This Privacy Policy explains how Rifaq ("Rifaq", "we", "us"),
operated by BrightByte LLC, handles your information when you use the Rifaq mobile
app and related services (the "Service"). Rifaq is a habit and task
accountability app with group leaderboards.
Information we collect
- Account details — your email address, display name, optional
avatar, time zone and language. Rifaq is passwordless: we never
collect or store a password.
- Sign-in identities — when you sign in with Google, Apple or
Facebook, we receive a provider user identifier and, where you allow it, your
email and name, solely to create or link your Rifaq account.
- Your content — the tasks, task completions, groups and invites
you create or join.
- Device & notifications — push-notification tokens and device
platform, so we can deliver notifications you have enabled.
- Support messages — when you write to us through the app's
Contact-us form, we store your message, the topic you chose, and the app
version, platform and language of the device you sent it from, so we can
answer you.
- Usage for features — records of notifications sent and read to
operate reminders, leaderboards and gamification.
How we use your information
- Provide, operate and secure the Service.
- Send one-time sign-in codes and group invitations by email.
- Compute daily leaderboards, streaks, badges and challenges.
- Deliver push notifications you have opted into (you can opt out per category).
Service providers we share with
We share limited data with processors strictly to run the Service. We do
not sell your personal data.
- Railway — application hosting and database.
- Resend — transactional email (sign-in codes, invites).
- Google Firebase Cloud Messaging — push-notification delivery.
- Google, Apple, Facebook — verifying your sign-in when you choose
social login.
Data retention & deletion
We keep your information while your account is active. You may request deletion
at any time — see our Data Deletion page. We remove
your personal data within 30 days of a verified request, except where limited
records must be retained to comply with law.
Security
Data is encrypted in transit (HTTPS). Sensitive tokens and one-time codes are
stored only as cryptographic hashes, and there are no passwords to leak.
Children
The Service is not directed to children under 13 (or the minimum age required in
your country). We do not knowingly collect data from them.
Your rights
You may access, correct or delete your data, and object to or restrict certain
processing, by contacting us at privacy@rifaq.app.
Contact
For anything about the app, write to
support@rifaq.app or use the Contact-us form in
the app under Settings. See our Support page.
Changes
We may update this policy; we will revise the effective date above and, for
material changes, notify you in the app.
Questions? Contact privacy@rifaq.app.