Privacy Policy

 Effective Date: July 7, 2026 Applies to: All mobile applications published under the MIT Apps Google Play developer account — currently and in the future — unless a specific app links to its own separate, dedicated privacy policy in its Play Store listing.

Not covered by this policy: Apps developed for third-party clients and published under that client's own Google Play developer account (e.g. any app internally labelled "Client ...") are not covered here, even if we built them. Each client's own app needs its own privacy policy tied to their own developer identity.

Before you publish this: confirm the developer name on your Play Console listings exactly matches "MIT Apps" — Google checks that the entity named in your store listing appears in your privacy policy.

Get a lawyer involved before you ship Categories M, N, or R. This document covers privacy disclosure, but three parts of the roadmap carry legal obligations beyond what any privacy policy can satisfy on its own: sensitive health tracking (Category M — e.g. a period/cycle tracker; GDPR treats this as "special category" data requiring explicit consent, and some US states have separate health-data statutes), real money transfers between users (Category N — some jurisdictions require a money-transmitter license once you're not just taking payment for your own app, but settling balances between third parties), and apps directed at children (Category R — COPPA in the US requires verifiable parental consent for certain data practices, enforced with real fines). This policy is a strong starting point for all three; it is not a substitute for a lawyer reviewing your specific implementation before launch.


1. Scope & how this policy stays current

This policy is organized around categories of practice — what an app does — rather than a list of individual app names. When we publish a new app, it doesn't need a new policy or an edit to this one; it automatically falls under whichever categories in Section 2 describe what it actually does. This was written with our product roadmap in mind — including camera-based fitness/pose tracking, AI photo and text generation, live coaching calls, payment settlement between users, and apps built specifically for children — so most planned apps are already covered below without a launch-day edit.

We revise this document when a new category of data practice appears that isn't already described below, or — as a deliberate exception — whenever a future app would combine Category M (sensitive health data) with cloud sync for the first time; that always gets fresh, explicit opt-in consent language before any such data would leave your device, regardless of the general rule above.

To see exactly which categories apply to a specific app, check that app's Google Play "Data safety" section, its in-app Settings / About screen, and the permission prompts it actually asks you to grant.

2. Categories of apps we publish

Core practices

A — Offline utility apps. Calculators, trackers, and games with no login. Everything stays local to your device. No account, no analytics, no ads. Deleting the app removes all data.

B — Advertising. Google AdMob or Unity Ads may use your advertising ID (AAID) and device info to select and measure ads. Never used in Category R (children's) apps in this form — see Section 6. Google's Privacy Policy · Unity's Privacy Policy.

C — Analytics & crash reporting. Firebase Analytics, Crashlytics, Remote Config — anonymized usage and crash data used only to fix bugs and improve the app.

D — Accounts & cloud sync. Firebase Authentication (incl. Google Sign-In) + Cloud Firestore sync your data across devices. You can request full account & data deletion at any time.

E — In-app purchases. Optional purchases via Google Play Billing only. We never see or store your payment card details.

F — Location. Used only for the specific in-app feature that needs it (e.g. prayer times, a speed readout, geotagging a photo) — never for advertising, never sold. Where an app lets you share a location or location-tagged content with other users, that sharing is opt-in and visible to you before it happens. A location permission with no matching visible feature indicates a leftover permission to remove, not active use.

G — Camera, microphone & storage. Used only for the feature you invoke — a photo, a recording, an exported file. Not uploaded to us unless the same app is also Category D, I, or J, and then only the specific content that feature requires. Where an app uses on-device biometric unlock (fingerprint/face) to lock the app itself, that check happens through the operating system's secure biometric API — we never receive or store your fingerprint or face data.

H — Third-party content & translation lookups. A minimal, non-identifying request (e.g. a pasted video URL, or text/audio for translation) to services like RapidAPI, the AlQuran Cloud API, Google Fonts, or Google's Translate/ML Kit Translate services, solely to fetch or convert what you asked for.

AI-assisted & live features

I — AI-processing services (third-party). Some apps let you submit a photo, text prompt, or voice clip to an AI feature — background removal, cartoon/anime filters, old-photo restoration, or AI-generated workout/content plans. What you submit is sent to the named third-party AI provider (e.g. Google's Gemini API, Replicate, Stability AI, remove.bg) solely to generate the output you requested. We don't use it to train our own models, and we don't retain it longer than needed to deliver the result; each provider's own retention and training policy governs their side. See Google AI / Gemini API Terms, Replicate's Privacy Policy, Stability AI's Privacy Policy, remove.bg's Privacy Policy.

J — Live video/audio calls & real-time coaching. Where an app connects you with a human coach or instructor (e.g. via WebRTC), your camera and microphone are streamed live through relay infrastructure that passes the stream through without recording or storing it — unless the app explicitly offers a recording feature, which would be separately disclosed and opt-in.

K — On-device computer vision, motion & signal detection. Pose/posture detection, camera-based heart-rate estimation, and microphone-based sound detection (e.g. "find my phone by clapping," a decibel meter) are all processed locally on your device using on-device ML models. Camera frames and audio are analyzed in real time and are not uploaded or stored for this purpose.

Health & fitness data

L — Fitness & self-reported activity data. Height, weight, fitness goals, step counts, workout logs, and calorie/food entries are used only to power that specific app's own tracking features. Stored locally by default; synced to the cloud only if that same app is also Category D.

M — Sensitive health tracking. A smaller set of apps (e.g. a menstrual/cycle tracker) collect more sensitive self-reported health data. For these apps specifically: data is stored locally on your device only, is never sold, never shared with advertisers or data brokers, and is never linked to an advertising identifier. Clearing the app's data or uninstalling it deletes it completely, since we hold no server-side copy. See the note in Section 1 about what happens if this ever changes.

We do not collect government ID numbers, full financial account credentials, or clinical health records (diagnoses, prescriptions, lab results) in any app. Categories L and M above are the outer bound of health-adjacent data we handle, and only in the specific apps that need them.

Money & other people

N — Payments & money transfers between users. For apps that go beyond a simple app purchase — e.g. settling a shared bill between users — real transactions are processed by a licensed payment processor (Stripe, PayPal, Razorpay, JazzCash, EasyPaisa) or Google Play Billing. We never store your full card or bank account credentials — the processor does, under its own policy. We keep a transaction ledger (amounts, participants, dates) only to power the app's own balance/settlement feature.

O — Information you provide about other people. Guest lists, split-bill participants, or birthday contacts: information you enter about someone else (their name, email, or phone number) is used only to deliver the specific feature you used it for — e.g. sending an invitation — and is not used to build a profile of that person or to market to them directly.

P — Third-party account linking & external cloud storage. Where an app lets you connect an external account — Google Drive, OneDrive, Spotify — via that provider's own sign-in flow (OAuth), we only request the access needed for the feature you're using and never see your password or credentials for that external service.

Q — Recovered or device-scanned files. Apps that scan your device's storage (e.g. to recover deleted photos) only read what's already on your device. Recovered files stay on your device and are only uploaded if you explicitly choose a cloud-backup feature (Categories D/P).

Apps directed at children

R — Apps directed at children. See Section 6 for the full set of rules that apply to every app in this category.

3. Data security

We use reasonable technical and organizational measures appropriate to our app portfolio: local, on-device storage by default (Categories A/G/L/M), and encryption of backup data for any Category D app that offers cloud backup. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.

4. Data retention

  • Locally stored data (Categories A, F, G, H, K, L, M, Q) stays on your device until you delete the app or clear its storage — we never hold a copy ourselves.
  • Cloud-stored data (Category D) is retained until you delete your account or request deletion, then removed from our active systems within a reasonable period.
  • Transaction records (Category N) are retained as required for accounting/tax purposes even after account deletion, separately from other profile data.
  • Content sent to a third-party AI provider (Category I) is retained only as long as that provider's own policy specifies for processing your request.

5. Your rights (GDPR, UK GDPR, CCPA/CPRA and similar laws)

If you're in the EEA, UK, California, or another jurisdiction with similar protections, you may have the right to:

  • Access the personal data we hold about you;
  • Request correction or deletion of your data;
  • Request a portable copy of your data;
  • Object to or restrict certain processing;
  • Withdraw consent at any time, where processing is consent-based — this applies in particular to Category I (AI processing) and Category M (sensitive health data), which we only process based on your affirmative action within the app.

We do not sell your personal information, and do not share it with third parties for their own independent marketing. To exercise any right above, contact talhashapp@gmail.com. For any app that only falls under Categories A/F/G/H/K/L/M/Q, deleting the app or its data from your device already accomplishes full deletion.

6. Children's privacy

General-audience apps (everything except Category R) are designed for users aged 13 and older. We do not knowingly collect personal information from children under 13 through them.

Apps in Category R are built specifically for children, and follow additional rules required by COPPA and Google Play's Families Policy:

  • No behavioral or interest-based advertising, and no use of the advertising identifier (AAID). Any ads use child-directed, Families-Policy-certified settings only — or the app carries no ads at all.
  • No account sign-in requiring personal information. Where an optional feature would ever need it, we obtain verifiable parental consent first.
  • Data collection is limited to what the app's core educational or entertainment function needs — typically nothing beyond progress saved locally on-device.
  • Parents or guardians can contact talhashapp@gmail.com at any time to review, correct, or request deletion of information collected from their child.

If you believe a child has provided us with personal information outside of these safeguards, contact us and we will take steps to delete it.

7. International data transfers

Where an app uses cloud services (Firebase/Google Cloud — Category D) or a third-party AI provider (Category I), your information may be processed on servers outside your country of residence, including the United States, under the data protection safeguards those providers maintain.

8. Changes to this policy

We update this policy when we introduce a genuinely new category of data practice, or for legal-compliance reasons — not for every new app release. The one standing exception is described in Section 1 (Category M gaining cloud sync). Material changes are reflected by an updated effective date at the top of this page. Continued use of an app after changes take effect constitutes acceptance of the revised policy.

9. Contact us

MIT Apps Email: talhashapp@gmail.com

10. Apps currently published under this policy

For the current, authoritative list of every app this policy covers, see our Google Play developer page: [insert your Play Store "developer page" URL here — e.g. play.google.com/store/apps/dev?id=XXXXXXXXXXXXXXXXXXX]. That listing updates automatically every time we publish or remove an app.

As of the effective date above, this includes: Daily Planner, Deen Tracker, Habit Tracker, Health Tracker, 2048, HD Video Saver and Downloader, TikSave IO, Zakat Calculator, Tik Downloader: No Watermark, VAT Calculator, Finance Tracker Pro, My Coach (Category D, G, I, J, K, L), Shazi Life Tracker, Shazi TikSave Pro, Splitwise, Zen Bonsai, and Resume Builder - CV Maker. (Illustrative only — the linked developer page is authoritative.)

11. Exceptions

(None currently.) If a future app needs to deviate from Section 2 in a way not already anticipated there, we'll document that exception here, or give that app its own separate policy, rather than changing the general rules for everything else.