Privacy & data

Your worship journey is personal.

This policy explains what Mizan collects, why it is needed, who can see it, and how you can delete it.

Effective August 10, 2026 Version 1.2

No ads or tracking

Mizan does not sell personal data or use advertising, behavioral analytics, or tracking SDKs.

Limited group sharing

Group members see your profile presentation and aggregate score, not your individual worship entries or email.

Deletion is built in

You can permanently delete your account and associated activity history from your profile.

01

Who we are

Mizan is an Islamic activity-tracking application developed and operated by Omar El Mokadem (GitHub username oelmokadem), referred to in this policy as “Mizan,” “we,” “us,” or “our.” This policy applies to the Mizan mobile application, its application programming interface, and this privacy website.

Questions or privacy requests can be sent to omarsamirelmokadem@gmail.com.

02

Information we collect

We collect only the information needed to provide Mizan's account, history, and group features.

Account information

When you create an account, we collect your email address, display name, chosen avatar color, password, and account timestamps. We assign an internal user identifier. Your password is converted into a one-way cryptographic hash before storage; we do not store your readable password.

Worship and activity information

Mizan stores the activities you record, such as prayer, Quran reading, adhkar, fasting, sadaqah, dua, and custom activities. Records may include an activity identifier, calendar date, completion status, numeric count, completion time, and record timestamps. This information can reveal religious beliefs or practices and is treated as sensitive information.

Group information

If you create or join a group, we store the group name, invite code, creator and member identifiers, membership, and creation time. Group leaderboards calculate an aggregate completed-activity count for the selected period.

Safety, blocking, and moderation information

If you block another member, Mizan stores the two account identifiers needed to enforce the block. If the operator removes and bans a member from a group after review, Mizan stores the group and account identifiers needed to prevent that account from rejoining until the ban is lifted. If you report a group name or group member, we may collect the reporter and reported account identifiers, group and context identifiers, report category, details you choose to provide, case status, actions taken, appeal correspondence, and timestamps. A report may include a limited server-generated snapshot containing the relevant group name and, for a member report, the target member's display name as they appeared when reported. It is not designed to include passwords or individual worship entries.

Information stored on your device

The app stores a signed session token, a cached copy of basic profile details, and your custom activity labels on your device. On supported mobile devices, the session token is kept in secure device storage. Session tokens normally expire after seven days.

Network and security information

When you connect, our hosting and security infrastructure may process your IP address and basic request metadata to deliver requests, prevent abuse, enforce rate limits, troubleshoot failures, and protect Mizan. We do not use this information for advertising or cross-app tracking.

Information Mizan does not request

The current app does not request precise location, contacts, advertising identifiers, camera, microphone, photo library, health data, payment data, or social-media login. It contains no advertising, behavioral analytics, or marketing-tracking SDK.

03

How we use information

We use the information described above to:

  • create, authenticate, secure, and maintain your account;
  • save and synchronize your activity history across sessions;
  • show history, progress, group membership, and group leaderboards;
  • enforce blocks, investigate reports, apply the community rules, prevent repeat abuse, and review appeals;
  • respond to support, access, correction, export, or deletion requests;
  • detect abuse, enforce technical limits, and protect the service; and
  • meet legal obligations and enforce our rights.

Recording worship activities is voluntary. When you choose to record them, you ask us to process that sensitive information to provide the features you selected. You may stop recording information, remove custom-activity history, leave groups, or delete your account at any time.

04

Sharing and service providers

We do not sell personal information. We do not share it for targeted advertising or cross-context behavioral advertising.

Other group members

Members of a group can see your display name, avatar color, internal member identifier, and aggregate completed-activity count for the selected leaderboard period. They cannot see your email address, individual activity entries, custom activity labels, or password through the group features.

Blocking and moderation access

A block is enforced symmetrically in shared leaderboards, so neither blocked account is shown to the other there. Reports do not automatically delete content or accounts. The Mizan operator reviews reports and may take action when appropriate. Report details, snapshots, enforcement records, and appeals are not shown to ordinary group members through Mizan. Access is limited to the Mizan operator and any person specifically authorized to perform support, safety, legal, or moderation work, together with service providers that must process the information to operate the API, database, or support mailbox.

Service providers

We use service providers only as needed to run Mizan:

  • MongoDB Atlas, a managed database service provided by MongoDB, Inc., hosts the active database containing account, activity, and group records.
  • Vercel hosts and delivers the Mizan API. In doing so, Vercel may process API request content, IP addresses, request headers, and basic request metadata on our behalf.
  • Google Gmail hosts the published Mizan support and privacy mailbox and processes the messages and attachments you choose to send there.
  • GitHub Pages hosts this public privacy website.

These providers process information on our behalf to provide their services. You can review the MongoDB Privacy Hub, Vercel Privacy Notice, Google Privacy Policy, and the GitHub Privacy Statement.

Legal and safety reasons

We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or the public, investigate abuse, or defend Mizan's rights. If Mizan is transferred to a new operator, information may transfer as part of that transaction subject to this policy or advance notice of material changes.

05

Retention and deletion

Account, activity, and group-membership records remain in the active database while your account is active, unless you delete particular eligible custom-activity history or leave a group. Mizan does not currently apply an automatic inactivity expiration to active accounts.

You can permanently delete your account from Profile → Privacy & Data → Delete Account. After password confirmation, Mizan removes your profile and activity logs, removes you from groups, deletes groups with no remaining members, and transfers ownership of shared groups when necessary. A shared group's name and activity may remain for its other members, but your membership is removed. Mizan also removes active blocked-user relationships and active group-moderation bans keyed to the deleted account, and the app clears its local session and account-scoped custom activity labels.

Mizan does not keep a separate archival copy for marketing or analytics. Limited copies may remain temporarily in service-provider backups, security records, or diagnostic logs until their normal rotation, or longer when retention is required by law or necessary to prevent fraud and protect legal rights. Deleted account data is not restored to active use from a backup except when necessary for disaster recovery, in which case deletion controls will be reapplied where reasonably possible.

Active block relationships and group moderation bans are kept while they remain in place and the relevant accounts and groups remain active; unblocking or an operator unban removes the active relationship. Moderation reports, limited report snapshots, enforcement records, and related appeal correspondence may be retained for up to 12 months from the date the report or related correspondence is received so we can document the decision, handle appeals, identify repeat abuse, and protect the service. We then delete or de-identify those records, unless a longer period is required by law or reasonably necessary for an active safety, fraud, or legal matter. These limited safety records may therefore remain after account deletion for the stated period and are not used to restore a deleted account.

See the account deletion page for step-by-step instructions and an alternative request method if you cannot access the app.

06

Security

We use administrative and technical safeguards designed to protect information, including one-way password hashing, signed expiring session tokens, secure mobile token storage where supported, authenticated API access, request-size limits, origin controls, security headers, and rate limiting. Production connections must use HTTPS. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

If you believe your account or Mizan's systems are at risk, contact us promptly and do not send your password.

07

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information.

  • Review: your basic account details and activity history are available inside Mizan.
  • Delete activity: eligible custom-activity history can be removed from the app.
  • Leave a group: you can leave groups from the group controls.
  • Block or unblock: block a member from a group's detail screen and manage blocks from Profile → Blocked Members.
  • Report or appeal: report a group name or group member from the group's detail screen, or follow the reporting and appeal instructions on our Support page.
  • Delete your account: use the in-app deletion control or follow the alternative process on our deletion page.
  • Other requests: email omarsamirelmokadem@gmail.com. We may need to verify that you control the account before acting.

You may complain to your local data-protection authority where that right applies.

08

Children's privacy

Mizan is not directed to children under 13, and we do not knowingly collect personal information from a child under 13 without authorization required by applicable law. We do not collect birth dates. If you are a parent or guardian and believe a child provided information improperly, contact us so we can investigate and delete it. Additional age or consent rules may apply in some countries.

09

International processing

Our service providers may process information in countries other than your own. Privacy and data-protection laws can differ between countries. Where required, we use appropriate contractual or legal safeguards for international processing.

10

Changes to this policy

We may update this policy when Mizan's features, providers, or legal obligations change. We will post the revised version here, update the effective date, and provide additional notice in the app when a material change requires it. Previous versions remain available through this site's public Git history.

11

Contact us

For privacy questions, rights requests, or account-deletion assistance:

Mizan — Omar El Mokadem
Email: omarsamirelmokadem@gmail.com
GitHub: github.com/oelmokadem
Email privacy support

For troubleshooting, safety reports, community rules, and appeals, visit the Mizan Support page.