§ 1 Who we are
Aydeen ("we", "our", "us", or "the App") is an Islamic companion mobile application. Aydeen is published by Deepfai Inc. ("Deepfai", "the Company"), an Illinois corporation based in Chicago, Illinois, USA, operating under the registered fictitious business name (DBA) "Deenify." When this policy refers to "Deenify," it refers to Deepfai Inc. operating under that brand.
We can be contacted at:
- Email: privacy@deenify.com
§ 2 Scope of this policy
This policy explains what personal data Aydeen collects, why we collect it, how we use it, who we share it with, and the rights you have over your data. It applies to your use of the Aydeen mobile application on iOS and Android, our website at deenify.com and aydeen.app, and any related services.
By installing, using, or registering for Aydeen, you agree to the practices described here.
§ 3 The short version
- We collect only what we need to make the App work for you.
- Your prayer history, Qur'an reading progress, and devotional data are private — we do not sell them.
- Group location is shared with your group leader only when you are outside your hotel geofence, and is auto-deleted at the end of your trip.
- Document images for verse/hadith verification are processed entirely on your device and never leave your phone.
- AI-assisted Q&A answers (where enabled) are educational and never substitute scholarly fatwa.
- You can export or delete your data at any time from the App's Privacy & Data screen.
§ 4 What data we collect
4.1 Information you provide directly
- Account information: when you sign in, we receive your phone number (for SMS OTP), or your Google account email + display name (for Google Sign-In).
- Profile information: language preference, country, fiqh school (madhhab) selection, and any display name you set.
- Group information: group name, role (leader or member), 6-digit join code, and the hotel location your group leader sets for the trip.
- User-generated content: lost-and-found item descriptions, Qur'an mistake reports, ritual checklist entries, prayer tracker entries, and any in-app questions you submit through the Ask-a-Question screen.
4.2 Information collected automatically
- Identifiers: Firebase Authentication user ID (uid), device installation ID, FCM (push notification) token.
- Location data (when authorized): GPS coordinates and approximate location accuracy. Used only for: (a) Qibla direction calculation (on-device only), (b) group location sharing (only when outside the configured hotel geofence), (c) prayer time calculation by location, and (d) finding nearby mosques (on request).
- Usage data: in-app screen visits, feature interactions, and anonymous event analytics (e.g., onboarding completed, group joined). We do not track you across other apps or websites.
- Diagnostic data: crash logs, performance metrics, and device identifiers (model, OS version, locale) collected by Firebase Crashlytics and Performance Monitoring to fix bugs and improve reliability.
- Battery level: included with location publishes so your group leader can see if your phone is running low.
4.3 Information processed only on your device (never uploaded)
- OCR and image data from the verse/hadith verification feature: photos you select are processed by on-device Google ML Kit text recognition. The images and recognized text are never uploaded to our servers.
- Speech audio for the voice-search and Ask-a-Question features: audio is processed by your device's system speech engine (Apple Speech / Android SpeechRecognizer) and is not stored or transmitted by Aydeen.
- Compass and motion sensor data for Qibla orientation: read transiently and never stored.
§ 5 Why we collect it (lawful bases under GDPR)
| Purpose | Data | Lawful basis |
|---|---|---|
| Provide and maintain the App | Account info, identifiers | Contract (you signing up to use the service) |
| Group location safety | Location, battery | Consent (you toggle group location sharing on) and legitimate interests (pilgrim safety) |
| Prayer time calculations and reminders | Location, time zone | Contract; you can opt out at any time |
| Crash reporting and performance | Diagnostic data | Legitimate interests (keeping the App reliable) |
| Customer support | Contact email, account info | Legitimate interests |
| Premium subscription billing | Apple/Google receipt data, user ID | Contract |
| Compliance with law | All of the above as applicable | Legal obligation |
We do not use your data for behavioral advertising or sell it to third parties.
§ 6 Who we share data with
We share data only with the following categories of recipients, and only as needed to operate the App:
- Google Firebase (Authentication, Firestore, Realtime Database, Cloud Functions, Cloud Messaging, Storage, Analytics, Crashlytics, Performance Monitoring, Remote Config, App Check) — for authentication, data storage, real-time sync, push notifications, crash reporting, and abuse prevention. Firebase is operated by Google LLC. See Firebase Privacy and Security.
- Google Maps Platform (Maps SDK, Places API, Geocoding) — for displaying maps, searching hotel addresses, and navigating to holy sites. Operated by Google LLC. See Google Maps Privacy.
- Google AdMob — only for free-tier users and only on non-devotional screens. Currently disabled by default. When active, AdMob may collect device identifiers for ad personalization (you can disable personalized ads in your device's privacy settings). See AdMob Privacy.
- Google ML Kit — for on-device text recognition. Image data does not leave your device.
- Apple App Store and Google Play Store — for in-app purchase processing. Subscription receipts are validated by our Cloud Functions but no payment-card information ever reaches our servers.
- OpenWeatherMap (planned) — for weather and heat-index alerts in the holy sites. Only your approximate location at the time of the lookup is shared.
- Open Exchange Rates / open.er-api.com — for currency conversion rates. No personal data is shared.
- Google Sign-In (when used) — for OAuth authentication.
We do not share your personal data with advertisers, data brokers, or for behavioral profiling outside the App.
§ 7 Group location sharing — the explicit rule
This feature is the most sensitive and we want to be very explicit:
- Sharing is OFF by default. Only after you join a group and grant background-location permission does any location data leave your device.
- Hotel geofence rule: while you are within your group's configured hotel geofence (typically a 100–500m radius set by your group leader), Aydeen does NOT publish your latitude/longitude. Only a status flag indicating you are at the hotel is published.
- Outside the hotel: your latitude, longitude, accuracy, and battery are written to a real-time database visible only to your group leader.
- Auto-deletion: location data is automatically deleted at the end of your trip.
- You can stop at any time by leaving the group, disabling location permissions in your OS settings, or signing out.
- No historical trail: we deliberately overwrite a single location field rather than logging a path, so no breadcrumb history is retained on our servers.
§ 8 AI-assisted Q&A and religious content
- All Qur'an translations bundled in Aydeen are sourced from the King Fahd Glorious Qur'an Printing Complex (KFGQPC) and openly licensed translations (Sahih International, Pickthall, Yusuf Ali). Original Arabic text is from Tanzil.net.
- Hadith content is sourced from public-domain canonical collections.
- Where AI-assisted Q&A is enabled, answers are generated by large language models and are educational only. They are not a substitute for scholarly fatwa and we display this disclaimer prominently.
- For matters of personal status (marriage, divorce, inheritance, complex religious rulings), please consult a qualified scholar.
- We do not store transcripts of your AI Q&A questions beyond the duration needed to generate and serve a response, except as needed for safety review.
§ 9 Children's privacy
Aydeen is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13.
If we learn that we have inadvertently collected personal information from a child under 13, we will delete it promptly. Parents or guardians who believe their child has provided personal information to us should contact privacy@deenify.com.
For users in the European Economic Area (EEA) or United Kingdom, the minimum age is 16 unless verified parental consent is obtained.
§ 10 Where your data is stored
- For users physically located in the Kingdom of Saudi Arabia, data is processed in our
me-central2Firebase region (Dammam, KSA) to comply with Saudi Personal Data Protection Law (PDPL) requirements. - For users elsewhere, data is processed in regional Firebase data centers selected based on proximity to the user (typically
me-central1for GCC,europe-west1for EU/UK,asia-southeast1for SE Asia,us-central1for the Americas). - Real-time location data lives in regional Firebase Realtime Database instances and is auto-deleted after 24 hours of inactivity or trip end.
§ 11 How long we keep your data
- Account data: retained until you delete your account (see §13).
- Group data: retained until the group leader deletes the group, plus 30 days for backup.
- Location data: auto-deleted within 24 hours of your last published position, or upon trip end.
- Crash logs and diagnostic data: retained for 90 days, then aggregated and the original logs deleted.
- Subscription receipts and purchase history: retained for the duration of legal record-keeping requirements (typically 7 years for tax purposes).
- Lost-and-found, ritual checklist, prayer tracker: retained until you delete them or delete your account.
§ 12 Your rights
You have the following rights over your personal data, regardless of where you live, but specific procedures may vary by jurisdiction:
- Right to access: request a copy of the data we hold about you.
- Right to correction: correct inaccurate data through the App's profile editor or by contacting us.
- Right to deletion: delete your account and all associated data (see §13).
- Right to data portability: export your data in a machine-readable format (JSON).
- Right to restrict or object to processing: ask us to limit how we use your data.
- Right to withdraw consent: any consent-based processing (e.g., location sharing, push notifications) can be withdrawn at any time in App Settings or your OS settings.
To exercise any of these rights, contact us at privacy@deenify.com or use the Privacy & Data screen within the App.
Region-specific addenda
- GDPR (EU/UK): you also have the right to lodge a complaint with your local data protection authority. The Data Controller is Deepfai Inc.; for EU representation requirements, please contact us.
- CCPA / CPRA (California): you have the right to know what personal information is collected, to delete it, to correct it, and to opt out of the sale or sharing of personal information for cross-context behavioral advertising. Aydeen does not sell or share personal information for behavioral advertising.
- Saudi PDPL: you have the right to be informed of your data processing, to access your data, to request correction, to object to or withdraw consent for processing, and to file a complaint with the Saudi Data and AI Authority (SDAIA).
- Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act): rights are similar; contact us to exercise them.
§ 13 Account deletion
You can delete your account at any time:
- Open the App and go to Settings → Privacy & Data → Delete my account, OR
- Email privacy@deenify.com from the email address associated with your account.
Upon deletion request:
- Your user profile, prayer tracker, Qur'an bookmarks, ritual checklist, and group memberships are deleted within 24 hours.
- Group data you authored as a leader is anonymized (your name is removed) and the group is dissolved if you are the only leader.
- Crash logs and diagnostic data tied to your user ID are anonymized within 30 days.
- Subscription receipts are retained for 7 years for tax and audit purposes (your name is replaced with a synthetic ID).
You will receive a confirmation email when deletion is complete.
§ 14 Security
We use industry-standard practices to protect your data:
- All network traffic is encrypted with TLS 1.3.
- Sensitive subscription tier data is locked to Cloud Functions (clients cannot tamper with it).
- Firebase App Check is enforced on production endpoints to prevent abuse.
- We do not store payment card information; all payment processing is handled by Apple App Store and Google Play.
- Document vault feature (when re-enabled) uses client-side AES-256-GCM encryption with PBKDF2-derived keys.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify you in accordance with applicable law.
§ 15 Third-party links and services
The App may contain links to third-party services (e.g., YouTube live streams of the Haramain, external map navigation). We do not control these third parties; their privacy policies apply when you visit them.
§ 16 International data transfers
If you use Aydeen from outside your home region, your data may be transferred to and processed in regional Firebase data centers operated by Google LLC. We rely on Standard Contractual Clauses (SCCs) and Google's data processing terms for these transfers.
§ 17 Changes to this policy
We may update this policy from time to time. Material changes will be communicated through:
- An in-App notification on next launch
- An email to your registered address (if any)
- A "Last updated" date change at the top of this document
Continued use of the App after a change indicates acceptance of the updated policy.
§ 18 Contact us
For privacy questions, data subject requests, or concerns:
- Email: privacy@deenify.com
This policy is governed by the laws of the State of Illinois, USA, except where local laws give you stronger rights.