EU Privacy Notice (GDPR)

Effective: 3 August 2026 · Version 1.1

Controller: TAFSIR MIND service, Türkiye
Privacy and data rights: privacy@tafsirmind.com
Technical support: support@tafsirmind.com

Scope

This notice explains how TAFSIR MIND processes personal data in its web and mobile Quran study applications when the EU General Data Protection Regulation applies. It supplements the detailed Turkish privacy policy. TAFSIR MIND is not an official Quran Foundation application.

Data, purposes, legal bases and retention

Data and purposeGDPR basisRetention
Name, email, account identifiers and profile details for registration, sign-in, membership access, security and supportContract; legitimate interests in service security; legal obligation where applicableWhile the account is open, then removed from active systems after deletion
Notes, bookmarks, saved words, reading state, preferences and interactions for the personal study archive, sync and requested app functionsContract for requested functions; where the content reveals religious or philosophical beliefs, the applicable Article 9 condition, including explicit consent where requiredUntil the user deletes the content or account
Friend links, invitations, live lessons and lesson archives for one-to-one lessonsContract; legitimate interests in abuse prevention; explicit consent for sensitive live processing where requiredUntil the related lesson or account is deleted
Live microphone audio transmitted through LiveKit and transcribed by DeepgramBoth participants’ separate, versioned explicit consentProcessed during the live session; TAFSIR MIND does not create a raw-audio file
Lesson transcripts and messages shown in both participants’ archivesExplicit consent for live processing and the requested archive functionUntil the related lesson or participant account is deleted
User-initiated AI input and output for explanations, translations and summaries; limited usage records for quota and abuse controlsContract for the requested feature; legitimate interests in security; the applicable Article 9 condition for sensitive contentWhile associated with the account; OpenAI requests are sent with persistent response storage disabled
IP address, device, error and security records for delivery, troubleshooting and protectionLegitimate interests in secure and reliable service; legal obligation where applicableNormally no more than 90 days, longer only for a security incident or legal requirement

Study notes, searches and transcripts may reveal religious or philosophical beliefs and therefore can be special-category data. We do not use this content for advertising, cross-service tracking or profiling.

Recipients and international transfers

We use Supabase for authentication, database and server functions; LiveKit for live audio transport; Deepgram for live speech-to-text; OpenAI for user-requested AI features; Google or Apple for sign-in chosen by the user; Google Fonts for app typefaces, which may receive an IP address and standard web request information; and hosting/CDN providers for secure delivery. These providers may process data in Türkiye, the European Economic Area or the United States.

Where required, transfers use an adequacy decision, data-processing agreement, Standard Contractual Clauses or another lawful safeguard. Ask privacy@tafsirmind.com for information about the safeguard relevant to your data or a copy of it.

Your rights

You may have the rights to be informed, access your data, correct inaccurate data, erase data where the conditions apply, restrict processing, receive data you provided in a machine-readable format and transfer it where applicable, and object to certain processing. We do not make decisions based solely on automated processing that produce legal or similarly significant effects.

You may withdraw consent at any time for the future without affecting processing that was lawful before withdrawal. You can decline live lesson processing or withdraw by leaving the lesson. You can export data and delete your account in the app. You can also send a request from your account email address to privacy@tafsirmind.com.

We respond without undue delay and normally within one month. We may request limited information to verify identity, but we will not ask for your password or one-time sign-in code. If we extend the deadline or refuse a request, we will explain why and describe available remedies.

You may complain to the data protection authority in the EU/EEA country where you live, work or believe an infringement occurred, and you may seek a judicial remedy. The European Data Protection Board member list identifies national authorities.

Deletion, storage, cookies and security

Deleting an account starts removal from active systems. Ordinary backup copies rotate out within 30 days. Limited records required by law or security audits are isolated and deleted or irreversibly anonymised when their purpose expires. See the account deletion page.

We currently use only authentication, security, preference, offline-data and performance storage required for requested functions. We do not use advertising, marketing or analytics cookies. “Understood” on the in-app notice only dismisses that notice; it is not consent. See the cookies and device storage notice.

We use encryption in transit, access controls, row-level security, rate limits and data minimisation. No system is completely secure. Report security issues to security@tafsirmind.com.

Children and changes

The service is not directed to anyone under 18. If we learn that an under-18 user has created an account, we will take steps to delete the account and related data. If this notice changes materially, we will provide notice in the app or on this page and request fresh consent for any new purpose that requires it.