diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS
new file mode 100644
index 0000000..fc2b286
--- /dev/null
+++ b/.github/CODEOWNERS
@@ -0,0 +1 @@
+* @BTheCoderr
diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md
new file mode 100644
index 0000000..59934ee
--- /dev/null
+++ b/.github/ISSUE_TEMPLATE/bug_report.md
@@ -0,0 +1,40 @@
+---
+name: Bug report
+about: Report a reproducible DeenNotes problem
+title: "[Bug] "
+labels: bug
+assignees: ""
+---
+
+## What happened?
+
+## What did you expect?
+
+## Where did it happen?
+
+- [ ] iPhone/iPad app
+- [ ] Web companion
+- [ ] Authentication
+- [ ] Reflect / AI
+- [ ] Quran / audio
+- [ ] Prayer / Salah Planner / Qibla
+- [ ] Premium / purchases
+- [ ] Other
+
+## Steps to reproduce
+
+1.
+2.
+3.
+
+## Device / version
+
+- DeenNotes version:
+- iOS / browser:
+- Device:
+
+## Evidence
+
+Screenshots, screen recordings, console output, or error text are helpful.
+
+> Do not post passwords, API keys, Supabase tokens, private notes, or other sensitive account data.
diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md
new file mode 100644
index 0000000..e5ce1a0
--- /dev/null
+++ b/.github/ISSUE_TEMPLATE/feature_request.md
@@ -0,0 +1,23 @@
+---
+name: Feature request
+about: Suggest a product or engineering improvement
+title: "[Feature] "
+labels: enhancement
+assignees: ""
+---
+
+## Problem
+
+What user problem or workflow should improve?
+
+## Proposed experience
+
+What should happen from the user's point of view?
+
+## Why it belongs in DeenNotes
+
+How does this support reflection, Quran study, prayer planning, journaling, reminders, or related productivity?
+
+## Notes / constraints
+
+Include accessibility, privacy, subscription, device, or religious-scope considerations when relevant.
diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md
new file mode 100644
index 0000000..835f67e
--- /dev/null
+++ b/.github/PULL_REQUEST_TEMPLATE.md
@@ -0,0 +1,30 @@
+## What changed
+
+
+
+## Why
+
+
+
+## Verification
+
+- [ ] Web typecheck passes
+- [ ] Tests pass
+- [ ] Mobile typecheck passes when mobile code changed
+- [ ] Production build passes when web/server code changed
+- [ ] No secrets, credentials, private keys, or real service-role values were committed
+- [ ] User-facing copy stays within DeenNotes' reflection/study scope and does not present AI output as a religious ruling
+
+## Product surfaces checked
+
+- [ ] Sign in / account
+- [ ] Reflect
+- [ ] Quran / audio
+- [ ] Prayer / Salah Planner / Qibla
+- [ ] Premium / restore purchases
+- [ ] Settings / account
+- [ ] Not applicable
+
+## Deployment
+
+
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
new file mode 100644
index 0000000..a73517d
--- /dev/null
+++ b/.github/dependabot.yml
@@ -0,0 +1,23 @@
+version: 2
+updates:
+ - package-ecosystem: npm
+ directory: /
+ schedule:
+ interval: weekly
+ day: monday
+ open-pull-requests-limit: 5
+ labels:
+ - dependencies
+ commit-message:
+ prefix: deps
+
+ - package-ecosystem: npm
+ directory: /apps/mobile
+ schedule:
+ interval: weekly
+ day: monday
+ open-pull-requests-limit: 5
+ labels:
+ - dependencies
+ commit-message:
+ prefix: deps-mobile
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
new file mode 100644
index 0000000..705d7a0
--- /dev/null
+++ b/.github/workflows/ci.yml
@@ -0,0 +1,85 @@
+name: CI
+
+on:
+ pull_request:
+ push:
+ branches:
+ - main
+
+concurrency:
+ group: ci-${{ github.workflow }}-${{ github.ref }}
+ cancel-in-progress: true
+
+permissions:
+ contents: read
+
+jobs:
+ web-quality:
+ name: Web quality
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ steps:
+ - name: Checkout
+ uses: actions/checkout@v4
+
+ - name: Use Node.js 20
+ uses: actions/setup-node@v4
+ with:
+ node-version: 20
+ cache: npm
+
+ - name: Install dependencies
+ run: npm ci
+
+ - name: TypeScript
+ run: npm run typecheck
+
+ - name: Tests
+ run: npm test
+
+ mobile-quality:
+ name: Mobile quality
+ runs-on: ubuntu-latest
+ timeout-minutes: 15
+ steps:
+ - name: Checkout
+ uses: actions/checkout@v4
+
+ - name: Use Node.js 20
+ uses: actions/setup-node@v4
+ with:
+ node-version: 20
+ cache: npm
+
+ - name: Install dependencies
+ run: npm ci
+
+ - name: Mobile TypeScript
+ run: npm run mobile:typecheck
+
+ web-build:
+ name: Web production build
+ runs-on: ubuntu-latest
+ timeout-minutes: 20
+ env:
+ NEXT_PUBLIC_SITE_URL: https://deennotesai.netlify.app
+ NEXT_PUBLIC_APP_STORE_URL: https://apps.apple.com/us/app/deennotes-ai/id6767057471
+ NEXT_PUBLIC_SUPABASE_URL: https://example.supabase.co
+ NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY: ci-placeholder-key
+ MOCK_QURAN_API: "true"
+ QURAN_GRACEFUL_MOCK_FALLBACK: "true"
+ steps:
+ - name: Checkout
+ uses: actions/checkout@v4
+
+ - name: Use Node.js 20
+ uses: actions/setup-node@v4
+ with:
+ node-version: 20
+ cache: npm
+
+ - name: Install dependencies
+ run: npm ci
+
+ - name: Build
+ run: npm run build
diff --git a/CHANGELOG.md b/CHANGELOG.md
new file mode 100644
index 0000000..0f32802
--- /dev/null
+++ b/CHANGELOG.md
@@ -0,0 +1,30 @@
+# Changelog
+
+Notable DeenNotes AI changes are tracked here alongside the App Store release history.
+
+## [1.0.4] - Current production release
+
+### Product
+
+- Salah Planner improvements
+- beginner-friendly Learning Mode
+- Quran reading and audio experience improvements
+- prayer and reminder experience improvements
+- khutbah / reminder recording improvements
+- ongoing reliability and polish across the mobile experience
+
+### Platform
+
+- Expo / React Native mobile client
+- Supabase-backed authenticated account data with RLS
+- RevenueCat-backed iOS subscriptions
+- Next.js web companion and API
+- pluggable AI-provider architecture
+
+## Earlier releases
+
+Earlier production versions predate this repository changelog. Their exact historical notes should be sourced from the App Store release record rather than reconstructed from memory.
+
+## Changelog policy
+
+New production releases should add a dated entry before or alongside release work. Keep user-facing product changes separate from infrastructure/security changes where practical.
diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md
new file mode 100644
index 0000000..a3f07ba
--- /dev/null
+++ b/CODE_OF_CONDUCT.md
@@ -0,0 +1,17 @@
+# Code of Conduct
+
+DeenNotes contributors should keep technical discussion respectful, specific, and focused on the work.
+
+## Expected behavior
+
+- discuss code and product decisions without personal attacks
+- assume good faith while still reviewing critically
+- protect user privacy and never post sensitive account or journal data
+- respect the product's faith-sensitive context
+- distinguish personal religious opinions from product requirements
+
+## Unacceptable behavior
+
+Harassment, threats, discriminatory attacks, deliberate disclosure of private information, credential sharing, or attempts to use the project to present AI output as authoritative religious rulings are not acceptable.
+
+Repository maintainers may remove content or participation that violates these expectations.
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
new file mode 100644
index 0000000..af2de9e
--- /dev/null
+++ b/CONTRIBUTING.md
@@ -0,0 +1,40 @@
+# Contributing to DeenNotes AI
+
+DeenNotes AI is a shipped mobile product with an Expo/React Native client, a Next.js web companion/API, Supabase-backed accounts, RevenueCat subscriptions, Quran/audio features, prayer utilities, and AI-assisted reflection organization.
+
+## Product scope
+
+Contributions should support the product's role as a reflection, study, journaling, and productivity companion. AI-generated content must not be presented as a fatwa, authoritative religious ruling, or substitute for qualified scholarship.
+
+## Before opening a pull request
+
+1. Create a focused branch.
+2. Keep secrets out of tracked files. Use the documented environment-variable examples.
+3. Run:
+ ```bash
+ npm ci
+ npm run typecheck
+ npm test
+ npm run mobile:typecheck
+ ```
+4. If web/server behavior changed, also run:
+ ```bash
+ npm run build
+ ```
+5. Test the product surface you changed.
+
+## Pull requests
+
+Keep PRs small enough to review. Explain what changed, why it changed, and how it was verified. A merged code change does not automatically mean it should be deployed to production.
+
+## Security
+
+Do not open a public issue containing credentials, tokens, personal journal content, or a vulnerability that could expose user data. See [SECURITY.md](SECURITY.md).
+
+## Database changes
+
+Treat `supabase/migrations/` as the source of truth. Preserve RLS on account-owned data and avoid broad grants to public roles.
+
+## Mobile releases
+
+For App Store changes, follow the current mobile and release documentation under [docs/](docs/README.md). Versioned mobile configuration lives under `apps/mobile/`.
diff --git a/LICENSE b/LICENSE
new file mode 100644
index 0000000..c5492ce
--- /dev/null
+++ b/LICENSE
@@ -0,0 +1,7 @@
+Copyright (c) 2026 Baheem Ferrell
+
+All rights reserved.
+
+This source code is publicly viewable for portfolio, review, and collaboration purposes. No permission is granted to copy, modify, distribute, sublicense, sell, or create derivative works from this repository except with the copyright holder's prior written permission.
+
+Third-party dependencies and assets remain subject to their own licenses and terms.
diff --git a/README.md b/README.md
index df794a6..69b5b70 100644
--- a/README.md
+++ b/README.md
@@ -1,5 +1,19 @@
# DeenNotes AI
+
+
+
+
+[](https://github.com/BTheCoderr/DeenNotesAI/actions/workflows/ci.yml)
+
+
+
+
+
+
+**App Store:** https://apps.apple.com/us/app/deennotes-ai/id6767057471 · **Web companion:** https://deennotesai.netlify.app/
+
+
**Project snapshot:** DeenNotes AI is a shipped iPhone/iPad app for Islamic reflection, Quran study, prayer planning, journaling, reminders, and AI-assisted note organization. The product is intentionally scoped as a reflection and productivity companion—not a source of fatwas or religious rulings.
@@ -27,6 +41,33 @@
5. Save account-owned reflections securely with Supabase Auth + RLS.
6. Unlock premium features through RevenueCat-backed App Store subscriptions.
+## Architecture
+
+```text
+iPhone / iPad (React Native + Expo)
+ │
+ ├──────────────► RevenueCat ─────► App Store subscriptions
+ │
+ ▼
+ Next.js web/API
+ │ │ │
+ ▼ ▼ ▼
+ Supabase AI Quran services
+ Auth/DB providers/content/audio
+ + RLS
+```
+
+See [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) for the system boundaries and production responsibilities.
+
+## Repository guide
+
+- [CHANGELOG.md](CHANGELOG.md) — production release history
+- [ROADMAP.md](ROADMAP.md) — shipped, improving, and exploring
+- [docs/README.md](docs/README.md) — current vs. historical product documentation
+- [CONTRIBUTING.md](CONTRIBUTING.md) — development and review expectations
+- [SECURITY.md](SECURITY.md) — vulnerability and secret-handling policy
+- [.github/workflows/ci.yml](.github/workflows/ci.yml) — automated web/mobile verification
+
## Engineering highlights
- React Native + Expo Router mobile app in `apps/mobile`
@@ -48,6 +89,19 @@ DeenNotes AI is mobile-first: the shipped React Native / Expo app is the primary
Treat this repo as **safe to make public**: tracked files must not contain database passwords, Supabase **service_role** or **secret** keys, AI provider keys, JWTs, or real **Project Refs**. Clone [`.env.example`](.env.example) to **`.env.local`** (or `.env`), add your values only on your machine, and rely on **`.gitignore`** (`.env*` with an exception for `.env.example`). The Next.js app uses the **anon/publishable** client key with **RLS**; `SUPABASE_SERVICE_ROLE_KEY` is optional and **not** used by app routes—never prefix it with `NEXT_PUBLIC_`.
+## Repository quality gates
+
+Every pull request is set up to run GitHub CI for:
+
+- root TypeScript verification
+- Vitest tests
+- mobile TypeScript verification
+- a production-style Next.js build using safe CI placeholder configuration
+
+Dependency update PRs are managed by Dependabot. Pull requests and issues use repository templates, and CODEOWNERS routes changes to the maintainer.
+
+**Deployment is deliberately separate from CI.** A passing GitHub check or merged pull request is not treated as permission to publish a Netlify or App Store release.
+
## Production / release checklist
For ongoing releases and maintenance:
@@ -219,3 +273,8 @@ From the repo you can also use **`npm run netlify:deploy:prod`** (see [Netlify C
## Product disclaimer
DeenNotes is for organizing Islamic learning and personal reflection. It does not provide fatwas or religious rulings. Users should consult a qualified scholar or imam for religious decisions.
+
+## License
+
+Copyright © 2026 Baheem Ferrell. All rights reserved. This public repository is viewable for portfolio, review, and collaboration purposes; it is **not** released under an open-source license. See [LICENSE](LICENSE).
+
diff --git a/ROADMAP.md b/ROADMAP.md
new file mode 100644
index 0000000..7e90d08
--- /dev/null
+++ b/ROADMAP.md
@@ -0,0 +1,40 @@
+# DeenNotes AI Roadmap
+
+This roadmap describes product direction, not guaranteed dates.
+
+## Shipped
+
+- Islamic reflection and journal capture
+- AI-assisted structured summaries, takeaways, reminders, and action steps
+- Quran reading and audio
+- Qibla
+- prayer reminders and planning
+- Salah Planner
+- Learning Mode
+- local recording support
+- authenticated account storage
+- premium subscriptions and restore-purchase flow
+- iPhone/iPad App Store release
+- web companion and account entry points
+
+## Improving
+
+- accessibility coverage and App Store accessibility declarations
+- reliability and observability
+- AI-provider resilience and graceful fallbacks
+- account/authentication QA
+- Quran/audio polish
+- prayer-planning usability
+- subscription and restore-purchase reliability
+- documentation and release automation
+
+## Exploring
+
+- deeper organization of saved reflections
+- better search and retrieval across personal notes
+- richer Quran-to-reflection workflows
+- stronger continuity between mobile and web
+
+## Product boundary
+
+DeenNotes supports reflection, study, organization, and personal practice. It should not present AI output as an authoritative religious ruling.
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..bbc17fe
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,37 @@
+# Security Policy
+
+## Supported version
+
+Security fixes target the current production release of DeenNotes AI and the current `main` branch.
+
+## Reporting a vulnerability
+
+Please do **not** open a public GitHub issue for vulnerabilities that could expose user accounts, private reflections, credentials, tokens, subscription data, or server-side secrets.
+
+Prefer GitHub's private vulnerability-reporting / Security Advisory flow when it is available for this repository. Otherwise, contact the repository owner privately through GitHub before sharing exploit details publicly.
+
+Include:
+
+- affected surface and version
+- reproduction steps
+- expected vs. actual behavior
+- impact
+- screenshots or logs with secrets and personal data removed
+
+## Secrets
+
+Never commit:
+
+- Supabase service-role or secret keys
+- database passwords
+- AI provider keys
+- JWTs or user session tokens
+- Netlify personal access tokens
+- private Quran provider credentials
+- RevenueCat secret credentials
+
+Public/publishable client values should still be managed through documented environment variables.
+
+## Data access model
+
+Account-owned data should remain protected by Supabase Row Level Security and least-privilege grants. Server-only credentials must never be exposed through `NEXT_PUBLIC_*` or `EXPO_PUBLIC_*` variables unless the credential is explicitly designed to be public.
diff --git a/docs/ARCHITECTURE.md b/docs/ARCHITECTURE.md
new file mode 100644
index 0000000..e2e349a
--- /dev/null
+++ b/docs/ARCHITECTURE.md
@@ -0,0 +1,54 @@
+# DeenNotes AI Architecture
+
+## Product surfaces
+
+```text
+┌──────────────────────────────┐
+│ iPhone / iPad │
+│ React Native + Expo Router │
+└──────────────┬───────────────┘
+ │
+ auth / data / API
+ │
+ ┌────────▼─────────┐
+ │ Next.js │
+ │ web companion/API│
+ └───────┬──────────┘
+ │
+ ┌──────────┼───────────────┐
+ │ │ │
+ ▼ ▼ ▼
+Supabase AI providers Quran services
+Auth/DB structured content/audio
++ RLS reflection
+
+iOS app ───────────────► RevenueCat ───────────────► App Store subscriptions
+```
+
+## Mobile
+
+The primary shipped product lives in `apps/mobile/` and uses React Native, Expo, Expo Router, Supabase, RevenueCat, Sentry, audio/device APIs, notifications, location, and motion sensors.
+
+## Web companion / server
+
+The Next.js app provides the public web experience, account entry points, server routes, legal/product pages, and server-side integrations that should not expose credentials to clients.
+
+## Data
+
+Supabase provides authentication and Postgres persistence. Account-owned tables should remain protected by Row Level Security and least-privilege grants.
+
+## AI
+
+AI-provider selection is pluggable rather than tied to a single vendor. Structured validation is used so reflection output can remain predictable across providers. AI output is scoped to organization/reflection support, not religious rulings.
+
+## Quran
+
+Quran routes support provider-backed content/audio with explicit environment configuration and controlled mock/fallback behavior for development and resilience.
+
+## Monetization
+
+RevenueCat handles the mobile subscription entitlement layer while Apple's App Store remains the purchase platform for iOS.
+
+## Deployment boundary
+
+GitHub code changes, CI verification, Netlify deployment, and App Store release are separate stages. Merging code should not be treated as equivalent to publishing a production release.
diff --git a/docs/README.md b/docs/README.md
new file mode 100644
index 0000000..398c65e
--- /dev/null
+++ b/docs/README.md
@@ -0,0 +1,26 @@
+# DeenNotes Documentation
+
+The repository contains both **current production documentation** and **historical launch artifacts**. Historical files are intentionally retained because they document how the product was validated before and during launch.
+
+## Current production / operations
+
+- [AUTH_PRODUCTION_QA.md](AUTH_PRODUCTION_QA.md) — production authentication checks
+- [DEPLOY_CHECKLIST.md](DEPLOY_CHECKLIST.md) — web deployment verification
+- [MOBILE_EAS_LAUNCH.md](MOBILE_EAS_LAUNCH.md) — Expo/EAS build and release mechanics
+- [QURAN_API_ROUTES.md](QURAN_API_ROUTES.md) — Quran service/API routes
+- [QURAN_NETLIFY_ENV.md](QURAN_NETLIFY_ENV.md) — Quran-related production environment configuration
+- [SALAH_PLANNER_MVP.md](SALAH_PLANNER_MVP.md) — Salah Planner implementation notes
+- [BRAND_SYSTEM.md](BRAND_SYSTEM.md) — product brand system
+- [ARCHITECTURE.md](ARCHITECTURE.md) — high-level system architecture
+
+## Historical launch / validation records
+
+These remain useful as release-history and QA evidence, but their milestone names do **not** mean the product is still pre-launch:
+
+- [MVP_LAUNCH_QA.md](MVP_LAUNCH_QA.md)
+- [M6_TESTFLIGHT_LAUNCH_READINESS.md](M6_TESTFLIGHT_LAUNCH_READINESS.md)
+- [M7_PRODUCTION_QA.md](M7_PRODUCTION_QA.md)
+- [M8_MONETIZATION.md](M8_MONETIZATION.md)
+- [M9_TESTFLIGHT_SUBSCRIPTION_VALIDATION.md](M9_TESTFLIGHT_SUBSCRIPTION_VALIDATION.md)
+
+When current behavior conflicts with a historical milestone document, current production configuration and newer documentation take precedence.