Privacy Policy
v1 policy — periodically reviewed.
Effective date: 2026-07-18 Last updated: 2026-07-18
1. Who we are
Healing Al Hajar is a community-led, non-profit initiative based in the United Arab Emirates. We operate this Service to enable environmental cleanup reporting and coordination.
2. Data we collect — LOCKED
We collect only what we need for the Service to function.
From you, when you sign up:
- Email address (via Apple Sign-in or Google OAuth)
- A username you choose (validated for uniqueness)
- An optional profile photo (avatar) — if not provided, we generate a deterministic letter-on-gradient placeholder
- Your real name from OAuth providers (Apple may use Hide-My-Email; Google may share name) — we store this privately and never display it publicly
From you, when you use the Service:
- Photos you upload of trash spots and cleanups
- GPS coordinates for spots you report (you confirm each pin)
- The text you write (notes, descriptions)
- The chips/tags you select (place type, trash type, environment flags, affiliations)
Automatically:
- Device platform and OS version (for push notification routing)
- App version (to debug platform-specific issues)
- Anonymized usage events (which screens you visit) — see §7 Analytics
What we DON'T collect:
- IP addresses on regular requests (only on auth events for anomaly detection)
- Device fingerprints
- Cross-app tracking data
- Real names displayed publicly (usernames only)
- Payment data (the Service is free)
3. Third-party processors — LOCKED
We share data with the following processors under data-processing agreements:
| Processor | Purpose | Data shared |
|---|---|---|
| Supabase (Postgres + Auth + Storage hosted on AWS) | Backend database, authentication, file storage | All app data |
| Apple / Google | OAuth sign-in | Email, name (per their terms) |
| Expo Push Service | Push notification delivery to your device | Device token + notification body |
We do NOT share data with advertisers, data brokers, or analytics providers.
4. How we use your data
- To run the Service: show you nearby spots, route notifications to you, save your reports
- To moderate content: our stewards review submitted photos and reports
- To improve the Service: anonymous usage events show us which features people use
- To respond to your requests: data export, account deletion, abuse reports
We do NOT use your data for advertising or sell it to third parties.
5. Photo retention — LOCKED
This is non-standard policy worth highlighting:
- Public photos (the versions other users see) are retained for 365 days from upload.
- However, photos for spots that someone has updated, healed, or marked as authority-support-needed are kept FOREVER. The community record stays intact.
- Stale photos only — spots that nobody touched for a year — get auto-deleted at 365 days. The spot record itself stays; only the images expire. We notify the original reporter 5 days before expiry so they can re-photograph if the spot is still relevant.
- Original-resolution photos (with EXIF) live in an admin-only bucket for 90 days then auto-delete.
- Public-served photo variants have ALL EXIF metadata stripped before serving.
- Achievement share cards (PNG snapshots generated when you complete a heal) are cached forever so old social shares don't break.
6. Account deletion — LOCKED
When you delete your account (Settings → Account → Delete account):
- A 30-day grace window starts. Sign in during this window to cancel deletion.
- After 30 days, your profile is anonymised, not row-deleted. This keeps the integrity of the community record (your reported spots and verified heals stay attributed to "a healer" rather than disappearing).
- Specifically: username becomes `deleteduser<short-random>`, avatar/email/preferences/push tokens/notification settings are cleared, sessions revoked.
- This is a deliberate choice to preserve the historical record of community contributions while honouring your right to be unidentifiable.
You can request a copy of your data before deleting by emailing us at healingalhajar@gmail.com.
7. Analytics — LOCKED
The app currently contains no analytics — no third-party SDK and no usage-event tracking of our own. We do not log which screens you visit or which features you use.
If we ever add privacy-first usage analytics (self-hosted, no third parties), we will update this policy first and describe exactly what is collected and for how long.
8. Your rights
Under UAE PDPL and equivalent regulations, you may:
- Access your data — email us at healingalhajar@gmail.com to request a copy
- Correct your data — Edit Profile
- Delete your account — Settings → Account → Delete account (anonymisation model in §6)
- Restrict processing — Settings → Notifications (mute) or Privacy (hide from leaderboard)
- Object — contact healingalhajar@gmail.com
9. Children
The Service is not directed at children under 13. Apple/Google sign-in includes age-gating in their own flows. If we learn we have collected data from a child under 13 without parental consent, we will delete it.
10. International transfers
We use Supabase, which operates infrastructure in the EU and US. Your data may be transferred outside the UAE for processing.
11. Security
We use industry-standard security: HTTPS, encrypted storage at rest, Row Level Security on the database, JWT-based session tokens with auto-refresh. We do not use passwords (only OAuth + magic-link).
No system is perfectly secure. If we discover a breach, we will notify affected users within 72 hours where required by law.
12. Changes to this Policy
We may update this Policy. Material changes will be communicated via in-app notification before they take effect.
13. Contact
Questions: healingalhajar@gmail.com

