Privacy Policy
Last updated: September 19, 2026
Sakeenah ("the app," "we," "us," or "our") is an Islamic journaling app, developed and maintained by an independent solo developer based in Manitoba, Canada. This policy explains what information the app collects, why, how it's protected, and what rights you have over it. It is written to comply with Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Google Play's developer policies.
1. Who We Are
Sakeenah is an independent, solo-developed project. The individual responsible for privacy matters relating to this app can be reached at support.sakeenah@gmail.com.
2. Two Ways to Use Sakeenah
2.1 Guest Mode
If you use Sakeenah without signing in, your journal entries, favorites, journeys, and settings live locally on your phone only. We have no visibility into any of it, and none of it is ever transmitted anywhere. The one exception is subscription support: when the app starts, our billing provider (RevenueCat) may be contacted in the background and assigns your device an anonymous identifier, and it can see technical data such as your IP address. RevenueCat never receives your journal content. See Section 3.10.
This also means it isn't backed up. If you're using Guest Mode and you uninstall the app, lose your phone, or switch devices, everything you've written is permanently lost - we have no copy to recover, because none ever left your device. If you'd like your data protected against this, sign in with Google to enable cloud backup.
2.2 Signed-In Mode (Google Sign-In)
If you choose to sign in with Google, your data is backed up to the cloud in addition to your device, so it isn't lost if you lose your phone or reinstall the app.
3. Information We Collect
We only collect what the app needs to function.
3.1 Account Information
Signing in uses Firebase Authentication (Google Sign-In). This gives us your email address, a unique user ID, and basic authentication metadata. We never see or store your Google password.
3.2 Journal Entries & Matched Verses (Signed-In Users Only)
Your journal entries - including text, mood, any optional locally-attached image, and the Quran verses matched to each entry - are saved to Cloud Firestore under your account.
3.3 Favorites (Signed-In Users Only)
Saved verses, duas, hadiths, or names of Allah are stored in Cloud Firestore under your account so they're available across devices.
3.4 Journeys (Signed-In Users Only)
Habits or goals you create - including their titles, your stated intention (niyyah), status, and any quick notes attached to them - are stored in Cloud Firestore under your account.
3.5 App Preferences & Security Credentials (Signed-In Users Only)
Certain settings sync to Cloud Firestore so they carry over across devices: your preferred display name, theme, notebook font settings, and prayer time calculation preferences.
If you set an in-app PIN or recovery code - used to keep your journal private from others with access to your phone, not to control access to your account itself - we never store the plaintext PIN or recovery code anywhere. Instead:
- The PIN and recovery code are hashed using SHA-256 with a securely generated random salt.
- These salted hashes are stored locally using Android's EncryptedSharedPreferences (AES-256, backed by the Android Keystore).
- If you enable cloud backup, the same salted hashes - never the plaintext PIN - are also synced to Cloud Firestore, so your privacy lock carries over if you install the app on a new device.
3.6 Prayer Times & Location
Sakeenah calculates prayer times using your device's approximate location. This location data is stored only on your device (as your last known coordinates) and is used exclusively for local prayer time calculations.
To automatically configure the most accurate calculation method for your region, Sakeenah uses offline, on-device coordinate mapping. Your location data is processed entirely locally and never leaves your device for this purpose.
Your location is never uploaded to Firestore, included in cloud backups, sent to third-party APIs, or transmitted to us in any form, regardless of whether you're signed in or using Guest Mode.
3.7 Verse Matching
Sakeenah uses a machine learning model built into the app to match your journal entries with relevant Quran verses from a verse library also built into the app. This runs entirely on-device and your journal text is never sent to a server, an external API, or any third party for this purpose, and it works without an internet connection.
3.8 Notifications
Journey reminders and prayer time notifications are generated entirely on-device using Android's native scheduling tools (WorkManager and AlarmManager). We do not use Firebase Cloud Messaging or any external push notification service, and we do not collect or store any device push token.
3.9 Verse Match Reports (Optional)
If you flag a Quran verse match as not fitting what you wrote, the app opens your device's default email app with a pre-filled message addressed to us. This includes the verse reference and its category and never your journal text. You may optionally add a short description of what your entry was about before sending. This is entirely optional, initiated only by your own action, sent directly from your email app (not through Firebase or Firestore), and used solely to improve verse matching.
3.10 Subscriptions and Payment Processing
We offer an optional paid upgrade (Sakeenah Plus), available as a monthly or annual subscription. When you subscribe, your payment is processed entirely and securely by Google Play Billing. We do not intercept, collect, or store your credit card or financial information.
To verify and manage your Sakeenah Plus access, we use RevenueCat. When the app starts, RevenueCat may be contacted in the background and assigns your device an anonymous identifier, and it can see technical data such as your IP address; this happens even if you haven't signed in or subscribed. If you subscribe, which requires signing in, RevenueCat links your purchase to your Firebase account ID, along with your transaction receipt and subscription status, so your access carries over if you switch devices. That data is not anonymous. Google Play and RevenueCat process only what's needed to manage your subscription; they never receive your journal entries, journeys, or personal reflections.
4. What We Don't Collect
Sakeenah does not use Firebase Analytics, Crashlytics, or any other analytics/tracking SDK, nor any advertising SDK (the app is ad-free). We do not collect or store your payment information directly.
5. Third-Party Services
The only third-party services Sakeenah relies on are:
- Firebase Authentication (Google) - for Google Sign-In only.
- Cloud Firestore (Google Cloud) - for optional cloud backup.
- Google Play Billing - to securely process in-app purchases.
- RevenueCat - to validate purchase receipts and manage subscription entitlements.
Cloud Firestore is a Google Cloud Platform infrastructure product, governed by Google Cloud's data processing terms - separate from Google's consumer advertising business. Per those terms, Google does not use data stored in Firestore to build advertising profiles or sell it to third parties.
Cross-border storage and processing: Firebase infrastructure is operated by Google, and RevenueCat may also process data on servers outside Canada, including in the United States. By enabling cloud sync or subscribing to Sakeenah Plus, you consent to this cross-border storage and processing.
6. How We Use Your Information
- To create and manage your account, if you choose to sign in
- To back up and sync your data across your devices, if you're signed in
- To grant you access to Sakeenah Plus features, if you choose to upgrade
- To respond to support requests
We do not sell your personal information, and we never share it with advertisers or data brokers.
7. How Your Data Is Stored and Secured
Locally, always: the app works fully offline. Your PIN and recovery code credentials are encrypted using Android's EncryptedSharedPreferences (AES-256, backed by the Android Keystore) - see Section 3.5. Your journal entries and general app settings are stored in standard local Android storage (Room/SQLite and Jetpack DataStore), protected by Android's standard OS-level app sandboxing, which prevents other apps from accessing them, though this data is not separately encrypted at rest beyond that sandboxing.
In the cloud, only if you sign in and enable sync: synced data is stored in Cloud Firestore, which encrypts data in transit (TLS) and at rest. It is not currently end-to-end encrypted - see Section 8 below.
Access control: Firestore security rules restrict each signed-in user's data to that user's own account; other users cannot read or write your data through the app.
8. Who Can Access Your Data
As the app's developer and sole owner of the Firebase project, it is technically possible for us to access data stored in the cloud through Firebase's administrative infrastructure, separately from the per-user access controls described above. We do not access individual users' journal content in the ordinary course of operating the app.
This is a limitation of the current architecture, not a design choice we're comfortable with long-term. End-to-end encryption - where even we could not read your entries - is a planned future improvement, and this policy will be updated when it's implemented.
We do not sell or rent your personal data. We share limited data with the service providers listed in Section 5 only to operate the app.
9. Data Retention and Deletion
Locally stored data remains on your device until you delete the app or the entries themselves. As noted in Section 2.1, local-only (Guest Mode) data is unrecoverable once lost.
If you're signed in, cloud-backed data is retained until you delete your account. Uninstalling the app does not delete your cloud-backed data
- it persists in Firestore until you explicitly delete your account.
You can delete your account and all associated cloud data from within the app. When you do, an automated process runs immediately, wiping your data from both Cloud Firestore and your local device - we do not hold data in a pending-deletion state.
Subscriptions and billing records: deleting your account does not cancel an active Sakeenah Plus subscription; cancel it in Google Play Account Settings -> Subscriptions. Purchase records are also held by Google Play and by RevenueCat under their own retention practices. If you would like your RevenueCat record deleted, contact support.sakeenah@gmail.com and we'll request it.
If you'd rather not use the app, you can also request deletion from our Account Deletion page, which explains both methods in detail. Requests made this way are processed manually and completed within 30 days of receipt. Once processed, deletion is immediate and permanent, identical to the in-app method (subject to the billing records described in this section) - we do not retain data in a pending state beyond that 30-day processing window.
10. Data Breach Notification
In the event of a data breach that creates a real risk of significant harm to you, we will notify you and report the breach to the Office of the Privacy Commissioner of Canada as soon as feasible, as required under PIPEDA.
11. Your Rights
Under PIPEDA, you have the right to access the personal information we hold about you, correct inaccurate information, withdraw consent for cloud sync at any time (your local data is unaffected), delete your account and all associated data directly in the app or via our Account Deletion page, and file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe we've mishandled your personal information.
Identity verification: if you contact us to manually exercise any of these rights, we'll ask you to verify your identity - for example, by reaching out from the specific Google account associated with your Sakeenah data - to protect your privacy from unauthorized requests.
12. Age Requirements
Sakeenah's core journaling features (Guest Mode) are open to users of any age, as no journal content or account data is collected in this mode. However, our cloud backup and sync features (Signed-In Mode) are not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with information, contact us using the details below so we can delete it.
13. Regional Availability
Sakeenah is not offered in, and is not directed at individuals located in, the following countries and regions: the European Economic Area (all EU member states, plus Iceland, Liechtenstein, and Norway), the United Kingdom, Switzerland, Russia, Vietnam, Saudi Arabia, Egypt, Turkey, Kazakhstan, and Israel. In all other regions, availability depends on Google Play and applicable local law. If you are located in an excluded region, please do not download or use the app. We do not knowingly collect personal data from individuals in those regions, and we may restrict access if we learn a user is located in one. If you believe we hold your data in error, contact support.sakeenah@gmail.com and we'll delete it.
14. Changes to This Policy
We may update this policy as the app evolves. If we make a material change, we'll notify you inside the app in addition to updating the "Last updated" date at the top of this page.
15. Governing Law
This policy is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and the laws of the Province of Manitoba and Canada.
16. Contact Us
For privacy questions, rights requests, or data deletion, contact support.sakeenah@gmail.com.