This policy is a draft awaiting formal legal review — it accurately describes what the current version of the Umrī app actually does (checked directly against its source code and permissions), but it has not yet been reviewed by a lawyer for legal sufficiency in any specific jurisdiction. Do not treat it as final or legally binding until that review is complete.

Who this is

Umrī is developed by deenbook, a UK-based team also behind Zakātī, Ḥaydī and other Islamic productivity apps. This policy covers the Umrī Android app and this website.

The short version

  • Umrī doesn't require an account to use. Your profile lives on your own device.
  • Your Wallet documents (passport, visa, hotel bookings, etc.) are encrypted on your device and are never uploaded anywhere.
  • There are no advertising or third-party analytics SDKs in this app. Nothing is sold to advertisers, because there are no advertisers.
  • A small number of opt-in features (below) do send limited data to our backend (Google Firebase) to work at all — never more than the feature genuinely needs.

Data stored only on your device

The following never leaves your phone unless you explicitly export or share it yourself:

  • Your profile(s) — name, gender, and preferences you enter during setup.
  • Wallet documents — encrypted at rest using your device's own secure hardware (Android Keystore, AES-256-GCM), gated behind their own PIN or biometric check on top of the app's own lock.
  • Ṭawāf/Saʿī tracking data — sensor and location readings used to count your laps/lengths live, and your resulting history.
  • Training progress, test scores, and du'ā bookmarks.

Permissions the app requests, and why

  • Location (fine/coarse) — used only for live Ṭawāf/Saʿī tracking (detecting your position relative to the Kaʿbah/Ṣafā-Marwah) and for the optional local weather widget on the Home screen. Never used for advertising, and never sent to us except as described under Family Link below.
  • Physical activity — used to help detect walking/movement during live tracking.
  • Notifications — used for local reminders (Wallet document expiry, itinerary items, pilgrimage countdown) computed entirely on your device, and to deliver push notifications via Firebase Cloud Messaging (see below).
  • Camera — Umrī never accesses your camera directly. Adding a document photo to your Wallet opens your phone's own camera app via the standard Android system picker; Umrī only receives the resulting image.

Family Link (opt-in)

If you choose to create or join a Family Link code, your display name, current pilgrimage type, and a last-updated timestamp are stored in our Firebase database under that code so other devices with the same code can see them. This is intentionally lightweight — there are no accounts, and no other profile data is uploaded.

Known limitation: a Family Link code works like a shared passcode — anyone who has the code can read or write that code's member list. Treat a Family Link code the way you'd treat a Wi-Fi password: share it only with people you're actually travelling with, not publicly.

Push notifications

If you set a planned pilgrimage date, your device's Firebase Cloud Messaging token, pilgrimage type, target date, and notification preference are stored so we can trigger a milestone reminder at the right time. We do not store your name or any other profile detail alongside this.

Content updates

Some in-app content (lesson text, duʿās, Ziyārah site info) can be refreshed from our Firebase database without an app update. This is a one-way, read-only content feed — nothing personal is sent as part of it.

What we don't do

  • We don't run ads, and there is no advertising SDK in this app.
  • We don't use third-party analytics or tracking SDKs. A small on-device event log used for our own feature-usage debugging never leaves your phone.
  • We don't sell or share your data with any third party for marketing.
  • We don't require an account, email address, or phone number to use the core app.

Third-party services we rely on

Umrī's backend runs on Google Firebase (Cloud Messaging, Firestore). Google processes this data on our behalf as our service provider, governed by Google's own privacy policy. We don't control what Google Play Services itself collects at the OS level — see Google's policy for that.

Your choices

  • Every feature described above except core tracking is opt-in — Family Link and pilgrimage-date notifications only activate if you turn them on.
  • Uninstalling the app removes all locally-stored data. Leaving a Family Link removes your entry from that code's shared list.
  • You can revoke location, notification, or activity-recognition permission at any time in your device's system settings; the features that depend on them will simply stop working until re-granted.

Children

Umrī isn't specifically directed at children, and pilgrimage travel is generally an adult/family activity. If a family profile is created for a child, the same on-device, no-account approach applies to their data as to anyone else's.

Contact

Questions about this policy: privacy@umri.deenbook.co.uk