1. Introduction
Welcome to Misbaha — مسبحة. This Privacy Policy explains how information is processed when you use the Misbaha mobile application and its related Sakina service.
Misbaha provides a digital Tasbih and Dhikr experience, including counting, Adhkar, statistics, customization, reminders, widgets, a floating counter, sharing tools, rewards, and Qur’anic reflection through Sakina.
2. Information stored on your device
Most core Misbaha information is stored in the app’s private storage on your device so that your settings and progress remain available between sessions.
Android backup is enabled for one app preferences file. If Android backup is enabled for your device, Google or your device provider may copy that file to your cloud backup and restore it on another device. This is controlled by your Android backup settings, not by a Misbaha account.
- Tasbih counts, rounds, targets, history, daily progress, streaks, and per-Dhikr statistics
- Selected, favorite, and custom Dhikr text
- Language, sound, vibration, bead, color, background, and other appearance preferences
- Reminder schedules, notification preferences, widget state, and floating-counter settings
- Journey, collection, achievement, reward, and feature-use progress
- Reflection notes if that optional feature becomes available and you choose to use it
3. Custom Dhikr and statistics
Custom Dhikr and detailed Dhikr statistics are stored in the Android preferences file described above. Misbaha does not intentionally send their text or detailed counts to the Misbaha Sakina server, Firebase events, or advertising requests.
They may leave the device only through an Android backup you have enabled or when you deliberately export or share content using the device’s sharing tools. Avoid entering information you consider highly sensitive into free-form fields.
4. Analytics
The Android app uses Google Analytics for Firebase. Firebase automatically measures general app activity and Misbaha records feature, navigation, notification, reward, advertising, and sharing events to understand reliability and improve the product.
Analytics may process app and device information, a per-installation identifier, app version, operating-system information, language, session and interaction events, and developer-defined event parameters. Misbaha does not intentionally place custom Dhikr text or Sakina messages in analytics events.
The audited Android app starts Firebase Analytics without an in-app analytics opt-out control.
5. Crash and diagnostic information
Release builds use Firebase Crashlytics to diagnose crashes, non-fatal errors, and stability problems. Crashlytics can process stack traces, relevant application state, device metadata, a Crashlytics installation identifier, session information, and Analytics breadcrumbs immediately before a crash.
Misbaha adds technical advertising lifecycle breadcrumbs and error messages to some reports. The audited code does not intentionally attach custom Dhikr text or Sakina messages to Crashlytics. Crash reporting is disabled in debug builds and enabled in release builds.
6. Advertising
Misbaha uses Google AdMob / Google Mobile Ads and may show banner, native, interstitial, rewarded, rewarded-interstitial, and app-open ads. The Mobile Ads SDK is initialized when the app starts.
According to Google’s Mobile Ads disclosure, the SDK automatically collects and shares IP address, product interactions, diagnostic information, and device or account identifiers—including the Android advertising ID and app set ID where available—for advertising, analytics, and fraud prevention. IP address may be used to estimate general location.
Misbaha does not request Android precise or coarse location permissions. Any general location associated with ads or network services is inferred from network information rather than GPS permission.
7. Advertising consent and privacy choices
The audited Android source does not contain a Google User Messaging Platform (UMP) consent form or a separate in-app advertising privacy-options screen. Ads may therefore be requested according to Google’s SDK behavior, account settings, device settings, region, and ad-serving configuration.
You can reset or delete the Android advertising ID and manage ad personalization in your Android or Google settings. You may disable notifications in system settings and disable reminders or the floating counter in Misbaha settings.
8. Notifications
Misbaha schedules reminders and smart notifications locally using Android alarms and WorkManager. It may request notification permission, exact-alarm access, vibration, and permission to restore schedules after a device restart.
No Firebase Cloud Messaging SDK or remote-push service was found in the audited Android app. Notification interaction events and technical delivery status may be sent to Firebase Analytics, but notification content is selected locally.
9. Remote Config and App Check
Firebase Remote Config is used to change feature and product settings without an app update. Google states that Remote Config processes country code, language, time zone, platform and OS version, Firebase App ID, package name, SDK version, and a Firebase installation ID.
Firebase App Check with Google Play Integrity protects the Sakina API from abuse. It processes a Firebase user agent and an integrity token. Misbaha sends the resulting App Check token to its Sakina server with each protected request.
10. Sakina
Sakina is an optional feature inside Misbaha that provides relevant Qur’anic verses, simple reflections, and a suitable Dua based on text you choose to submit. It is intended for spiritual reflection and is not professional medical, psychological, legal, financial, or religious-ruling advice.
When you submit a Sakina request, the app sends your message, language, and provider selection over HTTPS to the Misbaha server at misbaha.hassanjaber.dev. It also sends a Firebase App Check token. The server receives ordinary network metadata such as your IP address and uses IP address for rate limiting.
The server adds curated Qur’anic context and sends the request to OpenAI through the Responses API. The production server’s public health endpoint identifies OpenAI as the active provider. The request is configured with store set to false.
The server code defaults to a zero-second cache for personalized Sakina responses, but the production cache environment value was not inspected. Its application request log records method, path, status, duration, and request ID—not the submitted message. Provider or unexpected error logs may contain technical error messages, and hosting infrastructure may keep separate network logs under its own retention practices.
The Android client keeps the current prompt and answer in memory for the active screen and does not save them to its persistent Sakina usage store. Debug builds can log up to the first 300 characters of a server response; release builds do not perform that debug log.
OpenAI states that API data is not used to train its models by default unless the API customer opts in. OpenAI may retain prompts, responses, and derived metadata in abuse-monitoring logs for up to 30 days by default, unless approved data-retention controls apply or longer retention is required for safety or legal reasons. We have not verified that the production OpenAI account has Zero Data Retention or that optional data sharing is disabled, so we do not promise zero provider retention.
11. Widgets, floating counter, and sharing
The home-screen widget and optional floating counter read local count and Dhikr state to provide their functions. The floating counter requires Android’s display-over-other-apps permission and runs as a foreground service while enabled. These features are not designed to read content from other apps.
When you create or share an image, video, text, or achievement, Misbaha creates the requested file locally and passes it to Android’s share sheet or saves it where you choose. The destination app or service then handles the shared content under its own privacy practices.
12. Accounts and information not requested
The audited Android app has no user-account system, Firebase Authentication, Firestore, Firebase Storage, Firebase Performance Monitoring, contact access, camera access, microphone access, or GPS location permission.
Misbaha does not ask you to provide a legal name, postal address, phone number, government identifier, contacts, payment-card details, photos, or recordings as part of its core app experience.
13. Third-party services
The audited Android app uses Google Analytics for Firebase, Firebase Crashlytics, Firebase Remote Config, Firebase App Check with Play Integrity, Google Mobile Ads, Google Play in-app update and review services, and OpenAI for Sakina. Android backup and hosting infrastructure may also process data as described in this policy.
These providers process information under their own terms and privacy policies. Misbaha does not sell your personal information. Data is transferred to service providers only to operate features, show and measure ads, analyze usage, diagnose failures, protect the service, and comply with law.
14. Retention
Local app data remains until you delete an item, use an available reset control, clear app storage, or uninstall Misbaha. An Android cloud backup may remain according to your Google or device-provider backup settings and can restore the included preferences file later.
Misbaha does not set Firebase, Google Ads, Hostinger, or OpenAI retention periods. Those services retain information under their configurations and policies. Sakina provider retention is described above; no broader or shorter retention promise is made.
15. Deleting your information
You can delete individual custom Dhikr entries, reset statistics where the app provides that control, clear all app storage from Android settings, or uninstall the app. You can manage or delete Android backups through your device and Google account settings.
Misbaha has no account that can be deleted. The Sakina server does not create a user account and its application request log excludes prompts. Because production cache and hosting-log retention were not verified, contact Misbaha Support if you have a request concerning identifiable developer-controlled information.
16. Security and international processing
Misbaha uses HTTPS for Sakina and disables cleartext network traffic in the Android app. App Check protects the Sakina endpoint, and app data is stored in Android’s private app storage. No system can be guaranteed completely secure.
Google, OpenAI, hosting providers, and other service providers may process information in countries other than yours, subject to their infrastructure, contractual terms, and applicable safeguards.
17. Children’s privacy
Misbaha is a general devotional app and is not designed to create profiles of children. We do not knowingly ask children to provide direct contact information.
The app nevertheless includes third-party advertising and analytics SDKs. A parent or guardian should supervise a child’s use and device privacy settings. Advertising configuration and consent requirements must be reviewed for every region and intended audience before distribution.
18. Your rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or information about certain processing. Many Misbaha records are held only in your device storage and can be controlled directly by you.
To ask about developer-controlled information or exercise an applicable right, contact us using the address below. We may need enough information to understand and verify your request, but we will not ask for unnecessary information.
19. Changes to this policy
We may update this policy when features, SDKs, service providers, configurations, or legal obligations change. The revised policy will show a new Last Updated date. Material changes should be published before or when the related feature is released.
20. Contact us
For questions, concerns, or privacy requests, contact Misbaha Support using the email address or Support page linked below.
Official service information
These official pages explain the practices of services used by Misbaha: