Last updated: 29 July 2026
Controller: Auryte Limited, trading as Halood ("we", "us", "our") Company number: 17288539 Contact email: support@halood.app Registered in: England and Wales
Halood is the data controller for all personal data described in this policy. We are established and primarily operating in the United Kingdom and are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions, requests, or concerns about your personal data, contact us at the email above. We aim to respond within 30 days.
ICO Registration: We will register with the Information Commissioner's Office (ICO) before launching the app. Our ICO registration number will be published here once confirmed. You have the right to complain to the ICO at ico.org.uk or by calling 0303 123 1113.
This policy applies to:
It does not apply to third-party websites or services that we link to. Those services have their own privacy policies and we encourage you to read them.
We collect personal data in the following categories. For each category we state: what we collect, why we collect it (purpose), and our lawful basis under UK GDPR Article 6 (and Article 9 where applicable).
What: When you use the app, we assign you a Firebase anonymous UID. If you choose to sign in with Apple or Google, we receive a stable opaque user ID from those providers, and optionally your name and email address as shared by you.
Why: To identify your account, save your preferences and favourites, and enable personalised features across sessions and devices.
Lawful basis: Performance of a contract (Article 6(1)(b)) — necessary to provide the app service you have requested.
Notes: Anonymous accounts do not require you to share any identifying information. We do not require your real name. If you sign in with Sign in with Apple and choose to hide your email, we receive only the Apple-provided relay address.
What: With your permission, we access your device's location, including precise location. Depending on the feature, we use:
Precise coordinates are sent to our backend (Cloudflare Worker) to return nearby places, and to routing providers (Apple Maps for car/walk; via our backend, HERE for transit and Mapbox for cycling) to calculate routes. We do not build advertising profiles from your location and do not sell or share it with advertisers.
Why: To deliver the map, nearby-places, directions, navigation, mosque-finder, and prayer-time features — these cannot work without location.
Lawful basis: Consent (Article 6(1)(a)) for accessing device location; performance of a contract (Article 6(1)(b)) for delivering the location-based features you request. You can withdraw consent at any time via iOS Settings > Privacy & Security > Location Services > Halood, and you can choose "While Using the App", "Once", or precise/approximate in iOS. Withdrawing location does not delete your account; some features will not work.
Notes: We do not retain a continuous history of your movements. Location is used to serve your request and is not stored as a movement profile.
What: When you scan a food product barcode or photograph an ingredient list, we process the input to determine halal status. See Section 4 for the full on-device vs. server breakdown.
Server-side data: If on-device AI cannot resolve the query, we may send a tokenised list of ingredient names (not the image) to our Cloudflare Worker, which forwards them to Cloudflare Workers AI. We do not send full images to our servers.
Why: To deliver halal verdict results and improve verdict accuracy over time.
Lawful basis: Performance of a contract (Article 6(1)(b)) for delivering the scan result; Legitimate interests (Article 6(1)(f)) for improving verdict accuracy, balanced against your privacy (we minimise data to ingredient tokens only).
Retention of scan data: Per-scan results may be cached in your local app storage so you do not need to rescan the same product. We do not store a timestamped log of every barcode you have ever scanned linked to your identity on our servers by default.
What: If you submit a new halal spot (restaurant, shop, or other venue), you may provide: name, address, category, halal certification details, and optionally a photo.
Why: To expand and maintain the community-sourced directory of halal spots.
Lawful basis: Consent (Article 6(1)(a)) — you choose what to submit.
Notes: Submitted spot data becomes part of our community dataset and may be visible to other users. Spot submissions are moderated. Photos you submit are associated with the spot, not with your personal profile, unless you explicitly add a profile photo.
Automated moderation: Before publication, the text and photos in your submission are automatically screened for safety (e.g., sexual content, hate, violence, self-harm) by OpenAI's moderation API — see Section 5. Submissions that pass this screen publish automatically; submissions the screen flags, or that it cannot process, are held and reviewed by a human before any decision to publish is made. This is a content-safety check, not a decision about you.
What: If you choose to create a public profile, you may provide: a display name, a username, and optionally a profile photo. You are not required to use your real name.
Why: To personalise your experience and enable social/community features (where available).
Lawful basis: Consent (Article 6(1)(a)). Profile creation is optional.
What: We collect pseudonymised app usage data, including app launches, screens viewed, features used, session duration, selected tap events, and purchase-funnel events. PostHog events are associated with your Firebase user ID so that sessions and funnels work across sign-in states. AppsFlyer receives selected acquisition and conversion events, an AppsFlyer installation ID, IDFV, technical device and network information, and coarse location derived from IP address. We do not send AppsFlyer search text, precise location, names, or email addresses. If you grant permission through Apple's App Tracking Transparency prompt, AppsFlyer may also access the IDFA for advertising attribution; it is disabled otherwise.
Why: To understand how the app is used, improve performance, fix bugs, prioritise features, and measure which advertising campaigns lead to installs and subscription conversions.
Lawful basis: Legitimate interests (Article 6(1)(f)) for product analytics, service improvement, fraud prevention, and privacy-preserving attribution. Consent (Article 6(1)(a)) applies where AppsFlyer uses the IDFA or performs tracking under Apple's definition. You can deny or withdraw tracking permission in iOS Settings and can disable app analytics in Settings → Privacy & blocking.
Tools used: PostHog (product analytics), AppsFlyer (install and campaign attribution), and Firebase Crashlytics (crash reports and device metadata). See Section 5.
What: If the app crashes, Firebase Crashlytics automatically collects: device model, OS version, app version, crash stack trace, and a pseudonymous installation identifier. We do not collect names or email addresses in crash reports.
Why: To identify and fix bugs.
Lawful basis: Legitimate interests (Article 6(1)(f)).
What: If you purchase a Halood Premium subscription, Apple StoreKit processes the transaction. We receive from Apple: a subscription receipt, subscription status (active/expired/trial), and a pseudonymous App Account Token. We do not receive your Apple ID, payment method, or full billing address. We send pseudonymous purchase events and subscription status to RevenueCat for subscription analytics. When app analytics are enabled, we also send AppsFlyer the purchased product identifier as a conversion event for campaign attribution. We do not send AppsFlyer your price, payment method, receipt, or Apple ID.
If you explicitly allow purchase-usage sharing, RevenueCat may send Apple consumption information when Apple asks us to respond to your refund request. This may include whether the subscription was delivered and used, whether a trial or sample was provided, and our preferred resolution. Where access was delivered, we may recommend declining the refund. Apple always makes the final refund decision.
Why: To unlock premium features, manage your subscription status, measure subscription performance, and, only with your permission, help Apple review a refund request.
Lawful basis: Performance of a contract (Article 6(1)(b)) for purchase processing and entitlement management; legitimate interests (Article 6(1)(f)) for pseudonymous subscription analytics; consent (Article 6(1)(a)) for sharing consumption information with Apple for refund review. You may purchase without providing this consent and may withdraw it at any time in Settings → Privacy & blocking without losing subscription access.
What: If you contact us by email, we retain your name (if provided), email address, and the content of your message.
Why: To respond to your enquiry and maintain a record of communications.
Lawful basis: Legitimate interests (Article 6(1)(f)) — providing customer support and maintaining a record of service interactions.
What: Where available in your version of the app, the Community feed and direct/group messaging features collect: posts, comments, reactions, photos, and direct and group message content.
Why: To enable community interaction between users.
Lawful basis: Performance of a contract (Article 6(1)(b)) and Consent (Article 6(1)(a)) where social features require opt-in.
Note on special category data: Posts or messages may incidentally contain dietary or religious information. To the extent this constitutes special category data under UK GDPR Article 9 (data revealing religious belief, health data), our lawful basis is your explicit consent (Article 9(2)(a)), which you give by voluntarily posting that content publicly.
Where community and messaging features are available in your version of the app, the categories above (posts, comments, photos, reactions, direct and group messages, reports, and blocks) are processed via Google Firebase (Firestore and Storage) to deliver those features.
What: When you request directions, we process your origin (your location), the destination, and travel mode. During turn-by-turn "follow" mode we process continuous location to provide live guidance, spoken voice instructions (synthesised on-device), arrival estimates, and a lock-screen Live Activity showing route progress.
Why: To provide directions and navigation to halal places and mosques.
Lawful basis: Performance of a contract (Article 6(1)(b)); consent for background location (Article 6(1)(a)).
Recipients: Apple Maps (car/walk routes), and — via our backend — HERE (transit routes) and Mapbox (cycling routes). Voice guidance and the Live Activity are generated on your device.
What: To find nearby mosques and calculate prayer times, we use a destination or your location. Mosque facility details and opening hours are looked up from OpenStreetMap (Overpass). Prayer times are calculated on your device.
Lawful basis: Performance of a contract (Article 6(1)(b)).
What: We record activity used for points, streaks, quests, and tiers (e.g. scans, saves, posts). If a leaderboard is available, your display name, tier, and points may be shown publicly to other users on that leaderboard.
Why: To operate gamification features and community standings.
Lawful basis: Performance of a contract (Article 6(1)(b)); consent for any public display of your name on a leaderboard, which you can avoid by not using a display name or by not participating.
Recipients: Google Firestore.
What: Some places show "Order" buttons or menu previews that link to third-party delivery platforms (Uber Eats, Deliveroo, Just Eat, GrabFood). Tapping a button opens that platform's page (in an in-app browser or its own app).
What we share: Nothing. We do not send your personal data to delivery platforms. We only open a link. Once you are on their platform, their own privacy policy applies. Where we participate in an affiliate or referral programme, a link may carry a referral tag so we can be credited for a resulting order; this is link-based only, does not use a tracking SDK, and does not track you across other apps (so no App Tracking Transparency prompt is triggered).
Lawful basis: Performance of a contract (Article 6(1)(b)) for showing the links; legitimate interests (Article 6(1)(f)) for any affiliate referral, balanced against your privacy (no personal data is shared).
What: If you join the waitlist at halood.app, we collect your email address, optional device-platform preference, the page URL you joined from, and your browser user-agent string. Your IP address is used transiently for abuse rate-limiting and is not stored in the waitlist table.
Why: To record your request and send the promised launch notification. Waitlist data is stored in Cloudflare D1 and is accessible only through an authenticated administrator route.
Lawful basis: Consent (Article 6(1)(a)). You can withdraw at any time by emailing support@halood.app. We do not use the waitlist for unrelated marketing or sell it to third parties.
We have designed the scanner to maximise your privacy. The processing ladder is:
| Stage | Where it runs | Data involved | Leaves device? |
|---|---|---|---|
| 1. Bundled ontology lookup | On-device (IngredientOntology) | Ingredient name string | No |
| 2. Apple Foundation Models (on-device LLM) | On-device (Apple Neural Engine) | Ingredient tokens | No |
| 3. Halood Worker AI | Cloudflare Worker + Workers AI | Ingredient token list only (no image or barcode) | Yes — see Section 5 |
In practice: the vast majority of common ingredient lookups are resolved at stage 1 or 2 and never leave your device. A request only escalates to stage 3 when earlier stages cannot produce a confident verdict.
We never send food photos to our servers. OCR of ingredient label photos is performed on-device. Only the extracted ingredient text tokens are forwarded if escalation is needed.
Halal verdicts are guidance, not a religious ruling. Results are provided for informational purposes. You should verify with certifying bodies for critical decisions.
We use the following processors and sub-processors. Each processes personal data only on our documented instructions and has agreed to appropriate data protection terms.
We do not sell your personal data to any third party. We do not share personal data with advertisers.
Halood is UK-based. Some of our processors are located in or transfer data to the United States or other countries outside the UK. We ensure adequate safeguards are in place for all international transfers:
You can request a copy of the relevant transfer safeguards by contacting us at support@halood.app.
We retain personal data only as long as necessary for the stated purpose or as required by law.
| Data category | Retention period |
|---|---|
| Anonymous auth UID (no sign-in) | Until account deletion request or 2 years of inactivity |
| Signed-in account (Apple/Google) | Permanently deleted immediately after in-app confirmation; residual backups rotate within 30 days |
| Profile data (name, username, photo) | Until deletion request |
| Scan results (local cache) | Stored locally on your device; cleared when you delete the app or clear app data |
| Scan tokens sent to Worker (stage 4) | Not persistently stored server-side; processed in-flight only |
| Favourite spots | Until deletion request or account deletion |
| User-submitted spots | Retained in the directory after account deletion (as anonymised community data) unless you request removal |
| PostHog product analytics | Raw pseudonymous events retained for up to 14 months, then deleted or aggregated; earlier erasure requests are handled where legally required |
| AppsFlyer attribution data | Retained only while needed for attribution, fraud prevention, and reporting, subject to AppsFlyer project settings and valid erasure requests |
| Crash reports | 90 days (Firebase Crashlytics default) |
| Purchase receipts | 7 years (legal obligation — tax and accounting records) |
| RevenueCat purchase analytics and refund preference | Until account deletion or the end of our RevenueCat service relationship, subject to necessary legal and security retention |
| Website waitlist | Until the launch notification is sent, you withdraw consent, or the waitlist is closed, after which it is deleted unless law requires longer retention |
| Support emails | 3 years from resolution of the enquiry |
| Community posts / DMs (when live) | Until account deletion; account-owned content is deleted during the immediate deletion process |
After the applicable retention period, data is securely deleted or irreversibly anonymised.
Under the UK GDPR and Data Protection Act 2018, you have the following rights. To exercise any of them, contact us at support@halood.app. We will respond within one calendar month (extendable by two further months for complex requests, with notice).
You can request a copy of the personal data we hold about you and information about how we process it. We will provide this in a commonly used electronic format.
If any personal data we hold about you is inaccurate or incomplete, you can ask us to correct it. You can also update your display name and profile directly in the app at any time.
You can ask us to delete your personal data. We will do so unless we are required to retain it by law (e.g., financial records) or it is necessary for the establishment, exercise, or defence of legal claims. See also Section 9 for in-app deletion.
You can ask us to restrict processing of your data in certain circumstances — for example, while we verify a rectification request or while you contest our legitimate interests basis.
Where processing is based on consent or contract and is carried out by automated means, you can request a machine-readable export of your personal data (e.g., your profile, favourites, scan history stored server-side).
You can object to processing based on legitimate interests (Article 6(1)(f)) at any time. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
You have an absolute right to object to processing for direct marketing (we do not currently engage in direct marketing profiling).
Where processing is based on your consent (e.g., location access, community features), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. For location, withdraw in iOS Settings > Privacy & Security > Location Services > Halood.
We do not make decisions about you solely by automated means that produce legal or similarly significant effects. Halal verdicts are guidance only and do not constitute automated decisions with significant effects.
You have the right to complain to the Information Commissioner's Office (ICO) at any time:
We would, however, appreciate the opportunity to address your concern first.
You can delete your account and associated personal data at any time. We provide two methods:
For every account type, confirming deletion starts permanent deletion immediately. The action cannot be cancelled or reversed after confirmation. The app reports success only after account-owned data in our active Firebase and Cloudflare systems and the Firebase Auth account have been deleted.
During permanent deletion:
Email support@halood.app with the subject line "Data Deletion Request" from the email address associated with your account (or your Apple relay address). We will process the request within 30 days and confirm completion.
After deletion, we may retain:
This deletion process meets Apple App Store Review Guidelines requirement 5.1.1(v) for an in-app account deletion mechanism.
Halood is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13 without parental consent, we will delete it promptly.
Age tiers (enforced by our in-app age gate, which records your birth year):
This gate is in place in accordance with UK GDPR Article 8, Apple's App Store Guidelines, and UK age-appropriate design guidance. If you are a parent or guardian and believe your child under 13 has provided us with personal data, please contact us at support@halood.app and we will take steps to delete that information.
The Halood app is a native iOS application and does not use browser cookies. However, similar tracking and identifier mechanisms are in use:
| Identifier / SDK | Purpose | Opt-out / Control |
|---|---|---|
| Firebase Installation ID | Pseudonymous identifier for analytics and crash reporting | Deleted when you delete the app or your account |
| Firebase UID / PostHog distinct ID | Links product events to the same Halood account without sending a name or email | Disable analytics in Settings; account deletion starts the process in Section 9 |
| AppsFlyer ID, IDFV, and technical device data | Install attribution, campaign measurement, and fraud prevention | Disable analytics in Settings; IDFV resets after uninstalling all apps from this vendor |
| Apple IDFA | Advertising attribution only when you grant Apple's App Tracking Transparency permission | Deny the prompt or withdraw permission in iOS Settings > Privacy & Security > Tracking |
| Apple StoreKit App Account Token | Links your in-app subscription to your Halood account | Deleted with account |
| RevenueCat App User ID | Links pseudonymous subscription events and refund-handling preference to your Halood account | Account deletion or a support erasure request, subject to required retention |
| Apple Sign in with Apple opaque ID | Stable user identifier for authentication | Revocable via Apple ID settings: Settings > [Your Name] > Password & Security > Apps Using Apple ID |
AppsFlyer cannot access the IDFA unless you grant ATT permission. Where granted, the IDFA, AppsFlyer identifiers, coarse location derived from IP, selected product interactions, purchase events, and technical device or network data may be combined for advertising attribution and measurement across third-party apps or websites. Apple defines this as tracking. Halood does not sell this data and does not display third-party advertising inside the app. If app analytics are disabled, Halood stops sending selected in-app conversion events and asks AppsFlyer to anonymise attribution data, while privacy-preserving aggregate install attribution may continue.
Our website (halood.app). Separately from the app, our website provides product, legal, universal-link, and waitlist pages. It does not use analytics, advertising, or tracking cookies. It may set strictly necessary cookies through Cloudflare for security and bot management. The waitlist form sends the data described in Section 3.15 without using a tracking cookie. For details, see our Cookie Policy.
We implement technical and organisational measures to protect your personal data:
Technical measures:
Organisational measures:
No method of transmission or storage is 100% secure. In the event of a breach affecting your rights and freedoms, we will notify you and the ICO as required by law.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
Breach notifications will include: the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed.
We may update this policy from time to time to reflect changes in our practices, features, or legal requirements. When we make material changes, we will:
The current version of this policy is always available within the app (Settings > Privacy Policy) and at halood.app/privacy.
Continued use of the app after the effective date of an updated policy constitutes acceptance of the updated terms, to the extent permitted by law.
The following is a mapping of our data practices to Apple's App Store Privacy Nutrition Label categories. This summary is provided for transparency; the full detail is in the sections above.
Device ID, coarse location, selected product interactions and purchase events, and technical device or network data. AppsFlyer uses these for install attribution, campaign measurement, analytics, and fraud prevention. IDFA-based tracking occurs only if you grant App Tracking Transparency permission. Without permission, Halood disables AppsFlyer's access to the IDFA and uses privacy-preserving attribution methods where available.
| Apple category | Specific data | Purpose |
|---|---|---|
| Identifiers | User ID (Firebase UID, Apple/Google opaque ID, RevenueCat App User ID) | App functionality, account management, analytics |
| Identifiers | Device ID (AppsFlyer ID, IDFV and, with ATT permission, IDFA) | Analytics, app functionality, developer advertising or marketing |
| Location | Coarse location derived from IP by AppsFlyer | Analytics, app functionality, developer advertising or marketing |
| User Content | Photos, posts, comments, reviews, and direct/group messages (when available) | App functionality |
| Usage Data | Product interaction (app launches and selected screens or features used) | Analytics, app functionality, developer advertising or marketing |
| Diagnostics | Crash data and performance data | App functionality, analytics |
| Purchases | Purchase history and subscription status | App functionality, analytics, advertising attribution |
| Contact Info | Name and email address, when provided for sign-in, profile, support, or website waitlist | App functionality, customer support, requested communications |
| Other Data | AppsFlyer installation ID, IDFV, and technical device or network information | Analytics, app functionality, developer advertising or marketing |
| Apple category | Specific data | Purpose |
|---|---|---|
| Location | Precise location used for a requested nearby search or route, without a retained movement profile | App functionality |
Aggregated statistics may no longer identify a person, but source product analytics, attribution, crash, and subscription events can be associated with a Halood account or device before aggregation. We therefore use the more conservative linked-data declarations above for those categories.
For questions about this policy, contact support@halood.app.