MuslyWave, last updated 1 August 2026
MuslyWave is a listening app. To work it needs to know who you are, what you have listened to and what you have saved. This notice says exactly what that means, who else sees any of it, and how to get rid of all of it.
MuslyWave is made and run by an independent developer based in Italy, not by a company. That person decides how the information described here is processed and is the data controller for the purposes of the GDPR.
The contact point for everything in this notice, questions, complaints, and any of the rights below, is muslywavesupport@gmail.com. It is read by the person who wrote this, and it is the fastest way to get an answer. A postal address is available on request; it is not published here because there is no company office to publish, only a home.
When you sign in with Google or with Apple, that provider tells us your email address, and, if you allow it, your name and profile picture. We store the email address so that one account is one person and so we can contact you about the service. We never receive your password, and after this version there is no password to receive: signing in with an email address and a password has been removed.
If you sign in with Apple and choose "Hide My Email", we only ever see the relay address Apple gives us and that is fine, everything works the same.
The display name, biography, note, profile picture, banner, name colour and font, and, for subscribers, any image or font you upload. All of this is chosen by you, and everything except a private profile is visible to anyone using the app.
We record which tracks you play and when. It is what makes the home screen, the charts, the "continue listening" row, your streak and your badges work, and it is what tells us which creator to pay. Specifically we keep your recent plays, running totals per category, the days on which you listened, and how many of those were at night or before dawn.
Liked tracks, playlists you build, playlists you open, creators you follow, comments and replies you post, and the hearts you receive. Anything posted in the community is public by design.
You can send a private message to somebody once you are both friends. We store, on our servers, everything a message is made of: the text you type, the emoji reaction you tap, the playlist, track or verse you forward, who sent it, who received it, when it was sent, when it was read, whether one of you starred it, and which message it was a reply to.
Messages are private between the two of you. They are not end-to-end encrypted, which means that in principle the person who runs this app can read them. In practice we do not, with two exceptions: when somebody reports a message to us, so that we can decide what to do about it, and where the law requires it. If you would not write it on a postcard, do not write it here.
Blocking somebody stops them writing to you and we keep the list of who you have blocked. Reporting a message or a person sends us the message or the profile together with the reason you chose, and we keep who reported whom. The person you report is not told that it was you.
If you subscribe to MuslyWave Pro, the purchase itself happens with Apple. We receive from Apple, through RevenueCat, an anonymous purchase identifier, which product was bought, and when it expires. We never receive your card number, your billing address or your Apple ID.
If you are an approved creator we record the advertising impressions attributed to your playlists, what they earned, and, when you request a payout, the payment details you type in yourself, such as an IBAN or a PayPal address. We keep those only to pay you and for as long as accounting law requires us to.
If you turn notifications on, we store the push token for your device together with its time zone and language, so a reminder about your streak arrives in the evening rather than at four in the morning. Turning notifications off deletes the token.
When somebody sends you a message you get a notification that says who wrote to you. It does not contain the message. That is deliberate: a notification is read off a lock screen by whoever happens to be looking at the phone, and what was written is nobody else's business.
So that we can tell whether the app is working for people, we count five things: that the app was opened, that something was played, that a search was made, that something was shared, and that the subscription screen was seen. We count that they happened. We do not record what you played, what you searched for, or what you shared.
These counts are attached to a random number that the app generates for itself the first time it runs and keeps on your device. It is not your name, not your email address, and not Apple's advertising identifier: it identifies an installation, not a person, and nobody outside this app ever sees it. Delete the app and that number is gone; install it again and a new one is generated, with no way to connect the two.
We do this because without it we would have no idea whether anybody comes back after the first day, and no way to find the point where the app is losing people. The counts are aggregated for that purpose alone. They are not sold, not shared with any advertiser, and not used to target advertising. Counts older than roughly a year are deleted.
If you tap "Use my location" on the prayer times screen, the app asks the phone for your approximate position and uses it, on the device, to work out the times for where you are. That position is not sent to us and not stored on our servers. You can type a city instead and never grant the permission at all, and turning the permission off later changes nothing except that you go back to typing a city.
We do not ask for your contacts, your microphone, or your health data. We ask for the photo library or the camera only at the moment you choose a picture to upload, and only that picture reaches us. We do not build advertising profiles from what you listen to.
One honest caveat about Article 9 GDPR. MuslyWave is in part a religious app: it has Quran recitations, adhkar and prayer times, so what you listen to and which reminders you turn on can reveal a religious belief. We treat that as ordinary data about your use of the app because it is what makes the app work for you, we never use it for advertising, and it is deleted with your account like everything else. If you would rather it did not exist at all, deleting the account removes it.
Unless you subscribe to MuslyWave Pro, the app shows banner advertising. Ads are served by Unity Ads, operated by Unity Technologies, which acts as an independent controller for the data it collects. To serve an ad, Unity may receive your device's advertising identifier, its model and operating system, the country you are in and the fact that an ad was displayed.
We do not send Unity your email address, your name, your listening history or anything you have written. We do not target advertising using what you listen to.
On iOS, no advertising identifier is used for tracking unless you allow it when the system asks. You can change your mind at any time in Settings → Privacy & Security → Tracking, and you can turn off personalised advertising entirely in Settings → Privacy & Security → Apple Advertising. Unity's own privacy policy explains what it does with what it receives.
Subscribing to MuslyWave Pro removes every advertisement from the app.
Audio and video are played through YouTube. The app uses YouTube API Services, and by using it you also agree to the YouTube Terms of Service, which you can read at https://www.youtube.com/t. Google's Privacy Policy at https://policies.google.com/privacy describes what Google does with the information it receives when a video is played, which includes your IP address and the fact that a particular video was requested. We do not control that and cannot delete it on your behalf; you can review and remove the data Google holds about you at https://myaccount.google.com/.
We do not sell your personal information. It reaches other companies only where the app cannot work without them:
We will also disclose information where the law requires it, to enforce our terms, or to protect somebody's safety, and, if the app were ever sold or merged, to the buyer, who would be bound by this notice until it told you otherwise.
Our providers store data on servers in the European Union and in the United States. Where information leaves the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses or on an adequacy decision. You can ask us for a copy of the safeguards that apply.
For people in the EEA and the UK, the legal bases are:
You can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent, you can withdraw it. Write to muslywavesupport@gmail.com and we will answer within one month.
You can also delete your account yourself, from Settings → Delete Account, without writing to anybody. That removes your profile, your library, your listening, your comments, your uploads and your messages. Deleting your messages deletes them for the person you were talking to as well: a conversation is one set of rows and there is no copy of it that survives you.
If you think we have got it wrong you can complain to your national data protection authority. We would rather you told us first.
If you live in California, you have the right to know what we collect and why, to delete it, to correct it, and not to be treated differently for asking. We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined by the CCPA. The same address works: muslywavesupport@gmail.com.
MuslyWave is not for children under 13. We do not knowingly collect anything from them. If you believe a child has created an account, write to muslywavesupport@gmail.com and we will delete it.
Because people can write to each other here, this matters more than it would in an app you only listen to. If you come across a message that makes you think you are talking to a child, or that a child is being approached, report it from inside the conversation and we will look at it first, before anything else in the queue.
Traffic is encrypted in transit. The database enforces, row by row, who is allowed to read and write what, rather than trusting the app to ask nicely. Passwords do not exist in our systems because sign-in is delegated to Google and Apple. No system is perfect, and if a breach ever affects you we will tell you and the relevant authority as the law requires.
If we change this notice we will update the date at the top, and for anything that materially affects you we will tell you inside the app before it takes effect. Last updated 1 August 2026.