Back to home

Privacy Policy

Effective 16 August 2026

Ayah Ink is built local-first. Your notebooks, handwriting, highlights, and notes live on your device, and everything essential works with no account and no connection. This policy explains what leaves your device, when, and why, in plain terms.

Ayah Ink (“the app”) is operated by Northstar Engineering Ltd (“we,” “us,” “our”), a company registered in Mauritius. This policy also covers this website. We are the data controller for the limited personal data described below, and we handle it under the Mauritius Data Protection Act 2017. If you are in a region with additional protections, such as the EU/UK under the GDPR, those rights are honored too.

The short version

What we collect, and when

Content you create

Notebooks, handwriting and highlights, shapes, page and verse notes, bookmarks, layers, and reading positions are stored locally on your device first. This content is not sent to us unless you sign in from Sync settings (which makes the immediate private snapshot described below) or explicitly publish a notebook for invited collaborators. Local backups you export are files under your control and are not uploaded to us.

Account information

An account is optional. If you create one, we process your email address and an account identifier through our processor Supabase to authenticate you. An account is required for personal cloud sync, collaboration, and purchasing Pro, but not for local study. We do not use your cloud account email for marketing unless you separately ask to receive it.

Cloud sync content

Signing in from the Sync settings creates or updates one private account snapshot immediately. If you then enable Automatic sync, later changes are backed up in the background; you can also choose Sync now yourself. The snapshot includes your explicit khatm page-marking progress so it can follow you across signed-in devices, but excludes your local reminder schedule, your diagnostics consent, your Automatic sync choice, and collaboration caches; each device keeps those choices to itself. Row-level security restricts ordinary client access to your signed-in account. Deleting your cloud account removes this snapshot and does not touch the notebooks stored on your device; those retained local notebooks remain fenced from any different account that later signs in.

Collaboration content

When an owner or editor chooses Publish my changes, that notebook copy is stored separately in Supabase and becomes readable to the invited members according to their roles. Verse discussions are also stored for those members. Collaboration publishing is independent of the Automatic sync setting; it happens only after an explicit publish or comment action. Removing a member ends their server access, although copies already downloaded to their device remain outside our control. We retain the shared notebook identifier, title, and creation time with that member's account after revocation or notebook deletion only so an older app cannot mistake its cached copy for personal content and upload it again; those lineage records are removed when that member deletes their account.

Subscription information

On iOS and Android, purchases are handled by the app store on your device. On the web, purchases are handled by Paddle, our merchant of record, which processes your payment details, billing address, and email to complete the purchase and issue receipts under its own privacy policy. In both cases our processor RevenueCat records your purchase and entitlement status; when you buy Pro with a cloud account, your account identifier and email address are shared with RevenueCat so the purchase can be restored on your other signed-in devices. We never receive or store your full payment card details; those are handled by the app store or by Paddle.

Analytics

The app sends a small set of product events (for example, that a notebook was created or the Pro screen was viewed) to our processor PostHog to help us understand which features are used. These events never include your notes, ink, verse text, or any notebook content. There are two tiers:

The iOS and Android apps have no cookieless tier: there, the same switch (and, in the regions above, the same first-launch question) decides whether anonymous product events are sent at all. Off means nothing is sent.

Online scripture content

The complete Qur’an, its bundled translation, and word-by-word study data ship inside the app and are read offline. When you request reviewed translations, tafsir, or recitation for a selected verse, the app sends that request through our licensed content gateway to retrieve the material. Retrieved content is cached on your device for no more than seven days.

Reminders

If you enable the daily study reminder, it is scheduled as a local notification on your device. No reminder schedule or notification profile is uploaded to us.

This website

This website uses Cloudflare Web Analytics to count visits and see which pages and referring links are used. It sets no cookies, stores nothing on your device, and does not follow you across sites or build a profile of you. Figures are aggregate: page addresses, referrer, country, browser, and device type.

The website also sends page views and clicks to PostHog on the same two tiers as the app: anonymous and cookieless by default, with a remembered browser only if you allow it. In the EU/EEA, the UK, and Switzerland a banner asks on your first visit; elsewhere the browser is remembered by default. Either way, the Cookie settings link in the footer reopens the choice at any time. Your answer is kept in your browser’s local storage so we do not ask again. The site’s fonts are served from our own hosting, so viewing this website sends no request to any font provider.

If you reach this site through a link we gave to a specific person or channel, that link may carry a plain campaign label (for example the name of a creator or a blog post). If you then request mobile launch updates, that label is stored beside your email so we know which link brought you. It is a label for the link, not an identifier for you, and nothing is recorded unless you choose to submit the form.

Mobile launch updates

If you request mobile launch updates on this website, the email address you enter is stored with our processor Supabase (hosted in the EU) and used for exactly one thing: a single announcement when the iPhone, iPad, or Android apps are ready. It is not used for other marketing, not shared, and not linked to any app account. We delete the list after that announcement is sent, and you can ask us to remove your address at any time using the contact below.

Who processes data for us

We use a small number of service providers (processors) to run these features. Each receives only what that feature needs.

ProcessorPurposeWhat it receives
SupabaseAccounts, cloud sync, collaboration, mobile launch updatesEmail and account identifier; your private synced snapshot when you use sync; shared notebook copies, membership records, and discussions when you use collaboration; your email if you request mobile updates
RevenueCatSubscriptions and entitlementsPurchase and entitlement status linked to your account identifier
PaddleWeb checkout (merchant of record)Payment details, billing address, and email for web purchases; we never see your card number
PostHogProduct analytics for the app and this websiteAnonymous product events and page views, cookieless by default; a random device identifier only if you allow “Remember this device”. Never your notes, ink, or verse text
CloudflareHosting, website analytics, and the country lookup that decides whether to ask before remembering a deviceAggregate visit counts for this website; your network address’s country, used once per visit and not stored
Qur’an content gatewayLicensed online tafsir, translations, and recitationThe verse reference you request, to fetch the material

These providers may process data on servers outside Mauritius, including in the EU and the United States. Where that happens, we rely on the providers’ own safeguards for international transfers. Each provider maintains its own privacy policy governing how it handles data.

How long we keep it

Your rights

Under the Mauritius Data Protection Act 2017 (and the GDPR where it applies), you can request access to the personal data we hold about you, ask us to correct or delete it, object to or restrict certain processing, and request a copy in a portable form. You can delete your cloud account at any time from within the app; Delete your account and data explains the steps, what is removed, and how to ask by email if you have already removed the app. To make any other request, contact us at the address below. You also have the right to lodge a complaint with the Data Protection Office in Mauritius, or your local supervisory authority.

Children

Ayah Ink is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

Security

Your content is local-first, which limits what is exposed in the first place. Cloud data is protected by authentication and row-level security that restricts ordinary client access to the signed-in account that owns it. No method of storage or transmission is completely secure, but we work to protect your information appropriately.

Changes to this policy

We may update this policy as the app evolves. When we make a material change, we will update the effective date above and, where appropriate, note it in the app.

Contact

For any privacy question or request, contact Northstar Engineering Ltd at hello@northstarengineering.mu.