Hasalati Privacy Policy

Last updated 27 August 2026

The short version

Hasalati is offline-first. Everything you log is stored on your device. Nothing is transmitted to us unless you deliberately create an account and turn on sync.

There is no analytics, no advertising, and no tracking. We do not sell or share your data with anyone.

Who we are

Hasalati is an independent app developed by Esam Jaafar. For any privacy question, write to esamjaafarai@gmail.com and we will reply within 7 days.

Data stored on your device

The following never leaves your iPhone unless you turn on sync or export it yourself:

Data we receive only if you turn on sync

Creating an account stores your email address and a password. The password is hashed by our authentication provider; we never see it in plaintext.

Once sync is on, the transaction fields listed above — including your free-text notes — plus recurrence identifiers, deletion markers, and your settings are stored as rows tied to your user ID.

Row-level security means each row can be read and written only by the account that created it. We do not read your entries.

Service providers

Three companies are involved in delivering the app:

What Hasalati does not do

Notifications

The daily reminder is a local notification scheduled by iOS on your device. No push tokens are created and no server is contacted. Turning the reminder off cancels it immediately.

Files you export

Export as JSON produces an unencrypted file that you send wherever you choose through the iOS share sheet. Once it leaves the app it is outside our control — treat it as you would a bank statement.

Retention and deletion

Your rights

Access and portability are built in: Export as JSON gives you your complete data in a machine-readable file. Erasure is built in: Delete account.

Because we do not profile, advertise, or sell data, there is no opt-out to offer under CCPA or CPRA. Under GDPR, the lawful basis for handling synced data and for sending the verification email is performance of the service you asked for.

Security

All network traffic uses TLS. Cloud access is restricted per user by row-level security, and the key embedded in the app is a public, restricted key that grants no access without a valid signed-in session.

No system is perfectly secure. Hasalati's strongest protection is that you can simply leave sync off.

Children

Hasalati is not directed at children under 13, or under 16 in the EEA and UK, and we do not knowingly collect their data.

Changes to this policy

We will update the date above when this policy changes, and for material changes we will surface a notice in the app before they take effect.