The short version.
We can see that you opened a sealed app, never what you did inside it. The intention you write at the gate is saved to your account so you can revisit it; it stays yours, never sold or mined. We don't run ad networks or build a profile of you. Ever.
Sadd exists to put a deliberate barrier (سدّ) between you and the scroll, and to turn each crossing into sadaqah. That mission only works if you trust the barrier. This policy is the long form of a simple promise: we collect the minimum required to run the app, and nothing for our own gain.
The full detail follows, but you are not required to read it. The summary above is binding, not decorative.
What we collect.
We group data by why it exists. If a use disappears, so does the data.
What we never see.
Some boundaries are not configurable; they are structural. The iOS Screen Time API does not expose this data to us, and we have designed the app so it never could.
- The content of any app we shield: what you scrolled, posted, watched, messaged, or searched inside Instagram, TikTok, X, or anything else.
- Your contacts, photos, microphone, or camera. (Location is used to compute prayer times and qibla, and, only if you enable Silent Mosque Mode, an on-device geofence around a single mosque you choose; see section 02. Your coordinates are never stored on our servers.)
- The text of your niyyah: see the next section.
- Your browsing history or any data from apps you have not explicitly chosen to seal.
Your niyyah text.
There are two kinds of niyyah in Sadd, and they are handled differently, so it is worth being exact.
The single intention you set once (during onboarding, editable in Settings), the one shown on your shield and your Niyyah widget, is stored only on your device. It is never transmitted to our servers.
Each time you write an intention at the Niyyah Gate, that text is saved on your device, not to our servers. What reaches us is the fact that you wrote one, which is all your muḥāsaba and your halaqa count needs. We cannot read what it said.
If you turn on Back up intentions (Settings → Niyyah, off by default), a copy is also stored on our servers so your history survives a lost phone. That copy is deleted automatically after 90 days, and you can erase all of it at any time with Settings → Niyyah → Clear intention history, without deleting your account.
We never sell it, never use it for advertising, and never share the text with your halaqa or your charity (they see only counts and totals; see section 06).
Changed 19 August 2026. Until this version, every gate intention was stored on our servers and kept until you deleted your account. We moved it to your device: nothing about the feature needed the text to leave your phone, and a timestamped record of what someone wrote at their weakest moment is not ours to hold.
Payments & sadaqah.
The app itself never charges you. Sadaqah works as a commitment contract you set up once on our web portal (sadd.app): you save a card with Stripe and authorize "charge me $X every time I log a bypass," up to a monthly cap. Here is the data trail.
- Stripe stores and processes your card under its own privacy terms. We receive a customer reference and a confirmation, never your card number.
- When you log a bypass in the app, our server records the amount, the charity, and the timestamp, then asks Stripe to charge your saved card.
- The donation is routed to the charity you chose through Stripe Connect. Stripe emails you a receipt for each donation charge.
- Charities receive disbursement totals, never your identity, niyyah, or app usage.
How long we keep it.
- Standing niyyah: on your device only; removed when you delete the app.
- Gate intentions: on your device until you clear them. If you turned on backup, the server copy is deleted automatically after 90 days, or immediately via Settings → Niyyah → Clear intention history.
- Bypass records: the time, duration and whether an intention was written (never the text) are kept with your account until you delete it.
- Sadaqah & bypass records: kept with your account until you delete it, then erased. Stripe retains its own copy of payment records under its terms and applicable law.
- Push token: until you disable notifications or delete your account, whichever comes first.
- Account data: kept until you delete your account, then deleted immediately (residual copies clear with routine backup rotation).
Your controls.
Wherever you live, you can exercise these rights from inside the app, no email required.
- Delete: Settings → Account → Delete account. Immediate and irreversible; purges your bypass records and gate intentions.
- Correct: edit your profile, pledge settings, and worship preferences at any time.
- Clear your intentions: Settings → Niyyah → Clear intention history. Erases every intention on this device and any backed up, without touching your account or your counts.
- Review your intentions: Settings → Niyyah → Your past intentions shows every gate intention on your account.
- Access & export: email privacy@sadd.app and we'll provide a copy of your data.
Residents of the EU/UK (GDPR) and California (CPRA) have additional statutory rights, including objection and non-discrimination. Reach us at privacy@sadd.app and we will respond within 30 days.
Children.
Sadd is rated 12+ and is not directed at children under 13. We do not knowingly collect data from children under 13. A parent or guardian may set up Sadd for a minor using Apple Family Sharing; in that case the organizer is responsible for consent.
Changes to this policy.
When we make a material change, we will update the date above and notify you in-app before it takes effect. Continuing to use Sadd after the effective date constitutes acceptance. Past versions are archived and available on request.
Contact us.
Questions about your privacy are answered by a human, not a form.
Sadd, Inc. · Hattiesburg, Mississippi · We aim to reply within two business days.