About Projects Blog Contact

Qufl

Android app by nulltolife · com.nulltolife.qufl

Privacy policy

What the Qufl app keeps on your phone, the two things that can ever leave it, and why each Android permission is asked for.

Last updated

On this page · 9 sections

The short version

Qufl has no account, no analytics and no server. Everything it knows about you — which apps you lock, what you have read, your streak — is stored on your phone and stays there.

What the app stores on your device

  • The apps you chose to lock, and your unlock rule and schedule.
  • Your reading position, bookmarks, and a per-day count of verses read, minutes read and Arabic letters read.
  • Whether the Qufl Plus subscription is active, and the time Google Play last said so. No card details, no order number, no account — Play keeps all of that, and the app never sees it.
  • Nothing else. Removing the app deletes all of it.

What leaves your device

Two things, both of them optional:

only when you press play

Recitation audio

When you press play on a verse, the recitation audio is streamed from cdn.islamic.network. That request tells the server which verse was requested and your IP address, as any web request does.

only if you subscribe

Qufl Plus

The payment is handled entirely by Google Play, and the app asks Play whether the subscription is active when it starts and when you return to it. That conversation is between your phone and Google Play; we are not told who you are, and the app sends nothing of its own. Google's handling of the payment is covered by their privacy policy.

If you never press play and never subscribe, the app makes no network requests at all. Nothing about your reading is ever uploaded, subscribed or not.

Languages

The language you pick is stored on the phone with the rest of your settings, and is handed to the app's own background service so the notification and the home-screen widget match. It is not sent anywhere.

Backup files

With Qufl Plus you can save everything the app holds to a file. The file is written through Android's own file picker, so you choose where it goes — a folder on the phone, a memory card, or a cloud folder if you point the picker at one. The app does not upload it, does not keep a copy, and is not told where you put it.

In the file

  • Your reading history
  • Your settings

Never in the file

  • Payment details
  • An account
  • Anything about the subscription

Once the file exists it is yours and it is unencrypted, readable JSON: it holds your reading history and settings, so treat it like any other personal file. The subscription field is deliberately left out when the file is written, and ignored if it is put back in by hand.

Restoring a file replaces what is on the phone. Nothing is sent anywhere when you do it.

Permissions and how they are used

Usage access
Reads which app is currently in the foreground, so a locked app can be covered. Usage history is read only to show each app's screen time on the “choose apps” screen. It is never stored or sent.
Display over other apps
Lets the lock screen appear over an app you chose to lock.
Accessibility service optional
Receives window-change events so a locked app is covered immediately. Qufl reads only the package name of the app that opened. It does not read screen content, messages or anything you type, and it has canRetrieveWindowContent="false" set. It can be turned off at any time in Android settings; the app still works.
Notifications
The ongoing status notification and the two-minute warning before apps lock again.
Network state no prompt
Added by the recitation player and by Google Play's billing client to see whether there is a connection before trying. It is granted automatically, shows no prompt, and tells them nothing about you.
Battery optimisation no permission held
The app opens Android's battery settings so you can set Qufl to unrestricted, which stops the system closing the blocking service. The app holds no permission for this and cannot change the setting itself.
Run at startup
Restarts the blocking service after a reboot.

Children

The app collects nothing, so there is nothing to collect from children either.

Changes

Any change to this policy will appear on this page, with a new date at the top.

Contact

Questions about this policy or your data?

qufl@nulltolife.com