Privacy Policy - Sirran
1) Who we are
Sirran is provided by Saifullah Ahad ("we", "us", "our"). Our website/portfolio is: https://saifullah.ai.
2) What this policy covers
Sirran is a zakat calculation and private community-coordination tool. Calculation can be used locally. Community features use Firebase and a Cloudflare Worker so vouchers can issue blind signatures and recipients can redeem a threshold credential.
3) Information we collect
- Local calculation data: asset amounts, method choices, results, and calculation history stay in the app's local database.
- Authentication data: community features use either a Firebase anonymous identifier or an email address and password you provide. Google Firebase processes authentication credentials.
- Community data: a join code, community display information, voucher display name, Firebase user identifier, RSA public key, blinded signing requests, signature state, and claim status may be stored in Firestore.
- Redemption data: the app sends a community identifier, a random 32-byte credential token, voucher signatures, payout route, and an optional mobile-money number to the Cloudflare Worker. The redemption request contains no Firebase authorization header or user identifier.
The Worker stores a one-way SHA-256 hash of a redeemed token with its redemption time to prevent reuse. Pending payout rows contain the community, epoch, payout route, and optional mobile number. The spent-token table does not contain a name, account identifier, phone number, community identifier, or signature.
Sirran uses INTERNET and network-state access for authentication, Firestore, and
Worker requests. It does not request camera, microphone, contacts, location, or broad file access.
4) Local data
Sirran stores calculation history in a local database on your device. This data includes the asset amounts you enter, the nisab basis you select, and the calculated zakat result. Private RSA keys, unblinded credentials, blinding factors, and the complete local credential remain on the device and are not uploaded as a set. Local data is removed when you delete it, clear the app's storage, or uninstall the app.
5) How we use information
- authenticate community participants and apply access controls;
- route blinded requests to selected vouchers;
- verify that a redemption has enough distinct valid voucher signatures;
- prevent the same random credential from being redeemed twice;
- hold small payout groups until the minimum privacy batch is reached; and
- provide the calculation, history, withdrawal, and payout-route features you request.
6) Sharing and disclosure
We use Google Firebase for authentication and display-layer community records, and Cloudflare Workers and D1 for voucher-key registration, redemption enforcement, double-spend prevention, and epoch processing. These providers process data only to operate those services under their own terms and privacy commitments. Sirran has no advertising SDK, analytics SDK, data broker, or behavioral tracking, and we do not sell personal information.
7) Data retention
Local records remain until you delete them, clear app storage, or uninstall. Cloudflare spent hashes and payout records are automatically removed after 13 lunar months. Voucher public-key registrations and Firestore community records are retained while needed to operate the community or until the service or relevant record is removed. Authentication records remain with Firebase until the account is deleted or the service record is removed.
8) Your choices and controls
- Delete history: you can delete individual calculations or all history from within the app.
- Choose authentication: use an anonymous account or, if preferred, email and password.
- Choose payout privacy: envelope is the default; a mobile number is transmitted only when you explicitly choose mobile money.
- Withdraw: you can withdraw an active local claim. A hash already used to prevent double spending cannot be reversed.
- Reset app data: clearing app storage from Android Settings removes all local data.
- Uninstall: uninstalling the app removes Sirran and all its local data.
- Privacy requests: contact us at the email below about account or hosted-data deletion.
9) Important note
Sirran is a calculation tool. It does not provide religious rulings (fatwa) or conclude any obligation. Different scholarly positions may give different results. Users should consult a qualified scholar for personal guidance.
10) Children's privacy
Sirran is a general utility and community-coordination app and is not directed to children under 13. We do not knowingly collect personal information from children. A parent or guardian who believes a child submitted information may contact us for review and deletion.
11) International transfers
Firebase and Cloudflare may process hosted data in countries other than yours. Their safeguards and infrastructure govern those international transfers.
12) Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy at https://privacy.saifullah.ai/sirran.html and update the effective date above.
13) Contact
If you have questions or requests, contact: Saifullah Ahad
Email: [email protected]
Phone: +8801711134346
Website: https://saifullah.ai
Location: Dhaka, Bangladesh