Last updated: 25 July 2026
Sirat is an independent, non-commercial service operated in the United Kingdom by Mohammud Ali. The operator is the controller of the personal data described here. Contact: [email protected].
This notice covers the Sirat iOS app, sirat.uk, and the Sirat API at api.sirat.uk. Mosque Times by Sirat, including its minimal aggregate service analytics and analytics objection control, is covered by a separate privacy notice.
What Sirat uses
When you plan a journey, Sirat sends the following to the Sirat API:
- the selected origin and destination, including their labels and coordinates;
- the departure time and journey preferences; and
- the app version and technical request information needed to return and secure the service.
Nearby mosque searches send the selected coordinates and search settings. Prayer lookups send the mosque, date, and calculation settings you choose. Sirat uses these values only to provide the requested result. It does not infer or record your religion, profile you, or treat you differently because of a supposed religious belief.
Typing a place into the app uses Apple MapKit search. Apple receives the search text and approximate search region under Apple's privacy policy. Sirat receives the selected result. Sirat does not send your live device location to Apple beyond what iOS and MapKit require for the Apple service you choose.
If you choose to open Apple Maps or Google Maps, the destination and route stops are handed to that provider. Its own privacy terms then apply.
The app stores journey history, recent places, Home, Work, and preferences on your device. Sirat has no account system and does not use advertising, third-party analytics, or cross-service tracking. Apple may collect diagnostics according to the diagnostics choices on your device; Sirat does not add a third-party crash-reporting SDK.
If you email support, Sirat and the services which deliver the email receive your address, message, and anything you attach. Please do not include precise journey details or other sensitive information unless it is necessary for the question.
Why Sirat uses it
Sirat relies on legitimate interests to provide the feature you request, operate a reliable service, prevent misuse, fix faults, and answer correspondence. The information is limited, most API requests are not retained, location is optional, and there are no accounts, advertising, or behavioural profiles. Sirat may also use or preserve information where necessary to comply with law or deal with a legal claim.
Who processes it
- Hetzner, in Germany, hosts the Sirat API and its database.
- An email-service provider delivers and stores Sirat's support email.
- Cloudflare provides domain-name services. The production and staging API hostnames are DNS-only: app API requests go directly to Hetzner and are not proxied through Cloudflare. Cloudflare does proxy the public
sirat.ukwebsite and processes website visitor IP addresses, requested URLs, and security/routing data. - Apple processes MapKit search, App Store delivery, and Apple-controlled diagnostics. Google receives route information only if you choose Google Maps.
Sirat does not sell personal data. Email and other providers may process some information outside the UK under their own privacy and transfer arrangements.
How long it is kept
- A shareable journey plan stored by the API expires within seven days and can be deleted sooner from the app where the deletion succeeds.
- The API does not keep routine access logs or a durable history of ordinary planning, Nearby, or prayer requests. A pseudonymous rate-limit token is held in memory for about 60 seconds.
- Journey history, saved places, and preferences remain on your device until you delete them or remove the app. Recent places are limited to eight.
- A temporary GPX export is removed after sharing or when the app lifecycle cleans it up.
- Support correspondence is kept for up to 12 months after the matter is resolved, unless needed longer for law or an active claim. Deleted mail may remain in provider backups for up to a further 30 days.
Sirat's current API backups stay on the same Hetzner server, exclude shareable plans, and retain up to 14 daily database copies. There is currently no off-site backup.
Location permission
Location access is optional. Sirat asks for foreground access only and uses it to fill “From here” or show nearby mosques. You can enter a place manually instead and can change permission in iOS Settings. Sirat does not track background location.
Your rights
Depending on the circumstances, UK data protection law gives you rights to access, correct, erase, restrict, or object to use of your personal data, and to receive some data in a portable form. You have the right to object to processing based on legitimate interests. Because most API requests are not retained and have no account identifier, Sirat may have no stored record that can be linked back to you.
Email [email protected] to exercise a right or make a complaint. You may also complain to the Information Commissioner's Office.
Changes
Material changes will be posted here with a new date.