Privacy Policy
Comma Labs Yazılım Anonim Şirketi ("Comma Labs," "we," "us," "our") makes the Prayer Journal application ("App"), published in Turkish as Dua Defteri. This Privacy Policy explains what the App handles, where it goes, and what rights you have. In short: your notebook stays on your phone, there is no account to create, and there is no advertising or tracking of any kind. One thing does leave your device, and it is the important one: the sentence you write before a prayer is composed. Sections 3 to 5 are about that, and they are the ones to read.
Data controller. Comma Labs Yazılım Anonim Şirketi, TOBB ETÜ TTO Garaj, Söğütözü, Ankara, Türkiye. Contact: hello@commalabs.co
1. What We Collect About You
Nothing about your use of the App. We do not receive, transmit or store any record of what you prayed for, when you opened the App, how often you use it, or what is in your notebook. There are no analytics, attribution, advertising or crash-reporting services in the App.
We hold no profile of you. There is nothing to build one from: the App never learns your name, your email address, your location or your phone number.
1.1 What the App does not touch
- No location, contacts, photos, camera, microphone, calendar or health data
- No advertising identifier (IDFA), and no App Tracking Transparency prompt, because nothing is tracked
- No analytics, attribution, advertising or crash-reporting SDK of any kind is present in the App
- No address book, no social graph, and nothing about any other app on your phone
2. What the App Keeps on Your Device
The notebook is a file inside the App's own sandboxed container. It holds:
- Every prayer you have kept: its text, its title, the date, the subject the App matched it to, and whether it was composed for you or written by you
- The answer you gave to the question about what you hold onto when things are hard, stored as one of a small set of values rather than as your own words
- Your chosen language, whether a daily reminder is on and at what time, whether sound and haptics are on, and how many prayers you have made this week
None of that is transmitted to us. We have no copy of your notebook, no backup of it, and no way to read it.
Two things are kept in the iOS Keychain rather than that file, because they are credentials rather than your own content: the identifier Apple returns if you sign in with Apple, and a token that lets the App renew the anonymous session described in section 7.
3. The Sentence You Write
When you ask for a prayer, the text you typed is sent over an encrypted connection to a function we operate, which passes it to a language model that writes the prayer. The prayer comes back and the App shows it to you.
We do not store it. The function keeps no record of what you wrote or of what was written back: no database row, no log line, no history, no profile. It is read, answered and gone. This is a constraint on how the function is built, not a setting that could be switched.
What is sent with it: the language to answer in, and nothing else. No name, no email, no device identifier, no location, no list of your other prayers, and nothing from your notebook.
Because that sentence is your own writing and can be about anything, two things are worth saying plainly. Write only what you are willing to have processed this way; and if you would rather nothing left the device at all, turning off the network works — the App has a complete offline composer built into it and will simply use that instead, with no error and no difference in how it behaves.
4. Artificial Intelligence
The prayers are composed by a large language model operated by Google LLC. We do not call Google directly: the request goes to Features and Labels, Inc. (fal.ai), who route it onward through OpenRouter, Inc. to Google. For that feature, and only that feature, the sentence you wrote passes through those three companies. That data:
- Is sent without anything that identifies you, and is not linked to an account, a device or a person
- Is processed only for as long as it takes to generate the reply, and is not retained by us afterwards
- Is never used for advertising, profiling, or any purpose other than composing the prayer you asked for
We do not promise that no company in that chain uses the sentence to improve its models, because that is not something we can verify at every link. What we can tell you is the chain itself, which is why it is named above. Each company's handling is governed by its own terms, and Google's by Google's Privacy Policy.
The model is given the App's own instructions and your sentence; it is not given access to anything else.
No other AI service is used, and no other feature of the App sends anything to a model.
5. Religious and Other Sensitive Data
This App is about prayer, so using it says something about your religious belief. Under Article 9 of the GDPR and Article 6 of the Turkish Personal Data Protection Law, religious belief is a special category of personal data and gets stricter treatment. What you write may also touch on health, family, bereavement or other sensitive matters, because those are the things people pray about.
Our answer to that is structural rather than procedural: we do not keep any of it. Your prayers and the subjects they concern stay on your device, we hold no copy, and the sentence you write is not retained after the prayer is composed. There is no database of ours in which your beliefs, your health or your circumstances are recorded, and therefore nothing of that kind to disclose, transfer, sell or lose.
What briefly leaves your device is described in sections 3 and 4, is not linked to your identity, and exists only for the moment the prayer is being written.
6. Legal Basis for Processing
For users in the EU, the UK and Türkiye:
- Your explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a); KVKK Art. 6) for sending the sentence you write to be composed into a prayer. You give it by writing something and choosing to send it, and you withdraw it by not doing so, or by using the App offline. Nothing is sent before you tap send.
- Performance of a contract (GDPR Art. 6(1)(b)) for handling a subscription you have bought.
- Legitimate interests (GDPR Art. 6(1)(f)) for the daily counter described in section 7, whose sole purpose is to keep the service available to everyone. It holds no content and is not linked to you.
Withdrawing consent does not make the App stop working. It composes offline instead.
7. The Anonymous Account
Before it can reach the function, the App signs in anonymously. This is not an account in any ordinary sense: there is no email address, no password, no name, and no sign-up step you ever see. It produces a random identifier and a renewal token, held in the systems of Supabase Inc., who host the function for us.
That identifier exists for one reason. It lets us count how many times a single device has asked for a prayer in a day, so that one script cannot exhaust the service for everybody else. One row is kept per identifier per day, and it holds a date and a number. It never holds anything you wrote.
The identifier is not linked to you, to your Apple Account, or to anything in your notebook. Deleting the App and reinstalling it produces a new one.
8. Sign in with Apple and Purchases
Signing in is optional everywhere in the App and nothing is withheld if you never do. Your notebook does not move when you sign in, because it never leaves the device in the first place.
If you do sign in, the App receives and keeps one thing: the user identifier Apple issues. Your name and email address are not requested, so they are never received. Signing out deletes that identifier from the Keychain, and you can revoke the App at any time in Settings › your name › Sign in with Apple.
Full Access is sold through Apple's In-App Purchase system using StoreKit. Apple processes the transaction. We never see, receive or store your payment card details, billing address or Apple Account credentials. The App asks Apple directly whether the Apple Account signed in on the device holds a valid entitlement; there is no purchase-tracking service such as RevenueCat in the App, and no third party is involved in that check. Apple's handling is governed by Apple's Privacy Policy.
9. Data Sharing
Four processors, no others:
- Supabase Inc. (United States) hosts the function and the anonymous sign-in described in section 7.
- Features and Labels, Inc. (fal.ai) (United States) carries the request to the model, as described in section 4.
- OpenRouter, Inc. (United States) routes it from fal.ai to the model operator.
- Google LLC (United States) operates the model that writes the prayer, as described in section 4.
Each acts as our data processor under a data processing agreement. There are no advertising partners, no analytics vendors and no data brokers involved in the App. We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we have never done so.
We may disclose information if compelled by a court order or other binding legal obligation, but there is very little that could be disclosed: your notebook is not ours to hand over, and what you wrote was not kept.
10. Retention and Deletion
- What you write: not retained at all, by us or on our behalf, once the prayer has been composed.
- Daily counters (section 7): hold no content, and are deleted once the day they count has passed.
- The anonymous identifier (section 7): deleted when you use Delete account in the App, and in any case carries nothing about you.
- The Apple identifier (section 8): deleted from your device when you sign out or delete the App.
- Your notebook: stays on your device until you remove it. There is nothing for us to delete on request, because we never had it.
The App's menu has a control that erases the notebook, every setting and every scheduled reminder, permanently. Deleting the App removes all of it too. Both are irreversible: there is no backup of ours to restore from, and no account to close.
11. Your Rights
Under the Turkish Personal Data Protection Law No. 6698 (KVKK), the EU and UK General Data Protection Regulation (GDPR), and comparable laws including the CCPA, you have the right to:
- Ask what personal data we hold about you, and obtain a copy
- Have inaccurate data corrected, or data erased
- Restrict or object to processing, and receive your data in a portable form
- Withdraw consent at any time, without affecting anything already done
- Not be discriminated against for exercising any of these
In practice the honest answer to most of these is that there is nothing held. Comma Labs holds no profile of you and nothing connected to your identity. Your prayers are under your direct control on your own device at all times.
Write to hello@commalabs.co with any request and we will answer within 30 days. You also have the right to lodge a complaint with your local supervisory authority; in Türkiye that is the Personal Data Protection Authority (KVKK Kurumu).
12. Children's Privacy
The App is not directed to children and we do not knowingly collect information from anyone, including children under 13 (or under 16 in parts of the EU, and the equivalent age under COPPA and local law). If you believe a child has provided information through the App, write to us and we will look into it, though there is by design nothing held that could identify them.
13. International Transfers
The processors named in section 9 are in the United States, and the sentence you write is processed there. Those transfers are covered by the data processing terms we have agreed with each of them, which incorporate the European Commission's Standard Contractual Clauses.
Nothing else is transferred anywhere, because nothing else leaves your device. Purchase transactions are carried out by Apple under Apple's own terms and transfer arrangements.
14. Security
- In transit: every connection the App makes is encrypted with TLS. The App makes no unencrypted requests.
- At rest on your device: your notebook sits in the App's sandboxed container, protected by iOS file-level encryption, which is active whenever the device is locked with a passcode, Face ID or Touch ID. Credentials are held in the iOS Keychain.
- On our side: the function that composes prayers holds no user data at all, and the only stored value is the counter described in section 7, which is unreadable to any client.
No system is completely secure, but the strongest protection here is architectural: because we keep no copy of what you write, there is no database of ours that a breach could expose. If a breach ever did affect data relating to you, we would notify you and the relevant authority within the periods the law requires. The most effective protection you can apply is a device passcode.
15. No Automated Decisions About You
A model writes text at your request. It does not make any decision that produces a legal effect or similarly significantly affects you, within the meaning of Article 22 of the GDPR. Nothing in the App scores, ranks, profiles or classifies you, and nothing it produces is used to decide anything about you.
16. Third-Party Links
The App and these pages link to a small number of outside sites, such as Apple's and Google's policies and the support address. We are not responsible for the privacy practices of sites we do not operate, and we suggest reading their policies before using them.
17. What the App Is Not
The prayers the App composes are written by a language model. They are not scripture. The App does not quote or paraphrase the Qur'an or hadith, does not cite a surah or an ayah, and gives no religious ruling. It also gives no medical, legal or psychological advice. This bears on privacy insofar as it explains why the App has no need for, and never asks for, anything about your health, your family or your circumstances beyond the sentence you choose to type.
18. Legal Compliance
This policy is written to comply with:
- Türkiye: Personal Data Protection Law No. 6698 (KVKK)
- European Union and United Kingdom: General Data Protection Regulation (GDPR)
- United States: California Consumer Privacy Act (CCPA/CPRA) and Children's Online Privacy Protection Act (COPPA)
- Apple's App Store privacy requirements and privacy manifest rules
19. Apple Privacy Disclosures
The App's App Store privacy label declares one item: other user content, used for app functionality, not linked to you and not used for tracking. That is the sentence described in section 3. The App ships a privacy manifest declaring its use of the User Defaults API, whose only purpose is to store the App's own settings on your device.
20. Changes
If this policy changes, this page is updated and the date at the top changes with it. Any material change, in particular the App beginning to keep what you write, would be disclosed clearly inside the App before it took effect.
21. Contact
Comma Labs Yazılım Anonim Şirketi
TOBB ETÜ TTO Garaj, Söğütözü, Ankara, Türkiye
hello@commalabs.co