Leyona Technologies SARL AU

Privacy Policy

This policy explains what Qatra stores about you, why, and how to make us delete it. It is written to be read, not to be survived — if a section is unclear, write to us and we will fix the wording.

Last updated 18 August 2026

01Who we are

Qatra is published by Leyona Technologies SARL AU, a Société à responsabilité limitée à associé unique registered in Morocco with a share capital of 100 000 MAD, whose registered office is at Rue Dakar, Imm. n°5, Appt. n°1, Océan, Rabat, Morocco.

For the purposes of the EU General Data Protection Regulation (GDPR) and of Moroccan Law no. 09-08 on the protection of individuals with regard to the processing of personal data, Leyona Technologies SARL AU is the data controller. You can reach us at privacy@getqatra.com.

02The short version

You can read Qatra without an account and without giving us your name or your email. We do not sell data, we do not share it with advertising networks, and there is no third-party analytics or advertising SDK inside the app.

What we do store falls into three groups: what is needed to run the app on your phone, what you deliberately give us so the reflections suit you, and what is needed to bill and support a subscription. Each is set out below.

03What we collect

Automatically, from the moment you open the app

An account record is created on first launch so your settings have somewhere to live. It is anonymous: it holds no name and no email until you choose to register.

DataWhy we hold it
A random account identifierTo attach your settings, favourites and streak to something. It is not derived from your device or from you.
Device identifier, platform and app versionTo deliver notifications to the right device and to know which app version a bug report came from.
Language and time zoneTo show the app in your language and to send reminders at the right local hour.
Push notification tokenIssued by Apple or Google. Without it we cannot send you a reminder. Removed when you disable notifications.

What you give us

DataWhy we hold it
Email address and passwordOnly if you create an account. The password is stored as a one-way hash and is never readable by us.
Onboarding answersOptional. Age band, life stage, family situation, the themes you want and the things you are working through. They steer which reflections you are sent. See section 04.
Followed and muted topicsA direct instruction about what to send you and what never to send you.
Reminder schedule and app settingsHow many reminders a day, in what window, on which theme.
Favourites, collections and your own written reflectionsSo they are still there tomorrow, and on your next phone if you subscribe.
Content reportsWhen you report a reflection, we keep the report so a human can review the text you flagged.

What the app records as you read

DataWhy we hold it
Which reflections you have seen, and whenSo the feed stops repeating itself, and so the streak can count a day as read.
Daily activity and streak countersTo draw the streak ring and the week.
Product analytics eventsFirst-party only: a short event name such as “opened from notification”, the screen it came from, platform and app version. Stored on our own servers, never sent to an analytics vendor, and never used to build an advertising profile.
Subscription status and billing eventsWhether your trial is running, whether a subscription renewed or lapsed, and which store it came from.

We do not collect your contacts, your location, your photos, your calendar, or the contents of anything else on your device.

04The onboarding questions, and why they are special

Qatra is an app of Islamic reflections, and the onboarding asks how you would describe your own practice and what you are currently struggling with. Under Article 9 of the GDPR, answers about religious belief — and answers that can reveal health or personal circumstances — are special category data and get stricter treatment.

So we treat them that way:

  • They are optional. Onboarding can be skipped entirely and the app works. You can also fill it in later, change any answer, or clear it, from your profile.
  • They are processed only with your explicit consent, given by answering, and only to choose which reflections you are sent.
  • They are never used for anything else. Not for advertising, not for profiling beyond the feed, and they are never shared with anyone outside Leyona Technologies SARL AU.
  • You can withdraw consent at any time by clearing your answers in the app or writing to us. Withdrawing does not affect processing that already happened, and the app keeps working — the feed simply stops being personalised.

06Who else touches it

We use a small number of service providers. They process data on our instructions, under a data processing agreement, and for no purpose of their own.

ProviderWhat for
Microsoft AzureHosting for this website and for our servers and database.
Apple & GoogleApp distribution, and delivery of push notifications through APNs and FCM. They also process every payment — we never see your card.
Expo (Expo Application Services)Relays push notifications to Apple and Google. It receives the notification text and your push token.
RevenueCatReconciles subscription receipts from the App Store and Google Play so the app knows whether your subscription is active.
SentryCrash and error reports, so we can fix what broke. Configured to report the fault, not the contents of your screen.

We do not sell personal data, and we do not share it for advertising or cross-context behavioural advertising under any law that uses those terms.

07Where it goes

Leyona Technologies SARL AU is established in Morocco, and some of the providers above are established in the United States. That makes some transfers international.

Where personal data leaves the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses, or by an adequacy decision where one applies. Transfers out of Morocco are made in accordance with Law no. 09-08 and, where required, with the authorisation of the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).

08How long we keep it

DataKept for
Your account and everything attached to itAs long as the account exists. Deleted within 30 days of a deletion request.
An anonymous account with no activityRemoved after 24 months of inactivity.
Reading history and analytics eventsRolling 24 months, then deleted.
Push tokensUntil the device stops responding or you turn notifications off, whichever is first.
Billing and subscription recordsAs long as tax and accounting law requires us to keep them — up to 10 years — after which they are deleted.
Support emails24 months from the last message in the thread.

09Your rights, and how to use them

You can ask us to:

  • Show you everything we hold about you, as a file you can keep.
  • Correct anything that is wrong.
  • Delete your account and its data — see Delete your account.
  • Restrict or object to processing based on our legitimate interests.
  • Withdraw consent for notifications or for the onboarding answers, at any time.
  • Take your data elsewhere, in a structured, machine-readable format.

Write to privacy@getqatra.com. We answer within 30 days and we do not charge for it. We may ask you to confirm control of the email address on the account, which is the only way we can tell it is you.

If you think we have got it wrong, you can complain to the CNDP in Morocco, or — if you are in the European Economic Area or the United Kingdom — to your local supervisory authority. We would rather you told us first, but it is your right either way.

10Children

Qatra is not directed at children under 13, and we do not knowingly collect data from them. Where local law sets a higher age for consenting to online services without a parent — 16 in several EU member states — that age applies instead.

If you are a parent or guardian and believe your child has given us data, write to privacy@getqatra.com and we will delete it.

11How it is protected

Traffic between the app and our servers is encrypted with TLS. Passwords are stored as one-way hashes with a per-password salt and are not recoverable, by us or by anyone who obtained the database. Sessions use rotating refresh tokens, so a stolen token can be detected and the whole session family revoked. Access to production data is limited to the people who need it to run the service.

No system is perfect. If a breach ever affects your data, we will notify the competent authority within 72 hours as required, and notify you directly where the risk to you is high.

12This website

getqatra.com sets no cookies, runs no analytics, and loads nothing from a third-party server — the fonts and images are served from this domain. Our host records standard server logs, including IP addresses, for security and to keep the site up; those logs are kept for a short period and are not used to identify you.

13Changes to this policy

When this policy changes, we update the date at the top. If a change materially affects how we use your data, we will tell you in the app before it takes effect, and where the law requires it we will ask for your consent again rather than assume it.

14Contact

Everything else

support@getqatra.com

By post

Leyona Technologies SARL AU
Rue Dakar, Imm. n°5, Appt. n°1, Océan, Rabat, Morocco