MyAlMasjid is a community app built to connect masjids and their members. This Privacy Policy explains, in plain terms, what personal data we collect when you use the app, why we need it, and how we protect it. We take your privacy seriously and comply with India's Digital Personal Data Protection Act 2023 (DPDPA) and the EU General Data Protection Regulation (GDPR).
1. Data We Collect
| Data Type | What We Collect | Why |
| Phone Number |
Your mobile number entered at registration |
One-time password (OTP) authentication via Firebase |
| Name |
Full name entered in your profile |
Display in the community and masjid dashboard |
| Date of Birth |
DOB entered in profile (optional) |
Profile completion |
| Profile Photo |
Photo you voluntarily upload |
Profile display within your masjid community |
| Approximate Location |
City-level GPS coordinate (coarse) |
Finding nearby masjids |
| Precise Location |
Exact GPS coordinate (fine) |
Qibla compass direction — processed on-device only, never sent to our servers |
| Device / FCM Token |
Firebase Cloud Messaging device token |
Sending prayer-time notifications |
| Crash & Diagnostics |
Crash stack traces via Firebase Crashlytics |
Identifying and fixing bugs |
| Audio (ephemeral) |
Live Azan audio streamed by the Imam |
Live Azan feature — streamed in real-time via LiveKit, not recorded or stored |
| Reports |
Reporter and reported user IDs, masjid ID, reason, optional content ID/type |
Reviewing reports of abusive members or objectionable community/Souq content |
| Blocked users |
Firebase UIDs of members you block |
Hiding their content from your feeds; synced on your device and our servers |
| TV Display Token |
Opaque display credential issued when a masjid admin pairs an Android TV / Fire Stick; device label and last-seen time |
Authenticate the hall prayer board to fetch that masjid’s prayer times (not a member login) |
| Advertising identifiers |
Device advertising ID (where permitted), approximate location for ads |
Contextual or personalised ads via Google AdMob (with your consent where required) |
We do not collect emails, financial information, health data, contacts,
racial or ethnic origin, sexual orientation, or political and religious beliefs. Note: when the Daily Sadaqah and Imam Hadiah payment features are activated, limited transaction-related data (amount, timestamp, payment status) will be processed by Razorpay on our behalf — this policy will be updated at that time.
2. How We Use Your Data
- Authenticate your account (phone OTP via Firebase)
- Display your profile within your masjid community
- Send prayer-time and announcement notifications
- Power the optional TV prayer display for a paired masjid (read-only schedule)
- Calculate Qibla direction (on-device — data never leaves your phone)
- Find masjids near your approximate location
- Monitor app stability and fix crashes (Firebase Crashlytics)
- Serve contextual or personalised advertisements (Google AdMob), subject to your consent
- Process reports and enforce blocks to keep community and Souq features safe
- Filter objectionable user-generated content using automated and manual review
3. Third-Party Services We Use
| Service | Provider | Data Shared |
| Firebase Authentication | Google LLC | Phone number |
| Firebase Cloud Messaging | Google LLC | Device FCM token |
| Firebase Storage | Google LLC | Profile photo |
| Firebase Crashlytics | Google LLC | Crash logs, device info |
| Firebase App Check | Google LLC | Device attestation (hardware-backed, no PII) |
| Google AdMob | Google LLC | Device identifier, approximate location (contextual ads) |
| LiveKit | LiveKit Inc. | Live audio stream (ephemeral, not stored) |
| Razorpay (Coming Soon) | Razorpay Software Pvt Ltd | Payment transaction data for Daily Sadaqah & Imam Hadiah features when activated. See Razorpay Privacy Policy. |
Google's Privacy Policy: policies.google.com/privacy.
LiveKit's Privacy Policy: livekit.io/privacy-policy.
Razorpay's Privacy Policy (applies when payment features are activated): razorpay.com/privacy.
We have Data Processing Agreements (DPAs) in place with all sub-processors listed above in accordance with GDPR Article 28 and DPDPA 2023 §9(2).
4. Data Retention
- Account data (name, phone, DOB, photo) — retained while your account is active.
- Prayer notifications — dispatch records deleted automatically after 30 days.
- Crash logs — retained for 90 days by Firebase Crashlytics.
- Live Azan audio — never stored; ephemeral only.
- Reports — retained while under review and for up to 12 months after resolution for audit and legal compliance.
- Blocked-user lists — retained while your account is active; removed when you unblock or delete your account.
- On account deletion all personal data is permanently erased within 30 days.
5. Your Rights (DPDPA 2023 & GDPR)
📋
Access
Request a copy of all personal data we hold about you.
✏️
Correction
Update inaccurate data directly via your in-app profile settings.
🗑️
Erasure / Account Deletion
Delete your account from Profile → Delete Account. All data erased within 30 days.
🔕
Withdraw Consent
Disable notifications anytime via app Settings or device notification settings.
⚖️
Grievance Redressal (DPDPA)
Raise a complaint with our Data Protection Officer at privacy@myalmasjid.com. We respond within 30 days.
6. Children's Privacy
MyAlMasjid is not directed at children under 18. We do not knowingly collect personal data from minors.
If you believe a minor has provided us with their data, please contact us immediately at
privacy@myalmasjid.com.
7. Data Security
We implement industry-standard safeguards including:
- Sensitive credentials stored in Android Keystore / iOS Keychain (never in plain storage)
- All data transmitted over HTTPS (TLS 1.2+)
- Firebase App Check (Play Integrity) — prevents unauthorised API access
- Rate limiting and input validation on all API endpoints
8. Masjid Accounts — Data Controller & Processor
When a masjid is registered on MyAlMasjid and its members join the community, two distinct data
protection roles come into play:
-
The Masjid is the Data Controller for the personal data of its own community members
(names, phone numbers, gender, date of birth, and any other profile information shared within that
masjid community). The Masjid determines why and how that data is used within their community.
-
MyAlMasjid acts as the Data Processor on the Masjid's behalf — we store, process,
and transmit that member data according to the Masjid's instructions and the configuration of the
platform, but we do not use it for our own independent purposes.
For all platform-wide data that MyAlMasjid collects independently — such as crash logs, device tokens,
in-app analytics, and advertising identifiers — MyAlMasjid is the Data Controller
and acts in accordance with this Privacy Policy.
Masjid Administrators are responsible for informing their members about data practices and for
complying with applicable data protection laws in their locality. The
Masjid Terms of Use set out these obligations in full.
Community feeds, announcements, events, Khutbah posts, and the Souq marketplace include user-generated content.
To meet Apple App Store safety requirements and India's intermediary rules, we provide tools to keep these spaces respectful:
- Community guidelines. Before accessing community or Souq features, you must accept our
Member Terms of Use and in-app Community Guidelines (no harassment, hate speech, extremism, or illegal content).
- Report. You may report a member or specific content. We store the reporter's and reported user's Firebase UID,
your masjid ID, a short reason, and optional content identifiers so our team can investigate.
- Block. You may block another member. Their posts will be hidden from your community and Souq feeds.
Block lists are stored on your device and on our servers so the block persists across sessions.
- Automated filtering. New community and Souq submissions are checked against keyword filters and,
where enabled, automated content-safety analysis. Severe violations may be blocked before publication.
- Human review. We aim to review pending reports within 24 hours. Confirmed violations may result in
content removal, account suspension, or referral to law enforcement where required by law.
To exercise rights over report or block data, contact privacy@myalmasjid.com.
For content disputes, you may also use our grievance process in Section 11 below.
10. Advertising (Google AdMob & Tracking)
We display banner advertisements through Google AdMob. Depending on your region and choices,
ads may be contextual or personalised using your device advertising identifier and approximate location.
We do not sell your personal data to advertisers.
- GDPR / EU & UK. On first launch, eligible users see Google's User Messaging Platform (UMP)
consent form for ad personalisation and related cookies/identifiers.
- iOS (14.5+). We request App Tracking Transparency (ATT) before using the advertising identifier
for personalised ads. You may decline; the app remains usable with less personalised ads.
- Opt out of personalised ads:
- iOS: Settings → Privacy & Security → Tracking → disable tracking for MyAlMasjid
- Android: in-app Settings → Ads → Opt out of Ads Personalisation
Google's privacy policy: policies.google.com/privacy.
TV Prayer Display (Android TV / Fire Stick)
Masjid administrators may install an optional MyAlMasjid TV app on Android TV or Amazon Fire Stick
to show that masjid’s daily Adhan and Iqama times in the prayer hall.
- Pairing. An admin generates a short-lived pairing code in the phone app (Admin → TV Display).
The TV enters the code once. Codes expire quickly and cannot be reused after a successful claim.
- Display token. After pairing, the TV stores a display token on the device. That token authenticates
read-only requests for the paired masjid’s prayer schedule. It is not a member account and does
not use phone OTP / Firebase Authentication on the TV.
- What the TV receives. Masjid name, city (if set), and the prayer times the masjid has published for the day,
plus next-prayer timing. The TV polls periodically so updates made by the Imam on the phone appear on the board.
- What we do not do on TV. The TV path does not use Firebase Cloud Messaging, Crashlytics, App Check,
advertising identifiers, or AdMob on the display app. It does not collect member profiles or phone numbers from the TV.
- Revocation. Admins can revoke a paired display in the phone app at any time. After revocation, the display
token stops working and the board returns to the pairing screen.
- Controller. Prayer times shown on the TV are the same masjid-published content as in the phone app.
Platform processing of display tokens is described under Data We Collect above and follows the same security and retention principles as other API credentials.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Effective" date at the top will be revised accordingly.
Continued use of the App after changes constitutes your acceptance of the updated policy.
Significant changes will be notified via an in-app banner.