This policy explains what personal data Niyyah collects, why, how we protect it, and the rights you have over it. We've written it in plain English. Niyyah is a Muslim marriage app that helps you find a spouse through profiles, matching, messaging, and scheduled calls.
Data controller: Niyyah, operated by Harres Khan (sole trader), based in Birmingham, UK. Contact: admin@niyyahapp.co.uk. This service is currently in beta. Formal business registration and ICO registration will be completed before public launch.
Niyyah is strictly for adults aged 18 or over. We ask for your date of birth during sign-up, and accounts identified as under 18 are removed. If you believe someone under 18 is using Niyyah, please report them in the app or email admin@niyyahapp.co.uk.
We only collect what we need to run the service. Here is what we collect, grouped by purpose.
Information about your religious beliefs and practice is "special category" data under UK GDPR (Article 9) and gets extra protection. Niyyah is a Muslim marriage app, so this information is central to matching.
We process it on the basis of your explicit consent (Article 9(2)(a)). By choosing to provide these details to build your matchmaking profile, you give your explicit consent for us to use them to power matching and show them on your profile to other members. You can withdraw this consent at any time by editing or deleting the information, or by deleting your account.
We plan to introduce optional face "liveness" verification later during the beta to help confirm that profiles are real people. This is not currently active, and no biometric data is collected at this time. When we enable it, verification will be carried out by Amazon Web Services in Ireland (EU), we will store only the result of the check (not a biometric template or face image), and we will notify you in the app and update this policy before it goes live.
During the beta we process the basic usage analytics described above on the basis of our legitimate interests (Article 6(1)(f)) — understanding how the app is used so we can improve it. This data is limited to behavioural events, a pseudonymous identifier, and coarse non-identifying groupings (such as an age band or broad region).
You can object to analytics processing at any time by emailing admin@niyyahapp.co.uk, and we will honour your request.
| Purpose | Lawful basis |
|---|---|
| Creating your account and delivering the core service (profile, matching, messaging, calls) | Performance of a contract (Art. 6(1)(b)) |
| Using your religious-practice details for matching and on your profile | Explicit consent (Art. 9(2)(a)) |
| Using your location, and sending push notifications | Consent (Art. 6(1)(a)) — via your device permissions |
| Analytics and improving the app | Legitimate interests (Art. 6(1)(f)) |
| Safety, moderation, reports and blocks | Legitimate interests (Art. 6(1)(f)) — keeping members safe |
| Sending a wali invitation you request | Legitimate interests (Art. 6(1)(f)) |
We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract, to run Niyyah:
| Provider | What they process | Where |
|---|---|---|
| Supabase | Sign-in, database, photo storage, real-time messaging, backend functions | European Union (Frankfurt, Germany) |
| Agora | Live audio/video call media (not stored) | Global routing; media may transit outside the UK/EU |
| Apple (Push Notifications) | Delivery of push notifications to your device | Apple infrastructure |
| Resend | Sending emails (e.g. wali invitations, safety notifications to our team) | United States |
| PostHog | Product analytics (behavioural events + pseudonymous ID) | European Union |
| Featurebase | In-app feature-request board — receives only an anonymised user identifier, no name, email, or profile data | Location of processing is being confirmed and will be updated in this policy |
| Sign in with Google, if you choose it | United States | |
| Apple | Sign in with Apple, if you choose it; app distribution | Apple infrastructure |
| Amazon Web Services | Face liveness verification — not yet active (see above) | European Union (Ireland) |
Your core data (account, profile, photos, messages) is stored in the European Union. Some providers listed above (for example Agora, Resend and Google) are based in, or route data through, the United States or other countries outside the UK/EU. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses, together with the UK "data bridge" / adequacy arrangements where they apply.
These retention periods are provisional during the beta and will be finalised before public launch:
| Data | Retention |
|---|---|
| Account and profile data | Kept while your account is active; deleted within 30 days of you deleting your account |
| Messages | Kept while both people have active accounts and the match is active; deleted when either account is deleted |
| Call metadata | Up to 12 months for safety and moderation, then anonymised |
| Reports and moderation records | Up to 24 months for safety — retained even after account deletion (see below) |
| Backups | Encrypted backups may retain personal data for up to 90 days after deletion, after which they are overwritten |
To keep members safe, we retain reports and related moderation records even after an account is deleted. This lets us detect and prevent repeat bad actors who might otherwise delete and recreate accounts. We do this on the basis of our legitimate interests in protecting our community. We keep this data for no longer than necessary for that purpose (up to 24 months).
The Niyyah app does not use cookies. Our analytics tool uses a device/user identifier to tell sessions apart, as described above. Our website (niyyahapp.co.uk) is a simple informational site; it does not use advertising or cross-site tracking cookies.
Under UK GDPR you have the right to:
To exercise any of these rights, email admin@niyyahapp.co.uk. We aim to respond within 30 days. Deleting your account in the app also triggers deletion of your data as described above.
We use access controls and encryption in transit and at rest, keep profile photos in private storage behind short-lived signed links, and limit who and what can access your data. No system is perfectly secure, but we take reasonable steps to protect your information.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it where required, and we will inform affected users without undue delay where the breach is likely to result in a high risk to them.
We may update this policy as Niyyah develops. When we make a significant change, we will update the version and date at the top and, where appropriate, notify you in the app or by email. Continued use of Niyyah after an update means you accept the revised policy.
For any privacy question, request, or complaint: admin@niyyahapp.co.uk.