Leyona Technologies SARL AU
Privacy Policy
This policy explains what Qatra stores about you, why, and how to make us delete it. It is written to be read, not to be survived — if a section is unclear, write to us and we will fix the wording.
Last updated 18 August 2026
01Who we are
Qatra is published by Leyona Technologies SARL AU, a Société à responsabilité limitée à associé unique registered in Morocco with a share capital of 100 000 MAD, whose registered office is at Rue Dakar, Imm. n°5, Appt. n°1, Océan, Rabat, Morocco.
For the purposes of the EU General Data Protection Regulation (GDPR) and of Moroccan Law no. 09-08 on the protection of individuals with regard to the processing of personal data, Leyona Technologies SARL AU is the data controller. You can reach us at privacy@getqatra.com.
02The short version
You can read Qatra without an account and without giving us your name or your email. We do not sell data, we do not share it with advertising networks, and there is no third-party analytics or advertising SDK inside the app.
What we do store falls into three groups: what is needed to run the app on your phone, what you deliberately give us so the reflections suit you, and what is needed to bill and support a subscription. Each is set out below.
03What we collect
Automatically, from the moment you open the app
An account record is created on first launch so your settings have somewhere to live. It is anonymous: it holds no name and no email until you choose to register.
| Data | Why we hold it |
|---|---|
| A random account identifier | To attach your settings, favourites and streak to something. It is not derived from your device or from you. |
| Device identifier, platform and app version | To deliver notifications to the right device and to know which app version a bug report came from. |
| Language and time zone | To show the app in your language and to send reminders at the right local hour. |
| Push notification token | Issued by Apple or Google. Without it we cannot send you a reminder. Removed when you disable notifications. |
What you give us
| Data | Why we hold it |
|---|---|
| Email address and password | Only if you create an account. The password is stored as a one-way hash and is never readable by us. |
| Onboarding answers | Optional. Age band, life stage, family situation, the themes you want and the things you are working through. They steer which reflections you are sent. See section 04. |
| Followed and muted topics | A direct instruction about what to send you and what never to send you. |
| Reminder schedule and app settings | How many reminders a day, in what window, on which theme. |
| Favourites, collections and your own written reflections | So they are still there tomorrow, and on your next phone if you subscribe. |
| Content reports | When you report a reflection, we keep the report so a human can review the text you flagged. |
What the app records as you read
| Data | Why we hold it |
|---|---|
| Which reflections you have seen, and when | So the feed stops repeating itself, and so the streak can count a day as read. |
| Daily activity and streak counters | To draw the streak ring and the week. |
| Product analytics events | First-party only: a short event name such as “opened from notification”, the screen it came from, platform and app version. Stored on our own servers, never sent to an analytics vendor, and never used to build an advertising profile. |
| Subscription status and billing events | Whether your trial is running, whether a subscription renewed or lapsed, and which store it came from. |
We do not collect your contacts, your location, your photos, your calendar, or the contents of anything else on your device.
04The onboarding questions, and why they are special
Qatra is an app of Islamic reflections, and the onboarding asks how you would describe your own practice and what you are currently struggling with. Under Article 9 of the GDPR, answers about religious belief — and answers that can reveal health or personal circumstances — are special category data and get stricter treatment.
So we treat them that way:
- They are optional. Onboarding can be skipped entirely and the app works. You can also fill it in later, change any answer, or clear it, from your profile.
- They are processed only with your explicit consent, given by answering, and only to choose which reflections you are sent.
- They are never used for anything else. Not for advertising, not for profiling beyond the feed, and they are never shared with anyone outside Leyona Technologies SARL AU.
- You can withdraw consent at any time by clearing your answers in the app or writing to us. Withdrawing does not affect processing that already happened, and the app keeps working — the feed simply stops being personalised.
05Our legal basis for each use
| What we do | Basis |
|---|---|
| Run the app, store your settings, sync a subscribed account | Performance of a contract (GDPR Art. 6(1)(b)). |
| Send you the reminders you configured | Consent, given through the operating system permission prompt and the in-app schedule (Art. 6(1)(a)). Withdraw it by turning notifications off. |
| Personalise the feed from your onboarding answers | Explicit consent (Art. 9(2)(a)). |
| Keep the service working, secure and free of abuse; understand which features are used | Legitimate interests (Art. 6(1)(f)), balanced against your rights and limited to first-party, non-advertising data. |
| Take payment and honour a subscription | Performance of a contract, and compliance with tax and accounting obligations (Art. 6(1)(b) and (c)). |
06Who else touches it
We use a small number of service providers. They process data on our instructions, under a data processing agreement, and for no purpose of their own.
| Provider | What for |
|---|---|
| Microsoft Azure | Hosting for this website and for our servers and database. |
| Apple & Google | App distribution, and delivery of push notifications through APNs and FCM. They also process every payment — we never see your card. |
| Expo (Expo Application Services) | Relays push notifications to Apple and Google. It receives the notification text and your push token. |
| RevenueCat | Reconciles subscription receipts from the App Store and Google Play so the app knows whether your subscription is active. |
| Sentry | Crash and error reports, so we can fix what broke. Configured to report the fault, not the contents of your screen. |
We do not sell personal data, and we do not share it for advertising or cross-context behavioural advertising under any law that uses those terms.
07Where it goes
Leyona Technologies SARL AU is established in Morocco, and some of the providers above are established in the United States. That makes some transfers international.
Where personal data leaves the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses, or by an adequacy decision where one applies. Transfers out of Morocco are made in accordance with Law no. 09-08 and, where required, with the authorisation of the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).
08How long we keep it
| Data | Kept for |
|---|---|
| Your account and everything attached to it | As long as the account exists. Deleted within 30 days of a deletion request. |
| An anonymous account with no activity | Removed after 24 months of inactivity. |
| Reading history and analytics events | Rolling 24 months, then deleted. |
| Push tokens | Until the device stops responding or you turn notifications off, whichever is first. |
| Billing and subscription records | As long as tax and accounting law requires us to keep them — up to 10 years — after which they are deleted. |
| Support emails | 24 months from the last message in the thread. |
09Your rights, and how to use them
You can ask us to:
- Show you everything we hold about you, as a file you can keep.
- Correct anything that is wrong.
- Delete your account and its data — see Delete your account.
- Restrict or object to processing based on our legitimate interests.
- Withdraw consent for notifications or for the onboarding answers, at any time.
- Take your data elsewhere, in a structured, machine-readable format.
Write to privacy@getqatra.com. We answer within 30 days and we do not charge for it. We may ask you to confirm control of the email address on the account, which is the only way we can tell it is you.
If you think we have got it wrong, you can complain to the CNDP in Morocco, or — if you are in the European Economic Area or the United Kingdom — to your local supervisory authority. We would rather you told us first, but it is your right either way.
10Children
Qatra is not directed at children under 13, and we do not knowingly collect data from them. Where local law sets a higher age for consenting to online services without a parent — 16 in several EU member states — that age applies instead.
If you are a parent or guardian and believe your child has given us data, write to privacy@getqatra.com and we will delete it.
11How it is protected
Traffic between the app and our servers is encrypted with TLS. Passwords are stored as one-way hashes with a per-password salt and are not recoverable, by us or by anyone who obtained the database. Sessions use rotating refresh tokens, so a stolen token can be detected and the whole session family revoked. Access to production data is limited to the people who need it to run the service.
No system is perfect. If a breach ever affects your data, we will notify the competent authority within 72 hours as required, and notify you directly where the risk to you is high.
13Changes to this policy
When this policy changes, we update the date at the top. If a change materially affects how we use your data, we will tell you in the app before it takes effect, and where the law requires it we will ask for your consent again rather than assume it.
14Contact
Privacy
privacy@getqatra.comEverything else
support@getqatra.comBy post
Leyona Technologies SARL AU
Rue Dakar, Imm. n°5, Appt. n°1, Océan, Rabat, Morocco