Subac · سُبَع

Privacy Policy

Last updated: 8 September 2026. This page is public — you do not need an account to read it.

Subac is a Qur'an memorisation app at https://subac.net. It is a product of Subac / Mohamed Jeyte. This policy explains what we collect, why we collect it, and how long we keep it. It is written for people using the website, the installable web app, and the Android / iOS wrappers that open the same service.

What we collect

  • Account details. Email address, name, and a hashed password when you sign up. Teachers and schools may also add a school name, website, and logo image. We do not store your password in plain text.
  • Session and progress. Which surah, juz, or page you are practising; scores; streaks; daily goals; badges; and a mistake journal (including the ayah, your transcript text, and accuracy). Teachers may store student names and optional emails, and parents see only students their teacher has linked.
  • Microphone audio. When you press Record in a practice session, we capture a short clip of you reciting so we can transcribe it, mark words green or red, and compute a score. We do not record in the background. Listen-only mode does not use the microphone.
  • Cookies and similar data. A signed-in session cookie (subac_session, httpOnly, about 30 days), plus language (subac_lang) and theme (subac_theme) preferences. These are for running the app, not advertising.
  • Payments. If you subscribe, payment is handled by Stripe. Subac stores your plan, subscription status, and Stripe customer identifiers — not your full card number.
  • Optional extras. Feedback you send us; crash reports (page, error message, stack); prayer-time city or mosque times you choose; and share-link settings for a practice session.

How we use recitation audio

Audio is used only for on-session practice and transcription. The clip is sent to Subac's speech checker (POST /api/transcribe). By default that runs on Subac's own server (local faster-whisper), which decodes the clip in memory and returns text. We do not sell recordings. We do not use them for advertising.

We do not keep a recitation library. After scoring, what we retain is the result of that turn: the transcript text, accuracy, and related progress — not the audio file itself. Server logs or backups are not used as a recording archive. If the operator enables an external speech provider (OpenAI Whisper), that clip is sent to OpenAI for transcription under OpenAI's terms; the default configuration does not do this.

How we use other data

Account, session, and progress data run the product: sign-in, saving where you left off, showing teachers and parents how students are doing, and enforcing plan limits. Feedback and crash reports help us fix bugs. Prayer-city search may query a geocoding service (Open-Meteo) with the city name you type. Reciter audio is streamed from a public Qur'an CDN and is not your personal data.

When you pay, Stripe processes the card and billing details. Subac uses Stripe to start checkout, open the customer portal, and keep subscription status in sync. We do not sell personal information.

Who else can see data

  • Teachers see progress and mistakes for students on their roster.
  • Parents see only students a teacher has explicitly linked to them.
  • Stripe sees payment information needed to charge and invoice.
  • Email is used to send password-reset links when that feature is configured.
  • Operator alerts. New signups and in-app feedback may be forwarded to the operator (for example via Telegram) so we can run the service. That is not advertising and is not a sale of data.

We do not use advertising SDKs, analytics pixels, or cross-app tracking.

How long we keep it

Account, progress, and mistake-journal records stay until the account is deleted or, for some free-plan history, trimmed to a rolling window. Session cookies expire after about 30 days of inactivity (active use can renew them). Password-reset tokens expire after a short period. Recitation audio is processed for the practice turn and is not stored as a recording library. Stripe keeps its own billing records under Stripe's policy.

Children and family accounts

Subac is used in homes and dugsis, including by children practising under a teacher, parent, or family plan. We collect student names (and optional emails) so the roster and progress screens work. We do not use this information for ads. A parent or teacher who added a child can request deletion of that student record.

Your choices

  • You can use listen-only practice without the microphone.
  • You can sign out at any time (Profile).
  • You can change language and night mode; those preferences are stored in cookies on your device.
  • Paid plans can be managed in Stripe's customer portal from the Plan page.
  • To access or correct an account, email [email protected]. To delete an account and its practice data, use subac.net/account/delete or email us with the subject “Delete my Subac account”.

Security

The live site uses HTTPS. Passwords are stored with scrypt hashes. Session tokens are httpOnly cookies. Speech checking and account APIs require a signed-in session. No method is perfect; if you believe there is a data incident, write to us at the address below.

Contact

Privacy requests: [email protected]
Account deletion: https://subac.net/account/delete
Product: Subac / Mohamed Jeyte
Website: https://subac.net

If this policy changes in a material way, we will update the date at the top of this page.

← Back to Subac