Privacy Policy

How we handle your data

Plain English. No dark patterns. We collect the minimum we need to run the app you signed up for, and nothing more.

Last updated · 5 June 2026

In this document
  1. Overview
  2. Data we collect
  3. How we use your data
  4. Who we share data with
  5. Group features & visibility
  6. Data retention
  7. Your rights and choices
  8. Security
  9. Children
  10. International transfers
  11. Changes to this policy
  12. Contact

1. Overview

Wasl ("Wasl", "we", "us") is a mobile app and service that combines an Islamic daily companion (Quran reader, prayer times, du'as, streaks) with group tools for Umrah and Hajj (live group map, lost-pilgrim helper, AI planner, bill split, hotel pinning, meeting points).

This policy explains what data we collect when you use Wasl, why we collect it, who we share it with, and the rights you have over your data. It applies to the Wasl mobile app on iOS and Android, our website at wasl.my, and any related services.

Short version: We collect what we need to deliver the features you signed up for. We don't sell your data. We don't show advertising. We share data with the people you choose to share it with (your group), and with service providers strictly to run the app (cloud hosting, payment processors, etc.).

2. Data we collect

Account data

Device & technical data

Location data

Quran / prayer / worship data

Group data

Receipt photos

Purchase data

Device & diagnostic data

3. How we use your data

We do not use your data for behavioural advertising, and we don't profile you for ad targeting. There are no ad networks embedded in Wasl.

4. Who we share data with

We rely on a small number of trusted service providers to run Wasl. Each one only receives the minimum data needed for their function:

ProviderPurposeWhat's shared
Cloud infrastructure provider Sign-in, database, server functions, push, crash reports Phone number, profile fields, app data
Google Play / Apple App Store Purchases, subscriptions Transaction info from the store back to our server
Subscription management provider Subscription state aggregator Anonymised user ID + entitlement status
Mapping & geocoding provider Maps and geocoding Coordinates and search queries (no account info)
AI provider Receipt OCR + AI planner queries The receipt image / query text (no profile info)
Email delivery provider Email delivery Your email + the message content we sent you

We do not sell your personal data to any third party. We do not share data with data brokers, ad networks, or marketing companies.

Legal disclosures

We will disclose data if compelled by a valid legal order from a competent court, or to protect the safety of our users or the public in a genuine emergency. We have not received any such requests as of the date of this policy.

5. Group features & visibility

When you join a Wasl group, certain data becomes visible to other members of that group:

If you leave the group (or are removed by the admin), your data is removed from the group's view immediately. Historical messages you posted before leaving remain visible to remaining members — same as any chat app.

Lost Pilgrim Helper

When someone you don't know uses the Lost Pilgrim Helper feature with your group's six-character code, your group receives an in-app notification with the helper's name and a "Block" button. The helper sees your group members' approximate locations. The feature is rate-limited per helper per group, and any group member can revoke a helper's access with a single tap.

6. Data retention

7. Your rights and choices

If you're in the EU/EEA, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA. Email us with "Privacy request" in the subject and we'll respond within 30 days.

8. Security

All data in transit is encrypted with TLS. Stored data is encrypted at rest by our cloud infrastructure. We use app attestation and server-side rules to prevent unauthorised access from non-Wasl clients.

No system is perfectly secure. If you suspect a security issue, please write to support@wasl.my with "Security" in the subject line — we read those urgently.

9. Children

Wasl is not directed to children under 13. We do not knowingly collect data from anyone under 13. If you believe we have collected data from a child under 13, please write to us and we will delete it.

10. International data transfers

Wasl is operated from Malaysia. Our infrastructure providers may store and process data in the United States, the European Union, or other regions. By using Wasl you consent to these transfers, which are governed by the providers' own data processing agreements.

11. Changes to this policy

If we make material changes to this policy, we'll notify you in the app and update the "Last updated" date at the top. For non-material edits (typo fixes, link updates) we'll just update the date.

12. Contact

If you have a question about this policy, or want to exercise any of the rights above:

Email: support@wasl.my
Website: wasl.my
Postal: Wasl, Malaysia