DeenDash

Privacy Policy

Effective Date: November 1, 2025

Last Updated: November 1, 2025

1. Preamble

DeenDash AI ("we," "our," "ours") is a mobile application that provides:

  • An Islamic AI assistant (Mufti GPT)
  • Prayer times tracking with notifications
  • Access to Qur'an, Hadith, and Du'a
  • Personal spiritual practice tracking

We consider privacy protection as a sacred trust (amānah). This document explains what data we collect, why, how we protect it, and your rights.

2. Data Collected

CategoryDetailsStored Where?Shared With?
AccountEmail (optional), first name, madhab, languageDevice + Encrypted FirestoreNever
LocationGPS coordinates once per requestDevice only (cached 30 days)Never
Spiritual JourneyPrayers, Qur'an pages, dhikr, charity, fastingEncrypted Hive + optional Firestore syncNever
Mufti GPT HistoryQuestions + answersEncrypted Hive + optional Firestore syncOpenAI receives only question + Islamic excerpts (no PII)
AnalyticsCrash reports, performanceFirebase CrashlyticsGoogle (anonymized)
PaymentManaged exclusively by Apple/Google

We NEVER collect:

  • Continuous location tracking
  • Contacts, photos, microphone
  • Browsing history
  • Biometric data
  • Financial information

3. Processing Purposes

PurposeLegal Basis (GDPR)
Prayer times calculationLegitimate interest (core service)
Mufti GPT responsesContract execution
Multi-device syncConsent (toggle switch)
Stability improvementLegitimate interest (anonymized)

4. Data Security

LayerProtection
In transitTLS 1.3, certificate pinning
At rest (device)Hive AES-256
At rest (cloud)Firestore AES-256 + security rules (UID-only access)
API KeysServer-side, rotated every 90 days
BackupsEncrypted, retained 180 days

5. Third-Party Sharing

Third PartyData SentPurposePrivacy Link
OpenAIQuestion + Islamic excerptsResponse generationopenai.com/policies
Google FirebaseAnonymized crash & metricsStabilityfirebase.google.com/support/privacy
Apple / GooglePurchase receipt (no card)SubscriptionsApple/Google policies

We never sell or rent any personal data.

6. Minors (COPPA / GDPR)

  • Minimum age: 13 years
  • Parental consent required for under 13 (email verification)
  • No behavioral advertising

7. Your Rights

RightHow to Exercise
AccessSettings → Data Management → Export JSON
RectificationEdit profile anytime
ErasureSettings → Delete Account (cloud data deleted within 30 days)
Objection / RestrictionDisable sync or analytics
PortabilityExport JSON
Withdraw ConsentDisable sync

8. Data Retention

TypeDuration
Local (device)Until uninstall or deletion
Cloud (active account)As long as account exists
Cloud (inactive)Deleted after 24 months
OpenAI Logs30 days (OpenAI policy)

9. International Transfers

  • Firebase: us-central1 (United States)
  • Standard Contractual Clauses (GDPR) in place

10. Changes

Major changes → in-app notification + email (if provided). Continued use = acceptance.

11. Contact

Data Protection Officer

Email: privacy@deendash.io

© 2025 DeenDash AI. All rights reserved.