read-quran.org
Privacy Policy
Version of 31 August 2026. This English text is a translation for convenience; in case of a discrepancy the Russian version prevails.
In short
- Reading requires no sign-up, name, phone number or e-mail address.
- The site has no ads, analytics counters, tracking pixels or cookies.
- The reading position, the selected ayah, bookmarks and settings stay on the user's device.
- The IP address is shortened before it is written to the server log; the log and the private statistics are kept for no more than 30 days.
- An external connection to EveryAyah.com is made only after the audio is started, and to e-mail services only after a message is sent.
- The public reader never asks visitors to sign in with Google, Yandex or the Quran Foundation.
1. General
1.1. This Privacy Policy (the "Policy") describes which data are processed, and how, when the website and installable web application read-quran.org (the "Site") and the private Read Quran Search Operations tool are used.
1.2. The data controller (the "Administrator") is the owner of the domain read-quran.org. Questions, data requests and error reports are accepted at contact@read-quran.org; messages to this address are forwarded to the Administrator's private mailbox.
1.3. The Policy takes into account the Russian Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" and the EU General Data Protection Regulation (GDPR). The Site is designed to process as little data as possible.
1.4. The Site is an independent free project and not an official product of the Quran Foundation, Quran.com, QuranReflect, Tanzil, EveryAyah, Google or Yandex. By using the Site the user confirms having read this Policy.
2. Data on the user's device
2.1. To restore the reading position and to work offline, the browser stores locally: the last reading position and the selected ayah; bookmarks; the language, theme, text size and display mode; the selected reciter, repeat and playback continuation; the application files, pages, metadata and fonts for the offline mode.
2.2. These data may reflect religious interests and are therefore treated as sensitive. They are processed only on the user's device for the functions the user switches on. The Site does not receive them, does not link them to an IP address and does not synchronise them between devices.
2.3. The functional browser storages are used: localStorage, sessionStorage and Cache Storage. The Site has no cookies and no cross-site tracking, so no consent banner for advertising or analytics cookies is shown: such technologies are not present on the Site.
2.4. The data stay on the device until the user deletes them or the browser clears its storage automatically. They can be removed in the browser settings: site data, local storage and cache of read-quran.org.
3. Server logs
3.1. The web server automatically records: the time of the request, a shortened network prefix instead of the full IP address, the method and path of the requested resource without parameters after the ? sign, the protocol and parameters of the secure connection, some technical browser headers, the response code, the response size and the processing time. The user's network port, the Referer header and client-sent headers with additional IP addresses are removed from the log before it is written to disk; the server hides Cookie and Authorization values.
3.2. The resource path may indirectly show which public static surah page was opened or which mushaf page was loaded. The ayah selected in the main reader is recorded after the # sign and is not sent by the browser to the server.
3.3. The logs are used only for protection against attacks, error diagnostics, availability monitoring and aggregated technical statistics. Only the Administrator has access to them and to the private report. The log rotates daily; the raw records, the database and the derived statistics are kept for no more than 30 days.
3.4. The logs are not used for advertising, personal recommendations, assessment of beliefs, automated decision-making or training of AI models; they are not sold and are not combined with local bookmarks.
3.5. The legal bases of the processing are the provision of the requested Site and the Administrator's legitimate interest in its security and reliability. Consent is not requested because no optional processing takes place.
4. Audio and external services
4.1. The text, layout and fonts are loaded from the Site; during ordinary reading the user's browser does not contact third-party servers. The public Quran data were obtained by the Administrator in advance through the Quran Foundation Content API without transferring any visitor data there; the Site does not use the Quran Foundation user APIs or OAuth.
4.2. After playback is started the browser requests the audio file directly from EveryAyah.com. From the file address this service sees the selected reciter and the number of the ayah being played, and it also receives the standard connection data, including the IP address and browser details; the processing on the EveryAyah side is governed by the rules of that service and may take place in another country.
4.3. Copying an ayah and the system "Share" function are started only by the user and are handled by the user's browser or operating system.
5. E-mail and requests
5.1. If the user writes to contact@read-quran.org, Cloudflare Email Routing receives the message and forwards it to Gmail. Cloudflare and Google process the sender and recipient addresses, the content and the technical headers of the message under their own rules, including outside the user's country.
5.2. The Administrator uses the message only to reply, to check the report and to protect the legitimate interests of the project. Correspondence is deleted or anonymised no later than 12 months after the request is closed; longer only if required by law or by an unresolved dispute. Request data are not used for mailings and are not linked to the reading history.
6. Hosting and cross-border transfer
6.1. The Site is hosted on a virtual server of VDSKA in Kazakhstan; the connection is protected by HTTPS. The hosting provider supplies the infrastructure and may process technical data to the extent necessary for the operation and protection of the server.
6.2. EveryAyah, Cloudflare and Google may process the data listed above in other countries under their own rules. The Administrator does not transfer the user's local bookmarks and reading position to them.
7. Service data of search engines
7.1. Read Quran Search Operations is a private tool available only to the owner of the Site. After the owner's separate authorisation it may receive, through the Google Search Console API, information about the verified read-quran.org properties, search impressions and queries, indexing and Sitemap files, and may perform the property management operations allowed by the owner. Similar private access may be used for Yandex Webmaster.
7.2. Visitors of the Site are not offered to sign in with Google or Yandex; the tool does not request their accounts or data. The service data received are used only to monitor indexing and to manage the Site; they are not sold, not passed to advertising systems and not used for profiling or for training AI models.
7.3. Access keys (service account keys and OAuth tokens) are kept in private files with restricted access until the authorisation is revoked or the integration is removed. The owner may revoke the access on the Google permissions page or request deletion at contact@read-quran.org; local keys are deleted no later than 30 days after such a request. The use of information received through Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
8. Security
8.1. Data minimisation, HTTPS, shortening of the IP address before logging, access restriction, protective browser headers, component updates and limited retention periods are applied. The Administrator does not sell personal data and does not pass them on for advertising; access is possible only for the providers listed in the Policy or under a binding legal demand.
8.2. The security practices meet the Quran Foundation requirements for developers; a suspected incident related to its API is reported to the Quran Foundation within 24 hours. No internet service can guarantee absolute security, but the amount of data processed by the Site is reduced to the minimum described in this Policy.
9. User rights
9.1. Within the applicable law the user may request information about the processing, access to the data, their correction, deletion, restriction of processing, or object to the processing. Requests are sent to contact@read-quran.org. The Administrator replies no later than within 30 days.
9.2. Because the IP address is shortened in advance, a specific log record may be impossible to link reliably to a person; the Administrator cannot find local data because they never reach the server.
9.3. The user also has the right to lodge a complaint with the data protection supervisory authority of their place of residence: in Russia — Roskomnadzor, in EU countries — the local supervisory authority. The Administrator asks, where possible, to write to the contact address first so that the matter can be resolved faster.
10. Children
10.1. The Site is available to visitors of different ages, but it does not create children's profiles, does not ask for age and does not collect data for advertising. The minimised technical logs are processed in the same way for all visitors. A parent or legal guardian may write to the contact address about a child's data.
11. Changes to the Policy
11.1. If the ways of processing data change, the Policy will be updated before the corresponding function is launched; the date of the current version is stated at the beginning of the document. Material changes are published on this page and on the "About" page available from the reader. New optional processing does not start without a separate clear notice where one is required.