Privacy Policy
Hisab is a private daily muḥāsaba (self-accounting) journal. Privacy is the point of the product, not an afterthought. This policy explains exactly what we do and do not collect.
The short version
- Your journal, every reflection and every score, is end-to-end encrypted on your device before it ever leaves it. We store only unreadable ciphertext. We cannot read your journal, and neither can anyone who compromises our servers.
- We do not sell your data, show ads, or use third-party advertising/analytics trackers.
- The only personal data we can actually read is your email address (so you can sign in and reset your password) and non-sensitive routing metadata (which dates have entries) needed to sync and draw your calendar.
- You can export all your data and delete your account at any time, from inside the app.
What we collect and why
1. Account data (readable by us)
- Email address, used to create your account, sign you in, and send password-reset codes.
- Password, stored only as a salted hash by our auth provider; we never see it in plaintext.
2. Your journal content (encrypted, NOT readable by us)
- Your reflection notes, all category scores, weakness labels, and excusal notes are encrypted on your device with a key derived from your encryption passphrase (which we never receive), then synced as ciphertext. We hold an encrypted copy of your data key that we cannot unlock.
- Because of this design, if you lose both your passphrase and your 12-word recovery phrase, your encrypted entries cannot be recovered by anyone, including us.
3. Routing metadata (readable by us, non-sensitive)
- For each entry we store, in plaintext, only what’s needed to sync and organize: an entry id, your user id, the entry date, created/updated timestamps, an encryption-version flag, and a cryptographic nonce. This lets your calendar and consistency counts work without revealing content.
4. On-device data (never leaves your device)
- A local copy of your journal (so the app works fully offline), and your app settings (theme, language, gender, check-in style, reminder time, app-lock preference).
- Approximate location, only if you opt in, used solely on your device to match the optional Dynamic theme to your local sunrise/sunset. It is never transmitted to us or anyone; if you decline, we fall back to your device time zone.
5. What we do NOT collect
- No advertising identifiers, no third-party ad/analytics SDKs, no behavioral tracking, no contact list, no social graph. Hisab has no feed, no leaderboards, and no sharing.
6. On-device intelligence
- The reflections and insights Hisab shows are generated on your device. Nothing about your journal is sent to any cloud AI service.
How your data is processed and who else is involved
We use a small number of service providers (“processors”) strictly to operate the app:
- Supabase: database, authentication, and hosting of your account + encrypted data, protected by row-level security so you can only ever access your own rows.
- Resend: sends transactional email only (password-reset codes). No marketing email.
- Cloudflare: domain and DNS for
dailyhisab.app(and email routing for our contact address). - Expo / EAS: app builds and over-the-air app updates.
- Apple App Store / Google Play: app distribution (subject to their own privacy policies).
Your encrypted journal content remains ciphertext to all of the above.
We use your email only for account authentication and password resets (transactional). We do not send marketing email.
Data retention and your choices
- Export: export all your data to a file from Settings at any time.
- Delete: “Delete all my data” / account deletion removes your entries and account data from your device and our servers. Encrypted backups already written may persist briefly in routine system backups before rotating out.
- We retain your data until you delete it or close your account.
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing (e.g. under GDPR or CCPA). Because your journal is end-to-end encrypted, we are technically unable to access its contents to fulfil a content-based request, but you can export or delete it yourself in-app at any time. To exercise other rights, contact us at support@dailyhisab.app.
Security
End-to-end encryption (XChaCha20-Poly1305 with an Argon2id-derived key), row-level security on the server, transport encryption (HTTPS/TLS), and an optional biometric app lock. No system is perfectly secure, but our zero-knowledge design means a server breach exposes only unreadable ciphertext.
Children
Hisab is not directed to children under 13 and we do not knowingly collect their data.
International transfers
Your account data and encrypted content may be processed in the regions where our providers operate. We rely on those providers’ safeguards for any cross-border transfers.
Changes to this policy
We may update this policy; we will post the new version here and update the effective date. Material changes will be surfaced in-app or by email where appropriate.
Contact
Questions or requests: support@dailyhisab.app · Hisab · Ontario, Canada