Legal
Privacy.
Fasih is built to work offline, and keeps your learning on your phone. This page says what stays there, what we receive, and what you can do about any of it.
The short version
Who is responsible
Fasih, of Islamabad, Pakistan, is the data controller for the personal data described here. You can reach us at thecreativejnd@gmail.com.
What stays on your device
The core of Fasih is a local app. The following is stored on your phone, and copied to our servers only if you sign in to back up and sync:
- the words you have saved, and your collections;
- your review history and the schedule built from it;
- which words you have read, your streak, and your practice results;
- your settings: tashkeel, theme, accent colour, typeface, reminder times, quiet hours and the widget.
Reminders are scheduled on your phone, and the home screen widget reads from the app on your phone, so neither needs our servers. On Pro you can export your saved words at any time. Deleting the app deletes the copy held on that device.
The app also sends usage analytics to PostHog, as section 3 describes.
What we receive
| What | Why | Kept |
|---|---|---|
| Subscription status | A receipt token from Apple or Google, so the app knows whether Pro is active. It identifies the purchase, not you. | While the subscription is active, plus the period the store requires |
| Your free trial | A one-way hash of an identifier for your device, so the free day can be used once per device. The identifier itself never leaves your phone. | While Fasih offers a free trial |
| Your account and synced data, if you sign in | Your name and email address from Google, and a copy of your saved words, collections, reading history, review schedule and settings, so another device can pick up where the first left off. | Until you delete your account, or ask us to |
| Ads, on the free plan only | When the free plan shows an ad, Google's Mobile Ads SDK sends Google your device's advertising ID, IP address, device and app details, and how you interact with the ad, so Google can choose it, show it, measure it and prevent fraud. We only see totals, like how many ads were shown. | By Google, under its own policies. We never receive it about you individually. |
| Usage analytics | How the app is used, such as the screens you open and the features you use, sent to PostHog so we can see what works and improve it. If you sign in, it is linked to your account. | Up to 12 months |
| Crash reports | The error, with your device model, OS version and app version, so we can fix it. The app sends these to PostHog, and Google Play and the App Store pass on diagnostics from people who chose to share them with developers. | Up to 12 months |
| Emails you send us | Your address and whatever you write, so we can answer you. | Up to 24 months after the conversation ends |
What we never collect
- Your card details. Apple and Google take the payment; we never see a card number.
- Your contacts, photos, microphone, or precise location. The app doesn't ask for them.
- Tracking across apps and sites. We don't follow you across other apps or websites, and we don't join our data to anyone else's.
We do not sell personal data. The free plan's ads are the one place data about your device goes to an advertising company: Google receives what section 3 describes so it can show ads. Some US state laws count that as sharing for targeted advertising. You can limit it by turning off ad personalisation or deleting your advertising ID in your phone's settings, and on iPhone Google can only use your advertising ID if you allow tracking when the app asks. The trial and Pro show no ads.
Why we are allowed to
Under the UK GDPR and the EU GDPR, we rely on:
- Contract: to give you the app you asked for, and to keep Pro working for the term you paid for.
- Consent: for reminders, for sync, and, where the law requires it, for personalised ads. You turn reminders and sync on yourself. Google's consent form asks about ads before the first one is shown, and you can change your answer in Settings under Ad privacy choices.
- Legitimate interests: to fix crashes, to see how the app is used so we can improve it, and to prevent abuse, including more than one free trial per device. We keep this to the minimum that answers the question.
- Legal obligation: tax and accounting records for purchases.
Who else touches it
We use a small number of service providers, each bound to use the data only to provide their service to us:
- Apple and Google: app distribution and payments. Their own privacy policies govern what they do as controllers of your store account.
- Supabase: the database that stores your account and synced data if you sign in, and the one-way device hashes that keep the free trial to one per device. Hosted in the EU.
- Google Sign-In: confirms who you are if you choose to sign in with Google.
- RevenueCat: records whether a purchase is active, so the app can unlock Pro. If you sign in, it also keeps your email address and the name on your Google account, so we can find your purchase when you write to us. It never sees a card number; Apple and Google handle payment.
- PostHog: usage analytics and crash reports from the app, so we can see how it is used and fix what breaks. Hosted in the US.
- Google AdMob: shows the ads on the free plan and, where the law requires it, asks for your consent first. Google acts as an independent controller for the data its ads collect; see how Google uses information from apps that use its services.
- Google Firebase Hosting: serves this website only. It is not used by the app.
- Platform diagnostics: Expo, and the App Store and Play Store, provide crash traces and aggregate delivery statistics tied to a device and build rather than to you.
We will also disclose data if the law genuinely requires it, or to establish or defend a legal claim. If we are ever bought or merged, your data moves with the app under the same terms, and we will tell you before it does.
How long we keep it
Only as long as the purpose needs. The table in section 3 gives the period for each item. Purchase records are kept for as long as tax law requires, currently six years in the UK. Anything else is deleted or anonymised when its period ends.
Where it goes
Our providers may process data outside the UK and the EEA, including in the United States. Where that happens we rely on the UK International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or an adequacy decision, together with the safeguards our providers publish. You can ask us for the detail.
Your rights
You can ask us to:
- Show you what we hold about you, and give you a copy;
- Correct anything wrong;
- Delete it, where we have no overriding reason to keep it;
- Limit or stop a particular use, including anything based on legitimate interests;
- Port it to another service in a machine-readable form;
- Withdraw consent for reminders, sync or personalised ads, which does not affect what was done before you withdrew it.
Write to thecreativejnd@gmail.com. We answer within one month, free of charge. Some of this you can do yourself and faster: export your words from the app on Pro, turn reminders off, change your ad choices in Settings, reset your advertising ID in your phone's settings, or delete the app to remove the local copy.
To delete your Fasih account and its cloud-synced data, follow the steps on our Delete account page. It explains how to request deletion by email or in the app, what is removed, what is retained, and how to clear the local copy on your devices.
If you are in California or another US state with similar law, the same rights apply to you, and we will not treat you differently for using them.
Children
Fasih is intended for people aged 13 and over and is not designed for young children. We do not knowingly collect data from a child under 13. If you believe we have, tell us and we will delete it.
Security
Traffic between the app and our services is encrypted in transit. Access to anything we store is limited to the people who need it to run Fasih. Your learning data lives on your device, so the strongest protection it has is your own device lock. Keep it on.
No system is perfectly secure. If a breach ever put your rights at risk, we will tell you and the relevant regulator within the time the law allows.
This website
This site sets no cookies and stores nothing in your browser. Fonts are loaded from Google Fonts, which means your browser's IP address reaches Google in order to fetch them. Our host, Firebase Hosting, keeps standard server logs.
Changes
When this policy changes, the date and version at the top change with it. For a change that materially affects you, we will say so in the app before it takes effect rather than quietly editing the page.
Contact and complaints
Fasih
Islamabad, Pakistan
thecreativejnd@gmail.com
If you think we have handled your data badly, please tell us first. We would rather fix it. You can also complain to the UK Information Commissioner's Office at ico.org.uk, or to the supervisory authority where you live.