EISAAL

Privacy Policy

Applies to the Eisaal mobile app for iOS and Android.

Effective date: 1 September 2026  ·  Policy version: 1.0.0 (this is the version number the app records when you accept it)


Eisaal Foundation (“we”, “us”) publishes the Eisaal app. This policy explains what the app collects, why, who else receives it, how long it is kept, and how you can export or delete it. Each item below describes something the app actually does; nothing here is included as a precaution against features we do not have.

Summary

You can use Eisaal without giving us any personal details. Prayer times, Quran, duas, ziyarat, taqeebat, aamaal, tasbeeh, khums and qibla all work offline on your device. Continuing as a guest creates an anonymous account record on our backend that holds no name, email or profile data — see §1.1.

We do not sell your data. We use no advertising identifiers, show no ads, and do not track you across other apps or websites.

Your location is not stored on our servers. It is used on your device to calculate prayer times and the qibla direction. It is sent to a mapping service only at the moment you ask the app to find your city — see §2.

The sajda (Mohr-e-Ameen) feature does not keep or send any image. On iPhone it reads the camera only as a light meter; each frame is reduced to a single brightness value and discarded.

You can delete everything from inside the app, or by requesting deletion here.

Contents: 1. What we collect · 2. Location · 3. Camera, sensors & photos · 4. Notifications · 5. Why we use it & legal bases · 6. Service providers · 7. International transfers · 8. Retention · 9. Your rights & how to use them · 10. Children · 11. Security · 12. Changes · 13. Contact

1. What we collect

1.1 Account and profile data (collected only if you create an account)

Creating an account is optional. It exists so that your favourites, collections and qaza records follow you to a new device. This data is stored in our backend database (Supabase) and is linked to your identity.

Guest use. If you tap “Continue as Guest”, the app creates an anonymous session on our backend. That record is an account identifier and nothing else: no email address, no name, no profile fields. It exists so that the app has a session to work with, and it is deleted along with everything else if you delete your account. Nothing you record while you are a guest is synced to our servers — favourites, qaza records and the rest stay on your device until you create a full account.

DataWhere it comes fromWhy
Email addressYou, or your Google / Apple sign-inTo identify your account and sign you in
Account identifier (a random user ID)Generated by our backendTo link your records to your account
NameYou, or your Google / Apple sign-inTo greet you and personalise the app
Profile photo (optional)You, from your photo libraryShown in your profile
Gender (optional)YouFiqh rules that differ by gender (e.g. qaza obligations)
City, state / locality, country (optional, typed by you)YouPrayer-time defaults; this is a self-reported place name, not GPS
Marja you follow (optional)YouTo show rulings and khums guidance for your marja. This reveals a religious affiliation and we treat it as sensitive — see §5.
Khums start date (optional)YouTo calculate your khums year
Privacy-policy version accepted, and the date you accepted itRecorded when you acceptTo prove and manage consent, and to re-prompt if this policy changes

Profile photos. Your profile photo is stored in our backend’s file storage and the link to it is saved with your account record. That file store is configured for public read access: the photo is not listed or indexed by us, but anyone who has the link can open the image without signing in. Please do not upload a photo you would not be willing to share. You can change or remove it at any time in the app, and it is deleted when you delete your account (§9).

1.2 Your religious activity records (synced only if you are signed in)

These records are linked to your identity and stored in our backend so that they survive a change of device:

1.3 Data that stays on your device

The following is stored locally on your phone and is never uploaded to our servers. We hold no copy of it, so we cannot read it, recover it or delete it for you. It is removed when you uninstall the app, and it is included if you choose to export your data (§9).

1.4 Diagnostics and app usage (released app versions only)

Released builds of the app include Google Firebase Crashlytics and Firebase Analytics. Development builds have both switched off. While you are signed in, both are tagged with your account identifier, so this data is linked to your identity. When you sign out, that identifier is cleared.

What is collectedByPurpose
Crash reports and non-fatal error reports: stack traces, device model, OS version, app version, and the account identifierFirebase CrashlyticsTo find and fix crashes
Screen views — the name of each screen you open in the appFirebase AnalyticsTo understand which features are used
Sign-in events (login, anonymous_sign_in) and whether the session is anonymousFirebase AnalyticsTo measure sign-in success and guest usage
Handled application errors (app_error)Firebase AnalyticsReliability monitoring
Standard Firebase measurement data: app instance ID, approximate coarse region derived from IP by Google, device and OS attributes, session timingFirebase AnalyticsBaseline analytics that Firebase collects automatically

We have explicitly disabled advertising ID (Android AAID) collection, iOS vendor identifier (IDFV) collection, and ad-personalisation signals. There are no advertising SDKs in the app, no App Tracking Transparency prompt, and no cross-app or cross-site tracking.

This version of the app does not include an in-app switch to turn diagnostics off: they are on in released builds and off in development builds. If you would prefer that we did not hold diagnostic data associated with your account, email shortfiqh@gmail.com and we will delete the records tied to your account identifier. Uninstalling the app stops all further collection.

1.5 Bot protection

Where bot protection is enabled on our sign-in flow, an hCaptcha challenge is loaded from hCaptcha’s servers in a web view during sign-in or sign-up. hCaptcha receives your IP address and interaction signals in order to decide whether you are a person rather than an automated script. We do not receive those signals ourselves.

2. Location

3. Camera, sensors and photos

Mohr-e-Ameen (sajda detection)

Photo library

The app asks for photo access only when you choose a profile picture. Only the single image you select is read, and it is uploaded to our file storage to serve as your avatar. The app never writes to your photo library and never scans it. As noted in §1.1, avatar files are served from a publicly readable URL, so treat the photo you choose as public.

4. Notifications

All reminders — prayer times, aamaal and events — are scheduled locally on your device. The app contains no push-messaging service: no push tokens (FCM or APNs) are generated, collected or stored, and we cannot send you a message remotely.

5. Why we use your data, and our legal bases

PurposeData usedLegal basis (UK/EU GDPR)
Providing the app’s core featuresOn-device data, location if grantedPerformance of a contract with you / legitimate interests
Creating your account and syncing your records across devices§1.1, §1.2Performance of a contract with you
Showing rulings and khums guidance for your marjaMarja followedYour explicit consent — this reveals religious belief, a special category of data under Article 9. It is optional; you may leave it blank or clear it at any time in the app.
Recording that you accepted this policyPolicy version + timestampLegal obligation / legitimate interests
Keeping the app stable and finding crashes§1.4Legitimate interests in a working, secure app
Preventing automated abuse of sign-inhCaptcha signals, IPLegitimate interests in security
Answering your support emailsWhat you send usLegitimate interests

We do not use your data for advertising, for profiling that produces legal effects, or for automated decision-making. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.

6. Service providers who process data for us

ProviderRoleWhat they receive
SupabaseBackend database, authentication and file storageEverything in §1.1 and §1.2, plus connection metadata such as IP address
Google (Firebase Crashlytics)Crash reporting§1.4 crash data, linked to your account identifier
Google (Firebase Analytics)Product analytics§1.4 usage events, linked to your account identifier
Google (Google Sign-In)Optional sign-in providerOnly used if you choose it; returns your email, name and photo to us
Apple (Sign in with Apple)Optional sign-in providerOnly used if you choose it; returns an identifier and, if you allow it, your email and name
hCaptchaBot protection at sign-in, where enabledIP address and interaction signals
OpenStreetMap Foundation (Nominatim)Turning coordinates into a place name, and place names into coordinatesApproximate coordinates or the place name you typed, plus a contact email in the request header — only at the moment you ask
Apple / Google app storesApp distribution and, where you use it, ratingsWhatever the store collects under its own policy; we receive only aggregate store reports

These providers process data on our instructions, with the exception of the sign-in providers and the app stores, which act as independent controllers for their own purposes. We may also disclose data where the law requires it, or where it is necessary to protect the rights and safety of our users. We have no other routine disclosures, and we do not disclose data to advertisers or data brokers.

7. International transfers

Our backend is hosted in Mumbai, India (AWS ap-south-1). Firebase and the sign-in providers process data in the United States and other countries. Where data leaves the UK or European Economic Area, transfers rely on the providers’ Standard Contractual Clauses and equivalent safeguards. If you are in the UK or EEA and want a copy of the relevant safeguards, email us.

8. How long we keep data

DataRetention
Account, profile and synced records (§1.1, §1.2)Kept while your account exists. Erased when you delete your account.
Backups of our databaseWe do not keep automated database backups, so no residual copy of your data survives deletion. Erasure is immediate and final.
On-device data (§1.3)Until you delete it in the app or uninstall the app. We never hold a copy.
Crash reportsRetained by Firebase Crashlytics for up to 90 days, per Google’s standard retention for that product.
Analytics eventsRetained for 2 months, as configured in our Firebase project, after which user-level records are deleted and only aggregates remain.
Support emails12 months after the conversation ends.

9. Your rights, and exactly how to use them

Depending on where you live, you may have the right to access your data, correct it, export it, delete it, restrict how it is processed, object to processing based on legitimate interests, withdraw a consent you have given, and complain to your data protection authority. We do not charge for these requests, and we will not treat you differently for making one.

Export your data — in the app

Open Eisaal → tap the settings icon in the top bar → LegalData & PrivacyExport My Data.

The app assembles a single JSON file on your device and hands it to your phone’s share sheet, so you can save it, email it to yourself, or send it wherever you like. The export includes your profile, settings and preferences, favourites and collections, bookmarks, qaza profiles, your aamaal and aamaal completions, your Hijri events, prayer notification settings, tasbeeh sessions, mohr sessions and khums calculations.

Delete your account and data

In the app: settings icon → scroll to Danger ZoneDelete Account → confirm.

If you have already uninstalled the app, or you would rather email us, follow the instructions on the Delete Account page.

Everything else

For access, correction, restriction, objection, or to withdraw a consent, email shortfiqh@gmail.com from the address on your account, so that we can confirm the request is yours. We reply within 5 business days and complete verified requests within 30 days. Deletions you start in the app take effect immediately. Most profile fields, including your marja, your gender and your city, can also be edited or cleared yourself in the app at any time.

10. Children

Eisaal is a general-audience religious utility. It is not directed at children, it contains no child-targeted content or features, and we do not knowingly collect personal data from anyone under 13 — or under 16 if you are in the European Economic Area or the United Kingdom, where we rely on that higher age unless local law sets a lower one. If you believe a child has given us personal data, email us and we will delete it. Younger users may of course use the app’s offline features without an account, under the supervision of a parent or guardian.

11. Security

Traffic between the app and our services is encrypted in transit using TLS. Access to account records in our backend is restricted by row-level security rules, so that one account cannot read another’s data. The one deliberate exception is the avatar file store described in §1.1, which is readable by anyone holding the file’s link. Data stored on your device is protected by your device’s own operating-system protections, so please keep a screen lock enabled. No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authority where the law requires it.

12. Changes to this policy

If we make a material change to this policy, we will update the effective date and increase the policy version number. The app records which version you accepted and will ask you to review and accept the new version the next time you sign in. The current version is always published at https://eisaal.com/privacy-policy.html.

13. Contact

Eisaal Foundation
EISAAL FOUNDATION, C/o Syed Sibte Raza, Chaura, Amroha - 244221, Uttar Pradesh, India
Email: shortfiqh@gmail.com

If you are in the UK or EEA, you have the right to lodge a complaint with your local supervisory authority.