Privacy Policy

Last updated 29 July 2026

This Privacy Policy (the “Policy”) describes how IHSAN FLOW LIMITED, a private company limited by shares incorporated in England and Wales under company number 17423949 (the “Operator”, “we”, “us”, “our”) collects, uses, discloses, stores, and protects personal data when a User uses the Ihsan Flow mobile application (the “Application”) for the iOS and Android platforms.

This Policy applies to data collected through the Application-whether the User accesses it in guest mode or through a user Account-as well as through associated customer support channels. This Policy should be read together with the Ihsan Flow Terms of Use, which is incorporated by reference. By using the Application, the User acknowledges that their personal data will be processed as described in this Policy.

Part I. General Provisions

1. Introduction and Scope

This Policy applies to all personal information collected and processed by the Operator in connection with the use of the Application, whether the User acts in guest mode or through a registered Account. This Policy does not govern the data-handling practices of third-party services that the Application may link or connect to, except as expressly stated (see Section 14).

Capitalized terms used in this Policy and not separately defined in Section 3 have the meanings given to them in the Ihsan Flow Terms of Use.

2. Data Controller

For the purposes of applicable data protection law, including the EU and UK General Data Protection Regulation (GDPR) where applicable, the controller of the personal data described in this Policy is IHSAN FLOW LIMITED (company number 17423949), incorporated in England and Wales, with its registered office at 87 Lozells Street, Birmingham, England B19 2AP, except where the Operator acts as a processor on behalf of a partner, or where a third-party service provider referred to in Section 12 acts as an independent controller of data it processes for its own purposes (for example, Apple or Google, in respect of data they process as providers of sign-in and push-notification services, or the operators of the Wallet and Charity services, in respect of data the User provides to them directly).

Contact details for privacy-related inquiries are set out in Section 31 of this Policy.

3. Definitions

In addition to the terms defined in the Terms of Use, the following terms are used for the purposes of this Policy:

  • “Personal Data”-any information relating to an identified or identifiable natural person.

  • “Processing”-any operation or set of operations performed on personal data, including collection, recording, storage, use, transfer, and deletion.

  • “Controller”-the entity that determines the purposes and means of the processing of personal data.

  • “Processor”-an entity that processes personal data on behalf of a controller.

  • “Consent”-a freely given, specific, informed, and unambiguous indication of the User's wishes by which the User agrees to the processing of their personal data.

  • “Cookies”-small text files stored by a browser when visiting web pages; used by the Application's embedded browser when opening third-party services (see Section 6).

  • “Advertising ID”-a device identifier provided by the operating system for advertising-analytics purposes.

Part II. Data We Collect

4. Categories of Personal Data Processed

Depending on how the User uses the Application, the Operator may process the following categories of data.

4.1 Account Data

  • internal account identifier;

  • name or display name;

  • email address;

  • age group;

  • gender;

  • sign-in method used;

  • Apple or Google identifier;

  • account creation date;

  • date of last login;

  • records of the version of the Terms of Use and this Policy accepted by the User.

4.2 Religious Practice Settings

  • selected madhhab;

  • prayer-time calculation method;

  • Asr calculation method;

  • selected level of religious practice;

  • prayer-notification settings;

  • selected notification sounds.

The selected madhhab and level of religious practice may reveal religious beliefs and are treated as special-category personal data. The Operator processes these data for religious personalization on the basis of the User's separate explicit consent, as explained in Section 8. Merely accepting the Terms of Use or acknowledging this Policy does not provide that consent.

4.3 Location Data

  • country;

  • region;

  • city;

  • coordinates-if the User has granted the corresponding permission;

  • time zone.

The manner in which location data is processed is described in more detail in Section 5 of this Policy.

4.4 Usage Data

  • saved dua and dhikr entries;

  • dhikr counter state;

  • quiz results;

  • activity streak;

  • memorized names (from the “99 Names of Allah” section);

  • selected widgets;

  • Application settings;

  • the fact of having viewed stories;

  • data-reset actions.

4.5 Technical Data

  • IP address when the server is accessed;

  • operating system type and version;

  • device model;

  • Application version;

  • Application language;

  • time zone;

  • internal Application installation identifier;

  • push token;

  • date and time of requests;

  • diagnostic data, error logs, and crash reports.

4.6 Support Inquiry Data

  • the name and email address provided by the User when making an inquiry;

  • the text of the inquiry and any materials attached to it.

5. Geolocation

Geolocation is used by the Application for the following purposes:

  • determining the User's city;

  • calculating prayer times;

  • determining the Qibla direction;

  • calculating the approximate distance to the Kaaba;

  • displaying the User's location on a map;

  • automatically configuring location-dependent widgets and notifications.

Access to current geolocation is requested through the device's system permission (iOS or Android) and is granted solely with the User's consent.

In the current version (MVP), the following model applies to the processing of location data:

  • location is determined only when the corresponding Application feature is used;

  • the Application does not build or store a history of the User's movements;

  • if location access is declined, the User may manually select a country, region, or city;

  • for notifications and widgets, the last saved location is used without continuously re-requesting GPS access.

6. Device Identifiers, Advertising ID, Cookies, and Analytics

The Application uses technical identifiers and related device information to maintain sessions, deliver notifications, protect the service, and understand how its features are used. We use PostHog for product analytics. Depending on the feature used, service configuration, and applicable permissions, analytics may involve interactions with screens and features, event timestamps, technical identifiers, and device and Application information described in Section 4. These data help us measure feature usage, identify usability and performance issues, and improve the Application.

Identifiers may distinguish an installation, session, device, or Account even if they do not contain a name. Where information can be linked to a User or device, it is treated as personal data. Where the Application accesses an operating-system Advertising ID, that access and its use are subject to applicable law and platform permission requirements. This Policy does not override the User's device permissions or privacy choices.

The Application does not contain advertising SDKs. Analytics data is not sold or used for targeted advertising. The legal bases and User choices applicable to analytics are described in Sections 8 and 19; international processing and retention are described in Sections 15 and 17.

When the User opens Wallet or Charity in the Application's embedded browser, the external service may use its own cookies, session storage, and analytics technologies under its own privacy policy, as described in Section 14.

7. How We Collect Data

The Operator collects the User's personal data in the following ways:

  • directly from the User-upon registration, when completing a profile, or when contacting support;

  • automatically-through use of the Application (technical and usage data);

  • from Apple and Google-when the corresponding sign-in methods are used;

  • from PostHog, used for product analytics;

  • from mapping and geodata providers (Nominatim / OpenStreetMap, GeoNames)-when searching for a location.

Part III. Use of Data and Legal Bases for Processing

8. Purposes of Processing and Legal Bases

Where the GDPR or equivalent law applies, the Operator relies on the legal bases described below. The applicable basis depends on the purpose and legal requirements identified for the processing. The User may request further information by contacting the Operator under Section 30.

Providing the Application's functionality

Example activities: Creating and maintaining an Account, or use in guest mode; saving settings; operation of offline features

Legal basis (GDPR): Performance of a contract with the User

Personalizing religious practice

Example activities: Calculating prayer times and the Qibla direction based on the selected madhhab and location

Legal basis (GDPR): Performance of a contract for requested functionality; consent for geolocation; separate explicit consent under Article 9(2)(a) of the EU or UK GDPR, as applicable, for processing personal data revealing religious beliefs.

The User may withdraw consent to religious-data processing at any time through the consent controls in the Application or by contacting support@ihsanflow.io. Withdrawal does not affect processing lawfully carried out before withdrawal. The Operator stops the processing covered by the withdrawn consent and deletes the relevant data unless a specific lawful retention exception applies. Features that depend on those data may no longer be available. Consent for religious personalization does not by itself authorize using religious data for analytics.

Notifications and reminders

Example activities: Sending push notifications about prayer times and other reminders

Legal basis (GDPR): Performance of a contract; consent, where required by device settings

Security and abuse prevention

Example activities: Detecting unauthorized access, fraudulent activity, or breaches of the Terms of Use

Legal basis (GDPR): Legitimate interest of the Operator (protecting Users and the Application)

Product analytics and improvement

Example activities: Measuring feature usage and evaluating usability and product performance through PostHog.

Legal basis (GDPR): Consent where required by applicable law. Where consent is not required, the Operator's legitimate interest in understanding and improving the Application, subject to the User's rights and the conditions of any applicable exception for statistical analytics. Where analytics involves data revealing religious beliefs, separate explicit consent must cover that analytics purpose.

Technical diagnostics

Example activities: Investigating errors, crashes, and faults affecting the Application.

Legal basis (GDPR): The Operator's legitimate interest in maintaining a reliable and secure service; consent where required for the technology used to collect the information.

User support

Example activities: Handling inquiries, responding to questions

Legal basis (GDPR): Performance of a contract; legitimate interest

Compliance with legal obligations

Example activities: Responding to lawful requests from government authorities, maintaining required records

Legal basis (GDPR): Legal obligation

Where processing relies on legitimate interests, the Operator considers whether those interests are overridden by the User's rights and interests before proceeding; the User may object to such processing as described in Section 20.

9. User Profile and Guest Mode

A profile is created for a registered User, which may include name, email address, age group, gender, religious-practice settings, location data, and saved progress within the Application.

Guest mode does not create a registered Account. Settings and progress are stored predominantly on the User's device. Technical and analytics data may nevertheless be processed as described in Sections 4.5, 6, 8, and 19, including identifiers that distinguish an installation, device, or session. Use in guest mode does not necessarily make that processing anonymous.

10. Notifications and Communications

The Operator sends the User service push notifications necessary for the Application's operation, including prayer-time reminders, technical notices, and notices of changes to this Policy or the Terms of Use. The Application uses Firebase for push notifications. Such notifications may be disabled by the User through device or Application settings, which may affect the availability of certain features.

As of the date of publication of this Policy, the Operator does not send marketing communications. If such functionality is introduced in the future, it will be carried out on the basis of the User's consent, which may be withdrawn at any time without affecting the User's ability to use the Application's core functionality.

11. Automated Decision-Making and Profiling

As of the date of publication of this Policy, the Operator does not use fully automated decision-making that produces legal effects concerning the User or similarly significantly affects the User. Features based on User activity (such as the activity streak or quiz results) are purely informational and motivational in nature and are not used to evaluate the User's personality or to make decisions affecting their rights.

Part IV. Sharing Data with Third Parties

12. Recipients of Data

The Operator shares categories of personal data with the following recipients, only to the extent necessary for the purposes described in Section 8:

Apple: Authorization via Apple Sign-In, push notifications, distribution of the Application through the App Store

Google: Authorization via Google Sign-In, delivery of push notifications via Firebase, distribution of the Application through Google Play

Hosting and backend provider (Amazon Web Services): Storage of Account data and synchronization of settings across devices

Product analytics provider (PostHog): Analysis of Application feature usage and product improvement

Mapping provider: Displaying the map and related geodata when the corresponding feature is used

Nominatim / OpenStreetMap: Online search for populated locations when determining location

Customer support service: Handling User inquiries-as the corresponding service is connected

Wallet and Charity: Only at the moment the User independently opens the corresponding external service (see Section 14)

Government and regulatory authorities: Only where disclosure of data is required by applicable law

The Operator does not sell Users' personal data to third parties and does not share it with advertising networks. The Operator requires service providers acting as processors on its behalf to implement appropriate technical and organizational safeguards and to process data solely in accordance with the Operator's instructions and applicable law.

13. External Services and APIs Used by the Application

The Application's current product architecture uses the following external services and technologies:

  • Nominatim / OpenStreetMap-online search for populated locations;

  • GeoNames-offline directory of cities;

  • wallet.shokran.io-external financial service (see Section 14);

  • charity.shokran.io-external charitable service (see Section 14);

  • Apple Sign-In;

  • Google Sign-In;

  • Apple and Google system services used for geolocation, compass, and notifications;

  • Amazon Web Services (AWS)-the Application's primary cloud infrastructure;

  • Keycloak-used for registration, authentication, authorization, and Account management;

  • Firebase-used for push notifications;

  • PostHog-used for product analytics, analysis of feature usage, and product improvement.

14. Third-Party Services: Wallet and Charity

The Application contains links to the external third-party services Wallet and Charity, which are independent products not developed or controlled by the Operator and which operate under their own terms of use and privacy policies.

As of the date of publication of this Policy, there is no technical or infrastructural integration between the Application and the Wallet or Charity services: the transition consists solely of opening an external website in the device's embedded browser. The Operator does not collect, receive, or process data that the User provides directly to Wallet or Charity.

With respect to the services referred to in this Section, the Operator acts solely as the party providing the technical means of accessing such services from within the Application, is not a party to the relationship between the User and the relevant third party, and is not liable for:

  • the content, accuracy, legality, or currency of any materials posted within such third-party services;

  • the availability, uninterrupted operation, or technical quality of such third-party services;

  • the collection, use, or protection of personal data that the User provides directly to such third-party services;

  • any acts, omissions, financial transactions, or other consequences arising from the User's use of such third-party services.

The Operator recommends that the User independently review the privacy policy and terms of use of the Wallet and Charity services before using them.

15. International Data Transfers

Personal data may be stored, processed, or accessed in countries where the Operator, its service providers, or their authorized subprocessors operate, including countries outside the United Kingdom and the European Economic Area. The applicable locations depend on the service and its configuration. The Application's service providers and technologies are described in Sections 12 and 13.

Where applicable data protection law restricts an international transfer, the Operator will make that transfer only where it is covered by an applicable adequacy decision or adequacy regulations, appropriate safeguards, or a permitted statutory exception. Appropriate safeguards may include the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses with the UK Addendum for transfers governed by the UK GDPR, or the European Commission's Standard Contractual Clauses for transfers governed by the EU GDPR. Where required, the safeguards must be supported by a transfer risk assessment and supplementary measures.

The User may request information about the destination countries, the transfer mechanism applicable to their personal data, and a copy of the relevant safeguards by contacting support@ihsanflow.io.

Part V. Data Storage and Security

16. Data Storage Model

  • settings and progress in guest mode are stored locally on the User's device; technical and analytics data may be processed as described in Sections 4.5, 6, 8, 9, and 19;

  • Account data and synchronized settings of a registered User are hosted using Amazon Web Services (AWS). International processing, access, and applicable transfer safeguards are addressed in Section 15.

17. Data Retention Periods

The Operator retains personal data only for as long as necessary for the purposes described in this Policy. The periods below are maximum routine retention periods, not minimum periods. Data is deleted or irreversibly anonymized sooner when no longer needed or when required following a valid deletion request or withdrawal of consent. Longer retention is limited to the specific exceptions described below.

Account data: For the duration of the Account's existence, while necessary to provide the Application. After Account closure, limited records of the contractual relationship, including the Account identifier, registration and closure dates, evidence of acceptance of the Terms of Use, and correspondence relevant to a contractual claim, may be retained for up to six years, only where necessary to establish, exercise, or defend contractual claims. Records are deleted or irreversibly anonymized sooner when no longer necessary, taking account of the applicable limitation period. Other Account data is deleted or irreversibly anonymized in accordance with Section 25.

Location and religious-practice settings data: While needed for the enabled features and, for data revealing religious beliefs, while the required consent remains valid. Data is deleted or updated when the User changes or deletes the relevant settings, withdraws the applicable consent, or deletes the Account, subject to the deletion process in Section 25 and any specific lawful exception. In guest mode, locally stored settings remain until reset or removed from the device.

Security and diagnostic logs: Up to 90 days from collection, where necessary to detect and investigate faults, abuse, or security incidents.

Product analytics: Up to 12 months from collection where necessary to compare feature usage and product performance over time. Where an applicable statistical-analytics exception requires earlier aggregation and deletion, individual-level information is kept only for that shorter period. The Operator does not retain identifiable information merely because the maximum period has not expired.

Support inquiries: Until the inquiry is resolved and for up to 24 months after resolution, where necessary to handle follow-up inquiries or related complaints. Attachments and other information no longer needed are deleted sooner. A valid deletion request may require earlier deletion; only specifically justified records may remain under the exceptions in this Section.

Data required to comply with legal obligations: For the period established by applicable law

The six-year period is a cap for justified retention of the limited contractual records described above; it does not apply generally to location data, religious-practice settings, usage history, or the full Account profile. Longer retention is permitted only to the extent required by law or necessary for a specific ongoing legal claim or binding preservation obligation. Any special-category data retained for a legal claim must also meet the applicable special-category processing condition.

A longer retention exception applies only to the particular records needed for the relevant legal obligation, specific ongoing claim, or binding preservation requirement. Access to those records is restricted and they are deleted when the reason for retention ends. Truly anonymous aggregate statistics that cannot reasonably be used to identify a User may be retained because they are no longer personal data.

18. Data Security

The Operator applies reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, and destruction. However, no system of electronic transmission, data storage, or online service can be guaranteed to be completely secure. The User is responsible for protecting their account credentials, device, and authentication methods, as provided for in the Terms of Use.

19. Cookies and Similar Technologies

The native Application may use software development kits (SDKs), local storage, and similar technologies even where browser cookies are not used. Technologies necessary to provide requested functions, such as authentication and notification delivery, are distinguished from optional analytics.

Where applicable law requires consent for storing or accessing information on a device, the relevant optional collection takes place only after consent. The User can withdraw that consent at any time through the controls provided when consent is requested, without affecting earlier lawful processing. The User may also contact support@ihsanflow.io to exercise their rights or obtain help with the controls applicable to their device.

Where statistical analytics lawfully operates without consent, it is limited to the conditions of the applicable exception, including clear information and a simple, free means of objection. Individual-level information processed under that exception is kept only for the time needed to produce anonymous aggregate statistics and is then deleted or irreversibly anonymized. An exception for statistical analytics is not used to justify retaining individual activity histories after aggregation.

Cookies and similar technologies used by Wallet and Charity when their websites are opened are addressed in Section 14 and in the respective service's privacy information.

Part VI. User Rights

20. User Rights Regarding Personal Data

Depending on jurisdiction and applicable law, the User may have some or all of the following rights in respect of their personal data:

  • the right to access the personal data held by the Operator;

  • the right to correct inaccurate or incomplete data;

  • the right to request deletion of their data;

  • the right to restrict or object to processing, including processing based on legitimate interest and direct marketing;

  • the right to data portability, in respect of data the User provided to the Operator and that is processed by automated means on the basis of consent or contract;

  • the right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out prior to such withdrawal;

  • the right to lodge a complaint with the competent data protection supervisory authority.

21. Exercising Your Rights

To exercise any of the rights described in Section 20, the User may contact the Operator using the contact details set out in Section 31. The Operator may need to verify the User's identity before processing a request, in order to protect data from being disclosed to the wrong person. The Operator aims to respond within the timeframe required by applicable data protection law (for example, within one month under the GDPR, extendable in complex cases with notice to the User).

22. Limitations on Rights

The rights described in Section 20 may be subject to legal limitations. In particular, the Operator may be required or permitted to retain or continue processing certain data for regulatory, tax, accounting, or other legally mandated purposes even after the User requests deletion of their data or objects to its processing; in such cases, the Operator will explain the relevant limitation when responding to the request.

23. Regional Additional Provisions

Where the terms of this Section conflict with any other provision of this Policy, this Section controls for Users located in the relevant region.

European Economic Area / United Kingdom: The rights described in Section 20 are provided under, and interpreted in accordance with, the EU or UK GDPR, as applicable. The User has the right to lodge a complaint with their local supervisory authority (for example, the data protection authority of an EEA member state, or the UK Information Commissioner's Office) in addition to contacting the Operator directly.

All other regions: No additional or modified provisions apply beyond mandatory local data protection law, which prevails over this Policy to the extent of any conflict.

This Policy is intended for international application and is not tied to the law of any particular country as its primary governing law; the applicable law and dispute-resolution mechanism are set out in the Terms of Use.

Part VII. Account, Data Deletion, and Final Provisions

24. Suspension of the Account

The User's Account may be temporarily restricted or suspended in the following cases:

  • breach of the Terms of Use or applicable law;

  • an attempt to gain unauthorized access to the Application or its systems;

  • interference with the operation of the Application or its servers;

  • use of automated means that place an excessive load on the Application;

  • fraudulent or otherwise clearly malicious activity;

  • circumvention of the Application's technical restrictions;

  • a threat to the security of other Users or the Operator's infrastructure;

  • a requirement of a court, government, or regulatory authority;

  • the need to investigate a security incident.

25. Data and Account Deletion

The Application provides two separate functions:

  • Reset app data-deletes local settings, onboarding data, saved dua and dhikr entries, quiz progress, and other data stored on the device;

  • Delete account-deletes the registered Account and the associated server-side data.

Once Account deletion has been confirmed:

  • access to the Account is terminated;

  • the profile and associated personal data are deleted or irreversibly anonymized from active systems without undue delay and no later than 30 days after a verified deletion request, or sooner where required by applicable law; only the limited records specifically needed for legal obligations or legal claims under Sections 17 and 22 are retained;

  • active sessions and push tokens are revoked.

The deletion process covers associated personal data in systems operated by the Operator and its service providers acting on its behalf, including authentication and identifiable analytics records. Anonymous aggregate statistics that can no longer identify a User are not personal data and are not affected by Account deletion.

Residual copies in backups are isolated from ordinary use and expire through the backup rotation no later than 90 days after the verified deletion request, unless a specific legal preservation requirement applies. If a backup is restored, the deletion is reapplied. Backup copies are not used for analytics, personalization, or other ordinary business purposes while awaiting expiry. These arrangements do not extend any shorter period required by applicable law.

Deleting the Application from a device does not, by itself, delete the registered Account.

Deleting an Ihsan Flow Account does not delete the User's accounts or data held in the Wallet or Charity services. To delete data held in those services, the User must contact the relevant service's operator directly.

26. Full List of Registration Data

26.1 Required for Registration by Email

  • email address;

  • name or display name;

  • age group;

  • gender;

  • agreement to the Terms of Use;

  • confirmation of having reviewed this Policy.

26.2 Received Automatically Upon Registration

  • internal Account identifier;

  • date and time of registration;

  • registration method;

  • email confirmation status;

  • version of the legal documents accepted;

  • IP address at the time of registration;

  • technical data about the device and the Application;

  • active session data and authorization tokens.

26.3 When Signing In via Apple or Google

  • the User's identifier with the relevant provider;

  • email address, or an Apple Private Relay email;

  • name, if provided by the provider;

  • authorization token;

  • date and method of sign-in.

The password for the User's Apple or Google account is not transmitted to, and does not become known to, the Operator.

26.4 Onboarding and Personalization Data

The data listed below is not mandatory for registration if the User can continue using the Application without providing it:

  • country, region, or city;

  • coordinates-only with the User's consent;

  • madhhab;

  • prayer-time calculation method;

  • level of religious practice;

  • notification settings;

  • selected language;

  • widget and content settings.

27. Children's Privacy

Use of the Application, including in guest mode, is not permitted for persons under 13 years of age. Users aged 13 and older who have not yet reached the age of digital consent established by applicable law (which in certain countries may exceed 13 years) may use the Application and provide their personal data only with the consent and under the supervision of a parent or legal guardian.

If the Operator becomes aware that personal data has been collected from a person who does not meet the age requirements set out above without the appropriate consent of a parent or legal guardian, the Operator will take steps to delete or restrict access to such data, subject to any conflicting legal retention obligation, and may suspend the associated Account.

28. Disclosure of Information as Required by Law

The Operator may disclose the User's personal data where necessary to:

  • comply with applicable laws and regulations;

  • respond to lawful requests from courts, regulators, or law-enforcement authorities;

  • prevent or investigate fraud or other unlawful activity;

  • protect Users or the public;

  • enforce the Terms of Use;

  • protect the rights, property, and safety of the Operator.

29. Changes to This Policy

The Operator may update this Policy from time to time to reflect changes in the Application's functionality, applicable law, regulatory requirements, technology, or the Operator's business operations. Where required by applicable law, the Operator will notify Users of material changes before they take effect. The effective date at the beginning of this Policy identifies when the current version takes effect.

30. Privacy Contacts and Language of the Document

For any questions, comments, or requests relating to this Policy or the processing of personal data, the User may contact the Operator at support@ihsanflow.io. The Operator may request additional information to verify the User's identity before processing certain requests.

This Policy has been prepared in English. Where translations are provided, the language-precedence provisions of the Terms of Use apply, subject to mandatory local law.

31. Operator's Details

Operator:

  • IHSAN FLOW LIMITED (company number 17423949), a private company limited by shares incorporated in England and Wales;

  • Registered address: 87 Lozells Street, Birmingham, England B19 2AP;

  • Contact email for inquiries regarding this Policy and data-subject requests: support@ihsanflow.io;