Privacy Policy
1. Who we are
This Privacy Policy explains how FahmPath (the “App”, “we”, “us”) processes personal data when you use the FahmPath mobile application and related online materials on fahmpath.com.
FahmPath is currently operated by an individual based in the United Kingdom, not through a registered limited company. For privacy matters, contact: privacy@fahmpath.com.
For UK data protection law, we act as the controller of personal data we decide how and why to process in connection with FahmPath, except where a third-party provider (such as Google) acts as an independent controller for its own services.
2. Scope of this policy
This policy covers:
- the FahmPath Android app (package name
com.fahmpath.fahmpath); - account, sync, subscription and advertising features as currently implemented; and
- this website’s publication of legal information.
It does not claim that FahmPath is “GDPR certified”, “fully compliant”, or that any system is perfectly secure. Those are ongoing legal and operational responsibilities, not guarantees.
3. Personal data we process
Depending on how you use FahmPath, we may process the categories below.
3.1 Account and authentication data
An account is required to use FahmPath. Depending on how you sign up, this may include:
- email address;
- password (for email/password accounts — handled by Firebase Authentication; we do not store your raw password in FahmPath app databases);
- display name / profile name where you provide one;
- email verification status for email/password accounts;
- a Firebase user identifier (UID);
- if you use Google Sign-In: basic Google account identifiers needed to create or link your FahmPath session (such as Google account id / email / display name as provided by the sign-in flow).
Apple Sign-In is planned for a future iOS release and is not part of the current Android authentication implementation described here.
3.2 Preferences and profile-related settings
During onboarding and later in Settings, you may set preferences such as preferred language, reciter, translation preference, tafsir depth / collection, daily listening goal, playback preferences, and reminder opt-in flags. A subset of these account-level preferences may sync to your cloud account (see below). Some device presentation settings (for example theme and text size) remain on-device and are not uploaded.
3.3 Bookmarks, reading position and activity metadata
We may process:
- bookmarks (Surah and ayah references and related timestamps; soft-deletes for sync);
- last reading / continue-listening style position metadata;
- a bounded set of activity events used for sync/progress foundations (for example that a Surah or player screen was opened, with Surah / ayah reference and timestamp).
FahmPath’s cloud sync design is intended not to upload Arabic Quran source text, translation source text, or authentication secrets as part of those sync payloads.
3.4 Local device storage
The App stores user-scoped data on your device (for example via on-device preferences storage) so features work offline and across app restarts. This can include preferences, bookmarks, reading position, activity metadata, and local entitlement cache information used to respect Premium status when appropriate.
3.5 Subscription / entitlement data
If you interact with FahmPath Premium, we may process subscription status and related entitlement metadata needed to unlock Premium features and suppress ads. Purchase completion is handled through Google Play Billing. FahmPath does not implement a separate “Remove Ads only” product; Premium is designed to be ad-free.
3.6 Advertising-related technical data (Free users)
If you use FahmPath as a Free (non-Premium) user on eligible non-sacred surfaces, Google’s advertising and consent technologies may process device and advertising identifiers, IP address, coarse location derived from IP, device/app information, and consent signals, as described in Section 6. Premium users are treated as ad-free in the App’s entitlement logic: the App is designed not to request or show ads for verified Premium users.
3.7 Technical and diagnostic information
Like most apps, the operating system, Google Play services, Firebase, and networking layers may process technical data necessary to run the App (for example device model, OS version, app version, connectivity state, and crash or performance signals generated by the platform). FahmPath does not currently wire Firebase Analytics or Firebase Crashlytics into active production feature code.
3.8 What we do not intentionally collect for ad targeting
FahmPath’s advertising architecture is designed so that exact ayah reading content, religious search queries, and Quran reading history are not sent to ad targeting systems for personalisation. Ads are restricted away from sacred reading, player, driving, authentication and onboarding surfaces.
4. Why we process data
We process personal data to:
- create and secure your account and authenticate you;
- provide core App features (listening preferences, bookmarks, sync, progress foundations);
- sync selected account data across your devices when you are signed in;
- provide and verify FahmPath Premium entitlements;
- show advertising to Free users on eligible surfaces, subject to consent rules where required;
- respond to privacy and support requests;
- maintain security, prevent abuse, and operate the service;
- comply with legal obligations where applicable.
5. Lawful bases (UK GDPR)
Depending on the processing, we rely on one or more of:
- Contract — to provide the App and account features you request;
- Legitimate interests — for example securing the service, basic product operation, and communicating about privacy requests, balanced against your rights;
- Consent — where required for advertising / personalised ads via Google’s User Messaging Platform (UMP) or similar consent flows in the UK/EEA;
- Legal obligation — where we must retain or disclose information under applicable law.
Where processing is based on consent, you may withdraw consent through the App’s privacy choices entry (when Google UMP requires it) and/or relevant device/Google settings, without affecting the lawfulness of processing before withdrawal.
6. Advertising, AdMob and consent
FahmPath uses the Google Mobile Ads / AdMob SDK and Google’s User Messaging Platform (UMP) to manage privacy messaging and consent readiness for users in regions where this is required (including UK/EEA contexts).
- Free users may see banner ads on approved non-sacred surfaces (for example Home, Search supporting areas, Profile, and Settings supporting areas), after configuration and consent rules allow ad requests.
- Premium users are ad-free under the App’s entitlement rules: the App is designed not to initialise ad loading or show ad slots for verified Premium users.
- Ads are not placed in Surah Detail / ayah streams, the player, Driving Mode, authentication, email verification, or onboarding screens.
- If UMP indicates that a persistent privacy-options entry is required, the App can surface a Privacy choices option in Settings that opens Google’s privacy options form.
- If consent is unresolved, unavailable, or does not allow ad requests, the App fails safe by not requesting ads.
Google and its partners may process advertising identifiers and related technical data under their own terms and policies. See Google’s disclosures for AdMob / advertising and the consent message presented in the App.
Integrating UMP does not by itself mean FahmPath has completed every legal or regulatory obligation relating to advertising. Additional store disclosures, privacy labels, and AdMob Privacy & messaging configuration remain your operational responsibilities as publisher.
7. Subscriptions and Google Play Billing
Premium subscriptions (monthly / yearly pricing as offered in the App / Play Store) are processed through Google Play Billing. Google processes payment details as the payment platform. FahmPath receives entitlement / purchase-related signals needed to unlock Premium features and remove ads. We do not ask you to enter card numbers into FahmPath itself.
8. Sharing and processors
We use service providers (“processors” or independent controllers, depending on the service) to operate FahmPath. Key providers include:
- Google Firebase — Authentication and Cloud Firestore for account and sync features;
- Google Sign-In — if you choose that sign-in method;
- Google AdMob / Google Mobile Ads / UMP — advertising and consent messaging for Free users where applicable;
- Google Play — distribution and in-app purchases / subscriptions.
These providers process data under their own terms, privacy policies, and (where applicable) data processing terms. We do not sell your personal data.
We may disclose information if required by law, to protect rights and safety, or in connection with a genuine transfer of the service, in which case we would take appropriate steps to protect personal data.
9. International transfers
FahmPath is operated from the United Kingdom. Google and other providers may process data in the UK, EEA, United States, and other countries. Where international transfers occur, they rely on the provider’s applicable transfer mechanisms (such as adequacy decisions or standard contractual clauses), as described in the provider’s documentation. If you need more detail about a specific transfer for your request, contact privacy@fahmpath.com.
10. Retention
We follow a data-minimisation approach based on what the App actually needs to operate:
- Account and synced personal data are generally retained while your account remains active and as needed to provide the service.
- FahmPath does not currently implement automatic deletion of inactive accounts.
- If you request deletion, we will delete or anonymise personal data we control within 30 days, unless we must retain limited information for legal obligations, security/fraud prevention, dispute handling, or short-lived technical backups.
- Local copies on your device are removed when you clear app data / uninstall, subject to how your device and OS manage storage.
- Google may retain certain authentication, billing, or advertising records under their own retention rules.
11. Security
We use reasonable technical and organisational measures appropriate to a consumer mobile app (including relying on reputable providers such as Firebase Auth and Firestore access controls tied to the signed-in user). No method of transmission or storage is completely secure. We do not claim absolute security.
12. Your rights (UK GDPR / GDPR)
If UK GDPR / GDPR applies to you, you may have rights including:
- access to your personal data;
- rectification of inaccurate data;
- erasure (“right to be forgotten”) in certain circumstances;
- restriction of processing in certain circumstances;
- data portability in certain circumstances;
- objection to certain processing based on legitimate interests;
- withdrawal of consent where processing is consent-based;
- complaint to a supervisory authority.
In the UK, you can complain to the Information Commissioner’s Office (ICO) (https://ico.org.uk. EEA users may contact their local supervisory authority.
To exercise rights with FahmPath, email privacy@fahmpath.com. We may need to verify your identity before fulfilling a request.
13. Account and data deletion
The App does not currently include an in-app account deletion button or automated self-serve deletion flow.
To request deletion of your FahmPath account and associated personal data that we control, email privacy@fahmpath.com from the email address associated with your account (or otherwise provide enough information for us to identify the account). Valid deletion requests will normally be processed within 30 days.
Deleting your FahmPath account does not automatically cancel a Google Play subscription. Manage or cancel Premium billing in Google Play subscription settings.
14. Children
FahmPath is intended for users aged 13 and over. It is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact privacy@fahmpath.com and we will take appropriate steps to delete the data we control.
If you are under the age of digital consent applicable in your country (which may be higher than 13 in some EEA states for certain online services), you should only use FahmPath with involvement of a parent or guardian as required by local law.
15. Changes to this policy
We may update this Privacy Policy from time to time. The “Effective / last updated” date at the top will change when we do. The current version will be published at https://fahmpath.com/privacy. Significant changes may also be highlighted in the App or by email where appropriate.
16. Contact
Privacy requests and questions:
Email:
privacy@fahmpath.com
Website: https://fahmpath.com
Location of operator: United Kingdom