Privacy Policy — Thābit
Last updated: 23 August 2026
Thābit ("the App") is published by DeenTeachings ("we", "us", "our"). This policy explains what data the App collects, why, and what you can do about it.
We want you to feel safe using Thābit. We try to collect as little as possible, store as much as we can on your own device, and never sell your data to anyone.
1. What we collect
1.1 Account and identity
- Firebase Authentication data. Your email address, display name, and the authentication provider you used to sign in (email/password, Sign in with Apple, or Sign in with Google), managed by Google Firebase Authentication. Purpose: account sign-in and account recovery. If you use a password, it is stored by Firebase in hashed form — we never see it in plaintext.
1.2 Content you create in the app
- Vault entries. Stored on your device only and encrypted at rest using XChaCha20-Poly1305 with a random 32-byte device-specific key. Not uploaded to any server we own. Only your device can decrypt them.
- Journal entries and mood check-ins. Stored on your device only. Not uploaded to any server we own. Only you can read them from within the App.
- Sakinah chat history. Stored locally on your device only, keyed to your signed-in user's ID. Purpose: showing you your own conversation history when you return. Not uploaded to any server we own. You can clear this history at any time from within the App.
- Settings and preferences. Theme, language, notification times, content filters, biometric lock state.
1.3 Health and sleep data (optional, only with your consent)
- Sleep data. If you choose "Import from Apple Health" (iOS) or "Import from Health Connect" (Android) in Sleep Sanctuary, we read your sleep records — time asleep and sleep stages — solely to show you a gentle summary and a 1–5 sleep-quality score. This reading happens entirely on your device. We never store or transmit the raw sleep samples, and only the derived score is saved locally alongside your sleep log.
1.4 Information collected automatically
- Firebase Analytics events, anonymized. Screen views and feature usage counts — no message content. Purpose: understanding which features are used so we can improve them.
- Approximate location. If you grant location permission, we use it locally on your device to calculate accurate prayer times. We do not transmit your precise coordinates to our servers.
- Country code. Used to route crisis hotlines to numbers relevant to your region. Stored on device.
- Crash and error reports. If the App crashes, we collect a stack trace and minimal device information (OS version, app version, device model) via Sentry to fix bugs. These reports do not include the content of your messages, journal entries, or Vault entries.
1.5 Information sent to third-party AI (with your consent)
Two features — the Sakinah chat companion and the Vault "Help me say this" script generator — send your text to Anthropic (the maker of Claude) so an AI model can generate a response. See §5 "Third-party AI services" below for the full detail. Nothing is sent until you have explicitly tapped "I agree" on an in-app consent sheet the first time you use each feature.
1.6 How we collect it
- Account fields are collected when you sign up or sign in.
- Analytics events are emitted by the App as you navigate.
- Chat history and on-device entries are created by you typing them, and stored locally through React Native's AsyncStorage.
- Message text is sent to Anthropic only after you accept the in-app consent sheet described in §5.
2. What we do not collect
- We do not collect contact lists, photos, microphone recordings (unless you use voice journaling, which is processed on-device only), or files outside what you explicitly enter into the App.
- We do not use third-party advertising trackers.
- We do not use analytics SDKs that profile your behavior across apps.
- We do not collect facial images or biometric data. The biometric lock uses your device's native Face ID or fingerprint system; we never receive that data.
- We never read your sleep or health data without your explicit, opt-in consent, and we never use it for advertising, marketing, or data mining.
3. Where your data lives
| Type | Where | How long |
| Account email, name, auth provider | Firebase Authentication (Google Cloud) | Until you delete your account |
| Vault entries | On your device only — encrypted at rest (XChaCha20-Poly1305, device-specific key) | Until you uninstall or use Delete Account |
| Journal entries, mood check-ins | On your device only | Until you uninstall or use Delete Account |
| Sleep data (Apple Health / Health Connect) | Read on-device only; raw samples are never stored or sent. Only the derived score is saved with your sleep log on-device | Until you uninstall or use Delete Account |
| Sakinah chat history | On your device only (keyed to your signed-in user ID) | Until you clear it or delete your account |
| Sakinah / Vault AI requests (message or entry text) | Transmitted to Anthropic over TLS; retained by Anthropic for up to 30 days for Trust & Safety monitoring, then deleted; not stored on our servers | Up to 30 days at Anthropic |
| Firebase Analytics events | Google Firebase Analytics (anonymized) | Per Firebase retention defaults |
| Crash reports | Sentry | 90 days |
4. Sharing with third parties
We share data only with these processors, only as needed to operate the App:
- Google Firebase / Google Cloud (Firebase Authentication, Firebase Analytics, push notifications)
- Google LLC (Sign in with Google)
- Apple Inc. (Sign in with Apple)
- Anthropic PBC (Claude API — for the Sakinah companion and the Vault "Help me say this" feature; see §5)
- Sentry (crash reporting)
We do not sell your data. We do not share it with advertisers. We do not give it to data brokers.
We only share personal data with service providers that process it for the purposes described in this Privacy Policy and that are required to use appropriate technical and organisational safeguards. We require these providers to protect personal data in a manner consistent with this Privacy Policy and applicable law.
On-device encryption. Vault entries are encrypted at rest with XChaCha20-Poly1305 using a random 32-byte device-specific key stored only on this device. The optional journal backup feature, if you enable it, encrypts the backup blob with AES-256-GCM using a key derived from your Firebase user ID via PBKDF2-HMAC-SHA-256.
5. Third-party AI services
We use Anthropic (the company behind the Claude family of AI models) as an AI subprocessor for two features in the Thābit iOS app: the Sakinah chat companion, and the Vault "Help me say this" script generator. The specific model used is claude-haiku-4-5, accessed through Anthropic's Messages API.
No transmission happens until you have tapped through the in-app consent sheet — which names Anthropic and the connection type — and tapped "I agree."
5.1 Sakinah chat companion
When you send a message in Sakinah, the message text — plus the recent conversation history, for context — is transmitted to Anthropic's Messages API over an encrypted TLS connection so Anthropic's model can generate a reply. The reply is then shown to you inside the App.
5.2 Vault "Help me say this"
The Vault is a private notes area for things you want to say to loved ones. "Help me say this" is an optional feature you can turn on from within a Vault entry. When you opt in, the entry text is transmitted to Anthropic in the same way, for that single request, and Anthropic's model returns a conversation opening script.
5.3 What Anthropic does — and does not do — with your text
- Retention. Anthropic may retain the request for up to 30 days for their Trust and Safety monitoring, per their standard API terms, and then deletes it. We do not have a Zero Data Retention agreement with Anthropic.
- No training. Anthropic does not use this data to train their models.
- Encrypted transport. All requests to Anthropic are sent over TLS (HTTPS).
5.4 What we do — and do not do — with your text
- We do not store the message content on our own servers. Sakinah chat history is stored locally on your device only (§1).
- We do not use these texts to train any model, our own or anyone else's.
5.5 Your consent
You can revoke this data-sharing choice at any time by clearing app data or deleting your account. The rest of the App continues to work without either AI feature.
5.6 Third-party protection
Anthropic has committed to providing equivalent data-handling protection through their standard Commercial Terms of Service and their Privacy Policy, which you're welcome to read directly to verify this yourself.
6. Your rights
You can, at any time and within the App:
- Export your data. Settings → "Export my data" produces a JSON file of everything we have associated with your account.
- Delete your account. See §7 below.
- Stop notifications. Settings → toggle each notification off.
- Filter content. Settings → "Content filters" — choose topics you'd rather not see (loss, infertility, marriage, parenting, etc.).
- Withdraw location access. Your device's system settings can revoke location permission at any time; the App will fall back to manual city selection.
- Revoke health data access. You can revoke Apple Health or Health Connect access at any time in your device's system settings; the App will simply stop importing sleep data.
If you live in the EU, UK, or California, you also have the right to request access to or deletion of your data under GDPR, UK GDPR, and CCPA respectively. The Export and Delete features satisfy these rights. For any further request, email [email protected].
7. How to delete your data
You control what stays and what goes.
- Clear your Sakinah conversation. Open Sakinah → tap "Clear conversation" in the header menu. This removes your chat history from your device. New conversations start fresh.
- Delete your account. Settings → Delete Account. This permanently:
- Deletes your Firebase Authentication user (email, display name, auth provider).
- Wipes local storage on the device (Sakinah chat history, journal entries, mood check-ins, Vault entries, cached settings).
- Revokes your AI-consent choice for Sakinah and Vault "Help me say this."
- Cannot be undone.
If for any reason the in-app deletion doesn't work, email [email protected] with the email address on your account and we will delete it manually within 30 days.
8. Children
Thābit is rated 17+ and is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has created an account, email [email protected] and we will delete it.
9. Security
We use industry-standard transport encryption (HTTPS) for all communication between the App and our servers, and between the App and Anthropic. Firebase Authentication handles password storage. The encrypted journal backup feature uses AES-GCM with PBKDF2 key derivation (≥600,000 iterations) when enabled. No system is perfectly secure; we will inform users without undue delay if a breach affects their data.
10. International transfers
Our processors (Google Cloud including Firebase, Anthropic, Sentry) operate globally. Data may be transferred to the United States or other countries. These processors are contractually required to maintain protections equivalent to GDPR standards.
11. Changes to this policy
If we update this policy in a way that affects how we use your data, we will surface the change in the App and update the "Last updated" date above. Continued use of the App after a material change means you accept the new policy. If you disagree, delete your account.
12. Contact
DeenTeachings
Email: [email protected]
Instagram: @deenteachings
This App is an act of ṣadaqah jāriyah for Aisha Yahaya رحمها الله.