Legal

Privacy Policy.

Last updated: August 30, 2026

This Privacy Policy explains what personal data Hadaff collects when you use the Hadaff app at hadaff.de and the native Android app, why we collect it, who can access it, and how long we keep it. It is written to reflect how Hadaff actually works today, not a general template.

This document describes our data practices. It is not a substitute for individual legal advice about your own rights or circumstances — if you have specific legal questions, please consult a qualified professional or your local data protection authority.

1. Who Is Responsible (Controller)

Mostafa Rashid
Heerstr. 441, 13593 Berlin, Germany
Email: hadaffysuppor@gmail.com

Hadaff is operated by a single developer, not a company with a dedicated legal or data protection department. Requests are handled personally by the contact above.

2. Data We Collect, Why, and On What Legal Basis

For every category of data below we explain: what is collected, why, the legal basis under Art. 6 (and, where relevant, Art. 9) GDPR, and roughly how long it is kept. General retention details are in Section 7; account deletion is covered separately in Section 8.

2.1 Account & Login Data

  • What: your user ID (a technical identifier generated by Firebase Authentication), full name, email address, username, registration date, account status (active/disabled), and basic authentication metadata (such as last sign-in time). Your password itself is never seen or stored by us — it is handled entirely by Firebase Authentication.
  • Why: to create, secure, and let you sign in to your account, and to let other users find and follow you by username.
  • Legal basis: Art. 6(1)(b) GDPR — performance of a contract (you cannot use Hadaff without an account).
  • Your username is public and visible to other users in search, follow lists, on your profile, and on your public profile page (hadaff.de/friend/<username>). If you don't choose one, we generate a random one for you; you can change it once every 30 days from Edit Profile. Your name and email address are not shown to other users.

2.2 Technical & Device Data

  • What: which platform you use Hadaff on (Android app or web app), and, where available, the time of your last activity or sign-in.
  • Why: to operate the app correctly across platforms, to show you your own account status, and for basic security and stability monitoring.
  • Legal basis: Art. 6(1)(b) GDPR (operating the service you signed up for) and Art. 6(1)(f) GDPR — legitimate interest in keeping the service secure, stable, and free of abuse.
  • Because this data is stored against your user ID, the platform you use and your last activity can be, and are, associated with your specific account — we do not treat this as anonymous or aggregate data at the point of collection.

2.3 App Usage & Session Data

  • What: session records (approximate time spent in the app, number of sessions, last-active date), streaks, and feature-usage counters (for example, how many habits you have or how many messages you've sent the AI assistant today).
  • Why: to show you your own streaks and stats inside the app, to keep the app synced and working reliably, to diagnose problems, to enforce fair-use limits (such as daily AI message limits), and to compile internal statistics about overall app usage (e.g. how many people used a feature on a given day).
  • Legal basis: Art. 6(1)(b) GDPR for the parts of this data that power a feature you see (your own streak, your own usage counters), and Art. 6(1)(f) GDPR — legitimate interest — for using the same underlying records to compile internal operational statistics.
  • Internal statistics compiled from this data are only used by us as the app operator to understand and improve the service. We do not sell this data, share it with advertisers, or use it to build advertising profiles. Note that because these records are stored per user ID, they are personal data linked to your account, not truly anonymous data, even when we look at them in aggregate for internal reporting.

2.4 Habits

  • What: the habits you create (name, icon, color, optional goal) and your daily completion/logging history for each one, used to calculate your habit streaks.
  • Why: so you can keep your habits, your progress, and your history in your account, and have them available on any supported device you sign in on.
  • Legal basis: Art. 6(1)(b) GDPR — this is a core feature you choose to use.

2.5 Prayer Tracker, Tasbeeh, Khatma & Athkar (Religious Activity Data)

Hadaff includes several optional Islamic practice-tracking features: the Prayer Tracker (daily prayer check-ins and prayer statistics), Tasbeeh (dhikr counter), Khatma (your Quran reading/completion progress), and Athkar (daily remembrance sessions and completion history).

  • What: which prayers you marked as completed and when, your Tasbeeh counts, your Quran/Khatma reading progress, and your Athkar completion history and streaks.
  • Why: to let you track your own religious practice over time, calculate related streaks, and sync this data across your devices — purely as a personal tool for you.
  • Special category data (Art. 9 GDPR): this data can reveal information about your religious beliefs and practice, and may qualify as a special category of personal data under Art. 9(1) GDPR, which requires a specific legal basis beyond the general grounds in Art. 6. We do not rely on "performance of a contract" alone for this category. The applicable basis is your explicit consent (Art. 9(2)(a) GDPR): the first time you open Prayer Tracker, Tasbeeh, Khatma, or Athkar, we ask you to separately agree before we start saving any data for that specific feature, and you can withdraw this consent for each feature independently at any time from Settings, which also deletes the data already saved for that feature.
To confirm before publishing: the separate, per-feature consent prompts and the Settings-based withdrawal (with deletion) described above have been implemented in the app. Please have a data protection professional confirm that the prompt wording, the consent record kept per feature, and the deletion-on-withdrawal flow meet the specific requirements of Art. 9(2)(a) GDPR before relying on this section.

2.6 Social Features

  • What: your followers and who you follow, pending follow requests, blocks you place or receive, records of who viewed your profile, any custom nicknames you set for people you follow, and reports submitted about accounts or content (including the report reason and the reported/reporting user IDs).
  • Why: to provide the follow/social features you use, let you control who can see your activity (e.g. private account settings), and to review reports and enforce our Terms of Service.
  • Legal basis: Art. 6(1)(b) GDPR for the follow/profile features themselves, and Art. 6(1)(f) GDPR — legitimate interest — for blocks, reports, and profile-view records, which exist to protect users from abuse and harassment.
  • What other users can see: your username, display name, and profile picture (if set), whether your account is public or private, and — depending on your settings — your follower/following lists and activity. What is only visible to you and to us as the operator: your email address, full name (unless you choose to display it), who has viewed your profile, and any blocks or reports involving your account.
  • If you enable it, other users you follow may see a basic online/last-active indicator (presence). We only show this to accounts with a mutual follow relationship, not to the public.

2.7 AI Assistant ("Hadi")

  • What Hadaff offers: an AI chat feature ("Hadi" / "Ask Imam") that answers Islamic questions and can read images you send it. It is limited to 30 messages and 3 image uploads per account per day.
  • What is processed: the text of your messages, any images you upload, and the last few messages of your conversation history (sent along so Hadi has context), plus whether you rate a response with a thumbs up/down.
  • Where it goes: your message, image, and recent conversation history are sent to OpenAI (a third-party AI provider based in the USA) in real time to generate a response. We do not process this with a local or on-device model — it genuinely leaves our systems and is sent to OpenAI's servers. The conversation itself, including any images, is also stored under your account in our database so you can continue it later and view your history.
  • Why: to provide the AI chat feature you choose to use.
  • Legal basis: Art. 6(1)(b) GDPR — this is a feature you actively choose to use, message by message.
  • Hadi is an automated AI system, not a human being or a certified Islamic scholar — see our Terms of Service for the full disclosure required under Article 50 of the EU AI Act. Please avoid sharing sensitive personal information in the chat. You can delete your AI chat history at any time from within the app without deleting your whole account.
To confirm before publishing: whether OpenAI retains or uses API request content for model training depends on the specific API terms/plan in use. Please confirm the applicable OpenAI API data-usage terms (and whether a zero-data-retention or "don't train on my data" setting applies) and reflect the accurate position here.

2.8 Support Tickets & Feedback

  • What: the category, description, and contact email you provide when you submit a support ticket or report a problem, plus any reply we send you and the ticket's status history.
  • Why: to respond to your request and keep a record in case you follow up.
  • Legal basis: Art. 6(1)(b) GDPR (responding to a request you made) and, where a ticket concerns a possible violation of our Terms by someone else, Art. 6(1)(f) GDPR — legitimate interest in investigating and resolving it.

2.9 Location Data

  • What: your device's GPS coordinates, only if you grant location permission, used to calculate accurate prayer times and to search for nearby places.
  • Why: so prayer times and the Athan (call to prayer) feature match your actual location.
  • Legal basis: Art. 6(1)(a) GDPR — your consent, given by granting location permission. You can withdraw it at any time in your device settings or the app's Tools section; you can still set your location manually instead.
  • Your coordinates are stored locally on your device (browser/app local storage), not on our servers, and are only transmitted at the moment a prayer-time calculation or place search actually happens — see Section 5 for which external services receive this data.
  • If you don't grant GPS permission, we fall back to an approximate, city-level location derived from your IP address via a third-party service (see Section 5). This is less precise than GPS but still involves sending your IP address to that service.

2.10 Data Stored Only On Your Device

  • Your theme preference (dark/light/system), your last-used location, and a short-lived cache of recently calculated prayer times are saved only in your browser's or device's local storage. This never reaches our servers on its own — it is only read from your device when a feature that needs it runs.

3. Administrator Access

Mostafa Rashid, as the operator of Hadaff, and any other individuals he designates as administrators, can access certain account and usage data through an internal admin dashboard when this is genuinely necessary for:

  • Responding to support requests and account issues
  • Account management (e.g. disabling an account, sending a password reset)
  • Investigating abuse, reports, or Terms of Service violations
  • Security monitoring and fraud prevention
  • Technical maintenance and troubleshooting
  • Operating the service generally

We do not claim that administrators can never access user data — as the operator, we have the technical ability to access data stored in our Firebase project and backend systems where necessary for the purposes above. What we do commit to is limiting and controlling that access: the admin dashboard is built to avoid showing sensitive information (such as your Prayer Tracker, Tasbeeh, or Khatma data) by default, requires a separate authentication step beyond a normal login, and every access to an individual account's details, and every administrative action taken, is recorded in an internal audit log (admin, action, target account, and timestamp) for accountability.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating, securing, and supporting the service — balanced against your rights through the access limitations described above.

4. Who We Share Data With

We do not sell your data, and we do not share it with advertisers. The following third-party services process data on our behalf or as part of providing specific features:

Google Firebase — Authentication, Firestore Database, Cloud Functions, Cloud Storage, Cloud Messaging, Hosting
Firebase is the backend platform Hadaff is built on. It handles your sign-in, stores essentially all of your app data (profile, habits, streaks, Prayer Tracker, Tasbeeh, Khatma, Athkar, social data, AI chat history, tickets), runs our backend logic, delivers push notifications, hosts your uploaded profile picture, and serves the web app itself. Operated by Google LLC / Google Ireland Limited.
Firebase Privacy Policy →
Google Cloud Storage (static app assets)
A separate storage bucket used to host static, non-personal app assets such as app icons and onboarding media. Operated by Google LLC.
Google Cloud Privacy Policy →
Resend
A transactional email service we use to send account-related emails: login codes, welcome emails, password reset links, support ticket confirmations, and account-deletion/inactivity notices. Your email address, name, and the content of these emails pass through Resend to deliver them to you.
Resend Privacy Policy →
OpenAI
Processes the messages and images you send to the Hadi AI assistant in order to generate a response. Operated by OpenAI, L.L.C. / OpenAI Ireland Ltd. Data may be processed outside the EU.
OpenAI Privacy Policy →
Aladhan API
Calculates prayer times for your location. Your coordinates are sent to this service only when a prayer-time calculation is performed. Operated by Aladhan.com.
Aladhan Privacy Policy →
OpenStreetMap Nominatim
Used to look up or search for place names from coordinates (geocoding/reverse geocoding) when you set or search for a location. Operated by the OpenStreetMap Foundation.
OpenStreetMap Privacy Policy →
ipapi.co
Used as a fallback to estimate your approximate (city-level) location from your IP address when you have not granted GPS location permission, so prayer times can still be calculated. Operated by ipapi.co.
ipapi.co Privacy Policy →
Google Fonts / Material Symbols
UI fonts and icons are loaded from Google's font CDN. Your IP address is transmitted to Google's servers when the app loads, which is technically necessary to display the interface.
Google Privacy Policy →
To confirm before publishing: please confirm that a GDPR-compliant Data Processing Agreement (Art. 28 GDPR) is in place with each processor above that qualifies as a processor (in particular Firebase/Google, Resend, and OpenAI), and that this list matches the services actually in production use at the time of publishing.

5. International Data Transfers

Several of the services listed in Section 4 (Google/Firebase, Resend, OpenAI, ipapi.co) may process data on servers located outside the European Economic Area, including in the United States. Where this happens, we rely on the safeguards those providers offer — such as the EU-US Data Privacy Framework, where applicable, or Standard Contractual Clauses approved by the European Commission — to ensure your data continues to receive a level of protection equivalent to the GDPR.

6. Data Retention

  • While your account is active, your account, habit, streak, religious-feature, social, AI chat, and support ticket data is kept for as long as your account exists, so these features keep working.
  • Automatic deletion for inactivity: if you have not signed in for 30 days, we send a warning email. If you have not signed in for 60 days, your account is automatically deleted following the process described in Section 8.
  • Manual deletion: if you request deletion yourself, your account is permanently deleted after a 14-day grace period (see Section 8) — signing back in during that window cancels the deletion.
To confirm before publishing: we do not currently have a separate, explicitly defined retention period for some categories once an account is active for a long time (for example, how far back AI chat history or activity logs are kept for an account that never gets deleted). If a maximum retention period should apply even to active accounts, this needs to be defined and implemented, then documented here.

7. Account Deletion

You can request deletion of your account at any time from within the app (Account → Delete Account). We want to be precise and honest about what this actually does today, rather than making a blanket promise we can't fully verify:

  • Your request starts a 14-day grace period. If you sign back in during this window, the deletion is cancelled and your account is restored exactly as it was.
  • Once the grace period ends, we delete: your account profile and authentication credentials, your uploaded profile picture, your AI chat history, your habit and streak data, your Prayer Tracker records, your Tasbeeh counts, your Khatma/Quran progress, your Athkar records, your session and AI-usage statistics, your follow relationships, pending follow requests, block records and profile-view records with other accounts, your social settings, your Athkar settings, your saved preferences, your support tickets, and your custom nicknames for people you follow.
  • Inactive accounts (see Section 6) go through the same deletion process automatically after 60 days of inactivity, without a grace period.
  • You can delete only your AI chat history at any time, without deleting your whole account, directly from the chat screen.
  • Backups, if any exist at the infrastructure level, and records we are legally required to keep (such as records needed to resolve an open support ticket or investigate a report filed before deletion) may persist for a limited additional time after deletion for legitimate, narrowly defined purposes.
To confirm before publishing: this section describes the deletion routine as updated in the codebase to cover every account-linked data category. Confirm the updated backend has actually been deployed to production (firebase deploy --only functions) and run an end-to-end test deletion before relying on this description.

8. Your Rights Under the GDPR

If the GDPR applies to you, you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Request erasure of your data / the "right to be forgotten" (Art. 17)
  • Request that we restrict processing in certain circumstances (Art. 18)
  • Receive a copy of your data in a portable format (Art. 20)
  • Object to processing based on our legitimate interest (Art. 21)
  • Withdraw any consent you've given at any time, without affecting processing carried out before the withdrawal (Art. 7(3))
  • Lodge a complaint with a data protection supervisory authority

To exercise any of these rights, contact us at hadaffysuppor@gmail.com. You can lodge a complaint with the authority responsible for us, the Berlin Commissioner for Data Protection and Freedom of Information (www.datenschutz-berlin.de), or with the authority in your own country of residence within the EU.

9. Data Security

We rely on the security measures built into the infrastructure we use: Firebase Authentication so we never see or store your password, Firestore security rules that restrict which data an app or user can read or write, HTTPS encryption in transit, and encryption at rest as provided by Google Cloud/Firebase infrastructure. Access to the admin dashboard requires a separate authentication step beyond a normal account login, and administrative actions are logged (see Section 3). No online service can be guaranteed 100% secure, and we do not claim a level of protection beyond what is described here.

We do not publish, and this policy does not disclose, any internal security keys, credentials, or configuration details.

10. Cookies and Local Storage

The Hadaff web app does not use advertising or tracking cookies, and we do not run third-party analytics or tracking SDKs. We use your browser's or device's local storage (not cookies) purely to remember technically necessary settings on your own device — your theme preference, your last-used location, a short-lived prayer-time cache, and whether you've already responded to the location-permission prompt. None of this leaves your device unless a feature you use actively needs to send part of it to one of the services listed in Section 4 (for example, sending your coordinates to calculate prayer times).

11. Age Requirement and Children's Privacy

Hadaff requires you to enter your date of birth when creating an account and requires you to be at least 18 years old to sign up. This is a self-declared age check based on the birthdate you enter — we do not independently verify it. Hadaff is not directed at children and is not intended for use by anyone under 18.

If we become aware that we have collected personal data from someone below this minimum age, we will delete that account and data. If you believe this applies to you or someone you are responsible for, please contact us at hadaffysuppor@gmail.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the app or legal requirements. We will notify you of significant changes through the app. Continuing to use Hadaff after a change takes effect means you accept the updated policy.

13. Contact

Mostafa Rashid
Heerstr. 441, 13593 Berlin, Germany
Email: hadaffysuppor@gmail.com