Privacy Policy
Last updated: 18 July 2026
Majlis is an app that connects people with verified scholars and imams for religious questions and answers. This policy explains what personal data we collect, why we collect it, and what you can do about it.
The short version. We collect the minimum needed to run the service: your email address, your display name, and what you write. We do not use analytics or advertising trackers, we do not sell your data, and you can delete your account from inside the app at any time.
Who is responsible for your data
The data controller for Majlis is Bako Bakhtyar Asaad, based in Doorwerth, the Netherlands. You can reach us at support@askmajlis.app.
What we collect
Information you give us
- Account details: your email address, display name, password, and optionally a phone number.
- Scholar profiles: if you apply to become a verified scholar, the biography, credentials and references you submit, plus a profile photo if you upload one.
- Content you write: questions, answers and posts, including any images attached to posts.
- Moderation actions: accounts you block, and reports you file, including the reason and any detail you add.
Information created by using the service
- Account state: whether your email is verified, when you accepted our terms, and your role in the app.
- Notifications generated when someone answers your question.
- IP address: used only in temporary memory to rate-limit sign-ups and login attempts, so the service cannot be abused. It is not written to our database and is discarded within minutes.
What we do not collect
Majlis contains no analytics SDK, no advertising identifiers, and no third-party tracking. We do not build advertising profiles and we do not sell personal data.
Why we use it, and our legal basis
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Email, password, display name | To create and secure your account, and verify your email | Performance of a contract |
| Questions, answers, posts | To provide the core service — publishing and answering questions | Performance of a contract |
| Reports, blocks, content filtering | To keep the community safe and meet app store safety requirements | Legitimate interests |
| IP address (temporary) | To prevent abuse, spam sign-ups and brute-force login attempts | Legitimate interests |
| Phone number (optional) | To help us contact you if needed | Consent — you choose whether to provide it |
Who processes data on our behalf
We use a small number of service providers. They process data only on our instructions:
- Neon — hosts our PostgreSQL database, holding account details and content.
- Cloudflare — stores and delivers profile photos and post images, and provides our domain and network layer.
- Resend — sends verification emails.
- Apple and Google — distribute the app; their own privacy policies apply to the app stores themselves.
Some of these providers operate outside the European Economic Area. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.
Public and private content
Please be aware of what is visible to others:
- Questions marked public, and their answers, can be read by anyone — including people who are not signed in.
- Questions marked private are visible only to you and the scholar you asked.
- Scholar profiles, including the photo and biography, are public.
- Your display name appears alongside anything you publish. It does not have to be your legal name.
How long we keep it
We keep your account data for as long as your account exists. When you delete your account:
- Your email address, password, phone number and profile photo are erased immediately.
- Your display name is replaced with "Deleted user".
- Private and unanswered questions you asked are deleted.
- Public questions that have been answered are kept, because they are content other people read and a scholar wrote a reply. They are no longer linked to your name.
- If you are a scholar, you choose whether your answers stay. If you keep them, your display name stays attached, because an unattributable religious ruling is of no use to anyone. If you ask for them to be removed, they are deleted along with the questions they answered.
- Your uploaded images are deleted from storage.
Reports about content may be retained after the reported account is deleted, so that we have a record of the safety decisions we made.
Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to how we use it, and receive a copy in a portable format. You can exercise most of these directly in the app — you can edit your profile and delete your account from the settings screen. For anything else, email us at support@askmajlis.app and we will respond within 30 days.
If you believe we have handled your data improperly, you have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), or to the supervisory authority in your own country.
Security
Passwords are hashed with Argon2 and are never stored in a readable form. All traffic between the app and our servers is encrypted with HTTPS, and access to the production database is restricted. No system is perfectly secure, but we take reasonable measures to protect your information.
Children
Majlis is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If we make significant changes, we will update the date at the top of this page and, where the change materially affects you, ask you to review it in the app.
Contact
Questions about this policy: support@askmajlis.app.