Privacy
Last updated 9 October 2026
Lahza is a small, independent app. We keep only what the app needs to work, we never sell data, and there are no ads, analytics or tracking scripts.
Who we are
Lahza is operated by PT Pelopor Digitalisasi Inovasi, Bogor, Indonesia. PT Pelopor Digitalisasi Inovasi is the data controller for the information described on this page.
What we store
When you sign in with your Quran.com (Quran Foundation) account, our server stores:
- Your Quran Foundation user ID.
- The sign-in tokens Quran Foundation issues to Lahza, so we can save bookmarks on your behalf. They are kept on our server and never sent to your browser.
- The passages you choose to keep: the verse reference, its translation, the mood you picked, and the date.
We do not receive your password. Your browser holds a session cookie that keeps you signed in, plus a local cache (language preference and recently loaded passages) so the app works offline. That cache never leaves your device.
Who else is involved
- Quran Foundation handles sign-in, provides the Quran text, translations, tafsir and recitation, and receives a copy of each bookmark you save.
- Quran MCP (mcp.quran.ai) receives a search phrase for the mood you picked. It does not receive anything that identifies you.
- equran.id provides Indonesian tafsir when you read in Indonesian.
- Google Fonts serves the typefaces, and sees your IP address as any website does.
- Fly.io (hosting) and Neon (database) run our servers in Singapore.
How long we keep it
Sign-in sessions are deleted when they expire. Saved passages stay until you ask us to delete them, because keeping them is the point of your personal Mushaf. Encrypted backups are kept for 30 days.
Your choices
You can ask us to export or delete everything we hold about you. Write to wali@lahza.one and we will act within 30 days. Bookmarks already copied to your Quran.com account are managed there.
Changes
If this page changes in a way that matters, the date above changes too.