Imantree
Effective: September 22, 2026 · Version 4.0
The controller for Imantree is Refik Emre Ak, Stuttgart, Germany. For privacy requests, contact contact@imantree.com. Further contact details are in the Imprint.
This policy covers the website, web app and mobile apps. Imantree does not sell personal data or display third-party advertisements in the app.
For registration and sign-in, we process your name or display name, email address, a password hash or the identifier of a Google or Apple account you choose to use, language, platform, alias, profile image and account settings. You may voluntarily provide a telephone number and date of birth. We use these data to authenticate you, manage your account and provide the app (Art. 6(1)(b) GDPR). When you use social sign-in, the identity provider also processes information about the sign-in.
If you continue as a guest without registering, our server creates a pseudonymous guest account with a randomly generated internal email address. We process an internal user identifier, platform, token and trial status, and the server features used with that guest account. Guest use is therefore not anonymous; server access also produces the connection data described in section 13.
Prayer records and reminders, Dhikr and Dua activity, Quran and Hifz progress, quiz, task, I’rab and Mufradat results, points, streaks, school of thought, Iman-Tree, school progress and contributions to religious groups can reveal religious beliefs and practice. They are special categories of personal data under Art. 9(1) GDPR.
Supported progress data remains on your device unless you grant separate permission. If you explicitly enable religious cloud sync, we store and sync the designated data with your account. The legal bases are Art. 6(1)(a) and Art. 9(2)(a) GDPR. The decision is stored in the account with the consent version and time. Local features remain available without cloud permission where they do not technically require a server feature.
You can withdraw permission in your profile for future processing. This deletes progress and contribution data assigned to the religious cloud. Withdrawal does not automatically end a family membership or related Premium seat, revoke an existing public certificate, or erase an existing real-world tree planting order and its proof. These activities have separate purposes and may be reviewed and, where applicable, erased or restricted through account deletion or a privacy request.
Older accounts may already have religious progress data on our server from earlier app versions. Without the new permission, we do not use those data for cloud features or send them back to your devices. We are reviewing how to clear these older records separately. You can request deletion at any time via contact@imantree.com.
Friend search may make accounts discoverable by name, alias or nine-digit user code. Depending on the feature, other users may see your name or display name, alias, profile image, friendship status, Premium status and shared activity. In family, Cemaat, Dhikr groups, duels and leaderboards, members may see membership, role, points, contributions, progress, duel data and results where the relevant feature requires it. Religious server-side group content requires religious cloud permission.
A Halal assessment submitted to the community is stored with your account and the relevant product. Imantree displays only aggregated votes publicly, not an individual voting profile. Submitting this type of religious assessment requires religious cloud permission. Content you voluntarily share through community features may be visible to the users identified by that feature.
For a Cemaat verification application, we process organization and location details, contact person, telephone number, free-text notes and any supporting evidence. Authorized administrators review these details; the Imam and Naib can see the processing status. Contact details and internal notes are not shown to ordinary members. These applications currently have no uniform automatic deletion period.
Automatically generated leaderboard posts for external social media contain anonymous rank labels only. Names, aliases, individual scores and award titles are not sent to X, Instagram, Telegram or WhatsApp for these posts.
If you open an official social-media link or the external design credit, you leave Imantree. The selected provider, such as X, Instagram, Facebook, TikTok, WhatsApp or pycie.com, receives your IP address, browser and connection data and the requested address under its own terms.
If you open a sharing feature yourself, Imantree prepares a text or link for the selected content. Depending on the feature, it may contain a tree level and points, a certificate link with user identifier, quiz result, Cemaat name and invitation code, or a partner link. This content is passed to the selected app, such as WhatsApp or another operating-system sharing target, when you open or send it; the recipient's terms then apply.
The app uses your location for prayer times, Qibla and, if requested, the mosque finder. After you grant device location access, the app checks location at launch, when it returns to the foreground and about every 15 minutes during active use. It updates the locally saved location after a move of about 5 km; a manually selected location disables this automatic change. While the Qibla screen is open, the app may additionally use live device location and refresh the display after a movement of about 150 metres or roughly 20 seconds.
For IP-based location, location search, geocoding, time zone, mosques and prayer times, your IP address, search location or coordinates may go directly from your device or through our server to ipapi.co, BigDataCloud, Nominatim or OpenStreetMap, Overpass and Aladhan. When you view a map, your device loads map tiles from OpenStreetMap or, if configured, CARTO. These providers receive the location and connection data needed for the request, including your IP address and the map area displayed.
If you expressly choose “Open in Google Maps” for Qibla or a mosque, your device passes the selected destination or coordinates to Google Maps. For the Fazilet Takvimi prayer-time method, our server sends the resolved district identifier and language to Fazilet Takvimi; the service also receives our server's technical connection data.
Location processing for the feature you request is based on Art. 6(1)(b) GDPR. If you enable server-based prayer reminders and religious cloud sync, we store rounded coordinates with push settings, time zone and device identifier on the server. Rounding reduces precision but does not make the data anonymous. You can revoke device location access and disable reminders in the app.
For Quran content and search, your device requests data directly from alquran.cloud; the search term or requested verse and edition, together with your IP address and technical connection data, are transmitted. For further Quran content, the verse and edition may be sent directly to Quran Foundation or quran.com. When you retrieve Risale facsimiles or audio, risalekulliyati.com receives the selected book, page or audio file and your connection data.
If you open an external source for Quran, Hadith, Fiqh, prayer or learning content, the relevant page is opened, for example at Quran Corpus, quran.ksu.edu.sa, Sunnah.com, HadeethEnc, SeekersGuidance, IslamQA.org, DarulIftaa.com, IslamWeb or data.nur.nu. The provider receives in particular your IP address, browser data and the requested address; the selection may reveal a religious interest.
For Quran audio you request, our server retrieves the selected audio file from MP3Quran or Islamic Network and relays it to your device. The audio provider receives our server's IP address and the requested file, not your account or device identifier directly. If our audio mirror is unavailable, your device may retrieve the fallback file directly from MP3Quran; that provider then receives your device's IP address, user agent and technical connection data.
When you start text-to-speech for a prayer or learning text, our server sends the selected text and target language to Google Translate Text-to-Speech and returns the generated audio file to your device. Selecting this content may reveal religious interests. These requests occur only when you use the relevant content, search or text-to-speech feature.
When you open the Zakat calculator, your device requests current exchange rates directly from finans.truncgil.com. The provider receives your IP address and connection data and can technically infer that the request came from this feature; the asset values you enter are not sent to that service.
For push notifications, depending on the platform, we process a Web Push subscription or an FCM/APNs token, device identifier, platform, language, time zone, permission and activity status, and your notification preferences. Prayer reminders also use the rounded coordinates. The title and content of the relevant account, service, prayer or feedback notification pass through Google's Firebase Cloud Messaging or Apple Push Notification service to your device. Optional push notifications are based on your consent (Art. 6(1)(a) GDPR), which you can withdraw in the app or device settings.
For Ask Imam, we process your question, language and conversation history. After your separate explicit AI consent, the app may also send selected context from your device, such as prayer progress, Dhikr count or school of thought; cloud sync is not required for this transmission. If religious cloud permission is also active, the server may supplement missing context from your cloud profile. Depending on server configuration, we send this input to NVIDIA, Google Gemini or OpenAI to generate an answer. Questions and answers are stored as a chat session with topic labels, consent version and any feedback you submit; guest chats are linked to a session identifier. If you request scholar review, authorized administrators or scholars can see the question, AI answer and, for accounts, your name and email address. A human answer, the reviewer's identifier and the review time are stored with the chat session; push notifications may be sent about the review. New requests do not create a separate training record or a personal profile derived from chat content.
After explicit AI permission, the Halal Scanner's AI analysis sends only the selected ingredient or E-number text, language and possibly school of thought to the configured AI service, not the camera image. Personalized AI suggestions may use limited context for which you have given permission. Optional AI processing is based on Art. 6(1)(a) GDPR and, for religious information, also Art. 9(2)(a) GDPR. Withdrawal applies to future requests; you may separately exercise your rights concerning stored chat sessions.
The Hifz voice check requires both religious cloud permission and separate explicit consent for voice recordings. The raw microphone recording goes through our server for the single automated transcription and answer-matching request you initiate to OpenAI Ireland Ltd. / OpenAI LLC as the service provider for optional Hifz voice evaluation, or to Groq LLC only when the configured Groq fallback is enabled. Imantree does not permanently store the recording; the transcript and recognized result may become part of your Hifz progress. You can decline the voice feature, continue the Hifz test with manual answers and withdraw your AI consent at any time for future processing.
If you use speech input provided by your browser or operating system, the browser or platform provider may process audio or a transcript under its own terms. The processing depends on your browser, device and system settings. Text input is available as an alternative.
Camera frames and OCR for the current scan are processed on your device; Imantree does not upload a photo to its server for this purpose. When you scan a barcode, your device requests product data directly from Open Food Facts, Open Beauty Facts or Open Products Facts. These services receive the barcode and, as a technical consequence, your IP address and other connection data. Scan history and cached product data remain locally on your device until you delete them there or remove the app data.
If you voluntarily submit a community assessment, the product, assessment and reason are stored with your account on the Imantree server; only the aggregated voting result is shown publicly. The permissions and information in section 8 also apply to AI analysis.
An issued I’rab certificate contains the holder's real name, module, score, issue date and serial number. The verification page and PDF are available without sign-in to anyone who knows the serial number or associated link. The information is therefore publicly accessible and recipients can share or copy it. Issuing a certificate requires religious cloud permission.
For a real-world tree planting order, we process the name, email address, optional telephone number, religious points spent, order and processing status, and certificate and proof data. Registered partner organizations that can take open orders see the information required to select and fulfil an order, in particular the name, tree type, certificate number and order date. The assigned organization also processes planting and image or video proof.
To notify a partner about a new order, Imantree may open a data-minimized message without personal data in WhatsApp. If an administrator exceptionally contacts you about an order through WhatsApp, WhatsApp or Meta processes your phone number, connection data and message content. The regular follow-up channel is an in-app push notification.
If proof is uploaded to YouTube, Google hosts it as “unlisted” by default. The recipient's name and certificate number may appear in the title or metadata. The video is normally absent from public search but can be opened and shared by anyone with the link. When the embed loads through youtube-nocookie.com, Google receives in particular the IP address, user agent and other connection data; “privacy-enhanced mode” does not make the request anonymous. Because the order is linked to religious points, it requires religious cloud permission. Withdrawing cloud permission alone does not erase a completed order or proof.
With your separate optional analytics consent, Imantree records internal events such as screen and feature views and the start of checkout. Screen and feature names may reveal which religious content you use. The events are stored on our server with your user identifier and limited metadata and are therefore personal data, not anonymous data. The legal bases are Art. 6(1)(a) GDPR and, because religious information may be revealed, also Art. 9(2)(a) GDPR. You can withdraw analytics consent in Privacy settings. We do not use an external advertising or analytics SDK for this.
The optional “For You” feature builds a local profile on your device from selected activities, topic labels and feedback. You can disable individual sources or turn personalization off. The raw text of your questions is not added to this local profile.
Web payments are handled by Stripe. In mobile apps, purchases are managed through Google Play or Apple's App Store and RevenueCat. Depending on the purchase route, these providers process payment and transaction data; Imantree receives identifiers, product, subscription status and events needed to grant and manage Premium access. RevenueCat sends us webhook and transaction data about purchases, renewals, cancellations and entitlement status. Full card details are not stored on our server. The basis is Art. 6(1)(b) GDPR; transaction and accounting records required by law are processed and retained under Art. 6(1)(c) GDPR.
If you join the partner program, we process your partner name, contact address, discount code, commission information and payout details to administer and settle the partner agreement (Art. 6(1)(b) GDPR).
We use your email for required account and service messages, including verification, sign-in, password resets and replies to support requests (Art. 6(1)(b) GDPR). Messages are sent through IONOS SE's SMTP service. We send promotional email only with valid consent or under the conditions of § 7(3) German UWG; you may object at any time.
When you submit feedback or contact support, we process the information you provide. The feedback form may collect name, email address, message, category, platform, app version, screen and user agent. Authorized administrators can view this content and sender information; a new submission may be shown to them through a push or real-time notification.
Our server is hosted by IONOS SE. The server and hosting provider process IP address, user agent, technical request and device information, possibly a security fingerprint and actor identifier, timestamps and security events when the app is accessed. This supports operation, error resolution, abuse prevention and security under Art. 6(1)(f) GDPR.
If optional error diagnostics are enabled for a deployment, Sentry, Inc. receives error and performance data such as the error message, stack trace, app version, environment, requested URL path without query parameters, a user identifier and, on the web, possibly a masked email address. Cookies, authorization headers and full IP addresses are not sent by default. We use this for error analysis and service stability under Art. 6(1)(f) GDPR; retention follows the configuration of the Sentry project.
Depending on the feature used, the following recipients receive the data required for their role: IONOS for hosting and email; Google and Apple for sign-in, push, app purchases, Google Maps, Google Translate Text-to-Speech and possibly YouTube; Google Gemini, NVIDIA and OpenAI for approved AI features and Groq only for the configured Hifz fallback; Stripe and RevenueCat for payments and subscriptions; Sentry when error diagnostics are enabled; ipapi.co, BigDataCloud, OpenStreetMap/Nominatim/Overpass, Aladhan, Fazilet Takvimi and CARTO for location, prayer time and map services; alquran.cloud, Quran Foundation/quran.com, Quran Corpus, quran.ksu.edu.sa, MP3Quran, Islamic Network, risalekulliyati.com, Sunnah.com, HadeethEnc, SeekersGuidance, IslamQA.org, DarulIftaa.com, IslamWeb and data.nur.nu for requested or opened religious content; finans.truncgil.com for exchange rates; Open Food Facts, Open Beauty Facts and Open Products Facts for barcode requests; X, Meta/Instagram/Facebook/WhatsApp, TikTok and pycie.com when you open a corresponding external link, shared content or order-related message; and partner organizations involved in a tree planting order. Other users or the public receive the information described in sections 4 and 10.
Some providers process data under their own responsibility. Transfers outside the European Economic Area, particularly to the United States, may occur. The applicable transfer mechanism depends on the provider and service, such as an adequacy decision or appropriate safeguards under Art. 46 GDPR. You can request details of a particular recipient and the mechanism used by contacting contact@imantree.com.
Account data is generally needed while the account exists. Religious cloud data is retained until cloud permission is withdrawn or the account is deleted, except where a separate activity described in section 3 applies. Analytics events are deleted after 180 days. Push registrations are removed when you unsubscribe or after 180 days without contact from the device. Structured audit and security events have a technical deletion period of 365 days.
There is currently no uniform automatic deletion period for chat sessions, guest chats, feedback, support data and server logs; they are stored according to purpose, necessity and legal obligations. Public certificates are removed from Imantree's system when the account is deleted; we cannot retrieve copies already downloaded or held in external caches. Real-world tree planting orders and proof may remain necessary for fulfilment, complaints and evidence and currently have no uniform automatic deletion period.
Payment, tax and partner records subject to statutory retention duties remain stored for the required period. Under § 147 German Fiscal Code, this may in particular mean eight years for accounting vouchers and ten years for books and annual financial statements. Data held by external recipients is subject to their own deletion duties. Withdrawal does not affect the lawfulness of processing before withdrawal.
The web app uses necessary cookies or similar technologies for sign-in and protection against forged requests, and local device storage for language, settings, tokens, cache and offline features, local progress, scan history and optional personalization. Local data generally remains until you delete it in the app, clear browser or app data, or uninstall the app.
Under § 25 German TDDDG, access to or storage on your device that is not strictly necessary for a service you request requires prior consent. Any subsequent processing of personal data is also governed by the GDPR.
Subject to the GDPR's conditions, you have rights of access, rectification, erasure, restriction and portability (Arts. 15–20 GDPR). You may object to processing based on legitimate interests under Art. 21 GDPR and to direct marketing at any time. You may withdraw consent at any time for the future. Contact contact@imantree.com. You can also remove your account via Delete account.
You may complain to a data protection supervisory authority. The authority for the controller in Baden-Württemberg is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg. The AI features described here do not make solely automated decisions with legal or similarly significant effects under Art. 22 GDPR.
Consent-based features are not intended for children to use without the required approval. In Germany, Art. 8 GDPR generally sets an age of 16 for a child's own consent to a directly offered information society service. Below that age, consent from a holder of parental responsibility is required. Parents and holders of parental responsibility may contact us to request access or deletion.