1. About this policy
KitabGrid is an educational website providing access to the Quran, Hadith, reviewed Islamic learning materials, practical tools, questions and answers, and related services. This policy explains how personal data is handled when you use account, contact, newsletter, correction, question, or AI-assisted features.
2. Data we may process
Depending on the feature, this may include account and verification data, security/session records, content you submit, communication preferences, reading or learning preferences where enabled, support requests, questions, corrections, and technical security logs.
3. Purposes and lawful bases
Processing may be necessary to provide requested services, protect the website and users, meet legal obligations, or operate optional services based on consent. Optional newsletter consent can be withdrawn at any time.
4. Cookies
Strictly necessary cookies or similar storage may be used for security, sessions, CSRF protection, language preferences and consent choices. Non-essential analytics or marketing technologies are not activated unless separately disclosed and lawfully enabled.
5. Ask KitabGrid and submitted questions
Do not include unnecessary sensitive personal information in questions or support messages. AI-assisted explanations may be stored with source references, review status and feedback where the feature is enabled. Automated answers may contain mistakes and should be checked against cited sources.
6. Retention and security
Data is retained only as long as reasonably required for the relevant purpose, security, dispute handling, backup or legal obligations. KitabGrid uses access controls, password hashing, secure sessions, restricted administrative permissions, logging, backups, rate limiting and secure error handling where applicable.
7. Your rights
Subject to applicable law, you may have rights of access, correction, erasure, restriction, objection, portability, withdrawal of consent and complaint to the competent supervisory authority. If the controller is established in Poland, the supervisory authority is generally the President of the Personal Data Protection Office (UODO).
8. Contact
Use the Contact page for privacy requests until a dedicated privacy address is shown here. The operator identity and formal privacy contact must be completed by the administrator before this policy is treated as legally final.