Niyyah Privacy Policy

Version 1.0 (Beta) · Effective 16 July 2026 · Last updated 16 July 2026

This policy explains what personal data Niyyah collects, why, how we protect it, and the rights you have over it. We've written it in plain English. Niyyah is a Muslim marriage app that helps you find a spouse through profiles, matching, messaging, and scheduled calls.

Beta notice. Niyyah is currently in private beta. Some details in this policy (such as exact data-retention periods) are provisional and will be finalised before Niyyah's public launch.

Who we are (data controller)

Data controller: Niyyah, operated by Harres Khan (sole trader), based in Birmingham, UK. Contact: admin@niyyahapp.co.uk. This service is currently in beta. Formal business registration and ICO registration will be completed before public launch.

Who can use Niyyah

Niyyah is strictly for adults aged 18 or over. We ask for your date of birth during sign-up, and accounts identified as under 18 are removed. If you believe someone under 18 is using Niyyah, please report them in the app or email admin@niyyahapp.co.uk.

What we collect and why

We only collect what we need to run the service. Here is what we collect, grouped by purpose.

1. Creating your account

2. Your profile and matching

3. Messaging

4. Video and voice calls

5. Notifications

6. Safety and moderation

7. Your guardian (wali)

8. Analytics and technical data

Special category data — your religious beliefs

Information about your religious beliefs and practice is "special category" data under UK GDPR (Article 9) and gets extra protection. Niyyah is a Muslim marriage app, so this information is central to matching.

We process it on the basis of your explicit consent (Article 9(2)(a)). By choosing to provide these details to build your matchmaking profile, you give your explicit consent for us to use them to power matching and show them on your profile to other members. You can withdraw this consent at any time by editing or deleting the information, or by deleting your account.

Your photos

Identity verification (not yet active)

We plan to introduce optional face "liveness" verification later during the beta to help confirm that profiles are real people. This is not currently active, and no biometric data is collected at this time. When we enable it, verification will be carried out by Amazon Web Services in Ireland (EU), we will store only the result of the check (not a biometric template or face image), and we will notify you in the app and update this policy before it goes live.

Analytics — our lawful basis and your choice

During the beta we process the basic usage analytics described above on the basis of our legitimate interests (Article 6(1)(f)) — understanding how the app is used so we can improve it. This data is limited to behavioural events, a pseudonymous identifier, and coarse non-identifying groupings (such as an age band or broad region).

You can object to analytics processing at any time by emailing admin@niyyahapp.co.uk, and we will honour your request.

Before Niyyah's public launch we intend to add an in-app consent control for analytics.

Our lawful bases for processing (UK GDPR Article 6)

PurposeLawful basis
Creating your account and delivering the core service (profile, matching, messaging, calls)Performance of a contract (Art. 6(1)(b))
Using your religious-practice details for matching and on your profileExplicit consent (Art. 9(2)(a))
Using your location, and sending push notificationsConsent (Art. 6(1)(a)) — via your device permissions
Analytics and improving the appLegitimate interests (Art. 6(1)(f))
Safety, moderation, reports and blocksLegitimate interests (Art. 6(1)(f)) — keeping members safe
Sending a wali invitation you requestLegitimate interests (Art. 6(1)(f))

Who we share data with (processors)

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract, to run Niyyah:

ProviderWhat they processWhere
SupabaseSign-in, database, photo storage, real-time messaging, backend functionsEuropean Union (Frankfurt, Germany)
AgoraLive audio/video call media (not stored)Global routing; media may transit outside the UK/EU
Apple (Push Notifications)Delivery of push notifications to your deviceApple infrastructure
ResendSending emails (e.g. wali invitations, safety notifications to our team)United States
PostHogProduct analytics (behavioural events + pseudonymous ID)European Union
FeaturebaseIn-app feature-request board — receives only an anonymised user identifier, no name, email, or profile dataLocation of processing is being confirmed and will be updated in this policy
GoogleSign in with Google, if you choose itUnited States
AppleSign in with Apple, if you choose it; app distributionApple infrastructure
Amazon Web ServicesFace liveness verification — not yet active (see above)European Union (Ireland)

International data transfers

Your core data (account, profile, photos, messages) is stored in the European Union. Some providers listed above (for example Agora, Resend and Google) are based in, or route data through, the United States or other countries outside the UK/EU. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses, together with the UK "data bridge" / adequacy arrangements where they apply.

How long we keep your data

These retention periods are provisional during the beta and will be finalised before public launch:

DataRetention
Account and profile dataKept while your account is active; deleted within 30 days of you deleting your account
MessagesKept while both people have active accounts and the match is active; deleted when either account is deleted
Call metadataUp to 12 months for safety and moderation, then anonymised
Reports and moderation recordsUp to 24 months for safety — retained even after account deletion (see below)
BackupsEncrypted backups may retain personal data for up to 90 days after deletion, after which they are overwritten

Reports and moderation

To keep members safe, we retain reports and related moderation records even after an account is deleted. This lets us detect and prevent repeat bad actors who might otherwise delete and recreate accounts. We do this on the basis of our legitimate interests in protecting our community. We keep this data for no longer than necessary for that purpose (up to 24 months).

Cookies and tracking

The Niyyah app does not use cookies. Our analytics tool uses a device/user identifier to tell sessions apart, as described above. Our website (niyyahapp.co.uk) is a simple informational site; it does not use advertising or cross-site tracking cookies.

Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email admin@niyyahapp.co.uk. We aim to respond within 30 days. Deleting your account in the app also triggers deletion of your data as described above.

How we protect your data

We use access controls and encryption in transit and at rest, keep profile photos in private storage behind short-lived signed links, and limit who and what can access your data. No system is perfectly secure, but we take reasonable steps to protect your information.

Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it where required, and we will inform affected users without undue delay where the breach is likely to result in a high risk to them.

Changes to this policy

We may update this policy as Niyyah develops. When we make a significant change, we will update the version and date at the top and, where appropriate, notify you in the app or by email. Continued use of Niyyah after an update means you accept the revised policy.

Contact us

For any privacy question, request, or complaint: admin@niyyahapp.co.uk.