Privacy Policy
Last updated: June 2026 — Compliant with Saudi Personal Data Protection Law (PDPL)
1. Who We Are
Zayenha Quran is an educational platform operated by Zayenha Hub for Apps (CR: 7042574579), King Abdullah Financial District (KAFD) — Riyadh, Saudi Arabia. Contact: z@zayenha.com
2. Data We Collect
- Identity data: User ID from Zayenha Hub (hub_user_id) — stored as a link only; name and email are not duplicated here
- Usage data: Bookmarks (saved cards), review progress (SM-2), read surahs, used tools
- Technical data: Anonymous fingerprint (truncated SHA-256 hash of IP) for security and anti-abuse — raw IP is never stored
- Email and phone: When subscribing to the newsletter — entirely optional
- Notification subscriptions: Web Push technical data (endpoint + keys) when you consent
3. Legal Basis for Processing (PDPL)
- Contractual necessity: Data required to provide the activation, review, and memorization service
- Legitimate interest: Security logs and service improvement
- Explicit consent: Newsletter and notifications — withdrawable at any time
- Legal obligation: Financial transaction records per ZATCA requirements
4. Data Sharing
We share your data only with:
- Zayenha Hub: Parent platform — for account and billing sync (via secure SSO)
- Cloudflare Inc.: Infrastructure (Workers, D1, KV, R2) — Cloudflare's privacy policy governs this data
- Competent authorities: When legally required
5. Data Retention
- Account and review data: During activity + 3 years after deletion (soft-delete)
- Security logs (ip_hash): 90 days
- Newsletter subscriptions: Until unsubscription
- Financial transaction records: 5 years (regulatory requirement)
6. Your Rights (PDPL)
Under Saudi PDPL, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (right to erasure) — via account settings or support
- Withdraw consent for optional data processing (newsletter / notifications)
- Lodge a complaint with the Saudi Data and AI Authority (SDAIA)
7. Data Security
We use TLS/HTTPS on all connections, Cloudflare D1 databases with access controls, session encryption, and identity data hashing (ip_hash). Sensitive data is never stored in logs or allowed to leak into outputs.
8. Cookies
- quran_session: Authentication session (HttpOnly, Secure, SameSite=Lax) — necessary
- zh_lang: Preferred language — necessary
- zh_theme: Theme (dark/light) — necessary
- zh-ref: Referral code (deleted after registration) — functional