Privacy Policy

How Muslimah Pro handles your data

Last updated: July 26, 2026

Who We Are

Muslimah Pro, also presented as muslimah.health, is operated by Sultan Ibne Usman in India ("Muslimah Pro," "we," "us," or "our"). This policy covers the mobile app, website, API, support channels, and related services.

We provide a health, wellness, and Islamic-practice companion. Some information described below—such as health, fertility, intimate-life, religious-practice, and precise-location data—is especially sensitive. We do not sell personal information and do not use or disclose health data for advertising or Meta campaign measurement.

Information We Process

Account, identity, and session data

  • An anonymous account ID created by the app; a display name if you provide one.
  • Apple or Google identifiers and email address if you choose to link or sign in with those providers.
  • An email address if you join a website waitlist or request access to the Android beta. For beta requests, use the Google account associated with your Play Store so we can manage tester access and essential beta updates.
  • Session and security data such as refresh-token records, linked-provider status, device or app-build context, IP address, user agent, request timing, and rate-limit or abuse-prevention events.

Profile, onboarding, health, and intimate data

  • App mode, onboarding answers, cycle observations, flow, discharge, symptoms, moods, digestion, intimacy indicators, notes, body measurements, nutrition goals, and related dates or timestamps.
  • Fertility and test information, ovulation and pregnancy tests, medications, pregnancy, pregnancy loss, postpartum and nifas records, ghusl records, skincare profile and observations, and fitness goals, plans, sessions, exercises, progress, pain, or recovery signals.
  • Islamic preferences such as madhab and worship settings, prayer and fasting logs, missed fasts, daily worship check-ins, and data used to calculate religious guidance.

Apple Health and Health Connect data

  • If you authorize Apple Health import, the app may read the specific types you approve, including height, weight, date of birth, biological sex, activity, steps, energy, exercise, stand time, walking or running distance, flights climbed, hydration, nutrition, mindfulness, sleep, body measurements, temperature, heart and respiratory metrics, oxygen saturation, glucose, peak flow, blood pressure, and blood type.
  • Most of that imported snapshot is used locally on your device. Height, weight, date of birth, and biological sex may be copied into your nutrition or profile fields and synced when you choose to use them in the app.
  • Android builds that enable Health Connect may request the approved types shown by Android, such as steps, active calories, height, weight, and sleep. We do not write data to Apple Health or Health Connect unless a future feature clearly asks you first.

Photos, scans, nutrition, and product data

  • Meal photos you choose, their storage references and metadata, descriptions, AI analysis jobs, suggested foods, ingredients, portions, calories, nutrients, and saved food-log history.
  • Skincare face photos selected for optional analysis, structured visible observations, scan metadata, consent status, routines, selected products, and daily skin logs. Original face photos are kept locally for the scan UI; a temporary analysis copy passes through the backend and is not saved there after the request finishes or fails.
  • Ingredient-label photos selected for extraction, decoded barcode numbers, product-submission drafts, and catalog data you choose to submit.

Location, notifications, support, purchases, and usage

  • City, country, precise latitude and longitude, timezone, and prayer-time calculation preferences when you enable location-based features.
  • Push tokens and notification preferences; support messages; review-prompt responses; first-party app analytics such as screen views, button taps, onboarding, paywall and purchase lifecycle events; and crash or unhandled-error details.
  • Product and transaction identifiers, receipts, purchase and expiry dates, renewal status, purchase-attempt records, store environment, gift or promo access, and app-store server notifications.
  • Limited Meta App Events measurement: app install or activation and subscription events with the store product identifier, price, and currency. The app's standard subscription-start event is sent only after backend verification. The Meta SDK also necessarily processes basic app, device, operating-system, language, IP/network, and event-time context when it delivers events.
  • On iOS, if you grant Apple's App Tracking Transparency (ATT) permission, Meta may also access Apple's device advertising identifier (IDFA) and use it with the limited event and technical data above to attribute installs and subscription conversions, measure campaigns, and deliver or personalize advertising. We do not obtain or store the IDFA in our account database.

Partner sharing

  • If you create or accept a partner connection, we process the invitation, partner identifiers, status, notification preferences, support actions, and the sharing scopes you approve.
  • Depending on your choices, a connected partner may receive read-only access to selected cycle, symptom, pregnancy, nutrition, worship, intimacy, or note information. You can change or revoke access in the app.

Why We Process It

  • Create and secure accounts, maintain sessions, sync data, restore access, and provide customer support.
  • Provide cycle, fertility, pregnancy, postpartum, nutrition, skincare, fitness, worship, partner-sharing, reminder, and Nura features you choose to use.
  • Generate estimates, plans, classifications, or suggestions and let you review or correct them.
  • Calculate prayer times, fasting schedules, and Hijri-date features when you provide location data.
  • Process subscriptions, verify purchases, restore entitlements, and manage gifts or promotional access.
  • Operate, troubleshoot, protect, and improve the service using first-party diagnostics, security logging, and abuse prevention.
  • With your ATT consent on iOS, measure, attribute, and improve Meta advertising campaigns using the device advertising identifier and limited app activation and verified subscription events. Without that consent, advertiser tracking remains disabled and only limited, non-IDFA measurement may operate.
  • Meet legal, security, accounting, tax, app-store, fraud-prevention, and dispute-resolution obligations.

Legal Bases and Consent

Where a legal basis is required, we rely on performance of our contract with you to provide requested features; your consent, including explicit consent where required for health or other sensitive data and optional AI or photo features; our legitimate interests in securing, debugging, and improving the service without overriding your rights; and legal obligations for purchases, records, safety, or lawful requests.

We rely on your explicit ATT choice for access to Apple's IDFA and cross-company app or website tracking on iOS. Declining or skipping that request does not affect access to Muslimah Pro. We do not treat acceptance of this Privacy Policy as ATT permission.

You may decline optional permissions or withdraw consent, but the related feature may stop working. We do not use app predictions or AI output to make decisions that create legal or similarly significant effects about you.

Nura, Gemini, and Other AI Features

AI features are optional. Before selected text, photos, or relevant app context is sent for AI processing, the app explains the feature and asks for permission where required. Google AI/Gemini processes optional meal images and descriptions, planning inputs, skincare face or label images, and other feature context needed to return the requested result. Nura messages and relevant cycle, health, worship, reminder, note, or preference context are processed by our Google Cloud-hosted Nura service using Google Gemini API or Vertex AI.

Only use an AI feature with information you want processed for that request. AI results may be wrong and must be reviewed. They are not medical, dietary, legal, or religious-professional advice. ModelsLab may receive a limited prompt to create an optional meal illustration; it does not need your original meal photo for that purpose.

Health Integrations

Apple Health and Health Connect access is optional and controlled by the permissions screen on your device. Muslimah Pro reads only the types you approve and uses them to display or personalize health, nutrition, fitness, recovery, or wellness features. We do not use Health integration data for advertising, marketing profiles, or sale to data brokers.

You can revoke individual Health permissions in system settings. Revoking access stops future reads but does not automatically delete profile fields you previously chose to import; those can be edited or deleted in the app or through account deletion.

Meta App Events and Ad Measurement

The mobile app uses the Meta App Events SDK to measure whether Meta ads lead to an app install or activation and, after our backend verifies a new store purchase, a subscription start. Subscription measurement may include only the store product identifier, price, and currency. Meta also receives the limited technical context necessarily generated when its SDK sends an event, such as app and operating-system version, device type, language, event time, and IP/network information.

Before requesting iOS tracking permission, the app presents an explanation. If you then choose Allow in Apple's ATT prompt, we enable Meta advertiser tracking and advertiser-ID collection, allowing Meta to access the IDFA for install and conversion attribution, campaign measurement, and advertising delivery or personalization. If you choose Ask App Not to Track, skip the request, are restricted, or have not decided, advertiser tracking and IDFA collection remain disabled. Android advertising-ID access remains disabled in this version.

We do not enable advanced matching, associate events with a Meta user ID, or send names, email addresses, phone numbers, Muslimah Pro account IDs, purchase transaction IDs, health or reproductive data, religious-practice data, onboarding answers, notes, photos, support messages, or precise-location fields to Meta. The advertising identifier and SDK-generated technical context described above are the only device-level identifiers used for this integration.

Meta processes the event, advertising-identifier, and technical data under its own terms and privacy policy. You can withdraw future ATT permission in iOS Settings under Privacy & Security → Tracking. Withdrawal stops future IDFA-based access by the app but does not retroactively invalidate or automatically delete data already processed by Meta. You may contact us about applicable rights and use Meta's own privacy controls.

Partner Sharing

Partner sharing is optional. The account owner chooses the connection and its scopes. A partner sees only data allowed by those scopes and receives read-only access unless the app clearly presents a separate confirmed support action. Do not invite someone you do not trust. You can change scopes or revoke the connection in the app.

Photos, Camera, and Device Permissions

Camera and photo-library access is requested only when you choose a feature that needs it. The system picker provides the images you select, not unrelated library items. Barcode decoding happens on the device and only the decoded number is sent for lookup.

Meal photos are uploaded through the authenticated API, analyzed, and stored in Cloudflare R2 so they can appear in synced food-log history. Skincare face photos stay in the app's local storage for baseline and progress views; a temporary copy is sent through the backend and Gemini for cosmetic, non-diagnostic analysis and is not retained by our backend after the analysis request. Ingredient-label photos are sent only when you choose label extraction.

How We Disclose Information

We disclose only the information reasonably needed for a provider to perform the requested service. Our current provider categories and uses include:

  • Amazon Web Services (AWS App Runner and relational database services) for API and database hosting.
  • Cloudflare R2 for meal-photo object storage.
  • Google Cloud and Google AI/Gemini, including Vertex AI where configured, for optional meal-photo and text analysis, nutrition, skincare and fitness planning, skincare face and label analysis, support automation, and Nura assistant requests.
  • ModelsLab for optional generated meal illustrations, USDA FoodData Central for nutrition reference data, and Open Beauty Facts for skincare product or barcode lookups.
  • Apple and Google for sign-in, app distribution, purchases, subscription management, Health integrations you authorize, and store notifications.
  • Expo for push-notification delivery and Aladhan for prayer-time calculations when location-based prayer times are used.
  • Meta Platforms for limited mobile-ad campaign attribution and measurement through Meta App Events. On iOS, device advertiser-ID access is enabled only after ATT authorization. Meta advanced matching and Meta user-ID association remain disabled.
  • Supabase/Postgres for website waitlist, blog, or admin data, and Vercel for website hosting and website analytics.

We may also disclose information when required by law, to investigate fraud or abuse, to protect users or the service, or as part of a merger, financing, acquisition, reorganization, or asset sale subject to appropriate confidentiality and notice requirements. We do not sell or rent personal information. Other than the limited Meta App Events measurement described above, we do not disclose app activity for advertising, and we never disclose health or other sensitive app data for behavioral advertising.

Where a provider receives personal data, we use provider terms or contracts that require confidentiality, security, limited-purpose processing, and protection consistent with this policy and applicable law.

Location and Notifications

Location is used for prayer times, fasting schedules, worship notifications, and related Hijri-date features. You may disable location and use a saved or manually selected place where supported. Push tokens are stored only so enabled reminders and service messages can be delivered.

Storage, Security, and Retention

We use HTTPS/TLS, authenticated API access, token-based sessions, a high-ceiling per-IP rate limit across protected API routes, database access controls, secret management, security logging, and account-deletion workflows. No service can promise absolute security or uninterrupted availability.

Synced account data, assistant history, structured analysis results, and meal photos are generally kept while your account is active or until you delete the relevant item. Local data remains until the app removes it, you clear app storage, or you uninstall. Temporary skincare analysis copies are not retained by our backend after the request finishes or fails.

Account deletion removes active account data and associated meal-photo objects. We may retain narrowly limited purchase, consent, security, fraud, tax, dispute, or legal records for as long as reasonably necessary, and provider backups may persist until their normal overwrite cycle. We use the purpose, legal requirements, sensitivity, and risk to decide retention when a fixed period is not specified.

Meta retains and handles App Events data under its own terms and retention practices. Account deletion removes data controlled by Muslimah Pro but does not automatically delete event data already processed independently by Meta; contact us to exercise applicable rights or use Meta's privacy controls.

If a qualifying incident affects personal or health information, we will investigate and notify users or regulators as required by applicable law.

Your Choices and Rights

  • Access and correct information in the app where controls are available, or ask us for a copy or correction.
  • Delete individual records, revoke a partner link, or delete your account in the app or through the deletion page.
  • Withdraw optional consent and control advertising tracking, camera, photos, location, notifications, Apple Health, and Health Connect through the app or device settings. Withdrawal does not make earlier lawful processing invalid.
  • Ask for deletion, restriction, objection, or portability where your local law provides those rights.
  • Appeal or complain to us and, where applicable, to your local data-protection authority.

Depending on where you live, sensitive personal information may include health, religious belief or practice, sex-life, and precise-location data. We use that information only for the disclosed service purposes and do not use it to infer characteristics for advertising. To exercise a right, contact us below. We may need to verify your account before acting.

Children

Muslimah Pro is not directed to children under 13, and we do not knowingly collect their personal information. A user below the age of majority where she lives may use the service only with parent or guardian consent. Contact us if you believe a child supplied information without appropriate consent.

International Processing

Providers may process information in India, the United States, or other countries where they operate. Those countries may have different data-protection laws. Where required, we use an approved transfer mechanism or other appropriate safeguard.

Changes to This Policy

We may update this policy when the product, providers, or law changes. If a change is material, we will give notice through the app, website, store listing, email, or another appropriate channel and request renewed consent where required.

Contact and Grievances

Operator and grievance contact: Sultan Ibne Usman

Privacy and support: muslimahpro.com@gmail.com

Account deletion: muslimahpro.com/delete-account

Describe the right or concern, the account involved, and how we can reply. We will acknowledge and respond within the period required by applicable law.