No ads or tracking
Mizan does not sell personal data or use advertising, behavioral analytics, or tracking SDKs.
Privacy & data
This policy explains what Mizan collects, why it is needed, who can see it, and how you can delete it.
Mizan does not sell personal data or use advertising, behavioral analytics, or tracking SDKs.
Group members see your profile presentation and aggregate score, not your individual worship entries or email.
You can permanently delete your account and associated activity history from your profile.
01
Mizan is an Islamic activity-tracking application developed and operated by Omar El Mokadem (GitHub username oelmokadem), referred to in this policy as “Mizan,” “we,” “us,” or “our.” This policy applies to the Mizan mobile application, its application programming interface, and this privacy website.
Questions or privacy requests can be sent to omarsamirelmokadem@gmail.com.
02
We collect only the information needed to provide Mizan's account, history, and group features.
When you create an account, we collect your email address, display name, chosen avatar color, password, and account timestamps. We assign an internal user identifier. Your password is converted into a one-way cryptographic hash before storage; we do not store your readable password.
Mizan stores the activities you record, such as prayer, Quran reading, adhkar, fasting, sadaqah, dua, and custom activities. Records may include an activity identifier, calendar date, completion status, numeric count, completion time, and record timestamps. This information can reveal religious beliefs or practices and is treated as sensitive information.
If you create or join a group, we store the group name, invite code, creator and member identifiers, membership, and creation time. Group leaderboards calculate an aggregate completed-activity count for the selected period.
If you block another member, Mizan stores the two account identifiers needed to enforce the block. If the operator removes and bans a member from a group after review, Mizan stores the group and account identifiers needed to prevent that account from rejoining until the ban is lifted. If you report a group name or group member, we may collect the reporter and reported account identifiers, group and context identifiers, report category, details you choose to provide, case status, actions taken, appeal correspondence, and timestamps. A report may include a limited server-generated snapshot containing the relevant group name and, for a member report, the target member's display name as they appeared when reported. It is not designed to include passwords or individual worship entries.
The app stores a signed session token, a cached copy of basic profile details, and your custom activity labels on your device. On supported mobile devices, the session token is kept in secure device storage. Session tokens normally expire after seven days.
When you connect, our hosting and security infrastructure may process your IP address and basic request metadata to deliver requests, prevent abuse, enforce rate limits, troubleshoot failures, and protect Mizan. We do not use this information for advertising or cross-app tracking.
The current app does not request precise location, contacts, advertising identifiers, camera, microphone, photo library, health data, payment data, or social-media login. It contains no advertising, behavioral analytics, or marketing-tracking SDK.
03
We use the information described above to:
Recording worship activities is voluntary. When you choose to record them, you ask us to process that sensitive information to provide the features you selected. You may stop recording information, remove custom-activity history, leave groups, or delete your account at any time.
05
Account, activity, and group-membership records remain in the active database while your account is active, unless you delete particular eligible custom-activity history or leave a group. Mizan does not currently apply an automatic inactivity expiration to active accounts.
You can permanently delete your account from Profile → Privacy & Data → Delete Account. After password confirmation, Mizan removes your profile and activity logs, removes you from groups, deletes groups with no remaining members, and transfers ownership of shared groups when necessary. A shared group's name and activity may remain for its other members, but your membership is removed. Mizan also removes active blocked-user relationships and active group-moderation bans keyed to the deleted account, and the app clears its local session and account-scoped custom activity labels.
Mizan does not keep a separate archival copy for marketing or analytics. Limited copies may remain temporarily in service-provider backups, security records, or diagnostic logs until their normal rotation, or longer when retention is required by law or necessary to prevent fraud and protect legal rights. Deleted account data is not restored to active use from a backup except when necessary for disaster recovery, in which case deletion controls will be reapplied where reasonably possible.
Active block relationships and group moderation bans are kept while they remain in place and the relevant accounts and groups remain active; unblocking or an operator unban removes the active relationship. Moderation reports, limited report snapshots, enforcement records, and related appeal correspondence may be retained for up to 12 months from the date the report or related correspondence is received so we can document the decision, handle appeals, identify repeat abuse, and protect the service. We then delete or de-identify those records, unless a longer period is required by law or reasonably necessary for an active safety, fraud, or legal matter. These limited safety records may therefore remain after account deletion for the stated period and are not used to restore a deleted account.
See the account deletion page for step-by-step instructions and an alternative request method if you cannot access the app.
06
We use administrative and technical safeguards designed to protect information, including one-way password hashing, signed expiring session tokens, secure mobile token storage where supported, authenticated API access, request-size limits, origin controls, security headers, and rate limiting. Production connections must use HTTPS. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
If you believe your account or Mizan's systems are at risk, contact us promptly and do not send your password.
07
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information.
You may complain to your local data-protection authority where that right applies.
08
Mizan is not directed to children under 13, and we do not knowingly collect personal information from a child under 13 without authorization required by applicable law. We do not collect birth dates. If you are a parent or guardian and believe a child provided information improperly, contact us so we can investigate and delete it. Additional age or consent rules may apply in some countries.
09
Our service providers may process information in countries other than your own. Privacy and data-protection laws can differ between countries. Where required, we use appropriate contractual or legal safeguards for international processing.
10
We may update this policy when Mizan's features, providers, or legal obligations change. We will post the revised version here, update the effective date, and provide additional notice in the app when a material change requires it. Previous versions remain available through this site's public Git history.
11
For privacy questions, rights requests, or account-deletion assistance:
Mizan — Omar El MokademFor troubleshooting, safety reports, community rules, and appeals, visit the Mizan Support page.