Halood Privacy Policy

Last updated: 29 July 2026


Table of Contents

  1. Who We Are and How to Contact Us
  2. Scope of This Policy
  3. Data We Collect, Why We Collect It, and Our Lawful Basis
  4. On-Device vs. Server Processing — Scanner Privacy
  5. Sub-Processors and Third-Party Recipients
  6. International Transfers
  7. Retention Periods
  8. Your Rights Under UK GDPR
  9. Account and Data Deletion
  10. Children and Age Restrictions
  11. Cookies, SDK Identifiers, and Device Data
  12. Security Measures
  13. Personal Data Breaches
  14. Changes to This Policy
  15. Apple App Store Privacy Nutrition Label Summary

1. Who We Are and How to Contact Us

Controller: Auryte Limited, trading as Halood ("we", "us", "our") Company number: 17288539 Contact email: support@halood.app Registered in: England and Wales

Halood is the data controller for all personal data described in this policy. We are established and primarily operating in the United Kingdom and are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have any questions, requests, or concerns about your personal data, contact us at the email above. We aim to respond within 30 days.

ICO Registration: We will register with the Information Commissioner's Office (ICO) before launching the app. Our ICO registration number will be published here once confirmed. You have the right to complain to the ICO at ico.org.uk or by calling 0303 123 1113.


2. Scope of This Policy

This policy applies to:

It does not apply to third-party websites or services that we link to. Those services have their own privacy policies and we encourage you to read them.


3. Data We Collect, Why We Collect It, and Our Lawful Basis

We collect personal data in the following categories. For each category we state: what we collect, why we collect it (purpose), and our lawful basis under UK GDPR Article 6 (and Article 9 where applicable).


3.1 Authentication Identifiers

What: When you use the app, we assign you a Firebase anonymous UID. If you choose to sign in with Apple or Google, we receive a stable opaque user ID from those providers, and optionally your name and email address as shared by you.

Why: To identify your account, save your preferences and favourites, and enable personalised features across sessions and devices.

Lawful basis: Performance of a contract (Article 6(1)(b)) — necessary to provide the app service you have requested.

Notes: Anonymous accounts do not require you to share any identifying information. We do not require your real name. If you sign in with Sign in with Apple and choose to hide your email, we receive only the Apple-provided relay address.


3.2 Location

What: With your permission, we access your device's location, including precise location. Depending on the feature, we use:

Precise coordinates are sent to our backend (Cloudflare Worker) to return nearby places, and to routing providers (Apple Maps for car/walk; via our backend, HERE for transit and Mapbox for cycling) to calculate routes. We do not build advertising profiles from your location and do not sell or share it with advertisers.

Why: To deliver the map, nearby-places, directions, navigation, mosque-finder, and prayer-time features — these cannot work without location.

Lawful basis: Consent (Article 6(1)(a)) for accessing device location; performance of a contract (Article 6(1)(b)) for delivering the location-based features you request. You can withdraw consent at any time via iOS Settings > Privacy & Security > Location Services > Halood, and you can choose "While Using the App", "Once", or precise/approximate in iOS. Withdrawing location does not delete your account; some features will not work.

Notes: We do not retain a continuous history of your movements. Location is used to serve your request and is not stored as a movement profile.


3.3 Scan History (Barcodes and Ingredient Text)

What: When you scan a food product barcode or photograph an ingredient list, we process the input to determine halal status. See Section 4 for the full on-device vs. server breakdown.

Server-side data: If on-device AI cannot resolve the query, we may send a tokenised list of ingredient names (not the image) to our Cloudflare Worker, which forwards them to Cloudflare Workers AI. We do not send full images to our servers.

Why: To deliver halal verdict results and improve verdict accuracy over time.

Lawful basis: Performance of a contract (Article 6(1)(b)) for delivering the scan result; Legitimate interests (Article 6(1)(f)) for improving verdict accuracy, balanced against your privacy (we minimise data to ingredient tokens only).

Retention of scan data: Per-scan results may be cached in your local app storage so you do not need to rescan the same product. We do not store a timestamped log of every barcode you have ever scanned linked to your identity on our servers by default.


3.4 User-Submitted Spots and Photos

What: If you submit a new halal spot (restaurant, shop, or other venue), you may provide: name, address, category, halal certification details, and optionally a photo.

Why: To expand and maintain the community-sourced directory of halal spots.

Lawful basis: Consent (Article 6(1)(a)) — you choose what to submit.

Notes: Submitted spot data becomes part of our community dataset and may be visible to other users. Spot submissions are moderated. Photos you submit are associated with the spot, not with your personal profile, unless you explicitly add a profile photo.

Automated moderation: Before publication, the text and photos in your submission are automatically screened for safety (e.g., sexual content, hate, violence, self-harm) by OpenAI's moderation API — see Section 5. Submissions that pass this screen publish automatically; submissions the screen flags, or that it cannot process, are held and reviewed by a human before any decision to publish is made. This is a content-safety check, not a decision about you.


3.5 Profile Data

What: If you choose to create a public profile, you may provide: a display name, a username, and optionally a profile photo. You are not required to use your real name.

Why: To personalise your experience and enable social/community features (where available).

Lawful basis: Consent (Article 6(1)(a)). Profile creation is optional.


3.6 Usage and Analytics Data

What: We collect pseudonymised app usage data, including app launches, screens viewed, features used, session duration, selected tap events, and purchase-funnel events. PostHog events are associated with your Firebase user ID so that sessions and funnels work across sign-in states. AppsFlyer receives selected acquisition and conversion events, an AppsFlyer installation ID, IDFV, technical device and network information, and coarse location derived from IP address. We do not send AppsFlyer search text, precise location, names, or email addresses. If you grant permission through Apple's App Tracking Transparency prompt, AppsFlyer may also access the IDFA for advertising attribution; it is disabled otherwise.

Why: To understand how the app is used, improve performance, fix bugs, prioritise features, and measure which advertising campaigns lead to installs and subscription conversions.

Lawful basis: Legitimate interests (Article 6(1)(f)) for product analytics, service improvement, fraud prevention, and privacy-preserving attribution. Consent (Article 6(1)(a)) applies where AppsFlyer uses the IDFA or performs tracking under Apple's definition. You can deny or withdraw tracking permission in iOS Settings and can disable app analytics in Settings → Privacy & blocking.

Tools used: PostHog (product analytics), AppsFlyer (install and campaign attribution), and Firebase Crashlytics (crash reports and device metadata). See Section 5.


3.7 Crash Reports and Diagnostics

What: If the app crashes, Firebase Crashlytics automatically collects: device model, OS version, app version, crash stack trace, and a pseudonymous installation identifier. We do not collect names or email addresses in crash reports.

Why: To identify and fix bugs.

Lawful basis: Legitimate interests (Article 6(1)(f)).


3.8 Purchase and Subscription Data

What: If you purchase a Halood Premium subscription, Apple StoreKit processes the transaction. We receive from Apple: a subscription receipt, subscription status (active/expired/trial), and a pseudonymous App Account Token. We do not receive your Apple ID, payment method, or full billing address. We send pseudonymous purchase events and subscription status to RevenueCat for subscription analytics. When app analytics are enabled, we also send AppsFlyer the purchased product identifier as a conversion event for campaign attribution. We do not send AppsFlyer your price, payment method, receipt, or Apple ID.

If you explicitly allow purchase-usage sharing, RevenueCat may send Apple consumption information when Apple asks us to respond to your refund request. This may include whether the subscription was delivered and used, whether a trial or sample was provided, and our preferred resolution. Where access was delivered, we may recommend declining the refund. Apple always makes the final refund decision.

Why: To unlock premium features, manage your subscription status, measure subscription performance, and, only with your permission, help Apple review a refund request.

Lawful basis: Performance of a contract (Article 6(1)(b)) for purchase processing and entitlement management; legitimate interests (Article 6(1)(f)) for pseudonymous subscription analytics; consent (Article 6(1)(a)) for sharing consumption information with Apple for refund review. You may purchase without providing this consent and may withdraw it at any time in Settings → Privacy & blocking without losing subscription access.


3.9 Support Tickets and Communications

What: If you contact us by email, we retain your name (if provided), email address, and the content of your message.

Why: To respond to your enquiry and maintain a record of communications.

Lawful basis: Legitimate interests (Article 6(1)(f)) — providing customer support and maintaining a record of service interactions.


3.10 Community Feed and Direct Messages

What: Where available in your version of the app, the Community feed and direct/group messaging features collect: posts, comments, reactions, photos, and direct and group message content.

Why: To enable community interaction between users.

Lawful basis: Performance of a contract (Article 6(1)(b)) and Consent (Article 6(1)(a)) where social features require opt-in.

Note on special category data: Posts or messages may incidentally contain dietary or religious information. To the extent this constitutes special category data under UK GDPR Article 9 (data revealing religious belief, health data), our lawful basis is your explicit consent (Article 9(2)(a)), which you give by voluntarily posting that content publicly.

Where community and messaging features are available in your version of the app, the categories above (posts, comments, photos, reactions, direct and group messages, reports, and blocks) are processed via Google Firebase (Firestore and Storage) to deliver those features.


3.11 Directions, Navigation, and Live Activity

What: When you request directions, we process your origin (your location), the destination, and travel mode. During turn-by-turn "follow" mode we process continuous location to provide live guidance, spoken voice instructions (synthesised on-device), arrival estimates, and a lock-screen Live Activity showing route progress.

Why: To provide directions and navigation to halal places and mosques.

Lawful basis: Performance of a contract (Article 6(1)(b)); consent for background location (Article 6(1)(a)).

Recipients: Apple Maps (car/walk routes), and — via our backend — HERE (transit routes) and Mapbox (cycling routes). Voice guidance and the Live Activity are generated on your device.


3.12 Mosque Finder and Prayer Times

What: To find nearby mosques and calculate prayer times, we use a destination or your location. Mosque facility details and opening hours are looked up from OpenStreetMap (Overpass). Prayer times are calculated on your device.

Lawful basis: Performance of a contract (Article 6(1)(b)).


3.13 Points, Streaks, and Leaderboards

What: We record activity used for points, streaks, quests, and tiers (e.g. scans, saves, posts). If a leaderboard is available, your display name, tier, and points may be shown publicly to other users on that leaderboard.

Why: To operate gamification features and community standings.

Lawful basis: Performance of a contract (Article 6(1)(b)); consent for any public display of your name on a leaderboard, which you can avoid by not using a display name or by not participating.

Recipients: Google Firestore.


3.14 Delivery and Ordering Links

What: Some places show "Order" buttons or menu previews that link to third-party delivery platforms (Uber Eats, Deliveroo, Just Eat, GrabFood). Tapping a button opens that platform's page (in an in-app browser or its own app).

What we share: Nothing. We do not send your personal data to delivery platforms. We only open a link. Once you are on their platform, their own privacy policy applies. Where we participate in an affiliate or referral programme, a link may carry a referral tag so we can be credited for a resulting order; this is link-based only, does not use a tracking SDK, and does not track you across other apps (so no App Tracking Transparency prompt is triggered).

Lawful basis: Performance of a contract (Article 6(1)(b)) for showing the links; legitimate interests (Article 6(1)(f)) for any affiliate referral, balanced against your privacy (no personal data is shared).


3.15 Website Waitlist

What: If you join the waitlist at halood.app, we collect your email address, optional device-platform preference, the page URL you joined from, and your browser user-agent string. Your IP address is used transiently for abuse rate-limiting and is not stored in the waitlist table.

Why: To record your request and send the promised launch notification. Waitlist data is stored in Cloudflare D1 and is accessible only through an authenticated administrator route.

Lawful basis: Consent (Article 6(1)(a)). You can withdraw at any time by emailing support@halood.app. We do not use the waitlist for unrelated marketing or sell it to third parties.


4. On-Device vs. Server Processing — Scanner Privacy

We have designed the scanner to maximise your privacy. The processing ladder is:

StageWhere it runsData involvedLeaves device?
1. Bundled ontology lookupOn-device (IngredientOntology)Ingredient name stringNo
2. Apple Foundation Models (on-device LLM)On-device (Apple Neural Engine)Ingredient tokensNo
3. Halood Worker AICloudflare Worker + Workers AIIngredient token list only (no image or barcode)Yes — see Section 5

In practice: the vast majority of common ingredient lookups are resolved at stage 1 or 2 and never leave your device. A request only escalates to stage 3 when earlier stages cannot produce a confident verdict.

We never send food photos to our servers. OCR of ingredient label photos is performed on-device. Only the extracted ingredient text tokens are forwarded if escalation is needed.

Halal verdicts are guidance, not a religious ruling. Results are provided for informational purposes. You should verify with certifying bodies for critical decisions.


5. Sub-Processors and Third-Party Recipients

We use the following processors and sub-processors. Each processes personal data only on our documented instructions and has agreed to appropriate data protection terms.

We do not sell your personal data to any third party. We do not share personal data with advertisers.


6. International Transfers

Halood is UK-based. Some of our processors are located in or transfer data to the United States or other countries outside the UK. We ensure adequate safeguards are in place for all international transfers:

You can request a copy of the relevant transfer safeguards by contacting us at support@halood.app.


7. Retention Periods

We retain personal data only as long as necessary for the stated purpose or as required by law.

Data categoryRetention period
Anonymous auth UID (no sign-in)Until account deletion request or 2 years of inactivity
Signed-in account (Apple/Google)Permanently deleted immediately after in-app confirmation; residual backups rotate within 30 days
Profile data (name, username, photo)Until deletion request
Scan results (local cache)Stored locally on your device; cleared when you delete the app or clear app data
Scan tokens sent to Worker (stage 4)Not persistently stored server-side; processed in-flight only
Favourite spotsUntil deletion request or account deletion
User-submitted spotsRetained in the directory after account deletion (as anonymised community data) unless you request removal
PostHog product analyticsRaw pseudonymous events retained for up to 14 months, then deleted or aggregated; earlier erasure requests are handled where legally required
AppsFlyer attribution dataRetained only while needed for attribution, fraud prevention, and reporting, subject to AppsFlyer project settings and valid erasure requests
Crash reports90 days (Firebase Crashlytics default)
Purchase receipts7 years (legal obligation — tax and accounting records)
RevenueCat purchase analytics and refund preferenceUntil account deletion or the end of our RevenueCat service relationship, subject to necessary legal and security retention
Website waitlistUntil the launch notification is sent, you withdraw consent, or the waitlist is closed, after which it is deleted unless law requires longer retention
Support emails3 years from resolution of the enquiry
Community posts / DMs (when live)Until account deletion; account-owned content is deleted during the immediate deletion process

After the applicable retention period, data is securely deleted or irreversibly anonymised.


8. Your Rights Under UK GDPR

Under the UK GDPR and Data Protection Act 2018, you have the following rights. To exercise any of them, contact us at support@halood.app. We will respond within one calendar month (extendable by two further months for complex requests, with notice).

8.1 Right of Access (Article 15)

You can request a copy of the personal data we hold about you and information about how we process it. We will provide this in a commonly used electronic format.

8.2 Right to Rectification (Article 16)

If any personal data we hold about you is inaccurate or incomplete, you can ask us to correct it. You can also update your display name and profile directly in the app at any time.

8.3 Right to Erasure ("Right to be Forgotten") (Article 17)

You can ask us to delete your personal data. We will do so unless we are required to retain it by law (e.g., financial records) or it is necessary for the establishment, exercise, or defence of legal claims. See also Section 9 for in-app deletion.

8.4 Right to Restriction of Processing (Article 18)

You can ask us to restrict processing of your data in certain circumstances — for example, while we verify a rectification request or while you contest our legitimate interests basis.

8.5 Right to Data Portability (Article 20)

Where processing is based on consent or contract and is carried out by automated means, you can request a machine-readable export of your personal data (e.g., your profile, favourites, scan history stored server-side).

8.6 Right to Object (Article 21)

You can object to processing based on legitimate interests (Article 6(1)(f)) at any time. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.

You have an absolute right to object to processing for direct marketing (we do not currently engage in direct marketing profiling).

8.7 Right to Withdraw Consent (Article 7(3))

Where processing is based on your consent (e.g., location access, community features), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. For location, withdraw in iOS Settings > Privacy & Security > Location Services > Halood.

8.8 Rights Related to Automated Decision-Making (Article 22)

We do not make decisions about you solely by automated means that produce legal or similarly significant effects. Halal verdicts are guidance only and do not constitute automated decisions with significant effects.

8.9 Right to Lodge a Complaint

You have the right to complain to the Information Commissioner's Office (ICO) at any time:

We would, however, appreciate the opportunity to address your concern first.


9. Account and Data Deletion

You can delete your account and associated personal data at any time. We provide two methods:

In-App Deletion

  1. Open the Halood app.
  2. Go to Settings (bottom navigation bar).
  3. Tap Account > Delete Account.
  4. Confirm deletion.

For every account type, confirming deletion starts permanent deletion immediately. The action cannot be cancelled or reversed after confirmation. The app reports success only after account-owned data in our active Firebase and Cloudflare systems and the Firebase Auth account have been deleted.

During permanent deletion:

Email Request

Email support@halood.app with the subject line "Data Deletion Request" from the email address associated with your account (or your Apple relay address). We will process the request within 30 days and confirm completion.

What We Retain After Deletion

After deletion, we may retain:

This deletion process meets Apple App Store Review Guidelines requirement 5.1.1(v) for an in-app account deletion mechanism.


10. Children and Age Restrictions

Halood is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13 without parental consent, we will delete it promptly.

Age tiers (enforced by our in-app age gate, which records your birth year):

This gate is in place in accordance with UK GDPR Article 8, Apple's App Store Guidelines, and UK age-appropriate design guidance. If you are a parent or guardian and believe your child under 13 has provided us with personal data, please contact us at support@halood.app and we will take steps to delete that information.


11. Cookies, SDK Identifiers, and Device Data

The Halood app is a native iOS application and does not use browser cookies. However, similar tracking and identifier mechanisms are in use:

Identifier / SDKPurposeOpt-out / Control
Firebase Installation IDPseudonymous identifier for analytics and crash reportingDeleted when you delete the app or your account
Firebase UID / PostHog distinct IDLinks product events to the same Halood account without sending a name or emailDisable analytics in Settings; account deletion starts the process in Section 9
AppsFlyer ID, IDFV, and technical device dataInstall attribution, campaign measurement, and fraud preventionDisable analytics in Settings; IDFV resets after uninstalling all apps from this vendor
Apple IDFAAdvertising attribution only when you grant Apple's App Tracking Transparency permissionDeny the prompt or withdraw permission in iOS Settings > Privacy & Security > Tracking
Apple StoreKit App Account TokenLinks your in-app subscription to your Halood accountDeleted with account
RevenueCat App User IDLinks pseudonymous subscription events and refund-handling preference to your Halood accountAccount deletion or a support erasure request, subject to required retention
Apple Sign in with Apple opaque IDStable user identifier for authenticationRevocable via Apple ID settings: Settings > [Your Name] > Password & Security > Apps Using Apple ID

AppsFlyer cannot access the IDFA unless you grant ATT permission. Where granted, the IDFA, AppsFlyer identifiers, coarse location derived from IP, selected product interactions, purchase events, and technical device or network data may be combined for advertising attribution and measurement across third-party apps or websites. Apple defines this as tracking. Halood does not sell this data and does not display third-party advertising inside the app. If app analytics are disabled, Halood stops sending selected in-app conversion events and asks AppsFlyer to anonymise attribution data, while privacy-preserving aggregate install attribution may continue.

Our website (halood.app). Separately from the app, our website provides product, legal, universal-link, and waitlist pages. It does not use analytics, advertising, or tracking cookies. It may set strictly necessary cookies through Cloudflare for security and bot management. The waitlist form sends the data described in Section 3.15 without using a tracking cookie. For details, see our Cookie Policy.


12. Security Measures

We implement technical and organisational measures to protect your personal data:

Technical measures:

Organisational measures:

No method of transmission or storage is 100% secure. In the event of a breach affecting your rights and freedoms, we will notify you and the ICO as required by law.


13. Personal Data Breaches

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

Breach notifications will include: the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed.


14. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, features, or legal requirements. When we make material changes, we will:

The current version of this policy is always available within the app (Settings > Privacy Policy) and at halood.app/privacy.

Continued use of the app after the effective date of an updated policy constitutes acceptance of the updated terms, to the extent permitted by law.


15. Apple App Store Privacy Nutrition Label Summary

The following is a mapping of our data practices to Apple's App Store Privacy Nutrition Label categories. This summary is provided for transparency; the full detail is in the sections above.

Data Used to Track You

Device ID, coarse location, selected product interactions and purchase events, and technical device or network data. AppsFlyer uses these for install attribution, campaign measurement, analytics, and fraud prevention. IDFA-based tracking occurs only if you grant App Tracking Transparency permission. Without permission, Halood disables AppsFlyer's access to the IDFA and uses privacy-preserving attribution methods where available.

Data Linked to You

Apple categorySpecific dataPurpose
IdentifiersUser ID (Firebase UID, Apple/Google opaque ID, RevenueCat App User ID)App functionality, account management, analytics
IdentifiersDevice ID (AppsFlyer ID, IDFV and, with ATT permission, IDFA)Analytics, app functionality, developer advertising or marketing
LocationCoarse location derived from IP by AppsFlyerAnalytics, app functionality, developer advertising or marketing
User ContentPhotos, posts, comments, reviews, and direct/group messages (when available)App functionality
Usage DataProduct interaction (app launches and selected screens or features used)Analytics, app functionality, developer advertising or marketing
DiagnosticsCrash data and performance dataApp functionality, analytics
PurchasesPurchase history and subscription statusApp functionality, analytics, advertising attribution
Contact InfoName and email address, when provided for sign-in, profile, support, or website waitlistApp functionality, customer support, requested communications
Other DataAppsFlyer installation ID, IDFV, and technical device or network informationAnalytics, app functionality, developer advertising or marketing

Data Not Linked to You

Apple categorySpecific dataPurpose
LocationPrecise location used for a requested nearby search or route, without a retained movement profileApp functionality

Aggregated statistics may no longer identify a person, but source product analytics, attribution, crash, and subscription events can be associated with a Halood account or device before aggregation. We therefore use the more conservative linked-data declarations above for those categories.

Data Not Collected


For questions about this policy, contact support@halood.app.