Privacy policy

Last updated 2 August 2026

NaashNaash is a health app for Muslim women. That means we hold two of the most sensitive kinds of information there are — what is happening in your body, and how you practise your faith. This page says exactly what we keep, why, for how long, and how to take it away. It is meant to be read, not agreed to.

The short version

  • We do not sell your data, and there are no advertising or analytics trackers anywhere in this app. Not a reduced set — none.
  • Your weight, meals, water, sleep, cycle and skin notes are visible to you alone. Nobody on our team has a screen that shows them.
  • Group competitions never show your weight. They show a percentage of your own progress, and only if you join one.
  • You can download everything we hold about you, or delete your account and all of it, from Privacy in the app. You do not have to ask us.

What we collect, and why

To have an account: your name, email address, the language and timezone you choose, and a password we never see — it is stored as a one-way hash. Optionally a country, city and phone number, used only if we need to reach you about your verification.

To verify that this space is women-only: one photograph, reviewed by hand by a woman on our team, then deleted within 30 days. It is never shown to other members, never used for anything else, and we do not run face recognition on it.

Health tracking, if you turn it on: the weights, meals, glasses of water and hours of sleep you write down. This is off until you switch it on, and switching it off stops new records without touching the old ones.

Cycle dates, if you turn them on separately: used for one purpose — pausing your streak so a rest week does not read as a failure. Kept for 90 days and then deleted automatically. This is the most sensitive thing the app touches and it is deliberately the shortest-lived.

Groups and chat, if you join one: the messages you send. They are encrypted in our database, so a stolen backup or a leaked copy is unreadable without a key we hold separately. Be clear about the limit of that, because it matters: it is not end-to-end encryption. The running app can read messages, because it has to in order to show them to you. If you are told otherwise by anyone, including us, that is wrong.

The wellness coach, if you use it: what you type is sent to Google's Gemini API to produce a reply. We send the minimum context needed and nothing that identifies you — no name, no email, no account number. We pay for that API rather than using the free tier, which matters: the published terms for the paid tier say Google does not use your prompts or the replies to improve their models, and the free tier says the opposite in as many words. Google does keep a short-lived log of prompts and replies to detect misuse of the service. If you would rather nothing at all left our servers, do not use the coach; the rest of the app works without it.

Where it lives

On a server we rent in Kuala Lumpur, Malaysia. Backups are encrypted before they leave that machine and the key to read them is not kept on it. Our team is small and access is limited to the people who need it to run the service.

How long we keep it

  • Verification photographs: deleted within 30 days of review.
  • Cycle dates: 90 days, then removed automatically.
  • Everything else: until you delete it, or until you delete your account, whichever comes first.
  • Encrypted backups age out on a rolling schedule. If you delete your account, the last copies of your data leave those backups as they expire rather than instantly — we would rather say so than imply a deletion is more absolute than it is.

What we do not do

  • No advertising, ever, and no advertising identifiers.
  • No third-party analytics. We do not know which pages you visit, because nothing is recording it.
  • No selling, renting or sharing your information with anyone for their own purposes.
  • No health values, message contents or tokens in our server logs. The logs record that something happened and whether it failed, not what it said.

Your rights

Under the GDPR and Saudi PDPL you can ask to see what we hold, correct it, delete it, take a copy elsewhere, or withdraw a permission you gave earlier. Most of this you can do yourself, immediately, from Privacy in the app — you should not have to write to somebody to get your own information. Withdrawing a permission never removes what you already stored; deleting is a separate, deliberate action.

If you would rather write to us, or if something here is wrong, email privacy@naashnaash.com. You also have the right to complain to your data protection authority.

Children

NaashNaash is not for under-16s. If we learn an account belongs to somebody younger, we delete it.

When this changes

If we change something that affects what happens to your data, we will tell you in the app and ask again where the law requires it — not quietly update this page and treat your continued use as agreement.