Version 1.0 · Last updated 2 October 2026
Applies to the Maalin iPhone app and the website at maalin.app.
Our promises
- Your data is yours. It lives on your phone, and a locked copy is kept with your account, so a new phone can get it back.
- Only you can read it. Your data is encrypted on your phone before it’s synced. We store it locked and can’t open it. Only your passkey or your recovery kit can bring it back.
- We never sell your data or use it for ads. It’s shared with another company only when you turn on a feature that needs it, and we name the company first.
- You can see, export and delete everything, including what Maalin has learned about you, at any time.
- No tracking in the app. No advertising or tracking companies’ code in the app. We count how the app is used without knowing who you are, you can turn that off, and anything more is your choice.
Nobody, Maalin included, can open your data without your passkey or your recovery kit. If you lose both, your data can’t be recovered by anyone. Section 15 explains what happens then.
The short version
| Where your data goes | What | Can Maalin read it? |
|---|---|---|
| Never leaves this iPhone | Your calendar, your voice recordings, meal photos while they’re read, the weather on your phone, and all of Maalin’s thinking: suggestions, patterns, prayer times and AI | No. It never reaches us |
| Locked with your account | Everything you log and everything Maalin learns: health, faith, spending, places, notes, settings | No. It’s encrypted on your phone first, and we hold no key |
| To run your account | Your sign-in identifier and email, your list of devices, and short server logs | Yes, only to run your account and keep it safe |
| Sent without your name | Anonymous counts of which screens are used; the city sent to Apple for the weather | There’s nothing to link back to you |
| Only if you turn it on | Anonymous weekly usage trends; place suggestions | Trends: only as anonymous totals. Places: no, they’re locked with your account |
On our website, maalin.app, analytics and advertising tools run only if you agree to them (section 8a).
The rest of this policy gives the details.
1. Who we are
Maalin is made by Maalin Technologies Ltd (“Maalin”, “we”, “us”), a company being registered in England and Wales (its company number and registered office will be added here once registration completes), with its head office in Nairobi, Kenya. Our team works from Kenya.
We decide why and how your personal data is used, so we’re the “controller” under data protection law. Our home law is the UK GDPR.
You can reach us at one address, company@maalin.app, for everything. Please use a subject line, so your message reaches the right person quickly:
- “Data request”: privacy questions and requests about your data
- “Health data request”: requests under our Consumer Health Data Policy
- “Appeal”: if we turned down a request and you want us to look again
- “Security”: security reports
- “Press”: press and media
For help with the app, write to the same address.
- Our representative in the European Union (GDPR Art. 27): we have not yet appointed an EU representative; contact company@maalin.app. We appoint one before anyone in the EU can create an account.
2. Who can use Maalin
Maalin is for people aged 18 and over.
When you first open Maalin, it asks your age before anything else. If you’re under 18, Maalin stops. Nothing you entered is stored or sent, not even anonymous counts, so you’ll be asked again the next time you open it. Where your iPhone shares an age range through Apple (Declared Age Range), Maalin uses the stricter of the two answers.
If you think someone under 18 has an account, write to company@maalin.app with the subject “Data request” and we’ll delete it.
3. What Maalin keeps, and where
Maalin is built to work on your phone. Everything is worked out there: suggestions, patterns, prayer times, insights and AI. Our server never calculates anything from your personal data.
3.1 On your iPhone
Maalin keeps these on your phone, in its own storage protected by iOS:
- Health: sleep, steps and distance, heart data (resting heart rate, heart rate variability, VO₂ max), activities and workouts, body measurements, meals and nutrition, water, mood, energy and sleep check-ins, and readiness. Maalin reads Apple Health when it needs to and keeps only the daily summaries it uses. It doesn’t copy your Apple Health history.
- Faith: your prayer log and prayer settings, religious habits (for example Qur’an reading), fasting windows and protected times for prayer.
- Spending: amounts, currencies, places paid and payment methods. Maalin never stores a balance.
- Places and location: the city you picked for prayer times and the weather (or a rounded location), places you log, and routes you chose to save.
- Your profile and safety profile: birth year, sex (optional), height, goals, age band, and if you’re pregnant or breastfeeding or use a wheelchair (all optional).
- Your schedule: day types, wake times, work hours, protected times, activity plans and meal times.
- What Maalin learned: your usual times, meals, places, prices and patterns.
- Notes you type, and your settings.
- Consent records: what you agreed to, which version of the text, and when. Like everything here, they’re locked with your account, so we can’t read them.
3.2 Locked with your account
Everything in 3.1 is encrypted on your phone and then synced to your account on our server. That’s how a new or reset phone gets your data back.
- Each record is locked with a key made on your phone, before it leaves.
- Our server stores only the locked copy. It sees a random ID for each record, the hour it was uploaded, which key version locked it, and its size rounded up to a standard size. It can’t see what kind of record it is, when you logged it, or what’s inside.
- Your key is itself locked by your passkey and by your recovery kit. We keep only those locked copies. We can’t open them.
Health and faith data are sensitive data under the law. We need your explicit consent to keep even a locked copy of them. Section 5 explains that consent.
3.3 What we can read: to run your account
To run your account and keep it safe, our server holds some data we can read:
-
Your sign-in: an account ID, how you sign in (Apple, Google or email), and the identifier Apple or Google gives us for you. We also keep your email address: the one you typed, or the one Apple or Google shares when you sign in. If you use Apple’s “Hide My Email”, it’s a relay address and we never see your real one. To limit how many sign-in emails an address gets, we keep a keyed hash of the address for about 1 hour after each sign-in email.
-
Your devices: a random ID for each device, its platform and app version, when it last synced, whether you marked it lost or stolen, and a push notification token. The name you give a device is encrypted, so we can’t read it.
-
Sessions: short-lived sign-in tokens for each device, so you can sign out one device at a time. When a token is replaced, or its device is removed or its account deleted, we keep only a hash of it for about 90 days, with nothing linking a deleted account’s hashes to it, so a stolen token is recognised.
-
Server logs: the time, which part of the server was used, whether it worked, and the size. For sync, the time is rounded to the hour and the size to its standard size. No record content and no plain sign-in identifiers are logged. Our server doesn’t store your internet (IP) address: to stop abuse, such as someone flooding an inbox with sign-in emails, it holds only a keyed hash of it, in memory, for at most 70 seconds.
-
Your WhatsApp number, only if you add one (section 3.5a).
We use this data only to sign you in, sync your devices, send the emails, notices and messages in sections 3.5 and 3.5a, and protect your account.
3.4 What never leaves your iPhone
- Your calendar. Maalin reads only each event’s start, end and whether it marks you busy, to plan around your time. It never reads places, attendees or notes, and never stores or sends anything from your calendar. Event titles are shown only if you turn on “Show event titles” (off by default). Titles stay in your phone’s memory while that’s on, and they never appear in widgets or notifications or shape a suggestion. A title can name other people; with titles off, Maalin handles no data about the people in your events.
- Your voice. Speech is turned into text on your iPhone. The audio isn’t kept.
- Photos. A meal photo is read on your iPhone and then deleted. Maalin never keeps, syncs or sends it; only the meal you confirm is saved.
- Face ID and Touch ID. Apple handles them. Maalin only learns whether it worked.
- Apple Health readings Maalin doesn’t need to keep. It reads them when it shows them.
- The weather on your phone, until the forecast expires.
3.5 Emails and notifications we send
- Sign-in email (if you sign in with email): a one-time link and a 6-digit code, valid for 15 minutes and usable once. If you turned on WhatsApp sign-in codes, the same code also goes to WhatsApp (section 3.5a).
- Security notices, by email and as a notification on your other devices: a device was added to your account; your account will be reset or deleted in 7 days. The notification says only which notice it is, with no names, dates or account details.
- Sync notices: silent pushes with no content, so your devices know to sync.
We don’t send marketing emails or newsletters. News on WhatsApp comes only if you turn it on (3.5a). Emails have no tracking pixels and no tracked links.
3.5a WhatsApp, if you add your number
Adding a phone number is optional, and you never need one to use Maalin. You can add it after you’ve set up the app, in You → Account and sync. We send a code to WhatsApp to confirm it’s your number.
You then choose what we may send there. There are three separate choices, and each is off until you turn it on:
- Sign-in codes and security alerts, such as a new device on your account. When this is on, each sign-in code goes to both your email and WhatsApp. It’s the same code, it lasts 15 minutes, and wrong tries on either count towards one shared limit. The code message is in English, because WhatsApp doesn’t support Somali for it.
- Reminders.
- News and offers about Maalin.
Our messages come from +252 61 088 4141. Meta Platforms delivers them through the WhatsApp Business Platform (section 9).
What we keep: your phone number (encrypted on our server, with a keyed hash so we can find it), when you confirmed it, your three choices with when you made them and which version of the text you saw, and whether each message was sent, delivered or failed. We don’t keep what the messages said. We never send any health information by WhatsApp.
You can turn any choice off in You → Account and sync, or reply STOP (or JOOJI) to one of our messages. You can remove your number there at any time (section 14).
We plan a separate WhatsApp number for support chats. Those chats go through Meta, so please don’t send health details there.
3.6 Sent without your name
- Anonymous counts of how the app is used (section 8).
- The weather. While Maalin is open, at most once an hour, your picked city or rounded location goes to Apple’s WeatherKit, with no Maalin account or device ID. Apple says it doesn’t link this location to anyone.
3.7 Only if you turn it on
- Usage trends (section 8): off by default.
- Place suggestions: when you log, your phone notes the place’s approximate location once, so Maalin can suggest the place next time. It’s locked with your account. It uses iOS’s location permission, only while the app is open, never in the background.
- Show event titles and Show numbers on the lock screen (section 10).
4. Why we use your data, and our legal basis
This table is for people in the EU and UK, where the law asks us to name a legal basis for each use. We apply the same rules everywhere.
| What we do | Data | Legal basis (GDPR and UK GDPR) |
|---|---|---|
| Create and run your account, sign you in, sync your devices | Account data (3.3) | Art. 6(1)(b): needed to provide the app you asked for |
| Keep the locked copy of your health and faith data, so a new phone can get it back | Encrypted records (3.2) | Art. 9(2)(a): your explicit consent at sign-up (section 5), with Art. 6(1)(a) |
| Keep the locked copy of your other data (spending, places, schedule, settings) | Encrypted records (3.2) | Art. 6(1)(b): needed to provide sync and restore |
| Send sign-in emails, security notices and sync notices | Email address, push tokens | Art. 6(1)(b); for security notices also Art. 6(1)(f), our legitimate interest in protecting your account |
| Keep short server logs and stop abuse | Server logs; a keyed hash of your IP address, for at most 70 seconds | Art. 6(1)(f): keeping the service and your account secure |
| Count how the app is used, anonymously | Anonymous counts (section 8) | Not personal data once sent, because it carries no identifier. Collecting it on your phone relies on Art. 6(1)(f) and the audience-measurement exemption to consent for device storage |
| Usage trends | Anonymous weekly counts (section 8) | Art. 6(1)(a): your consent, when you turn it on |
| Place suggestions | Approximate location of places | Art. 6(1)(a): your consent, when you turn it on |
| Keep records of what you agreed to | Consent records | Art. 6(1)(c): our legal duty to show consent (Art. 7(1)) |
| Answer your requests, report breaches, meet legal duties | What the request or duty needs | Art. 6(1)(c) |
| Answer your support emails | Your email address and what you write | Art. 6(1)(f): our legitimate interest in answering you |
| Send sign-in codes and security alerts by WhatsApp, if you turn them on | Phone number, delivery status | Art. 6(1)(b): needed to provide your account |
| Send reminders by WhatsApp, if you turn them on | Phone number, delivery status | Art. 6(1)(a): your consent |
| Send news and offers by WhatsApp, if you turn them on | Phone number, delivery status | Art. 6(1)(a): your consent |
| Run the website maalin.app | Your IP address and the pages you ask for, in Cloudflare’s logs | Art. 6(1)(f): keeping the website working and secure |
| Count website visits without cookies (Cloudflare Web Analytics), and Cloudflare’s security cookie when needed | Pages viewed, referrer, country | Art. 6(1)(f): running a working, secure website |
| Website analytics and advertising tools (section 8a) | What the tools collect on maalin.app | Art. 6(1)(a): your consent in the cookie banner; for the cookies, also PECR and the ePrivacy rules |
Maalin makes no decisions about you that have legal or similarly significant effects (GDPR Art. 22). Suggestions are suggestions, and you decide.
5. Your consent at sign-up
When you create an account, Maalin asks you to agree once, on the step where you create a passkey. There are two parts.
1. Your consent to keep your health and faith data. An unticked line, separate from the Terms:
I agree that Maalin keeps my health and faith data encrypted on its EU servers, so I can get it back on a new phone. I can withdraw by deleting my account.
Its link, “What’s included”, opens the list of data in our Consumer Health Data Policy. The consent covers everything you log and everything Maalin learns from it, including inferences such as readiness and patterns, stored in locked form on our servers in the EU (section 9).
2. The agreement line, directly above the button:
By tapping Create a passkey, you agree to the Terms of use and confirm you’ve read the Privacy Policy and Consumer Health Data Policy.
Nothing is ticked for you. Maalin records the time and the version of each text before your first sync, and keeps that record with your account. It’s included when you export your data.
Withdrawing. Maalin keeps your data with your account so it’s never lost with a phone. It can’t work without that. So you withdraw this consent by deleting your account (section 14). Every other consent is a switch you can turn off at any time.
6. How we use AI
AI turns a photo, something you said or something you typed into a log, and you check it before it’s saved. It also puts Maalin’s numbers into short sentences, like the reason under a suggestion.
It doesn’t decide what Maalin suggests. Suggestions come from fixed rules that are tested. It doesn’t make up numbers: every number it writes is checked against Maalin’s own, and a pre-written sentence is used if they differ.
It runs on this iPhone. Nothing is sent anywhere for AI. Speech is turned into text on this iPhone, and the audio isn’t kept. A meal photo is read on this iPhone and then deleted.
Speaking a log works in English. In Somali, you type.
On iPhones without Apple Intelligence, or with AI turned off, Maalin uses its own word matching and pre-written sentences, and asks you to describe a photo.
Short texts written by AI (the morning brief, the evening wrap-up, reasons and takeaways) are generated automatically from Maalin’s own numbers. Anything AI estimates, such as a meal from a photo, is tagged “Estimated” until you confirm it.
You can turn AI off in Privacy and data, with the switch “Use AI to understand photos and speech”. The switch also covers the short sentences AI writes: with it off, Maalin uses pre-written sentences.
7. What each permission reads, and why
Maalin asks for each permission with iOS’s own prompt, at the moment a feature needs it, and asks for the least access. Every feature works without it.
| Permission | What Maalin reads | Why |
|---|---|---|
| Apple Health (read) | Only the types your switched-on areas need: for example sleep, steps, heart data, workouts, body measurements, nutrition from other apps, and mood | To fill in your day without typing, and to learn your usual patterns. Maalin reads up to 90 days of history once, on your phone |
| Apple Health (write) | Meals, water, body measurements, sleep check-ins, mood check-ins (as State of Mind) and activities you record with your iPhone | So your other health apps see them too, only for the types you allowed |
| Calendar | Each event’s start, end and busy or free; titles only if you turn them on | To plan around your busy times (section 3.4) |
| Location, approximate, while using the app | Your rounded location, when the app opens | Prayer times and the weather, if you don’t pick a city; place suggestions, if you turn them on. Never in the background |
| Precise location, once | Your route during an activity you record | Only if you turn on “Record route”. The route is kept only if you save it |
| Motion and fitness | Steps and movement from your iPhone | When no watch or other device provides them |
| Camera | The meal photo you take | To read what’s on the plate, on your phone |
| Microphone and speech recognition | What you say when you log by voice | Turned into text on your phone; the audio isn’t kept |
| Face ID or Touch ID | Nothing. Apple checks it | To lock the app, and to confirm stopping a reset or a deletion |
| Notifications | Nothing | To send reminders and notices |
Why Maalin asks about your safety. The optional safety profile (pregnant or breastfeeding, wheelchair user) and your age band are used only by Maalin’s safety rules, on your phone, to keep suggestions safe for you. For example, if you’re pregnant or breastfeeding, Maalin suggests no calorie cuts, fasting or hard activity; if you use a wheelchair, it counts pushes instead of steps.
8. Measuring the app without tracking you
We want to know which parts of Maalin help people, without knowing who you are. There are two kinds of measurement, and neither ever contains your health, faith or spending.
On by default:
- Apple’s App Analytics. Apple shows us installs, sessions and how many people come back, only from people who agreed to share with app developers in their iPhone’s settings. Apple collects this, not Maalin.
- Crash and performance reports from Apple (MetricKit and Xcode Organizer), again only if you agreed in your iPhone’s settings.
- Maalin’s anonymous counts: which screens and features are used, the app and iOS version, and sessions without a crash. They carry no user ID and no device ID, and Maalin never stores your IP address with them or uses it to count (section 12). Screens of a health or faith area are counted only as “a module screen”, never by which one. Counts are sent in batches, so their timing can’t point to you. You can turn them off in You → Privacy and data.
Nothing is counted or sent until you’ve answered the age question and agreed at sign-up.
Only if you turn it on:
- Usage trends: weekly counts worked out on your phone, for example “logged on 5 of 7 days” or “notifications turned off”. Random noise is added on your phone before anything is sent, and results are only ever looked at for groups of 20 people or more. Maalin asks once, after your first week, and you can turn it on or off in You → Privacy and data. It’s off unless you turn it on.
We keep anonymous counts and trends as statistics. They carry nothing that could link them to you, and we don’t try to.
There are no ads, no advertising IDs and no analytics or tracking code from other companies in Maalin.
8a. Our website
This section is about the website maalin.app, for visitors anywhere in the world. The website is separate from the app.
We never use what you put into the Maalin app for advertising.
Always on. Cloudflare hosts the website. We count visits with Cloudflare Web Analytics, which uses no cookies, stores nothing in your browser and doesn’t use your IP address to recognise you. It tells us page views, which pages, the site that sent you and your country. Cloudflare may also set a security cookie (__cf_bm, 30 minutes), only when it’s needed to protect the site from bots.
Your choice. A banner asks you first, with two separate choices, Analytics and Advertising. “Accept all”, “Reject all” and “Choose” are equally easy, and nothing is ticked for you. You can change your choice any time with “Cookie settings” at the bottom of every page. If your browser sends Global Privacy Control or Do Not Track, we treat it as “Reject all”. We keep your choice in a cookie on maalin.app (maalin_consent) for 6 months, and ask again after that, or sooner if we add a tool or a purpose.
Until you choose, nothing from Google loads: we use Google Consent Mode v2 in its basic form, with every setting off, and no data is sent to Google before you agree.
If you choose Analytics, Google Analytics shows us the pages you view, how far you scroll, clicks on the App Store button and other links, the campaign that brought you, your type of device and browser, and your approximate location from your IP address. Google keeps this data for 14 months, and any audience built from it (for example, everyone who visited the site) lasts at most 14 months too.
If you choose Advertising, these tools measure our ads and can show them to people who visited the site. Each company may link your visit to an account you have with it:
- Google Analytics’ advertising features and Google Ads
- the Meta Pixel (Facebook and Instagram)
- the TikTok pixel and the LinkedIn Insight Tag, when we turn them on
No health data on the website. The website has no account and no forms, and collects no health data. The tools see only that someone visited maalin.app and what they clicked. We never build advertising audiences around health conditions, ever. Our lists are general, such as everyone who visited, or visitors who did or didn’t tap the App Store button.
App Store links on the website carry a campaign code, which tells Apple which page a download came from. Apple reports these to us only as totals.
The names of every cookie, who sets it and how long it lasts are in our Cookie notice, at maalin.app/cookies. Who these companies are, and their roles, are in section 9.
9. Who handles your data
We don’t sell your data, and we never share what you put into the app for advertising. These companies handle some data for us, provide services your iPhone uses, or run tools on our website:
| Company | What it does for Maalin | What it can see | Where |
|---|---|---|---|
| Scaleway SAS (France) | Hosts our server, database and backups | Your locked records (it can’t open them), your account data and server logs | Paris, France (EU) |
| Hetzner Online GmbH (Storage Box, Germany) | Keeps an encrypted copy of our database, made each night, as a second backup | Nothing readable: the copy is encrypted before it’s sent, and your records inside it are locked too | Germany (EU) |
| Scaleway SAS, Transactional Email (France) | Sends sign-in emails and security notices | Your email address and the email’s content (a sign-in code or a notice) | France (EU) |
| Cloudflare, Inc. (United States) | Hosts our website and these policy pages (Cloudflare Pages) | Your IP address and the pages you ask for, when you visit the website | Cloudflare’s global network |
| Google LLC (Google Workspace; Google Ireland Limited for people in the EU and UK) | Holds our mailbox, company@maalin.app | Your email address and what you write | Google’s data centres |
| Apple | Sign in with Apple, push notifications, WeatherKit, App Store and App Analytics, iCloud Keychain for your passkey. Apple Health, Face ID and on-device AI run on your iPhone | For sign-in: your Apple identifier and email. For the weather: a city or rounded location, with no account. For push: a device token. Your passkey is kept by iCloud Keychain or your password manager, not by Maalin | Apple’s services |
| Sign in with Google, if you choose it (identity only) | That you signed in to Maalin, and the identifier and email it shares with us | Google’s services | |
| Meta Platforms (WhatsApp Business Platform; Meta Platforms Ireland Limited for people in the EU and UK) | Delivers our WhatsApp messages, if you add your number (section 3.5a) | Your phone number and the message. Meta may keep the message for up to 30 days to deliver it | Meta’s services |
| Google (Google Analytics, Google Ads; Google Ireland Limited for visitors in the EU, UK and Switzerland) | Website measurement, with Analytics consent; advertising features and Google Ads, with Advertising consent (section 8a) | What the tools collect on maalin.app: pages, clicks, device and browser, approximate location, cookie IDs | Google’s services, including the United States |
| Meta Platforms (Meta Pixel; Meta Platforms Ireland Limited for visitors in the EU, UK and Switzerland) | Measures and shows our ads, with Advertising consent | Your visit to maalin.app, what you clicked, cookie IDs | Meta’s services, including the United States |
| TikTok (TikTok pixel; TikTok Technology Limited, Ireland, for visitors in the EU, UK and Switzerland) | Measures and shows our ads, with Advertising consent, when we turn it on | Your visit to maalin.app, what you clicked, cookie IDs | TikTok’s services, including the United States |
| LinkedIn (Insight Tag; LinkedIn Ireland Unlimited Company for visitors in the EU, UK and Switzerland) | Measures and shows our ads, with Advertising consent, when we turn it on | Your visit to maalin.app, what you clicked, cookie IDs | LinkedIn’s services, including the United States |
Scaleway and Hetzner handle data only on our instructions, under a data processing agreement (GDPR Art. 28). Cloudflare does too, for the website, its cookieless analytics and the inboxes, and so does Meta Platforms for our WhatsApp messages. We may use a WhatsApp Business Solution Provider to pass messages to Meta; we’ll name it here before we use it. Apple and Google provide sign-in and other services under their own privacy policies, as independent companies. Maalin has no Google code in the app: signing in with Google happens in a secure web sheet, and we keep no Google token.
On the website, Google handles Google Analytics measurement for us, as our processor. For Google’s advertising features and Google Ads, the Meta Pixel, the TikTok pixel and the LinkedIn Insight Tag, the company and Maalin decide together how data is collected on maalin.app and sent to it, so we’re joint controllers for that collection. Each company then uses the data under its own privacy policy, as an independent controller. Outside the EU, UK and Switzerland, these are the companies’ US or local companies.
Maalin uses no cloud AI at launch. If we add a feature that sends any of your data to another company, it will be off until you turn it on, and Maalin will name the company first.
If a court or authority asks. We can hand over only what we can read (section 3.3). We can’t open your locked data, so we can’t hand it over in readable form. We tell you about a request unless the law forbids it.
10. Your lock screen and notifications
- Notifications and widgets show no health facts, in numbers or words, unless you turn on “Show numbers on the lock screen”.
- A prayer or fast is named on the lock screen only in what you turned on for it: prayer reminders, a prayer widget you placed, or “Next prayer on the lock screen”. Everything else names a time instead.
- Siri may name a prayer in its answer, because Maalin answers only after your phone is unlocked.
- When Maalin goes to the background, its screen is covered so the app switcher shows nothing personal.
- Maalin never adds your logs to Spotlight search.
11. Where your data is stored and sent
Maalin Technologies Ltd is a UK company with its head office in Kenya. Your locked data and your account data are stored on Scaleway’s servers in Paris, France, in the European Union. An encrypted backup copy is kept with a second provider, Hetzner, in Germany, also in the EU.
Our team works from Kenya. To run accounts, they can reach the account data in section 3.3 from there. They can’t read your locked records: only you can. We protect this access with the UK and EU standard contractual clauses (for UK data, the UK International Data Transfer Agreement or Addendum).
Some data also passes through other countries:
- Cloudflare (United States) serves our website and forwards emails to our inboxes. It runs a global network, so your request may be handled outside your country.
- Apple and Google handle sign-in, push notifications and the weather under their own terms, which may involve the United States.
- Meta Platforms delivers our WhatsApp messages, if you add your number, and may handle them outside your country.
- Website tools from Google, Meta, TikTok and LinkedIn (section 8a), if you agree to them, may send data to the United States. They rely on the EU–US Data Privacy Framework (and its UK extension) or on standard contractual clauses.
Where the law requires it, we protect data sent abroad with safeguards such as the European Commission’s Standard Contractual Clauses.
In some countries, local law limits sending health data abroad. Until we’ve confirmed the rules there, Maalin may not sync in that country, and keeps everything on your phone instead. Maalin uses the region you choose when you set it up.
12. How long we keep it
| Data | Kept for |
|---|---|
| Your logs, daily summaries and what Maalin learned (on your phone and locked with your account) | Until you delete them or your account |
| Suggestions and what you did with them | 180 days on your phone, then only as a summary in your patterns |
| Voice recordings | Not kept. Deleted once turned into text |
| Meal photos | Not kept. Deleted once read |
| Calendar data | Never stored |
| Weather on your phone | Until the forecast expires; never synced |
| Something you deleted | Gone from the app at once, and its locked copy is gone from our server within 30 days. A small marker with no content tells your other devices to delete it too, and is removed once they have, 90 days at most |
| Your account data (section 3.3) | As long as you have an account |
| Your passkeys’ public data (never the passkey itself) | Until you remove that passkey, or your account |
| Devices and their push tokens | Until you remove the device, or Apple tells us the token no longer works |
| Sign-in codes and links | 15 minutes, and usable once |
| A keyed hash of your email address, to limit sign-in emails | About 1 hour |
| Sign-in tokens that were replaced, or belong to a removed device or a deleted account (only as hashes, so a stolen one is recognised) | About 90 days |
| Server logs | 30 days |
| IP addresses | Our server: only a keyed hash, in memory, for at most 70 seconds, to stop abuse; never for anonymous counts |
| Server backups, at Scaleway and at Hetzner (the second backup provider) | Encrypted, and deleted after 30 days |
| After you delete your account | Removed from our live server at once, and from backups within 30 days. Only the hashes of your devices’ sign-in tokens stay, for about 90 days, with nothing linking them to you (see above) |
| Consent records | As long as you have an account |
| Emails you send to our inboxes | 12 months after your question is answered, then deleted |
| Emails we send, in Scaleway’s logs | As long as Scaleway’s email service keeps its logs |
| Website visit logs at Cloudflare | As long as Cloudflare’s own retention rules set |
| Your WhatsApp number, your three WhatsApp choices and delivery status (section 3.5a) | Until you remove the number or delete your account |
| WhatsApp messages at Meta | Up to 30 days, to deliver them. We keep no message content |
| Website data in Google Analytics | 14 months |
Your cookie choice on the website (maalin_consent) |
6 months |
| Advertising cookies on the website | As set out in our Cookie notice: for example 90 days for Meta’s _fbp and _fbc and Google Ads’ _gcl_au, 13 months for TikTok, and 1 day to 1 year for LinkedIn |
Cloudflare’s security cookie (__cf_bm) |
30 minutes |
| Anonymous counts and usage trends | Kept as anonymous statistics |
Accounts nobody uses. We never delete or close an account because it hasn’t been used, and we don’t send emails about it. Your data stays until you delete it or your account.
13. Your rights, and how to use them
You can do almost everything yourself in the app, at any time. Your data is locked with your key, so in most cases the app is the only place it can be read, exported or corrected.
| You want to | How |
|---|---|
| See what’s kept | This policy says what and where. You → Privacy and data → What Maalin learned shows what Maalin has learned about you |
| Get a copy | You → Privacy and data → Export: everything as JSON and CSV in one tap, consent records included. You can take it to another app, or import it into Maalin again |
| Correct something | Edit any log, setting or learned value in the app |
| Delete something | You → Privacy and data → Delete data: one area’s data, one day, what Maalin learned (learning then starts again from new logs only), or everything |
| Delete your account | You → Account and sync → Delete account (section 14) |
| Change your mind | Turn off any permission, switch or connection in the same place you turned it on. The one exception is the consent at sign-up, which you withdraw by deleting your account |
| Object to the anonymous counts | Turn them off in You → Privacy and data |
| Ask us anything | Write to company@maalin.app with the subject “Data request” |
If you write to us, we reply within 14 days and answer your request within 30 days, or sooner where a law requires it. We may ask you to confirm the request from the app or from your account’s email, so we don’t act on someone else’s request. We can act on the account data we can read (section 3.3). For your locked data, we’ll point you to the app, because only you can open it. If we turn down your request, you can ask us to look again: write with the subject “Appeal”.
Depending on where you live, you may also have the right to restrict how we use your data, and the right to complain to a data protection authority (section 18). People in some US states have more rights, described in section 17 and in our Consumer Health Data Policy. Using any of your rights never changes how Maalin treats you.
14. Deleting your data and your account
Deleting everything (You → Privacy and data → Delete data → Everything) removes all your data on every device and in your account. Your settings, your consent records and your account stay, and you stay signed in.
Removing your WhatsApp number. You can remove it at any time in You → Account and sync. It’s deleted from our server at once, along with your WhatsApp choices. It’s also deleted with your account.
Deleting your account (You → Account and sync → Delete account):
- Export your data first if you want a copy. Maalin offers this on the same page.
- Confirm with your passkey. If you use Sign in with Apple, you sign in with Apple once more, so we can revoke Maalin’s access with Apple.
- At once: the locked copies of your key are deleted, so nothing on our server can be opened any more. Your records and account data are deleted from our live server.
- Within 30 days: they’re gone from our backups too, which are deleted after 30 days.
- If you use Sign in with Apple, Maalin’s access is revoked with Apple. We keep no Apple token, which is why step 2 asks you to sign in with Apple again.
- If you signed in with Google: we keep no Google token, so there’s nothing to revoke, and your Google ID is erased. To remove Maalin from your Google account as well, go to your Google Account → Security → “Your connections to third-party apps and services”, choose Maalin and remove the connection.
- Maalin removes its data from your iPhone and returns to the first step. Your other iPhones that are still signed in remove Maalin’s data and keys too, the next time they connect within 90 days.
If you have no passkey, you can still delete your account, after a 7-day wait:
- Every device on your account and your account’s email are told the date.
- Your account is deleted within a day after that date, so a phone still signed in can finish the Apple step; until then “Stop the deletion” cancels it. It’s in You → Account and sync, and asks for your iPhone’s Face ID, Touch ID or passcode, so someone holding a lost phone without your passcode can’t stop it.
- Your account is deleted as in steps 3, 4 and 6. If you use Sign in with Apple and one of your phones is still signed in, Maalin asks it for a quick Apple sign-in on the date, so we can revoke Maalin’s access with Apple. If none is, or that sign-in isn’t completed, your account is still deleted, and you can remove Maalin yourself in your Apple Account settings, under Sign in with Apple; the email on the deletion date says so too.
Signing out removes your keys and the copy of your data from that phone. The locked copy stays with your account. Maalin warns you first if anything hasn’t synced yet.
15. If you can’t sign in: the 7-day reset
Nobody, Maalin included, can open your data without your passkey or your recovery kit.
- Your passkey signs you in and, on most iPhones, unlocks your data on a new phone.
- Your recovery kit is a code shown once, when you set up your account. It unlocks your data on any phone. Keep it on paper or in a password manager.
If you lose every passkey and your recovery kit, your data can’t be recovered by anyone. You can then only reset your login to an empty account:
- The reset happens 7 days after you ask. Every device on your account and your account’s email are told.
- Until then, any of your devices that can still unlock your data cancels the reset by itself. You can also cancel it by unlocking with a passkey or your recovery kit, or with “Stop the reset” in You → Account and sync on a phone that’s still signed in. “Stop the reset” asks for that iPhone’s Face ID, Touch ID or passcode, so a thief without your passcode can’t cancel your reset.
- When the reset happens, your old locked data, its keys and your passkeys are deleted from our live server at once, and from backups within 30 days, as when you delete your account. Your other devices are signed out and erase their Maalin data. You keep your sign-in methods (Apple, Google or email) and start again with an empty account.
The 7-day wait gives you time to notice a reset or deletion you didn’t ask for, for example if someone took over your email.
16. How we keep your data safe
- Encrypted on your phone. Your data is locked with a 256-bit key made on your iPhone (AES-GCM, using Apple’s CryptoKit). The key is itself locked by your passkey and by your recovery kit. Our server stores only locked copies and can’t open them.
- Protected in transit. Maalin talks only to our own server, Apple’s services and, if you choose it, Google’s sign-in page, over encrypted connections (TLS 1.3, never below 1.2), and checks it’s really talking to our server.
- Protected on your phone. Maalin’s data uses iOS’s data protection. It isn’t included in iCloud or computer backups, because your account already keeps a locked copy. Keys stay in your iPhone’s Keychain and never leave that device in readable form. You can also lock the app with Face ID, Touch ID or your passcode.
- Hiding patterns. Our server sees only random record IDs, the hour of upload and rounded sizes, so the timing of your logs (for example around prayer times) can’t be read from it.
- Restoring on a new phone. Your data is unlocked only on that iPhone. Your other devices, and your account’s email, are told a device was added. If it wasn’t you, remove the device in You → Account and sync. Removing a device you mark as lost or stolen always makes a new key, so the old phone can’t read new data.
- Your recovery kit and iCloud Drive. iCloud Drive isn’t end-to-end encrypted unless you turn on Apple’s Advanced Data Protection. That’s why Maalin suggests keeping your recovery kit on paper or in a password manager instead.
- The remaining risk. Someone who controls your whole Apple account and knows the passcode of one of your trusted devices could reach passkeys in iCloud Keychain. Signing in alone never opens your data.
- A changed iPhone. If your iPhone’s security settings have been changed (for example, it’s jailbroken), Maalin shows one line at the top of Privacy and data, because data on it is less protected.
- Our side. Two-factor sign-in and hardware keys for our administrators, every administrative action logged, no real data in testing, and security tests before each release. The encryption and recovery design is reviewed independently before sync opens to testers.
If something goes wrong. If a breach affects your data, we tell the authorities within the time the law sets (72 hours in the EU, the UK and Somalia) and tell you plainly when the risk to you is high. Because your records are locked, a breach of our server could expose account data and metadata, never your health, faith or spending.
Found a security problem? Write to company@maalin.app with the subject “Security”.
17. Notice for people in the United States
- Not HIPAA. Maalin is an app you use directly. It isn’t a healthcare provider or health plan, so HIPAA doesn’t apply. This policy and our Consumer Health Data Policy do.
- Consumer health data. People in Washington, Nevada, Connecticut and other states with consumer health data laws: our Consumer Health Data Policy describes the health data Maalin handles and your rights over it. We apply it to everyone in the US.
- What we collect (the categories used by state privacy laws): identifiers (your sign-in identifier, email address, device IDs, and your phone number if you add one for WhatsApp); sensitive personal information (health data, religious beliefs, and precise location only if you save a route), all locked so we can’t read it; internet activity (server logs, kept 30 days and with no IP addresses: our server sees your IP address only as a keyed hash, in memory, for at most 70 seconds, to stop abuse; on the website, cookie IDs and what you view and click, only if you agree in the cookie banner); and inferences (Maalin’s patterns and readiness, worked out on your phone and locked with your account). Sources and purposes are in sections 3 and 4.
- No selling, no sharing for ads from the app. We don’t sell personal data. We don’t share anything from the app for cross-context behavioural advertising, and we don’t use it for targeted advertising or profiling with significant effects. We use sensitive data only to provide Maalin. On the website, advertising tools run only if you choose Advertising in the cookie banner, and Global Privacy Control counts as “Reject all” (section 8a).
- Your rights to know, get a copy, correct and delete are built into the app (section 13), whatever your state and whether or not a state law’s thresholds apply to us.
- Anonymous data. We keep anonymous counts in a form that can’t identify you, and we commit not to try to re-identify them.
18. Questions and complaints
Write to company@maalin.app (subject “Data request”). We reply within 14 days and answer a complaint within 30 days.
You can also complain to a data protection authority. Our regulator is the UK Information Commissioner’s Office, and you can always complain to the regulator in your own country instead:
- Our regulator: the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom (ico.org.uk).
- European Union: the data protection authority in the country where you live or work, or where you think the law was broken. The list is on the European Data Protection Board’s website (edpb.europa.eu).
- Somalia: for people in Somalia, the Data Protection Authority under the Data Protection Act 2023.
- United States: your state’s Attorney General (in Washington, the Attorney General’s Office enforces the My Health My Data Act), or the Federal Trade Commission.
- Elsewhere: your country’s data protection authority, for example Kenya’s Office of the Data Protection Commissioner.
19. Changes to this policy
When we change this policy, the new version gets a new number and date at the top. Earlier versions stay public at maalin.app/legal/history.
If a change matters to how your data is used, we tell you in the app and by email before it takes effect. If a change needs your consent again, for example a new use of your health or faith data, Maalin asks you, and nothing changes for you until you agree.
20. Words used in this policy
- Passkey: a way to sign in without a password, kept by iCloud Keychain or your password manager. In Maalin it also unlocks your data.
- Recovery kit: a code shown once at sign-up that unlocks your data on any phone.
- Locked, encrypted: turned into unreadable data that only your key can turn back.
- Sync: keeping the locked copy with your account up to date, so your devices match.
- Processor: a company that handles data only on our instructions.
Maalin gives general wellbeing guidance, not medical advice. Our Terms of use say more.