At a glance
- MosqueMe explains the data it collects for accounts, mosque features, safety, support, analytics, and optional sensitive features.
- Account deletion uses a 30-day recovery window before hard-delete processing starts.
- Hayd and Nifas, AI moderation, voice recordings, location, export limits, and third-party providers are described in the policy.
- Sensitive areas (health, location, AI moderation, and named third-party providers) are identified by name; everything else is grouped by data category rather than by the specific in-app feature that collects it.
MosqueMe Privacy Policy
Last Updated: 21 April 2026 Document Version: 1.0
This Privacy Policy explains how MosqueMe collects, uses, shares, stores, protects, retains, exports, and deletes personal data when you use the MosqueMe mobile application and related in-app features.
MosqueMe is provided by RK&RS INNOVATIONS LTD, Company No. SC810188, 163 Hammerman Drive, Aberdeen, Scotland, AB24 4SF, United Kingdom. In this policy, "MosqueMe", "we", "us", and "our" refer to that controller. You can contact us about privacy matters at privacy@mosqueme.com and about general support at support@mosqueme.com.
This policy is intended to support:
- UK GDPR and the Data Protection Act 2018
- EU GDPR where applicable
- Apple App Store review and App Privacy disclosure requirements
- Google Play privacy policy and Data safety disclosure requirements
MosqueMe is not currently actively offered in the European Economic Area (EEA). If we later actively offer MosqueMe in the EEA, we will review any additional EU/EEA representative, age-consent, sensitive-data, store-disclosure, and local-law requirements before that launch and update this policy where needed.
Please read this policy together with any in-app consent prompts, feature notices, and the store privacy disclosures for the version of the app you use.
1. Scope
This policy applies to the MosqueMe mobile app and the tools, storage, notifications, moderation, analytics, support, and account features we use to run it.
It covers data we collect:
- when you create, use, secure, deactivate, export, or delete an account
- when you use mosque, worship, community, or admin features in the App
- when you upload files, images, documents, or audio
- when you contact support, report a problem, or send feedback
- when the App stores limited data locally on your device
2. Personal Data We Collect
Depending on the features you use, we may collect the following categories of personal data.
Some features are named explicitly below where the law requires it (Sections 2.5, 2.9, 5, and 6). Others are grouped by data category rather than by the specific feature that collects them.
2.1 Account, Identity, and Authentication Data
- your MosqueMe account number, role, account status, and mosque linkage state
- display name, phone number, email address, date of birth, and selected mosque or mosque history
- sign-in details when you use Apple Sign In, Google Sign In, Microsoft Sign In, phone authentication, or other supported sign-in flows
- sign-in session, remembered device, and login history records used for sign-in and security
- records of your acceptance of terms, privacy, and related compliance notices
2.2 Profile, Mosque, and Community Data
- profile details you choose to add, such as gender selection and mosque preferences
- mosque membership, mosque selection, mosque-linked activity, and mosque-admin or member role information
- mosque feed posts, community notices, fundraiser posts, service information, and related mosque content created or managed by authorised Mosque Admins
- service requests, fundraiser pledge records, event registrations, support messages, feedback, bug reports, reports, and moderation content you choose to send
- account-support, safety-review, technical-support, and admin-review records handled by authorised MosqueMe central admins through web-based admin tools
2.3 Worship, Reading, Learning, and Engagement Data
- worship-activity records and related preferences, such as prayer check-ins, reminders, counters, and shared or partner-based activity records, together with any privacy preferences linked to those activities
- reading and learning progress, saved state, bookmarks, and completion history across religious-reading features
- prayer calculation and mosque timetable preferences
- event-engagement records linked to your account, such as lesson or audience engagement signals
- community feed engagement records, such as post view and reaction counts and limited viewer or reactor identifiers shown to authorised Mosque Admins where the feature provides admin-only engagement details
- voice-recording preferences, uploaded audio, and derived learning or quality summary metrics
In the current version of MosqueMe, a limited learning summary derived from voice-recording analysis may be saved to your account after you use supported voice-learning features. It can include progress stage, accepted learning counts, overall accuracy results, and similar high-level indicators. This summary is designed not to include your raw voice recordings or your full detailed voice-learning history.
Because MosqueMe is a faith-based app, some data you choose to provide or generate may reveal religious belief, religious practice, mosque affiliation, or worship activity.
2.4 Mosque Services and Fundraiser Interaction Data
- fundraiser interaction records, such as registrations, pledge or contribution preference selections, mosque-confirmed offline status fields, and related participation records
- service request, booking, and service-draft details, such as contact details, preferred dates, messages, linked mosque information, and mosque-handled fee or status information where relevant
MosqueMe does not currently process transactions, in-app card payments, donations, money collection, bank transfers, refunds, or receipt confirmation for fundraiser posts or mosque service requests, and does not store card details. Fundraiser and service amounts shown in the app are provided for information, notice, request, pledge-status, and mosque workflow purposes only. If a mosque independently includes bank-transfer details for its own external arrangements, those details are provided by the relevant mosque admin for reference only and are intended to be the mosque's registered charity or official mosque bank account details, not MosqueMe's bank details. Mosque admins are responsible for ensuring that any bank details shown for mosque services belong to the mosque, its registered charity, or its official mosque bank account. Mosque admins may record or confirm external fundraiser pledge or contribution information or mosque service status information, such as selected amount, amount the mosque marks as received, paid/unpaid status, or similar mosque-handled records.
2.5 Sensitive or Special Category Data
Some features may involve data that is sensitive under UK GDPR or EU GDPR, including:
- faith-linked use of the app that can reveal religious belief, worship activity, or mosque affiliation
- Hayd and Nifas feature data, such as consent records, episode and status history, and related reminders and privacy settings
- free-text information you choose to submit that may reveal health information, religious practice, or other sensitive matters
We treat Hayd and Nifas data as highly sensitive. Access is limited to the people and app areas that need it, and it is also controlled by feature privacy settings. Where required, we rely on your explicit consent before using this type of data. See Section 5 for additional Hayd and Nifas-specific safeguards and disclosures.
2.6 Images, Audio, Documents, and Other Uploads
- images you attach through supported upload or post-management flows where your role allows that feature
- PDFs and other files uploaded through supported service, learning, or admin workflows
- audio you upload or record through supported in-app features
Where supported, images are selected from your device library or system picker.
When in-app speech-recognition verification is used, speech recognition may be processed by your device or by Apple, Google, or other device speech services depending on your platform, device settings, and service availability. We do not currently force every speech-recognition path to remain only on your device.
We do not generate biometric identifiers from voice recordings for the purpose of uniquely identifying you.
2.7 Device and App Data
- device identifiers provided by your operating system, including Android's device identifier and Apple's app-vendor identifier, used for account security, session management, fraud prevention, and support
- device model, manufacturer, brand, operating system, app version, language, time zone, and connectivity type
- notification or iPhone Live Activity status and related tokens when notifications are enabled or registered
- device details used for account security, session management, and support
We do not use these identifiers for cross-app advertising or ad tracking.
2.8 Usage, Analytics, Diagnostics, and Support Data
- app events and feature interaction events needed to operate, secure, and improve the service
- analytics and performance signals used inside MosqueMe where enabled in the app build
- crash data, error logs, and performance diagnostics
- moderation and safety-operation metadata, such as field category, automated decision result, reason code, provider used where applicable, confidence where available, whether a case was flagged for human review, review outcomes where recorded, and related timestamps
- support and bug-report details, including message content and troubleshooting details such as screen name, app version, device type, network status, error summaries, and similar details needed to investigate the issue
2.9 Location Data
- precise or approximate location if you grant location access and use features that need it, such as direction-finding and location-based prayer calculations
- location data may also be cached locally on your device for feature continuity
We do not require background location for normal use of the app.
2.10 On-Device and Local Storage Data
The app stores some information locally on your device, including:
- device or session identifiers
- sign-in state and encrypted app session data
- app preferences such as language, theme, tracker visibility, and onboarding flags
- limited caches for feature speed and continuity, such as recent location coordinates, reading state, or offline-ready content
On Apple devices, some sign-in state and technical account identifiers may also be stored in a shared MosqueMe storage area used by MosqueMe widgets, extensions, or similar app features on the same device.
Credentials sit in secure storage; preferences and caches sit in regular app storage. Removing the app, clearing app storage, signing out, or deleting your account may remove some or all local copies, depending on how your device handles app data.
3. How We Collect Data
We collect personal data:
- directly from you when you register, sign in, choose a mosque, submit forms, upload content, enable features, request services, send feedback, or contact support
- automatically from the app, your device, and the services used to run MosqueMe while you use it
- from device features and permissions that you choose to grant, such as microphone, speech recognition, notifications, location, and photo-library or similar image-picker access for supported upload flows
- from sign-in providers and other services used to run the app
- from mosque admins, support staff, moderation workflows, or other users where the feature design requires it
4. Why We Use Data and Our Legal Bases
Depending on the feature and the situation, we rely on one or more legal reasons to use your data, including providing the service you asked for, our legitimate interests, legal obligations, and your consent where required.
4.1 To Perform Our Contract With You or Take Steps You Request
We use data to:
- create and manage your account and sessions
- authenticate sign-in and keep you logged in
- provide mosque-linked features, worship tools, reading progress, direction-finding, learning, notifications, community features, service-related features, uploads, and support features
- generate or rewrite admin-requested draft content in admin-only AI writing tools
- process timetable files uploaded by mosque admins so prayer times can be extracted, reviewed, corrected, and published
- save a limited learning summary to your account after you use supported voice-learning activity in the app
- let you export your data or deactivate or delete your account
4.2 For Legitimate Interests
We may also use data where needed to run, protect, and improve MosqueMe, such as:
- keeping the app secure
- preventing abuse, spam, fraud, and unauthorized access
- logging and auditing sensitive or admin actions
- diagnosing crashes and service failures
- improving reliability, moderation, usability, and performance
- defending legal claims and enforcing our terms and community rules
When we rely on legitimate interests, we try to balance our needs against your rights and expectations.
4.3 With Your Consent
We rely on consent where required, including for:
- optional permissions such as location, microphone, speech recognition, notifications, and photo-library or similar image-picker access for supported admin or post-management image-upload flows
- Hayd and Nifas feature activation and other explicit sensitive-data workflows
- any optional feature that clearly asks you to opt in before we process the data, for example voice recording or activation of a sensitive-data feature
You can withdraw consent at any time for permission-based features through your device settings, and for certain feature-based uses of data through in-app settings.
4.4 To Comply With Legal Obligations or Handle Legal Claims
We may process and retain data where necessary to:
- comply with applicable law, lawful requests, or regulatory obligations
- keep records required for legal, audit, or security reasons
- respond to lawful takedown, disclosure, or preservation requests
- establish, exercise, or defend legal claims
4.5 Special Category Data
Because MosqueMe is a faith-based app and includes optional health-related features, some uses of data may involve information that the law treats as very sensitive personal data under UK GDPR or EU GDPR.
We will only process this type of sensitive data where the law allows us to do so. For Hayd and Nifas and other clearly sensitive optional features, our main basis will usually be your explicit consent. For faith-linked use of MosqueMe, we treat that use as highly sensitive and only use this data where the law allows us to do so.
Where sensitive data reaches us incidentally through free-text submissions routed to safety moderation (for example where a user chooses to type health, religious practice, or other sensitive information into a support message, report, or moderated feature), we also rely on the substantial-public-interest safeguarding condition under Article 9(2)(g) of the UK GDPR read with Schedule 1 Part 2 of the UK Data Protection Act 2018, in order to protect users, mosques, and the wider community from abuse, harm, and unsafe content.
5. Hayd and Nifas Feature Data
The Hayd and Nifas feature is optional. In the current version of MosqueMe, it is protected by eligibility checks, access controls, explicit in-app consent checks, and feature-specific deletion controls. It is available only to users who meet the feature eligibility requirements shown in the app and who provide explicit, informed consent before activation.
This feature may process data such as:
- opt-in and consent records for the feature
- feature preferences, reminders, and privacy settings
- episode and status history, related record-keeping entries, and excused-status records
For the private Hayd and Nifas tracking data described in this section:
- we do not sell it
- we do not use it for advertising or cross-app tracking
- we do not use it to train our own AI models
- as of 21 April 2026, the current version of MosqueMe does not include HealthKit or Health Connect integration for this feature, and this tracking data is not synced to Apple Health or Android Health Connect
We will not voluntarily disclose private Hayd and Nifas tracking data to law-enforcement authorities, government bodies, or private parties unless we are legally required to do so. Where legally allowed, we will review, narrow, challenge, or resist overbroad requests for this sensitive data.
For users aged 13 to 17 who meet the feature eligibility requirements, this feature is designed to follow the principles of the UK Age Appropriate Design Code: feature data is used only to run the feature, is not used for profiling or personalised advertising, and consent information is presented in clear, age-appropriate language before activation.
If this feature is available on your account, you can delete your Hayd and Nifas data from the in-app settings inside the feature area. In the current version of MosqueMe, that delete flow is designed to remove feature episodes, top-level feature records, consent and opt-in records for the feature, and related summary flags linked to that feature.
6. AI, Moderation, and Automated Assistance
MosqueMe uses automated checks and, where needed, outside AI moderation providers to help protect users, mosques, and the wider community from spam, abuse, unsafe content, fraud, policy breaches, or ambiguous content.
Text that may be checked for safety is the specific text submitted in a feature — for example, free-text you submit in account, support, mosque-admin, and community-message fields (such as post bodies or support messages).
We do not intentionally send separate account records, account IDs, email addresses, phone numbers, full profile records, mosque membership records, or database documents to outside AI moderation. However, if you type personal data into the submitted text itself, that submitted text may contain personal data.
For outside AI moderation, we reduce the text sent where possible and redact obvious email addresses, phone numbers, and web links before sending it. This helps reduce risk, but it is not perfect. We cannot guarantee that every personal detail, name, religious detail, health detail, or other sensitive detail typed into a free-text field will be removed before moderation.
Some admin-only drafting or rewriting features may send admin prompts, instructions, current draft title/body text, and generated draft outputs to external AI providers to generate or revise mosque post drafts. Admins should avoid entering unnecessary personal or sensitive information into AI drafting prompts.
Some admin-only timetable or Hijri calendar upload features may send uploaded images or PDF files to services that help read the text from those files so the content can be reviewed and corrected by an admin.
Where OpenRouter is used for AI review or admin drafting flows, our current configuration requires zero-data-retention routing where available, denies provider data collection for eligible routes, disables broader provider fallback, and restricts routing to a limited approved provider list. If those routing controls cannot be satisfied, the request is blocked rather than routed.
Our automated checks use a combination of keyword, pattern, and third-party classifier signals. They do not make final account-termination decisions without human review, and you can request human review of automated-assisted outcomes as described in Section 12.2.
Important points:
- we use AI and automated assistance for safety, moderation, admin drafting, and upload text-reading purposes only as described in this policy
- we do not use your raw submitted text, personal data, or audio to train general-purpose AI models or shared AI models for other users
- supported in-app voice-recording features may analyse your saved audio and waveform patterns on your device to build a personal self-learning profile for your own use of that feature; where a summary is synced to your account, it is limited to high-level counters and status, not raw voice recordings, waveform files, or the full learning history
- we may keep narrow operational metadata about moderation checks and review handling, such as field category, decision result, reason code, provider used where applicable, confidence where available, whether a case was flagged for human review, review outcomes where recorded, and timestamps
- outside AI moderation may be used even where provider-side zero-retention or no-log settings are not enabled, because safety moderation is important to protect the app and community
- we do not currently enable provider-side zero-retention or no-log modes for every outgoing AI, moderation, or upload text-reading request
- where moderation checks, admin-only AI features, or upload text-reading features send text or uploaded timetable or Hijri calendar content to outside providers, those providers may handle it and may keep it for a period allowed by their own settings, contracts, and policies unless stricter no-retention or no-log settings are enabled for that provider
- you should avoid entering unnecessary sensitive personal data into free-text fields wherever possible
- moderation or AI outputs may be reviewed by human admins or support staff where needed for safety, debugging, or feature operation
- if you believe an automated or automated-assisted moderation, content, or account-related decision affecting you was wrong, you can contact support@mosqueme.com to request human review where applicable
7. App Permissions and Device Access
Depending on the features you use, MosqueMe may ask for permission to access:
- microphone, for recording audio through supported in-app features
- speech recognition, for supported voice-verification or transcript workflows, which may be processed by your device or by Apple, Google, or other device speech services depending on your device and settings
- photos, files, or media-library access, for uploads you choose to make
- location while using the app, including precise location where a feature needs it, for direction-finding and location-based prayer calculations
- notifications, to send alerts, reminders, service updates, and mosque or community notifications you enable
We do not currently require Contacts or Calendar access for normal app functionality. We also do not require background location for normal use.
If you refuse a permission, the app will still work in general, but the feature that depends on that permission may not work properly.
8. Advertising and Tracking
MosqueMe does not currently use third-party ad networks or personalised advertising.
As of 21 April 2026:
- we do not use third-party ad networks for cross-app behavioural advertising in the current version of MosqueMe
- we do not sell personal data
- we do not use advertising IDs or cross-app tracking identifiers for advertising measurement
9. Who Can Access and Receive Data
We may make personal data accessible only where necessary and only as described in this policy.
9.1 Companies We Use to Help Run MosqueMe
We use service providers that help us run the app, such as companies that help with:
- authentication and account services
- hosting, databases, storage, and related support services
- push notifications and messaging delivery
- security and abuse protection
- crash reporting, analytics, and performance monitoring
- speech recognition or device services used by app features
- services that help read timetable or Hijri calendar text for extraction and review
- outside moderation and AI services described in Section 6
Where these providers have access to personal data for services we use, we require them to protect that data to the same or an equivalent standard described in this policy.
Depending on the feature you use and your device, these providers may include:
- Google Firebase / Google Cloud, for sign-in, databases, storage, notifications, analytics, crash reporting, performance monitoring, remote configuration, and abuse protection
- Google Cloud Vision, for admin-only timetable or Hijri calendar image and PDF text extraction
- Apple, for Apple Sign In, Apple Push Notification service, and certain Apple device services used by app features on Apple devices
- Google, for Google Sign In and certain Google or Android device services used by app features on supported devices
- Microsoft, for Microsoft Sign In when you choose that option
- OpenAI, for text moderation
- Groq, Cerebras, and OpenRouter, for admin-only AI writing tools and some moderation-related AI review flows
Not every provider is used for every user or every feature.
When you use sign-in or device features provided by Apple, Google, or Microsoft, those companies may also handle some data under their own privacy notices.
9.2 Mosque Admins
Depending on the feature and your chosen settings, mosque admins may access data needed to run mosque-linked community, timetable, service, member, fundraiser, or support workflows where the feature is designed to surface that information.
Where a Mosque Admin creates or manages mosque feed posts, notices, or similar mosque content, the app may show that admin limited engagement information, such as aggregate view and reaction counts and limited viewer or reactor identifiers, for example member user numbers. These details are intended to help the mosque understand whether its notices reached members and are not displayed publicly to regular users.
9.3 Central Admins, Technical Staff, and Support Staff
Authorised MosqueMe central admins, support staff, or technical staff may access limited account, support, safety, security, and technical information through web-based admin tools where needed for moderation, abuse review, support, account handling, app security, or to diagnose specific service incidents you have reported.
Some central-admin features show limited personal progress summaries. In the current summary, raw audio and full detailed voice-learning history are not shown there.
9.4 Other Users and Mosque Community Context
In the current version of MosqueMe, other users do not receive a general public profile for you.
The main user-to-user visibility is through partner or shared ibadah features. If you invite, accept, or use a partner task, the other participant may see your display name or user number, invite status, and relevant shared task progress or comparison information for that shared task. Some progress details may be hidden where the feature provides privacy controls.
You can also choose a private "do not match again" preference for partner-based tasks. If you do, MosqueMe stores a no-match record for that user pair so the app can avoid matching you with that user again in future partner-based tasks until you remove the preference in your partner/shared-activity settings.
If you are a Mosque Admin and publish mosque feed posts, notices, or similar content, that published content may be visible to mosque members or the public according to the feature and post settings. Mosque fundraiser public views are designed to show campaign totals, counts, or limited non-identifying pledge/contributor entries rather than your private phone number, email address, or full account profile by default.
9.5 Legal, Safety, and Business Reasons
We may also disclose data:
- to comply with law, regulation, court order, or lawful request
- to investigate fraud, abuse, or security issues
- to protect users, mosques, admins, the public, or our rights
- in connection with a merger, acquisition, restructuring, financing, or sale of all or part of the business, subject to applicable law
10. International Transfers
MosqueMe may use service providers that process data in the UK, the EEA, the United States, or other countries where they or their infrastructure operate.
Where required by applicable law, we use protections for international transfers, such as:
- adequacy regulations or adequacy decisions
- standard contractual clauses, the UK International Data Transfer Agreement, or equivalent transfer mechanisms
- legal agreements and security measures with providers
International transfers may arise through hosting, notifications, crash reporting, speech services, moderation services, or AI providers. You can contact us if you want more information about the protections we rely on.
Current provider and transfer examples include:
| Provider | Main data or feature involved | Transfer / safeguard summary |
|---|---|---|
| Google Firebase / Google Cloud | Account sign-in, database records, file storage, cloud functions, notifications, app integrity, analytics, crash reporting, performance monitoring, and remote configuration | Data may be processed in the UK, EEA, United States, or other Google infrastructure locations. We rely on provider data-processing terms, contractual safeguards, and applicable transfer mechanisms such as SCCs, the UK IDTA, or equivalent measures where required. |
| Google Cloud Vision | Admin-only timetable or Hijri calendar image/PDF text extraction | Uploaded admin files and extracted text may be processed by Google Cloud services for text-reading and review workflows, subject to Google Cloud contractual and transfer safeguards. |
| Apple | Apple Sign In, Apple Push Notification service, Live Activity delivery, and Apple speech services on Apple devices | Apple may process sign-in data, push or Live Activity tokens, device-service data, and speech-recognition data where Apple services are used, under Apple's own terms and privacy notices. |
| Google / Android device services | Google Sign In and Android speech-recognition or device services | Google may process sign-in data and speech-recognition data where Google or Android services are used, under Google's own terms and privacy notices. |
| Microsoft | Microsoft Sign In where selected by the user | Microsoft may process sign-in identity data under Microsoft's own terms and privacy notices. |
| OpenAI | Text moderation checks | Submitted text and moderation-related data may be processed for safety checking under OpenAI service terms and applicable provider safeguards. |
| Groq | Admin-only AI drafting or rewriting and some moderation-related AI review flows | Submitted admin text, prompts, and generated draft outputs may be processed under Groq service terms and applicable provider safeguards. |
| Cerebras | Admin-only AI drafting or rewriting and some moderation-related AI review flows | Submitted admin text, prompts, and generated draft outputs may be processed under Cerebras service terms and applicable provider safeguards. |
| OpenRouter | Admin-only AI drafting or rewriting and some moderation-related AI review flows | Submitted admin text, prompts, and generated draft outputs may be processed under OpenRouter service terms and may be routed to a limited approved provider list where OpenRouter routing controls are satisfied. Current controls are intended to require zero-data-retention routing where available, deny provider data collection for eligible routes, and prevent broader provider fallback. |
11. Data Retention, Deletion, and Export
We keep personal data only for as long as reasonably necessary for the purposes described in this policy. Retention can vary by data type.
| Data category | Retention period / handling |
|---|---|
| Account, profile, and sign-in records | Usually retained while your account is active. If you request account deletion, the account enters a 30-day grace period. All supported in-app account deletion routes use this same grace-period flow. During that period, the account can be restored by completing the supported in-app recovery checks before final deletion begins. After that grace period, eligible personal data is deleted or de-identified starting on the next scheduled deletion run, unless another row below applies. |
| Account deletion request state | Kept during the 30-day grace period so the account can be restored through the supported recovery checks before final deletion begins. |
| Reserved phone-number or account-security mappings | May be kept for up to 90 days after account deletion where needed for abuse prevention, account recovery controls, or SIM-recycling protection. |
| Hayd and Nifas feature records | Kept while the feature or account is active, unless you use feature-specific deletion controls. If account deletion is requested, eligible Hayd and Nifas records are included in the deletion or de-identification process after the 30-day account-deletion grace period, unless law requires otherwise. |
| Voice, audio, and uploaded media | Kept until removed, replaced, or deleted through account or feature cleanup. Local recordings may remain on your device until you remove them, clear app data, or uninstall the app. |
| Speech-recognition transcripts and verification results | Device, Apple, Google, or other speech services may process audio or transcripts under their own terms where speech recognition is used. MosqueMe keeps any transcript, verification result, or troubleshooting record created by MosqueMe only as long as needed for feature processing, safety review, support, or the related voice-audio, support, or moderation retention rows. |
| Mosque-admin community content and other community-facing records | Kept while needed for the feature, mosque records, other users' history, fraud prevention, audit, or legal reasons. Some records may remain in author-stripped or de-identified form after account deletion where the record affects other users, mosque workflows, or public/community history. |
| Fundraiser, service, and worship-activity workflow records | Kept while needed for the feature, mosque records, accounting, audit, or legal reasons, and handled the same way as other community-facing records where author-stripped retention applies. |
| Support, feedback, report, moderation, and audit records | Kept while a request, investigation, review, or dispute is active, and normally up to 6 years where needed for legal claims, safety, audit, fraud prevention, or support continuity. Records may be removed or de-identified earlier where appropriate. |
| Notification tokens, device sessions, and Live Activity tokens | Kept until invalidated, replaced, signed out, expired, or no longer needed for delivery, security, or troubleshooting. |
| Analytics, crash, diagnostic, and performance data | Kept as configured with our service providers and only as long as needed for reliability, security, analytics, and troubleshooting. We aim to remove or de-identify this data when it is no longer needed. |
| Download-my-data export file | Generated when you request it and saved locally to your device. You control that local copy after download. We do not keep a separate hosted export file unless a feature specifically creates one. |
| Local device storage and app caches | May remain on your device until you sign out, clear app data, uninstall the app, or your device operating system removes it. |
| Backups and recovery copies | May remain for a limited recovery period after live-system deletion and are protected from normal use. They are overwritten or removed according to our provider backup and recovery cycles, unless legal or security reasons require longer retention. |
Deletion from live systems may not remove every copy immediately from backups or recovery systems, but those copies are protected and kept only for limited legal, security, or service-continuity reasons.
In some admin-deletion cases, mosque-authored operational content may remain visible while the author's identifying details are removed.
The current export feature gives you a downloadable file of your app data and selected related records saved to your device. To keep exports reliable, the current export tool limits each collection to 500 records, limits certain linked record sets to 250 records each, and reads nested records up to 6 levels deep. Large or separate stored files, such as uploaded media, are not always included directly inside that export file and may instead appear as file references or file locations.
12. Your Rights and Choices
Depending on your location and applicable law, you may have rights to:
- access your personal data
- correct inaccurate data
- receive a copy of certain data in a portable format
- request deletion
- withdraw consent
- object to or limit certain uses of your data
- request human review of certain important decisions made with automated assistance, where applicable under law
- manage visibility or privacy settings inside supported features
- manage device permissions
- complain to a data protection authority or privacy regulator
Some rights depend on the circumstances and the legal reason we are using your data.
We aim to respond to privacy rights requests without undue delay and within one month or 30 days, unless applicable law allows or requires a different timeframe. If a request is complex or law allows an extension, we will tell you where required.
If you are in the UK, you can complain to the Information Commissioner's Office (ICO): https://ico.org.uk/make-a-complaint/. If you are in the EEA, you may complain to your local data protection authority or privacy regulator.
To delete your data or manage in-app privacy controls, see Section 11 (retention and deletion) and Section 12.3 (in-app privacy and account controls).
12.1 Right to Object
Where we rely on legitimate interests, which means our genuine need to run, protect, or improve MosqueMe, you may have the right to object in certain circumstances. You can exercise that right by contacting us at privacy@mosqueme.com or through the in-app support routes listed in this policy.
12.2 Automated Review Requests
Where automated tools help identify spam, unsafe content, abuse, policy issues, or similar risks, a human may review the matter.
If you believe an automated or automated-assisted moderation or account-related decision affecting you was wrong, you can contact us at support@mosqueme.com or through the in-app support routes listed in this policy to request human review where applicable. You may also submit additional context or information for us to consider and may contest the outcome as part of that review. We may still maintain restrictions that are reasonably necessary for safety, fraud prevention, legal compliance, or the protection of other users while that review is carried out.
12.3 Privacy and Account Controls in the App
The app currently includes in-app controls such as:
Settings -> Privacy & Security -> Privacy settingsSettings -> Privacy & Security -> Login & devicesSettings -> Notifications -> Notification settingsSettings -> About & Legal -> Privacy PolicySettings -> Account actions -> Download my dataSettings -> Account actions -> Deactivate account (temporary)Settings -> Account actions -> Delete account
For Hayd and Nifas users, feature-specific privacy and deletion controls are available inside the feature area, as described in Section 5.
12.4 Identity Verification
Before we act on certain requests, we may need to verify your identity or confirm account ownership.
12.5 Limits on Rights
We may keep limited information where necessary to:
- comply with law
- complete security or fraud-prevention steps
- protect other users or mosques
- preserve evidence relevant to disputes, abuse, or legal claims
13. Security
We use reasonable security measures to protect data, including measures such as:
- encryption in transit
- encryption at rest where supported by our hosting, database, and storage providers
- role-based access controls
- checks on our systems for sensitive actions
- security and abuse-protection controls where enabled
- logging and audit controls for sensitive account or admin actions
- protected local storage for certain credentials and identifiers
No system is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a personal data breach, we will investigate it, take reasonable steps to contain and mitigate it, and document it as required.
Where required by applicable law, we will notify the relevant data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of a notifiable personal data breach. Where required by applicable law, we will also notify affected users.
14. Children's Privacy
MosqueMe is not directed to children under 13, and we do not knowingly collect personal data from children under 13 without the consent required by applicable law.
Some parts of MosqueMe may be accessed by users aged 13 to 17. Where UK children's privacy rules, including the Age Appropriate Design Code, apply, we aim to use privacy-by-design safeguards, collect only data needed for the feature, avoid personalised advertising, and give privacy information in a clear and age-appropriate way.
MosqueMe is not currently actively offered in the European Economic Area (EEA). If we later actively offer MosqueMe in the EEA, we will review EEA child-consent, sensitive-data, representative, and store-disclosure requirements before that launch and update this policy where needed.
Hayd and Nifas is an optional sensitive feature. It asks for explicit in-app consent before activation and is available only to users who meet the feature eligibility requirements shown in the app. Users who do not meet those requirements must not enable it.
If we learn that personal data from a child has been collected in a way that requires action, we will take reasonable steps to delete it, restrict the feature, or obtain the required consent.
15. Additional Information for Mosque Admins
Mosque admins have additional responsibilities and visibility within the app.
Admin accounts may submit or access:
- mosque profile data
- prayer timetable and day-to-day mosque data
- mosque-admin community content and uploaded media
- fundraiser and mosque-service workflow data
- member-related submissions where the feature is designed to surface them to mosque admins
Admins must use this access only for legitimate mosque or app purposes and must handle personal data responsibly and lawfully.
Certain admin or mosque working records may need to be retained even if an individual admin account is deleted, where the record forms part of an ongoing mosque workflow, audit trail, or other users' data history.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the app, providers, legal requirements, or privacy practices.
If we make material changes, we may notify you in the app and will update the "Last Updated" date above.
17. Contact Us
If you have questions, privacy requests, or complaints about data handling, you can contact us by:
- emailing privacy@mosqueme.com for privacy rights requests, data-protection questions, privacy complaints, export or deletion questions, or similar privacy matters
- emailing support@mosqueme.com for general app support
- using the in-app support flows at
Settings -> Support -> Help,Settings -> Support -> Report a problem, orSettings -> Support -> Feedback / Suggest a feature - writing to RK&RS INNOVATIONS LTD, Company No. SC810188, 163 Hammerman Drive, Aberdeen, Scotland, AB24 4SF, United Kingdom
We have not appointed a Data Protection Officer. Privacy enquiries should be sent to privacy@mosqueme.com.
As of the "Last Updated" date above, we have not appointed an EU or EEA representative because MosqueMe is not currently actively offered in the EEA. Before we actively offer MosqueMe in the EEA in circumstances where an EU or EEA representative is required, we will publish representative contact details in this policy and at the public privacy-policy URL used in the store listing.
18. Version History
| Version | Date | Summary |
|---|---|---|
| 1.0 | 21 April 2026 | First public release. |