MishMish app privacy policy

MishMish helps you record and organize your personal Islamic practice. This policy explains information used by the mobile app and how to control optional usage analytics or request deletion.

The app and this website

This policy covers the MishMish mobile app, published by Karim Karim. Optional app usage analytics start only after you choose to allow them and can be turned off at any time. Analytics on this website is separate: Google Analytics loads only after you accept it. See website privacy and cookies for browser choices. Changing website cookie preferences does not change your choice inside the app.

Your saved record

MishMish saves prayer marks, personal practices, adhkar progress, routines, prayer-day and pause records, settings, companion awards and room arrangements in Firebase under an account identifier. This includes custom practice and routine names. These records and prayer calculation choices can reveal religious beliefs and practice.

A guest account is created automatically. Firebase maintains this installation’s connection to the saved record. This release has no sign-up or sign-in screens. Clearing app data or reinstalling may lose access to the record. Restoring a store purchase does not restore a lost prayer or practice record.

Location and prayer times

Your chosen city or device location coordinates, city label, time zone, prayer calculation choices and language are saved in Firebase. Prayer times are calculated on your device. Location in historical prayer-day records is retained so past records keep their original prayer windows.

Device location is requested only when you choose to use it. You can choose a city instead. Android requests approximate location. There is no background location tracking.

When room weather is enabled, MishMish sends a coarse forecast area to its Firebase service, which retrieves and caches MET Norway forecasts. MET Norway receives the server request, not your app account identifier or device IP. An account-scoped request counter limits abuse. Forecast coordinates are not sent to product analytics.

Optional usage analytics: your choice

Optional usage analytics stay off until you explicitly allow them during setup or in Self. A previous refusal is preserved. An older default-on setting without an explicit consent choice does not enable analytics in the release described here. When enabled, PostHog receives your app account identifier, app and device information, screen and feature interactions, practice activity and experiment assignments. Analytics can also include the offers shown to you and purchase/subscription lifecycle events, subject to your analytics choice. These events can include trial, purchase, renewal, cancellation and refund status, product and store, amount and currency, event times and hashed transaction references. This helps us understand app use, evaluate features and improve the app.

You can turn off Allow optional usage analytics in Self at any time. The app does not send custom practice text or saved location coordinates to product analytics. Turning analytics off does not delete previously collected data; contact support to request deletion.

When analytics is enabled, RevenueCat can receive paywall impressions and limited language, app-distribution and measurement-version attributes to evaluate offers. Your purchase-measurement choice is synchronized with our server; changes take effect there when synchronization completes. The app clears the optional targeting attributes when you opt out. Disabling optional analytics does not stop Firebase from saving your practice record or RevenueCat from managing purchases and Pro access.

Crash diagnostics and technical information

In versions with crash reporting enabled, Sentry receives crash and hang diagnostics to help diagnose problems. Automatic personal-information collection is disabled and diagnostic content is redacted. Crash reports are configured to exclude your app account identifier, saved practice text and location. Screenshots and view-hierarchy capture are disabled. The optional usage-analytics switch is not a switch for core service processing or crash diagnostics.

Service providers also process technical information needed to operate and secure their services, such as app or installation identifiers, software versions and network information. Firebase uses an account identifier for authentication and may process IP addresses for security and abuse prevention. These are not advertising identifiers.

Notifications and app blocking

Prayer notifications are scheduled on your device. Your operating system controls permission and delivery.

On supported Android builds, optional app blocking uses Accessibility access to detect which app is in front and cover only apps you selected during Focus. It does not read screen text, passwords, messages or screen contents. Your selected-app list stays on the device and is not sent to product analytics. MishMish, Settings, phone and essential system apps are excluded. You can revoke Accessibility access in Android settings. On iOS, optional blocking uses Apple’s device app-selection and restriction controls.

Purchases

Apple or Google handles payment. RevenueCat receives your app account identifier and purchase and entitlement information to manage Pro access and subscription reporting. MishMish does not receive payment card details. Deleting the app or its account does not cancel a store subscription.

Service providers and security

Firebase supplies authentication, saved-record storage and account tools; RevenueCat manages purchase access; PostHog supplies optional usage analytics; Sentry handles crash diagnostics in versions where reporting is enabled. These providers process information to supply their services and may process information outside your country.

The app uses encrypted connections to send information to its services. Saved records are associated with your app identity; they are not a public profile or shared with other MishMish users.

Access, correction, retention and deletion

Use Self → Your data to export your synced record or request account deletion. An export is a readable copy, not an importable backup. You can also request access, correction or deletion by email. We may need information identifying the relevant app record before we can act. The deletion instructions explain the available routes, including without the app.

A confirmed deletion request blocks further account use and queues erasure from Firebase and relevant processors. The request reference helps support follow processing that remains. Confirmation does not mean all erasure has finished. Provider records, backups and information needed to handle a request can have separate retention or legal obligations. Contact support for retention information or the status of a particular request.

Contact

For support and privacy requests, contact Karim Karim at krayem.karim@gmail.com.