Privacy
App Privacy Policy
This policy covers the Qissora app on your phone. The website has its own, shorter policy.
App: Qissora — Kids Islamic Audio Stories
Publisher: Imaan and Akhlaq Talks (Private) Limited, Islamabad, Pakistan
Effective date: 20 September 2026
The short version
Qissora has no ads, no analytics, no crash reporting and no third-party tracking, and we run no server that stores anything about you.
The app uses the internet for three things: it streams the stories from our own audio host, it lets a parent sign in with Google, and it sells the Premium subscription through Google Play. Each is described below.
Everything the app remembers about your family — the child’s name, favourites, listening progress, the parents PIN — stays on the phone.
What the app sends over the internet
- A request for a story’s audio, to
audio.qissora.app, our own host. The stories are not bundled inside the app; they are fetched when played. - A Google sign-in, to Google, if a parent chooses to sign in. It is used to find a Premium subscription belonging to that Google account.
- A subscription purchase or restore, to Google Play, to sell and check Qissora Premium.
About the audio requests
Like any request to any website, a request for a story carries the device’s IP address and reaches our host’s standard server logs. We do not attach a name, an account or an identifier of our own to those requests, we do not build a profile from them, and the app sends nothing about the child with them. A story is kept on the phone the first time it plays, so it is not fetched again on later listens and it plays offline afterwards.
About signing in
Signing in with Google is optional, and is only needed to buy or restore Premium. It asks Google for the account’s email address, which the app shows in the Parents area and keeps on the phone so a subscriber is recognised on the next launch. We do not send that email anywhere — there is no Qissora account and no Qissora server to send it to. Signing out in the Parents area removes it from the phone. What Google does with a sign-in is covered by Google’s Privacy Policy.
About payments
Google Play handles the entire purchase. The app never sees or stores a card number, billing address or any other payment detail; it only learns from Google Play whether a subscription is currently active.
What the app stores on the phone
All of this is written to the app’s own private storage. None of it is sent to us, and we never see it:
- The child’s first name, as typed by a parent, to greet them on the home screen.
- Which stories are marked favourite or saved.
- Playback position and play counts per story, for “Continue listening” and the listening stats in the Parents area.
- Story audio, kept after the first play so it works offline.
- The parents PIN, stored only as a salted PBKDF2 hash — never the PIN itself.
- The count of incorrect PIN entries and any lockout deadline, to rate-limit wrong entries.
- The signed-in parent’s email address, if a parent signed in.
- Whether Premium is active, as last reported by Google Play, so a subscriber keeps Premium while offline.
- Theme choice, story language and the last sleep-timer length.
Deleting it
Clearing the app’s data or uninstalling the app removes all of it permanently. Inside the app, the Parents area can clear favourites, saved stories and listening history individually, and signing out removes the stored email address. There is no copy on any server of ours, so there is nothing for us to delete on request — and no way for us to restore it.
To cancel Premium or delete what Google holds about your purchase, use your Google account and Google Play; that data is theirs, not ours.
Device backups
If the device owner has turned on the operating system’s own backup — Android Backup or iCloud — the app’s data may be included in that backup under the device owner’s account. That backup is handled by Google or Apple under their own privacy policies, not by us.
What the app does not do
- No Qissora account, and no server of ours that stores your data.
- No advertising, and no advertising identifiers.
- No analytics, crash reporting or usage telemetry.
- No location, contacts, camera, microphone or photo access.
- No social features, no sharing, no user-generated content.
- Nothing sold or shared with anyone.
Permissions the app asks for
- Internet and network state — to stream the stories, and to notice when the phone is offline.
- Foreground service, media playback and wake lock — to keep a story playing when the screen is locked or the app is in the background.
- Notifications — to show the playback notification with pause and skip controls.
- Billing — to sell Qissora Premium through Google Play.
- Biometric and fingerprint — added by Google’s own sign-in libraries, which can offer a fingerprint instead of a password on the Google sign-in screen. Qissora itself never asks for a fingerprint and never receives one.
Children
This app is made for children and is meant to be used with a parent or guardian, and we have designed it so that nothing about the child is ever transmitted. The child’s first name, their favourites and their listening history are entered and kept on the phone and never leave it. The app shows no ads, contains no analytics or tracking, and has no social or sharing features.
The parts that do use the internet are the parents’ parts: streaming the stories, and — only if a parent chooses — signing in with Google to buy or restore Premium. A parent who never signs in never sends us or Google anything but a request for a story file.
We believe this meets the US Children’s Online Privacy Protection Act (COPPA) and the EU GDPR’s provisions on children’s data. We do not knowingly collect personal information from children.
Changes to this policy
If the app begins collecting or transmitting anything beyond what is described above, this policy will be updated and the effective date changed before that version is released.
Contact
Questions about this policy: write to imaanakhlaq44@gmail.com or message WhatsApp +92 333 5756028.
The website privacy policy covers qissora.app itself.