a notification subscription.
Section 1
Controller
The controller within the meaning of Art. 4(7) GDPR is the operator of this installation. Their name, address and contact details are in the imprint linked in the footer of every page; where a data protection contact or officer has been appointed, they are named there as well.
The developer of the software is not the controller: they do not run this installation, have no access to its data and receive no data from it (Section 17 of the terms of use).
Section 2
Principles, legal bases and voluntariness
Personal data are processed only where this is necessary for operating the services or where you have consented. The legal bases are Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning service), Art. 6(1)(a) GDPR (consent, for example for push notifications) and Art. 6(1)(c) GDPR (legal obligations).
You do not have to register or provide any personal data to use prayer times, the calendar, news, courses, adhkār or the app. There is no web analytics, no cross-site tracking, no advertising, no profiling and no automated decision-making within the meaning of Art. 22 GDPR.
Fonts and images are served by this website itself; simply opening a page establishes no connection to font or analytics providers.
Section 3
Visiting the website: server logs and hosting
When a page is opened, your browser transmits technically necessary data which the server or the hosting provider logs:
- IP address of the requesting device
- date and time of access
- the address requested and the status code
- the volume of data transferred
- the previously visited page (referrer), where transmitted
- browser type, version and operating system (user agent)
Section 4
Purpose and duration of logging
These data are necessary to deliver the page and additionally serve operational security, troubleshooting and the defence against attacks. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in stable and secure operation.
The logs arise at the hosting provider, which acts as a processor under Art. 28 GDPR, and are deleted there after a short period in accordance with its rules. These data are not combined with other data sources.
Section 5
Cookies and local storage
Only technically necessary cookies are set — none for analytics or advertising. A consent banner is therefore not required (§ 25(2) no. 2 TDDDG). In detail:
- “lang” — the language you selected, so that you need not choose it again on every visit (lifetime one year)
- session cookie of the administration area — only after a login, signed and not readable by the browser (HttpOnly), expiring after a few hours
- “event-vote-…” and “course-rsvp-…” — your own answer in a poll or course registration so that you can change it; they contain no identifier of your person
- local storage in the browser or on the device — the app's settings and, if you enabled notifications, the service worker registration
Section 6
Prayer times and place search
Prayer times are fetched a month at a time by this website's server from the AlAdhan interface (aladhan.com) and cached. What is transmitted are the mosque's coordinates and calculation settings — no visitor data.
For the place search in the administration area and in the app, the server queries the geocoding interface of Open-Meteo (open-meteo.com) with the place name entered.
For the worldwide mosque search in the app, the server queries the Overpass interface of OpenStreetMap (openstreetmap.org) for mosques in the surrounding area. Only the search area is transmitted, rounded to a coarse grid of about one kilometre — not your exact location; the result is cached.
In all cases the request is made by the server, not by your device; your IP address is not transmitted to these providers. The legal basis is Art. 6(1)(f) GDPR (displaying correct prayer times and findable mosques).
Section 7
Maps and directions
The directions button opens a maps application — such as Google Maps or Apple Maps — with the mosque's address only once you click it. Maps are not embedded into the page; without your click no connection to these providers is established. After the click their privacy policies apply.
Section 8
Embedded MAWAQIT widget
If the mosque has configured a MAWAQIT widget, the prayer times page loads a frame (iframe) from mawaqit.net. That provider thereby receives your IP address, technical details about your device and the page you opened. If no widget is configured — the default — nothing is loaded and this section is moot.
Where the operator uses the widget, they must ensure a legal basis for embedding it; depending on how it is set up, your consent is required (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
Section 9
Push notifications
If you subscribe to notifications about new posts, your browser generates a push address. What is stored is that address (endpoint), the associated encryption keys, the topics subscribed to and the time of the subscription — no name, no email address.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future: through the button on the page or in your browser's notification settings. Delivery runs through the push service of your browser or device vendor, which receives the push address and the encrypted message.
If that service reports a subscription as invalid — for instance after browser data has been cleared — the stored record is removed automatically.
Section 10
Polls and course registrations
Votes on events and registrations for courses require no account. Only a counter per answer option is stored; your own answer sits in a cookie on your device (in the app, on the device itself) so that you can change it. Attribution to a person is neither intended nor possible. The legal basis is Art. 6(1)(f) GDPR (planning the activities).
Section 11
Published content and uploaded images
News, events, courses, weekly programs and images are published by the respective mosque and may contain personal data — such as the names of speakers or people shown in photographs. The mosque is responsible for that publication; it must obtain the necessary legal basis and, for images, the consent of the people depicted (§§ 22, 23 KunstUrhG).
Uploaded images are re-encoded on the server and stored as WebP; embedded metadata such as EXIF or GPS information is not carried over.
If an image or a detail is to be removed, a message to the contact address in the imprint suffices; unlawful content is removed without delay.
Section 12
Administration area
For the people who maintain content, a username and a password hash generated with scrypt are stored; passwords are never stored in clear text. After logging in, a signed session cookie is set. The legal bases are Art. 6(1)(b) and (f) GDPR.
To fend off automated login attempts, the IP address of failed logins is counted for a short time (Art. 6(1)(f) GDPR); the counters expire by themselves shortly afterwards.
Section 13
Mobile app
The app stores your language, the mosques you subscribed to, the notification and calculation settings and the tasbih counter exclusively on your device. No account is required and no advertising identifiers are used.
For “mosques near me” the app asks for the location permission when you request it and sends the coordinates once to this website's interface in order to calculate the distances. The coordinates are not stored there; like any request, the call may appear in the server log. You can also search by name or place without a location.
Adhan alerts and adhkār reminders are scheduled and triggered locally on the device. For obtaining the app, the privacy notices of the respective app store apply in addition.
Mosque administrators can sign in inside the app to maintain their mosque's details. The username and password are transmitted to the server and checked there just as in the admin area; the device only stores a signed session token, which expires after twelve hours and is deleted on sign-out. The legal basis is Art. 6(1)(b) and (f) GDPR.
Section 14
Recipients, processors and third countries
Data are passed on to third parties only where this is necessary for operation or where a legal basis exists. Typical recipients are the hosting provider, the data storage provider, the push service of your browser vendor and — when obtaining the app — the respective app store. Which providers are used in detail is stated by the operator; contracts on commissioned processing under Art. 28 GDPR are to be concluded with them.
Where data are thereby transferred to a third country outside the EU/EEA, this occurs only on the basis of an adequacy decision or appropriate safeguards under Art. 44 et seq. GDPR, in particular the standard contractual clauses.
Section 15
Storage period and erasure
Server logs are deleted by the hosting provider after a short period. Notification subscriptions are stored until you unsubscribe or the push service reports them as invalid. Counters of polls and registrations disappear with the event or course they belong to. Published content remains stored until the mosque removes it. Administrators' credentials are deleted together with the account.
Beyond that, data are erased as soon as the purpose ceases to apply and no statutory retention obligation stands in the way. Data may persist in backups for the duration of the respective backup cycle.
Section 16
Your rights
In relation to the controller you have the right of access (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20). Consent once given may be withdrawn at any time with effect for the future (Art. 7(3) GDPR).
Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your residence or of the alleged infringement.
Section 17
Right to object
Where data are processed on the basis of legitimate interests under Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to that processing (Art. 21(1) GDPR).
If you object, the data concerned will no longer be processed unless there are compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. An objection can be sent informally to the contact address in the imprint.
Section 18
Changes to this privacy policy
This policy is amended when the processing changes — for instance because a feature is added or a service is switched. The version published on this page applies; its date is shown above the text.