Privacy Policy

Effective Date: Sept 1, 2026  |  Last Updated: Sept 1, 2026

Assalamu Alaikum. Welcome to ShukrApp.

At ShukrApp, we understand that seeking help for addiction requires immense courage and trust. Your privacy is not just a legal obligation for us—it is a sacred trust (amanah). We are committed to protecting your personal information with the highest standards of confidentiality, security, and Islamic ethics.

This Privacy Policy explains how we collect, use, protect, and share your information when you use the ShukrApp mobile application and website (collectively, the “Services”). By using our Services, you agree to the practices described in this Privacy Policy.

If you have questions or concerns about your privacy, please contact us at privacy@shukrapp.com.

1. Information We Collect

We collect only the information necessary to provide you with effective recovery support while maintaining your anonymity and dignity.

1.1 Information You Provide Directly

Account Information:

  • Email address (required for account creation and communication)
  • Username (you may use a pseudonym; real names are never required)
  • Password (encrypted and never stored in plain text)
  • Optional demographic information (age range, location by country/region only)

Recovery Journey Data:

  • Streak tracking and progress metrics
  • Habit tracker entries
  • Course completion status
  • Journal entries and personal reflections (stored with end-to-end encryption)
  • Community forum posts and messages (anonymous within gender-separated groups)

Support Interactions:

  • Messages sent to our support team
  • Feedback and survey responses
  • Panic button usage logs (for improving emergency support features)

Payment Information:

  • We use third-party payment processors (Stripe, Apple Pay, Google Pay) and do not store your full credit card information on our servers
  • We retain only transaction IDs and subscription status

1.2 Information Collected Automatically

Technical Data:

  • Device type, operating system, and app version
  • IP address (anonymized for analytics)
  • App usage analytics (pages viewed, features used, session duration)
  • Crash reports and error logs (anonymized)

Location Data:

  • We do NOT collect precise geolocation
  • We may collect country/region-level location for content localization and legal compliance

1.3 Information We Do NOT Collect

  • Real names (unless you voluntarily provide them)
  • Profile photos or identifying images
  • Precise geolocation or GPS coordinates
  • Contacts from your device
  • Social media profiles or connections
  • Browsing history outside the app

2. How We Use Your Information

We use your information solely to provide, improve, and protect our Services in accordance with Islamic principles of necessity (dharurah) and benefit (maslahah).

2.1 Primary Purposes

To Provide Recovery Support:

  • Deliver personalized recovery courses and content
  • Track your progress and celebrate milestones
  • Facilitate anonymous community support
  • Provide crisis intervention through panic button features
  • Send Islamic reminders and motivational content

To Improve Our Services:

  • Analyze usage patterns to enhance user experience
  • Develop new features based on community needs
  • Conduct research on addiction recovery effectiveness (using only aggregated, anonymized data)

To Communicate With You:

  • Send account-related notifications
  • Provide customer support
  • Share updates about new features and content
  • Send educational newsletters (you may opt out at any time)

To Ensure Safety and Security:

  • Prevent fraud, abuse, and violations of our Terms of Service
  • Protect against security threats
  • Comply with legal obligations

2.2 Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), UK, and other GDPR-compliant jurisdictions, we process your personal data based on:

  • Consent: You have given clear consent for us to process your personal data for specific purposes
  • Contract Performance: Processing is necessary to provide the Services you requested
  • Legitimate Interests: Processing is necessary for our legitimate interests in improving Services and preventing fraud, provided these interests do not override your rights
  • Legal Obligation: Processing is necessary to comply with applicable laws

3. How We Protect Your Information

We implement industry-leading security measures to protect your data, in compliance with HIPAA Security Rule standards, GDPR Article 32, and mental health data protection best practices.

3.1 Technical Safeguards

Encryption:

  • All data transmitted between your device and our servers uses TLS 1.3 encryption
  • Sensitive personal data (journal entries, private messages) is encrypted at rest using AES-256 encryption
  • End-to-end encryption for direct messages in community forums

Access Controls:

  • Multi-factor authentication (MFA) required for staff accessing systems
  • Role-based access controls ensuring staff can only access data necessary for their duties
  • Regular access audits and automatic session timeouts

Infrastructure Security:

  • Data stored on HIPAA-compliant, SOC 2 certified servers
  • Regular security assessments and penetration testing
  • Automated backup systems with encrypted storage
  • 24/7 security monitoring and intrusion detection

3.2 Administrative Safeguards

  • All staff undergo HIPAA privacy and security training
  • Strict confidentiality agreements for all employees and contractors
  • Background checks for personnel with access to user data
  • Incident response plan with breach notification procedures

3.3 Physical Safeguards

  • Servers hosted in secure, access-controlled data centers
  • Physical security measures including surveillance and restricted access

3.4 Anonymity Protections

  • Gender-separated communities with no cross-gender visibility
  • Anonymous usernames with no requirement for real names
  • No public profiles or user directories
  • Moderated forums to prevent doxxing or harassment

4. How We Share Your Information

We will NEVER sell your personal information to third parties.

Your trust is sacred to us. We share your information only in the following limited circumstances:

4.1 Service Providers

We work with carefully vetted third-party service providers who help us operate the Services:

  • Cloud Hosting: AWS, Google Cloud (HIPAA-compliant infrastructure)
  • Payment Processing: Stripe, Apple Pay, Google Pay
  • Email Services: SendGrid, Mailchimp (for newsletters and notifications)
  • Analytics: Google Analytics (with IP anonymization), Mixpanel
  • Customer Support: Zendesk

All service providers are bound by strict confidentiality agreements and Business Associate Agreements (BAAs) as required by HIPAA. They may only use your data to provide services to us and are prohibited from using it for their own purposes.

4.2 Legal Requirements

We may disclose your information if required by law, including:

  • In response to valid legal processes (subpoenas, court orders)
  • To comply with applicable laws and regulations
  • To protect the rights, property, or safety of ShukrApp, our users, or the public
  • In connection with investigations of fraud, security threats, or violations of our Terms

Important: We will notify you of legal requests for your information unless prohibited by law. We will challenge overly broad or inappropriate requests.

4.3 Emergency Situations

If we believe in good faith that disclosure is necessary to prevent imminent harm to you or others (e.g., credible suicide threats), we may share information with emergency services or appropriate authorities.

4.4 Business Transfers

If ShukrApp is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and prominent notice in the app before your information is transferred and becomes subject to a different privacy policy.

4.5 With Your Consent

We may share your information for purposes not described in this Privacy Policy with your explicit consent.

5. Your Privacy Rights

You have significant control over your personal information. We honor the rights granted under GDPR, CCPA, and other privacy laws.

5.1 Access and Portability

  • Right to Access: You may request a copy of all personal data we hold about you
  • Right to Data Portability: You may request your data in a structured, machine-readable format

5.2 Correction and Deletion

  • Right to Rectification: You may correct inaccurate or incomplete information
  • Right to Erasure ("Right to be Forgotten"): You may request deletion of your account and personal data, subject to legal retention requirements

5.3 Control and Restriction

  • Right to Restrict Processing: You may request that we limit how we use your data
  • Right to Object: You may object to processing based on legitimate interests
  • Right to Withdraw Consent: You may withdraw consent at any time where we rely on consent as the legal basis

5.4 Communication Preferences

  • Opt-Out of Marketing: You may unsubscribe from promotional emails at any time
  • Notification Settings: You may control push notifications through your device settings

5.5 How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@shukrapp.com or through the app's settings menu. We will respond within 30 days (or as required by applicable law).

  • For GDPR Requests: If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
  • For CCPA Requests: California residents may request information about data shared with third parties for marketing purposes and may opt out of such sharing.

6. Data Retention

We retain your personal information only as long as necessary to provide Services and fulfill the purposes described in this Privacy Policy.

Active Accounts

  • Account data is retained while your account is active
  • Recovery journey data (streaks, courses) is retained to support your ongoing progress

Inactive Accounts

  • If you do not log in for 24 months, we will send a reminder email
  • After 36 months of inactivity, we may delete your account and associated data

Deleted Accounts

  • When you delete your account, we will permanently delete your personal data within 30 days
  • Some information may be retained in anonymized form for research and analytics
  • We may retain certain data longer if required by law or to resolve disputes

Legal and Safety Data

  • Records of legal requests and safety incidents may be retained for up to 7 years as required by law

7. Children's Privacy

ShukrApp is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13.

If we discover that we have collected information from a child under 13, we will delete it immediately. If you believe a child under 13 has provided us with personal information, please contact us at privacy@shukrapp.com.

For users aged 13-17: We recommend discussing your use of ShukrApp with a parent or guardian. While we do not require parental consent for users 13+, we encourage family involvement in recovery where appropriate.

8. International Data Transfers

ShukrApp operates globally and may transfer your data to countries outside your residence, including the United States.

For EEA/UK Users

  • We comply with GDPR requirements for international data transfers
  • We use Standard Contractual Clauses (SCCs) approved by the European Commission
  • We participate in the EU-US Data Privacy Framework where applicable
  • Your data receives equivalent protection regardless of where it is processed

For All Users

  • We ensure all international transfers meet applicable legal requirements
  • Service providers in other countries are contractually bound to protect your data

9. Cookies and Tracking Technologies

9.1 What We Use

Essential Cookies:

  • Session cookies to keep you logged in
  • Security cookies to prevent fraud

Analytics Cookies:

  • Google Analytics (with IP anonymization) to understand how users interact with our Services
  • Mixpanel for feature usage analytics

Preference Cookies:

  • Language and display preferences

9.2 Your Choices

You may disable cookies through your browser settings, but this may limit functionality. We do not use advertising cookies or sell data to advertisers.

Do Not Track: We honor Do Not Track (DNT) signals from your browser.

10. Third-Party Links

Our Services may contain links to external websites (e.g., Islamic resources, mental health organizations). We are not responsible for the privacy practices of these third-party sites. We encourage you to review their privacy policies.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.

How We Notify You

  • Material changes will be communicated via email and in-app notification
  • You will be required to review and accept significant changes before continuing to use the Services
  • Non-material changes will be posted with an updated "Last Updated" date

Your Continued Use: Continued use of the Services after changes take effect constitutes acceptance of the updated Privacy Policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Email: privacy@shukrapp.com

For GDPR/EEA Users: EU Representative: privacy@shukrapp.com

Response Time: We aim to respond to all privacy inquiries within 7 business days.

13. Islamic Ethical Commitment

Beyond legal compliance, we are guided by Islamic principles:

  • Amanah (Trust): Your information is a sacred trust we protect with utmost care
  • Sitr (Concealment): We honor the Islamic principle of concealing others' faults and struggles
  • Ihsan (Excellence): We strive for excellence in protecting your privacy and dignity
  • Adl (Justice): We treat all users fairly and transparently

May Allah (SWT) accept our efforts to serve the Ummah with integrity and compassion.