Privacy policy

Last updated 1 October 2026

This is a draft, prepared for legal review. Every statement in it was written by checking what the app's code actually does, and it is published so that it can be checked. It is not legal advice, and it makes no claim to be sufficient, complete or compliant under any law. The section what legal review still has to settle lists what is deliberately not decided here.

Waddili Salami connects a pilgrim performing Umrah or Haj with the people at home who ask them to make a dua or carry their salaams. It is built to need as little about you as possible: there is no phone number, no password, no username, no location, no contacts and no advertising anywhere in it. What follows is the whole list of what it does hold.

One thing changed on 1 October 2026, and it is the only email address in this app. A pilgrim may now optionally attach an email address as a second way back into their own journey if they lose their phone. Until then this page said there were no email addresses at all, and an account still works exactly the same without one. But it is no longer accurate as a blanket statement, so it has been replaced by the entry below — including the part we cannot soften, which is that we store that address in a readable form and can therefore read it, because mail cannot be sent to a scrambled value.

And a second change, the same day: a pilgrim is now asked once, at the start. This page first said that nothing in the app ever asks for an address. That is no longer true, and the reason matters more than the wording: the people most likely to lose a phone are the ones least likely to go looking through Settings, so a safety net nobody finds does not protect anybody. So the app asks exactly once — immediately after it shows a new pilgrim their recovery code, on a step of its own, where "Add an email" and "Skip" are the same button twice and skipping takes one tap. Nothing is pre-filled and nothing is pre-ticked. That is the only time the app ever raises it; after that it is in Settings and nowhere else, and it never asks again.

On this page

Who we are

Waddili Salami is published by Moka Inspire, which is the controller of the personal data described here (the responsible party, in POPIA's words). You can reach us about anything on this page at [email protected].

What we collect, why, and on what basis

This is the complete list. Each entry says what the data is, why the app needs it, and the legal basis we rely on — and those bases are among the things legal review still has to confirm.

  • The display name you type. A pilgrim's name, so the people following them know whose journey it is; a follower's name, so the pilgrim knows who asked. Up to 50 characters, and it is whatever you choose to type — it does not have to be your real name, and nothing checks it against anything. Basis: performing the service you asked for (GDPR Article 6(1)(b)).
  • The requests you send, and the note on them. Which dua you asked for or that you sent salaams, when you sent it, and whether the pilgrim has marked it recited. Each request can carry an optional personal message of up to 300 characters, which the pilgrim reads. We do not read your notes to do anything else with them. Basis: performing the service you asked for (Article 6(1)(b)).
  • A pilgrim's journey progress. Which phase of the journey you are in, how far through its steps you are, and when that last changed; whether your journey begins in Makkah or Madinah; and which journey this is, if you have started a new one (each request is marked with the journey it was sent in). The phase and where the journey begins are shown to the people following you; that is the point of it. Basis: performing the service you asked for (Article 6(1)(b)).
  • An anonymous account identifier. When you start, the app signs in anonymously and is given a random identifier. It is not linked to an email address, a phone number or a name, and it identifies nothing outside this app. To keep that anonymous identity usable across app restarts, our server derives a synthetic internal credential for it that is shaped like an address ending in .invalid. That is not an email address and cannot receive mail — .invalid is a domain name reserved so that it can never be real. It is not the optional recovery address below, and the two are never confused inside the app: this one is a credential derived from your account, and no mail is ever sent to it by anything. Basis: performing the service you asked for (Article 6(1)(b)).
  • A recovery email address — only if you choose to add one. A pilgrim can attach an email address so that they have a second way back into their journey if they lose their phone — either when the app offers it, once, just after showing them their recovery code, or at any later time in the app's Settings. Read the following carefully, because it is the one place in this app where we hold something we can read:
    • It is optional, and you are asked for it once at most. The 8-character recovery code is still the way back in and still works on its own. A pilgrim who never adds an address loses nothing. The app raises the subject exactly once — on a step straight after your recovery code is shown, where refusing is one tap and is given the same prominence as accepting — and never raises it again. There is no reminder, no badge and no second prompt.
    • We store the address itself, not a one-way hash of it, and we can read it. There is no way around that: mail cannot be delivered to a scrambled value. It is held in a column only our own server code can reach — no app user, in either role, can read it, and nobody in a pilgrim's circle can see that one exists. Alongside it we store a keyed, scrambled copy used only to look the address up without searching on the plain text.
    • An address has to prove itself before it can do anything. When you add one we email it a one-time code, and until that code comes back the address can restore nothing at all. An unconfirmed address receives that single message and nothing else ever — so a typo sends one code to a stranger and then stops.
    • We only ever send one-time codes to it. One to confirm it, and one each time someone asks to get back into a journey attached to it. Each code can be used once and expires in 30 minutes. There is no newsletter, no announcement, no receipt and no mailing list.
    • You can remove it at any time, in the same Settings row, and getting back in by email stops working immediately when you do.
    • More than one pilgrim may use the same address — a household or a group travelling together often shares one inbox. In that case a request for a code sends one message listing each journey by the pilgrim's name with its own code.
    • Asking for a code tells nobody anything. If someone types an address into that screen, the app's answer is the same whether the address is attached to a journey or not, so the screen cannot be used to find out whether a person uses this app.
    Basis: your consent, given by typing the address into that screen after reading what it is for, and withdrawable by removing it.
  • A pilgrim's invite code, and a one-way hash of their recovery code. The invite code is the link you share. The recovery code is what lets you get back into your journey on a new phone: we store only a one-way hash of it, never the code itself, so we cannot tell you what your recovery code is — only check one you give us. Basis: performing the service you asked for (Article 6(1)(b)).
  • Your device's notification token. A token issued by Google's push service that identifies your app installation so a notification can be delivered to it — to tell a follower their dua was recited, and to tell a pilgrim a new request arrived. We ask your phone for notification permission first, and turning notifications off in your phone's settings withdraws it. The token is sent to Google's push service and to nobody else, and no other app or user can read it from our database. Basis: your consent, given through your device's notification permission and withdrawable in your phone's settings at any time.
  • Your IP address, briefly, to stop abuse. When a device registers a new pilgrim, joins a pilgrim's circle, or tries to recover a journey with a recovery code, our server counts that attempt against a short-lived counter. The counter's label contains your IP address for those three actions (and your account identifier for a few others, such as starting a new journey — the pilgrims-new-journey: counter). It holds nothing else: no name, no note, no request. It is discarded automatically within about a day. Basis: our legitimate interest in preventing abuse of a service that has no passwords to protect it (Article 6(1)(f)).
  • Crash and error diagnostics. When the app crashes or hits an unexpected error it sends a report to our error-reporting provider so we can fix it. What goes in it is deliberately narrow: the type of error and the stack trace, the device model, the operating-system version, the app version, and the template of the screen you were on — "the join screen", never the invite code that was in the address. The app is configured to strip the rest before anything leaves your phone: no user record, no IP address, no network request or URL, no free-form developer data, and none of the error's own free text — that text is generated from whatever object failed, and it is exactly where a name, a note or an invite code could otherwise hide, so the type of the error and its stack are kept and the text is thrown away. Alongside the crashes the app raises a small number of deliberate warnings; each of those is a fixed phrase plus a label naming which internal step went wrong, and nothing else — never anything you typed. Basis: our legitimate interest in keeping the app working (Article 6(1)(f)).

Using the web form instead of the app collects the same things: the name you type, the request and its optional note, and your IP address in the abuse counter. It sets no notification token, because there is no app installation to notify.

What we do not collect

Said plainly, because a privacy policy written from a template usually implies otherwise:

  • No phone number and no password. There is nowhere to type either. The one email address this app can hold is the optional recovery address above, which exists only because you chose to add it — and it is never used to identify you, to log you in, or to send you anything but a one-time code.
  • No location. The app never asks for a location permission and never records where you are — not even which city, and not even while a pilgrim is moving through the journey.
  • No contacts, calendar, microphone or camera.
  • No photos are read. On iOS the app asks for permission to add to your photo library, and only for one thing: saving your own invite QR code if you tap save. It cannot read your library.
  • No analytics, no advertising, no attribution and no tracking. Nothing in the app follows you across other companies' apps or websites, and there is no advertising identifier, no ad SDK and no marketing profile. Apple's App Privacy answer for tracking is "No", and it is declared that way in the app's own privacy manifest.
  • No age, gender, date of birth, payment details or health data. The app is free and has nothing to pay for.
  • No mailing list, and no message from us that you did not ask for. There is no newsletter and no announcement list. The only mail this app sends is a one-time code to an optional recovery address, and only in response to someone asking for it on that device or that screen. We have no way to contact anyone who has not added an address, and no reason to contact anyone who has.

What stays on your phone

Much of what you see in the app is stored on your own device and is never uploaded: the dua library and the journey content, your local copy of your requests and progress, and the queue of changes waiting for a connection when you are offline. Your session credentials are held in your device's own secure storage. Uninstalling the app removes all of that from the phone — but it does not delete your account on our side. For that, see deleting your account.

Who else receives it

We do not sell your data, and we do not share it for advertising — there is no advertising. Five providers process it on our behalf, each receiving only what it needs to do its job:

  • Supabase — hosting, the database and the anonymous sign-in. It holds everything in the list above except the crash reports: names, requests and notes, journey progress, invite codes, the recovery-code hash, an optional recovery email address, notification tokens and the short-lived abuse counters.
  • Resend — and only if you added a recovery email address. It is the service that delivers the one-time codes, so it receives that address and the code in the message. That is all: not your name, not your journey, not your requests and never a personal note. If you never add an address, nothing of yours ever reaches this provider.
  • Google (Firebase Cloud Messaging) — push notification delivery. It receives your device's notification token and the notification itself. Be aware of what that second part means: the notification's own wording names the other person — "Fatimah has asked you to recite a dua for them", "Abdul Rahman has recited a dua on your behalf" — so their display name passes through Google's service on its way to your phone, exactly as it would with any push notification on any app. Nothing else does: not your journey, not the request record, and never the personal note, which stays in our database and is only ever read inside the app.
  • Sentry — crash and error diagnostics. It receives only the scrubbed reports described above.
  • Cloudflare — serving this website and the join pages, and our domain's DNS. Like any web server, it sees the IP address and browser details of a request it answers.

Third parties on this website. These pages load their typeface from Google Fonts, and the join page loads one software library from the jsDelivr CDN. Both therefore see the IP address and browser details of the request that fetches the file, in the same way any website you visit does. They receive nothing else — no name, no request and no note.

These providers operate internationally, so data reaches servers outside your own country. The mechanism relied on for that transfer is one of the things legal review still has to settle; we would rather say so than name a mechanism we have not confirmed.

We would also hand over data if the law genuinely required it of us. Nothing else leaves.

How long we keep it

Be aware of what this means: we do not delete your account for you. Your name, your requests, your notes and a pilgrim's journey progress are kept for as long as the account exists. There is no automatic expiry, no inactivity cut-off and no scheduled purge — if you want it gone, you have to ask for it gone, and it goes immediately and completely when you do.

A recovery email address is kept until you remove it, like everything else — but unlike everything else you can take it away on its own, without closing your account, from the same Settings row you added it in. Removing it deletes the address, the scrambled copy used to look it up and any live one-time code, in one go, and getting back in by email stops working immediately. The one-time codes themselves expire 30 minutes after they are sent whether or not they are used.

Three things behave differently, and they are the only three:

  • The abuse counters that contain your IP address are discarded automatically within about a day. The counter for a code request holds a scrambled derivation of the address rather than the address itself, deliberately: those rows sit in a table for a day, and a plain address there would turn an abuse counter into a list of people's real addresses.
  • A record that a message was delivered, held by the mail provider on its own schedule and outside our database, if you added a recovery address.
  • Crash and error diagnostics are held by our error-reporting provider for up to 90 days and then expire. They are not linked to your account and cannot be traced back to it, so they are not part of an account deletion.
  • Notification delivery records held by Google's push service sit outside our database and expire on their own schedule.

Deleting your account and your data

If you have the app, you can delete your account from inside it in a few taps; if you only ever used the web form, the deletion page's email route does it for you. Either way the deletion is hard: the rows are removed. There is no tombstone, no archived copy and no anonymised record, and it cannot be undone — not even with a pilgrim's recovery code.

Two consequences are worth knowing before you do it. If a follower deletes their account, every request they ever sent disappears from the pilgrim's history too, including the ones the pilgrim has already recited, and the pilgrim is not told which ones went. If a pilgrim deletes their account, their whole circle loses access and every request sent to them is destroyed — but their followers' own accounts are not closed; those people are told the journey has ended and can follow someone else or delete their own account from there.

The deletion page has the exact steps for both roles, spells out what each one destroys, and gives an email route for anyone who cannot use the in-app one — someone who has lost their phone, already uninstalled the app, or only ever used the web form.

Your rights (GDPR)

If the GDPR applies to you, you have the right to ask for access to your personal data, to have it corrected, to have it erased, to have our use of it restricted, to object to processing we base on legitimate interests, and to receive a copy in a portable form. You can withdraw the notification consent at any time in your phone's settings. You can also complain to your national data-protection supervisory authority.

For most people erasure needs no request to us at all — you can do it yourself, from inside the app, in a few taps. If you sent your request from the web form and never installed the app, that route does not exist for you: use the email address on the deletion page and we will do it by hand.

Correcting your display name needs no request either, if you are the pilgrim. Edit "Your Name" in the app's Settings: the correction is stored on your phone straight away and sent to our server as soon as you have a connection. Your circle then sees the corrected name on their own screens the next time their app refreshes, and in any notification sent after that. Settings tells you if it has not been sent yet, and if sending it failed. If you are following someone, the name you chose when you joined has no edit screen yet, so for that one write to us at [email protected] and we will change it by hand.

One honest limit. Because accounts here are anonymous — no phone, no password, and an email address only if you chose to add one — we usually cannot tell who you are from an email asking us to act. Writing to us from an address you attached as a recovery address does not prove it is yours either, and we do not treat it as proof: that address is a way back into the app, where the device itself is the evidence, not a way to authenticate a letter to us. If you write to us we will ask for something that identifies the account, such as the display name you used together with your invite link or recovery code. If you cannot give us anything that ties you to an account, we may not be able to act on the request: not out of reluctance, but because we would otherwise be handing over or destroying a stranger's data on the word of whoever wrote in. Deleting from inside the app avoids this entirely, because there the device itself is the proof.

If you are in South Africa (POPIA)

Moka Inspire is the responsible party for this processing under the Protection of Personal Information Act, 2013. Under POPIA you may ask us to confirm what personal information we hold about you and for a record of it, ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, and object to processing. The limit described above applies here too: we can only act on a request we can tie to an account.

You may also complain to the Information Regulator (South Africa). No personal information is processed here for direct marketing, and none of it is used for automated decision-making about you.

How it is protected

  • Everything the app sends travels over HTTPS/TLS. Nothing is sent unencrypted.
  • The database enforces row-level security, so one account cannot read another's rows. A pilgrim sees their own circle's requests; a follower sees their own.
  • Notification tokens cannot be read by any app user at all, in either direction — only our own server code can see them, and only to send a notification.
  • A pilgrim's recovery code is stored only as a one-way hash, and the credential that restores their session is derived from that hash — so it stops working the moment the account is deleted.
  • A recovery email address is readable by our server code and by nothing else. No app user in either role can read it, in any way — not directly, not by filtering on it, and not as part of reading anything else. The scrambled copy used to look it up is keyed with a server-only secret, so a copy of the database on its own does not reveal addresses. That secret is deliberately separate from the one behind recovery codes, so that changing either of them cannot take both ways back in at once.
  • The crash reporter is configured to strip personal data before a report leaves the device, rather than relying on it being filtered after arrival.

No system is perfectly secure, and we are not claiming otherwise. What we can say is what the design does and does not put at risk: there is no password to steal, no mailing list to leak and no payment data anywhere in this app. The optional recovery addresses are the one readable personal detail here, which is exactly why they are optional, why the app asks for one at most once and never again, and why you can take yours back at any time.

Changes to this policy

If this policy changes we will update the date at the top of this page. This page is the only place a change is announced, and that is unchanged by the recovery address: it is used for one-time codes and nothing else, so we will not email you about a policy change even if we hold an address for you. The app's store listings link here, and so does the deletion page.

What legal review still has to settle

Listed rather than guessed at. Each of these is a legal determination, not a fact about the code, and this draft deliberately does not make it:

  • Whether the legal bases named per category above are the right ones.
  • The mechanism relied on for international transfers to the four providers named above.
  • Whether the retention described — indefinite until the user deletes — needs a stated limit.
  • Whether a statement about children's data is required, and what it should say. The app has no age gate and asks for no age.
  • The controller's registered details and postal address, and whether a representative or a data protection officer has to be named.
  • Whether this document, as worded, meets the disclosure requirements of the regimes it names.

Contact

[email protected]

For anything on this page, including a request to exercise a right above. Tell us whether you were the pilgrim or a follower and the display name you used, and include your invite link or recovery code if you have it — that is what lets us find the right account. We reply within 30 days.

Related