Privacy Policy
Last updated: April 19, 2026
1. Introduction
HifzAI ("we", "us", or "our") is a Quran memorization app built by NxGenZ Technologies. This Privacy Policy explains how we collect, use, store, and protect your information when you use the HifzAI mobile application and our website at hifzai.com.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address and name. We use Supabase for authentication — your password is hashed and never stored in plain text.
2.2 Audio Recordings
When you record your recitation, the audio is sent to OpenAI's Whisper API for transcription. Audio is processed in real-time and used solely to generate your feedback. We do not permanently store your raw audio recordings on our servers. Audio data may be temporarily cached during processing and is deleted within 24 hours.
2.3 Practice Data
We store your practice history, including: surah and verse numbers practiced, accuracy scores, streak data, spaced repetition (SRS) card states, and summary statistics. This data is stored in Supabase and is necessary to provide the Summary dashboard, Muraja'ah scheduling, and streak tracking features.
2.4 Payment Information
Payments are processed through Lemon Squeezy (website) and RevenueCat (in-app purchases). We do not store your credit card number or payment details. Transaction records are managed by these payment processors.
2.5 Device & Analytics Data
We may collect anonymous device information (OS, device model, app version) for crash reporting and performance monitoring. No personally identifiable information is shared with third-party analytics services.
3. How We Use Your Information
- To provide AI-powered recitation feedback
- To track your practice progress and streaks
- To manage your subscription and account
- To improve our app and fix bugs
- To communicate important updates about the service
4. Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. We share data only with:
- OpenAI — audio transcription via Whisper API (audio not stored by OpenAI)
- Supabase — secure database and authentication
- Lemon Squeezy / RevenueCat — subscription management
5. Data Retention & Deletion
You may request deletion of your account and all associated data at any time by contacting us at support@nxgenz.com. Upon deletion, your account data, practice history, and SRS cards will be permanently removed within 30 days.
6. Data Security
All data is transmitted over HTTPS/TLS encryption. Our database (Supabase) uses row-level security and encryption at rest. We follow industry-standard security practices to protect your information.
7. Children's Privacy
HifzAI may be used by minors with parental consent. We do not knowingly collect personal information from children under 13 without verifiable parental consent. Parents may contact us to review or delete their child's data.
8. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or in-app notification. Continued use of the app after changes constitutes acceptance of the updated policy.
9. Contact Us
For privacy-related questions or data deletion requests, contact us at: