Iffah
Privacy Policy
Effective date: 22 August 2026 · Version 1.0
Applies to the Iffah iOS application and the website at iffah.app
The short version
Iffah has no accounts and no server of its own. What you record in the app — your answers, your journey, your notes, your falls and your returns — is written to your own device and stays there. We cannot read it, because it never reaches us.
There are no analytics, no trackers, no advertising, and no third-party software development kits in Iffah other than the one that tells the app whether your subscription is active.
If you use Fortress, Iffah asks iOS to filter adult websites for you. Iffah does not receive, read, or store your browsing history.
The rest of this document explains all of that precisely, because a promise about privacy is only worth the detail behind it.
1. Who we are
Iffah is operated by Abdulbaasit Sayed, a sole trader established in the United Kingdom (“Iffah”, “we”, “us”). For the limited personal data described in this policy, we are the data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- Contact: hello@iffah.app
- Postal address: 88 Park View, Wembley, London HA9 6JX, United Kingdom
If you have any question about this policy, or want to exercise a right under data protection law, that email address reaches a person.
2. What Iffah is, in data terms
Iffah is a local-first application. It has:
- no sign-in and no user account;
- no Iffah-operated server, database, or backend;
- no synchronisation between devices;
- no analytics, telemetry, crash reporting, or usage measurement;
- no advertising, ad identifiers, or ad networks;
- no social features, public profile, feed, or shared streak.
Because there is no account, there is nothing for us to look up about you. The practical consequence is that most of the data you create in Iffah is never “collected” by us in any sense — it is written to storage on your iPhone that only Iffah can read, and it is deleted when you delete it or when you uninstall the app.
3. What stays on your device
The following are stored locally on your device, using Apple’s app storage and Iffah’s own on-device database. None of it is transmitted to us, and none of it is transmitted to anyone else.
Your answers when you begin
The responses you give in the opening journey — how long the struggle has held you, how often, when the waves come, where you stand with salah, and the rest of the questions in that funnel.
Your journey
Your current and longest clean stretch, your daily activity, the pledges you make, and the record of days.
Your urges and your returns
The urges you log, the feelings and contexts you attach to them, and the reflections you record after a fall, including anything you write in a Tawba debrief.
Your writing
Journal entries, private notes, and any du‘a you save to your library.
Your Garden
Your niyyah, what you have planted, and how it has grown.
Your preferences
Support settings, motion and sound settings, reminder style and times, and display settings.
Your prayer location
If you choose to set a salah anchor, Iffah stores the coordinates and a place label on your device so it can calculate prayer times. See section 4.
You can erase all of the above at any time from Profile → Privacy Centre. That screen offers targeted clears as well as “Erase everything on this device”, which removes everything above — including your onboarding answers and your saved location — and returns Iffah to the state it was in the day you installed it. Deleting the app from your iPhone also removes all of it.
4. Location
Iffah can use your location for exactly one purpose: to calculate the times of the five daily prayers where you are.
- It is optional. You can decline it and choose a city from a list that is built into the app instead, or skip the step entirely.
- When you tap “Use my location”, Iffah makes a single, foreground, low-accuracy request. A city-level fix is all the prayer-time calculation needs, so Iffah does not ask for a precise one.
- Iffah does not request background or “always” location access. iOS will not grant it, because the app does not declare it.
- The coordinates are stored on your device and used on your device. Prayer times are computed locally by a calculation library bundled into the app. Your location is never sent to us, never sent to a prayer-time API, and never sent to any third party.
- You can withdraw the permission at any time in iOS Settings → Iffah → Location, and you can delete the stored coordinates in Iffah’s Privacy Centre.
Where consent is the legal basis for processing (as it is here), you may withdraw it at any time without affecting anything done before you withdrew it.
5. Notifications
Iffah’s reminders are local notifications, scheduled by the app on your own device against times you have chosen.
- There is no push server. Iffah does not create, hold, or transmit a push token, and no notification is ever sent to your phone from the internet.
- Notifications never name the subject of the app. Nothing that appears on your lock screen, in Notification Centre, or in a banner discloses what Iffah is for.
- You can turn notifications off in iOS Settings, or change their style and times inside the app. Clearing your data in the Privacy Centre also cancels anything Iffah had scheduled.
6. Fortress (Screen Time / Family Controls)
Fortress is an optional feature that helps you fence off adult websites on your own device. It is reached from the Tools tab, and the app is fully usable without it.
With your explicit Screen Time authorisation, Iffah switches on Apple’s own automatic adult-web-content filter within a settings store belonging to Iffah. What that means in data terms:
- Iffah does not request app or website usage data from iOS.
- Iffah does not receive readable browsing history. The Screen Time framework is designed so that an app in Iffah’s position cannot see which sites you visit.
- Iffah does not log attempted visits, does not keep a record of blocked pages, and does not report anything about your browsing to anyone.
- No filtering data is sent to a server, because there is no server.
- Timed fences use an Apple device-activity extension solely to remove Iffah’s own setting when the period you chose has elapsed.
Your Screen Time authorisation is revocable at any time through iOS Settings. Iffah does not claim that the fence is impossible to bypass, and you should not treat it as one — see the Terms of Use for what Fortress does and does not promise.
7. Subscriptions, and the only data that leaves your phone
Iffah is a paid subscription app. Handling that subscription is the only reason the app makes a network connection at all.
7.1 Apple
Your purchase is made through the App Store, with your Apple Account. Apple processes the payment, not us. We never see and never receive your card details, your billing address, your Apple Account email, or your name. What we learn from Apple, indirectly, is whether an entitlement is currently active.
Apple’s handling of your purchase is governed by Apple’s own privacy policy.
7.2 RevenueCat
Iffah uses RevenueCat to check the status of your subscription and to restore purchases across reinstalls. RevenueCat is a subscription-management service and is the only third-party service the app communicates with.
- Iffah does not give RevenueCat your name, your email address, or anything you have written or recorded in the app.
- Iffah does not create a user identity. The app deliberately uses an anonymous app user ID generated on your device by RevenueCat’s software, which is not linked to any account, because Iffah has no accounts.
- RevenueCat receives what it needs to validate and track a purchase: the anonymous identifier, the App Store transaction and receipt information, the product purchased, and basic technical information about the device and app version.
- Legal basis: performance of our contract with you (Article 6(1)(b) UK GDPR) — we cannot give you access to a subscription app without confirming that the subscription exists.
- RevenueCat acts as our processor and is based in the United States. Where personal data is transferred outside the UK, that transfer is made under the safeguards permitted by the UK GDPR, including the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses.
RevenueCat’s own privacy policy describes its practices in full and is available at revenuecat.com.
That is the complete list of third parties. There is no analytics provider, no advertising partner, no error-tracking service, and no data broker, because Iffah does not use any.
8. The website
The website at iffah.app is a small marketing site. It has no accounts, no sign-in, and no forms — there is nothing on it to fill in and no way to send us anything through it. It does not hold or receive your app data, and the app never contacts it.
- Hosting. The site is hosted by Vercel Inc. Vercel records standard technical information for every request, such as IP address, the page requested, the time, and the browser user-agent string. This is used to serve the site and keep it secure, and is retained for a short period. Vercel acts as our processor. Legal basis: our legitimate interest in operating and protecting the site (Article 6(1)(f) UK GDPR). Vercel’s own privacy policy is at vercel.com/legal/privacy-policy.
- Audience measurement. The site uses Vercel Web Analytics to count how many people read each page. It is cookieless and stores no identifier on your device: it cannot follow you from one site to another, it does not build a profile of you, and what we see is an aggregate count rather than a record of a person. Legal basis: our legitimate interest in knowing whether the site works (Article 6(1)(f) UK GDPR).
- Cookies. The site sets no cookies at all — none for advertising, none for tracking, and none for analytics. That is why you are never asked to dismiss a consent banner here.
- No mailing list. There is no newsletter, no waitlist, and no sign-up form, and we do not collect email addresses through this site. If you write to hello@iffah.app we hold your message and your address because you sent them, and we use them only to answer you.
- Everything else is served from iffah.app itself, including the fonts. The site makes no request to any other company’s servers.
9. How long data is kept
- On your device: for as long as you keep it. You control this entirely through the Privacy Centre and by deleting the app.
- Subscription records at RevenueCat and Apple: retained by those companies in line with their own policies and their legal and accounting obligations. Because the identifier is anonymous, we generally cannot connect a subscription record to a named person.
- Support email: correspondence with hello@iffah.app is kept for as long as needed to deal with the matter, and then deleted.
10. Security
- App data is written to storage protected by iOS, readable only by Iffah, covered by the device encryption that your passcode enables.
- All network traffic the app makes uses encrypted connections.
- The strongest protection here is structural rather than technical: there is no central store of user reflections to breach, because we never collect them.
No system is perfectly secure, but the amount of your data we could lose in a breach is, by design, close to none.
11. Children
Iffah is for adults. It is rated 17+ on the App Store, it addresses adult subject matter plainly, and it is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact hello@iffah.app and we will delete it.
12. Your rights
Under the UK GDPR you have the right to access, rectify, erase, restrict the processing of, object to the processing of, and receive a portable copy of your personal data, and to withdraw consent where processing relies on it.
In Iffah’s case, these rights work slightly differently from most apps, and it is worth being honest about why:
- For everything in the app itself, you already hold the data and we do not. You exercise these rights directly and immediately through Profile → Privacy Centre, which is faster and more complete than any request to us could be. We cannot access, produce, correct, or delete that data on your behalf, because we have never had it.
- For the limited data our processors hold — subscription records and support correspondence — email hello@iffah.app and we will respond within one month. Please tell us as much as you can about the request (for example, the email address you wrote to us from); with an anonymous subscription identifier we may need your help to locate any record at all, and where we genuinely cannot identify you we may not be able to act.
You also have the right to complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). We would rather hear from you first, but that route is yours.
13. What we do not do
To state it plainly, and to be held to it:
- We do not sell your personal data. We never have and we will not.
- We do not share your data with advertisers or data brokers.
- We do not build a profile of you.
- We do not track you across apps or websites, and Iffah requests no App Tracking Transparency permission because it has nothing to track you with.
- We do not read your journal, your notes, or your reflections. We cannot.
14. Changes to this policy
If we change how Iffah handles data, we will update this page and change the effective date at the top. If a change is material — a new third party, a new category of data, a new purpose — we will say so clearly on this page, and where the change affects the app itself, in the app.
Iffah is local-first by design and not by accident. If that ever stops being true, you will be told, not left to notice.
15. Contact
Whether it is a question about this policy, a request under data protection law, or something about the app that troubles you — that address reaches a person, and we answer.