Privacy Policy
Effective Date: February 24, 2026
Last Updated: February 24, 2026
Hikayat Diri ("the App") is operated by Syed Mohamad Arif Bin Sayed Mohd Ali Saipuddin ("we", "us", or "our"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data.
Your spiritual data is an amanah (trust). We treat it with the respect it deserves. We do not sell your data. We do not serve ads. We do not target your spirituality for profit.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Password (encrypted and hashed — we cannot read it)
- Display name
If you sign in with Google OAuth, we receive your email address and display name from Google.
1.2 User-Generated Content
As you use the App, we store:
- Habits: Names, types, prayer block assignments, completion logs, streak data
- Niyyah (Intentions): Daily intention text
- Muhasabah (Reflections): Weekly reflection answers
- Dhikr: Counter sessions and history
- Quran Bookmarks: Last read position and saved surahs
- Tadabbur Insights: AI-generated insights and follow-up conversations (Premium)
1.3 Location Data
We request your location (GPS) to determine your JAKIM prayer time zone and calculate the Qiblah direction. This data is:
- Used locally to fetch accurate prayer times for your zone
- Stored as latitude/longitude and city name in your profile for convenience
- Never shared with third parties for advertising
You can choose to manually select your prayer zone instead of providing GPS access.
1.4 Technical Data
We automatically collect:
- Device type and operating system version
- App version
- Push notification tokens (if notifications are enabled)
- IP address (for approximate country detection only)
- Crash reports and error logs
1.5 Analytics Data
We use Firebase Analytics to understand how the App is used. This includes:
- Screen views (which screens are visited)
- Feature usage events (e.g., habit completion, niyyah saved)
- Subscription events (trial started, upgraded, cancelled)
Analytics data is aggregated and does not include the content of your habits, niyyah, or reflections.
2. How We Use Your Data
We use your data exclusively to:
- Provide and maintain the App's services
- Sync your data across devices via your account
- Calculate prayer times and Qiblah direction based on your location
- Generate personalized Tadabbur AI insights (Premium — based on your habit patterns)
- Send push notifications (prayer reminders, habit reminders)
- Improve the App through aggregated analytics
- Diagnose and fix technical issues via crash reports
- Manage your subscription
3. What We Do NOT Do
- We do not sell your personal data to anyone
- We do not serve advertisements in the App
- We do not share the content of your habits, niyyah, or reflections with any third party
- We do not use your spiritual data for marketing targeting
- We do not profile you for purposes beyond providing App features
4. Third-Party Services
The App integrates with the following third-party services, each governed by their own privacy policies:
- Supabase — Authentication and database storage. Data stored securely with TLS/HTTPS encryption, hashed passwords, and Row Level Security.
- Firebase (Google) — Analytics, crash reporting (Crashlytics), remote configuration, and push notifications.
- RevenueCat — Subscription management. Processes subscription status only; does not access your habits or personal content.
- Google Sign-In — OAuth authentication. We receive only your email and display name.
- waktusolat.app — JAKIM prayer times API. We send your zone code (not precise location) to retrieve prayer times.
5. Data Storage and Security
- Your data is stored securely on Supabase servers
- All data is transmitted via TLS/HTTPS encryption
- Passwords are hashed — we cannot read them
- Row Level Security (RLS) ensures you can only access your own data
- Authentication tokens are stored securely on your device using platform-specific secure storage
6. Data Retention
- Your account data is retained for as long as your account is active
- Analytics data is retained per Firebase's default retention policies
- Crash logs are retained for 90 days
- Upon account deletion, all your personal data is permanently removed
7. Your Rights
You have the right to:
- Access your data: View all your habits, niyyah, reflections, and profile information within the App
- Update your data: Edit your profile, habits, and content at any time
- Delete your account: Permanently remove all your data through Settings > Profile > Delete Account
- Opt out of notifications: Disable push notifications in your device settings or within the App
- Withdraw location permission: Revoke GPS access through your device settings at any time. You can manually select your prayer zone instead.
8. Children's Privacy
Hikayat Diri is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the App or by email. Continued use of the App after changes are posted constitutes acceptance of the updated policy.
10. Data Sharing
We may share your data only in the following circumstances:
- Legal compliance: When required by Malaysian law or a valid legal process
- Business transfer: In the event of a merger or acquisition, with prior notice to affected users
- Service providers: With the third-party services listed in Section 4, strictly for providing App functionality
11. Contact
For questions, concerns, or data requests regarding this Privacy Policy, contact us at:
Syed Mohamad Arif Bin Sayed Mohd Ali Saipuddin
Email: hikayatdaily.app@gmail.com