Privacy Policy
Last updated: April 20, 2026
This policy explains what Masjid.ly (“we”, “us”, “the app”) collects, why we collect it, and what choices you have. Masjid.ly is a consumer iOS app that helps you discover events and programs at local masjids. We are privacy-first by design — we collect as little as possible and never sell your data.
1. What we collect
- Account data (optional): If you choose to sign in, we store your email and a hashed password. You can use most of the app without an account.
- Profile preferences: Followed masjids, followed scholars, saved events, audience filter (brothers / sisters / family / all), and notification preferences — stored so they sync across reinstalls.
- Approximate location (optional): If you grant location access, we use your coarse location only on your device to sort masjids by distance. We do not store your precise GPS coordinates on our servers. You can deny or revoke this permission anytime in iOS Settings.
- Push token (optional): If you enable notifications, we store an Expo push token so we can send reminders for events you've RSVP'd to and events near you.
- Diagnostic data: Basic error logs and counts of API calls. These are not tied to your identity.
2. What we do NOT collect
- We do not collect your name, phone number, contacts, photos, or social graph.
- We do not track you across other apps or websites.
- We do not use third-party advertising SDKs.
- We do not sell or rent any user data to anyone, ever.
3. How we use the data
We use the data above exclusively to operate the app: showing you events, sorting masjids by distance, sending the notifications you opted into, and syncing your preferences across devices.
4. Event data
Event listings are gathered or submitted from public masjid websites, newsletters, and official social-media posts. We make a best effort to attribute each event to the correct source masjid. If you believe an event is incorrect or should be removed, please contact us at ss4108@rutgers.edu.
5. Children
Masjid.ly is rated 4+. It does not collect personal information from anyone, including children. Parents are welcome to use it with their kids to discover family-friendly events.
6. Data retention and deletion
You can delete your account at any time from Settings → Account → Delete my account inside the app. When you do so:
- Your account, saved events, followed masjids, followed scholars, and notification preferences are permanently deleted from our database within 7 days.
- Your push token is invalidated immediately.
- Event listings themselves are not user-generated and are unaffected.
If you can't use the in-app flow, email ss4108@rutgers.edu from the address tied to your account and we will delete it within 7 days.
7. Security
Passwords are stored only as salted hashes (PBKDF2). All API traffic between the app and our servers is encrypted over HTTPS.
We store session tokens in Apple's iOS Keychain via expo-secure-store.
8. Third-party services
- Expo / EAS — app delivery and push notifications.
- Railway — hosts our backend API.
- Apple Maps — renders the masjid map.
- Aladhan — daily prayer times by city.
We only send these services the minimum data required to deliver their feature.
9. Changes to this policy
If we change this policy, we'll update the “Last updated” date above and, when changes are material, surface a notice inside the app the next time you open it.
10. Contact
Questions, concerns, or takedown requests? Email ss4108@rutgers.edu. We usually reply within 2 business days.
© 2026 Masjid.ly. Made in New Jersey, for the community.