Privacy Policy (Draft)
Draft — not yet published
This is a starting draft, not a finished legal document. It has not been reviewed by a lawyer and should not be relied on as the app’s real Terms of Service or Privacy Policy until it has been — especially given the open questions about donations and children’s use of the app noted below.
1. Overview
This Privacy Policy explains what information the Minka Asalam app ("the App," "we," "us") collects, why, and how it is handled. The App does not run ads and does not sell your data.
2. Information We Collect
Account information: if you sign up with email and password, we store your email address and an encrypted password via our database provider, Supabase. If you use guest mode, no email address is collected at all.
Birthdate (self-reported, not verified): asked at sign-up or guest entry to route you to age-appropriate content. If you report being 13 or older, we also collect gender. If you report being under 13, nothing is stored: no account or guest session is created — see "Children’s Privacy" below for how a child uses the App through a parent.
Birthdate, gender, and whether an account is a child account are never shown publicly, and — unlike most of your profile — can’t even be read back by your own account through the App; they’re locked down at the database level specifically to limit who can see them.
Profile information: display name, a short bio, and a profile photo, if you choose to add them.
Content you create: comments you post, content you like, people and scholars you follow, content you bookmark, and any content reports you file.
Safety information: a list of accounts you have chosen to block.
Donation records: if you make a donation (see note below — no live payment collection is connected yet), a record of the intended amount and recipient (pooled, or a specific scholar).
We do not collect payment card details ourselves. If real payment processing is added in the future, it will be handled by a dedicated payment processor and this policy will be updated to name it.
3. How We Use Your Information
To operate your account, show your comments, likes, follows, and bookmarks correctly, let you find and block other users, and review content reports. We do not use your information for advertising, and we do not sell it to third parties.
4. Who We Share Information With
We use a small number of outside services to run the App, each of which processes some of your data on our behalf:
• Supabase — hosts our database, handles account sign-in, and stores uploaded files such as your avatar photo. Most of what is described in this policy is stored with Supabase.
• Resend — delivers account-related emails, such as sign-up confirmation and password-reset codes.
• Zoho Mail — hosts our support inbox, so messages you send to support@minkasalam.com are stored there.
• YouTube (Google) — some educational videos are embedded from YouTube for playback. When you watch one, YouTube’s own privacy policy and data practices apply to that playback.
• Mux — hosts and streams the videos and clips uploaded to the App directly (everything that is not embedded from YouTube), including files that verified scholars and creators upload.
• Sentry — receives crash and error reports so we can find and fix problems in the App. A report contains technical details such as your device model, operating system version, app version, and what the App was doing when it failed. It does not include your name, email address, or account details, and Sentry stores these reports on servers in the European Union.
We do not share your personal information with anyone else, except where required by law.
5. Children’s Privacy — family profiles, still to be reviewed by a lawyer
A child never has an account of their own on the App. Anyone who reports being under 13 at sign-up or guest entry is shown "Ask a parent" and nothing about them is stored. A child uses the App through a family profile that a parent creates from inside the parent’s own account, and the parent, not the child, provides the information below.
For a child profile we store: the display name and birthdate the parent entered (the birthdate only picks the content level and is never shown), a preset avatar chosen from a built-in set, the map level the parent chose, the interests the parent chose or the child added from the map, and the child’s likes, saves and follows. A child profile has no email address of its own (an internal, never-mailed address exists only so the profile can be signed in), no bio, no photo, no public profile page, and cannot post comments. The child’s birthdate is stored with the same protections as an adult’s (see "Information We Collect"). The phones a child profile is signed in on are listed to the parent, with a device name and last-used time.
The parent can see the child’s activity, change the interests and map level, open the profile on another phone with a one-time code, sign the profile out of any phone, and delete it: a deleted profile can be restored for seven days, after which it — and everything above — is erased; the parent can also erase it at once. A child profile is never deleted for inactivity while the parent’s account exists, and is erased when the parent’s account is deleted.
This is a deliberate design in which a parent stands as the consent for a child’s use of the App. It must still be reviewed by a lawyer — including whether it meets children’s privacy laws such as COPPA where they apply — before the App is published or a child’s information is knowingly collected.
6. How Long We Keep Your Data, and Account Deletion
You can request account deletion from Settings. Doing so signs you out right away and timestamps a deletion request, but actually erasing your data from our systems is currently a manual step we perform on the backend — not an instant one.
If you want to confirm your data has been fully erased, contact us at support@minkasalam.com.
7. Your Choices
You can edit or remove your profile information, block other users, unfollow people or scholars, remove your own comments, and request account deletion, all from within the App.
8. Security
We rely on Supabase’s infrastructure and its access controls to protect your data, but no system is completely secure, and we cannot guarantee absolute security.
9. Changes to This Policy
We may update this Privacy Policy as the App changes. We will update the notice in the App when we do.
10. Contact
Questions about this Privacy Policy can be sent to support@minkasalam.com.