1. Scope and who is responsible
This Privacy Policy explains how Muhammad Rabi, publishing under the AppCLabs brand (“AppCLabs,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you use appclabs.com, any mobile application published or operated by AppCLabs, or their updates, widgets, support channels, and related services (collectively, the “Services”).
AppCLabs is an unregistered publishing and brand name used by Muhammad Rabi; it is not a separate legal entity or registered company. Muhammad Rabi is the individual data controller or business responsible for the processing described here. Some vendors act as our processors or service providers; in some contexts a platform or advertising provider may act as a separate controller under its own terms.
In an app-store listing or in-app link, the app is identified by the display name attached to that listing or link. This lets one single AppCLabs policy cover new and existing products without leaving an outdated product list here. An app may provide a short just-in-time notice for a particular feature; that notice supplements this policy.
2. Information we collect
Information you provide
- Support and privacy requests: your email address, message, attachments, and information you choose to include.
- Account and sign-in information: where enabled in an AppCLabs app, identifiers and limited profile information supplied through Google Sign-In or Sign in with Apple.
- Purchase information: subscription status, entitlement, product, transaction or receipt identifiers, renewal and restore status. Apple or Google processes payment details; we do not receive full payment-card data.
Faith, prayer, location, and content features
- Prayer and app activity: prayer check-ins, streaks, preferences, reading/listening progress, recent items, reminder settings, and feature interactions.
- Location: precise location when you grant permission, used to calculate prayer, suhoor, and iftar times and related reminders. Approximate location may also be inferred from IP by service providers.
- AI content: prompts, chat text, and images you choose to attach or capture so an AI provider can generate a response. Local chat history and attachment thumbnails may remain on your device until cleared.
- Safety reports: when you report an AI response, the flagged response, nearest preceding text prompt, reason, and optional note. Images and attachments are excluded from the report.
- Notifications: push token, notification preferences, and delivery or interaction information.
Nutrition, meal, wellness, and health features
- Meal content: meal descriptions, voice recordings submitted for transcription, meal photos, notes, timestamps, meal type, and generated nutrition estimates.
- Profile and goals: age, gender, height, weight, goal weight, activity level, weekly pace, calorie target, and onboarding choices.
- Progress information: meal history, weight entries, calorie and macro history, streaks, wellness estimates, and reminder settings.
- Apple Health: if you connect HealthKit, authorized data may include VO₂ max, resting heart rate, heart-rate variability, one-minute heart-rate recovery, step count, walking speed, and waist circumference. In the current implementation, this information is processed on your device for wellness estimates and is not uploaded by us.
- Local operational data: locally stored app state and failed background jobs retained for retry until completed or removed.
Collected automatically in an app
- Device, installation, app-instance, vendor, advertising, account, or push identifiers, depending on platform permission, consent, and the SDK used.
- App interactions, screens, feature actions, session information, attribution data, consent choices, and subscription conversion events.
- Device model, operating system, app version, language, country or approximate region, network information, crash logs, diagnostics, and performance information.
- IDFA on iOS only when Apple’s App Tracking Transparency permission is granted; Android advertising identifiers where permitted by platform settings and law.
We do not intentionally collect government identifiers, full payment-card information, contact lists, genetic data, biometric templates, political opinions, trade-union membership, sexual orientation, or race/ethnicity. Religious activity and health- or wellness-related inputs may be considered sensitive under some laws and are handled only for the app functions you request and as otherwise described here.
3. Why we use information and our legal bases
| Purpose | Examples | Legal basis where GDPR applies |
|---|---|---|
| Provide the Services | Generate prayer times or AI responses, analyze meals, save preferences, deliver reminders, restore purchases. | Performance of a contract; consent where required for location, photos, microphone, or similar permissions; explicit consent where required for religious, health, or other special-category data. |
| Operate and secure | Authentication, fraud and abuse prevention, troubleshooting, crash detection, availability, and support. | Contract; legitimate interests in secure and reliable operation; legal obligation. |
| Measure and improve | Understand feature use, app funnels, reliability, and aggregated product performance. | Consent where required; otherwise legitimate interests, balanced against your rights. |
| Marketing and attribution | Measure campaigns, subscription conversions, and advertising effectiveness. | Consent where required, including relevant consent-management and platform choices. |
| Legal and compliance | Respond to rights requests, enforce terms, preserve records, or comply with lawful process. | Legal obligation; legitimate interests; establishment or defense of legal claims. |
Where processing relies on consent, you may withdraw it at any time without affecting processing already performed. Where we rely on legitimate interests, you may object as described in Section 10. We do not use your data to make decisions that produce legal or similarly significant effects solely through automated processing.
4. Service providers, SDKs, and disclosures
Depending on the app, platform, region, feature, and your consent choices, we use providers in the following categories:
| Provider or category | What it helps us do | Information that may be processed |
|---|---|---|
| Apple App Store / Google Play | Distribution, billing, subscriptions, refunds, platform services. | Purchase and entitlement information, store account or transaction identifiers, diagnostics. |
| RevenueCat | Subscription entitlement, purchase restoration, and related attribution. | App-user identifier, purchase and subscription status, device and attribution identifiers where permitted. |
| Firebase / Google | Core app services, Analytics, Firestore, Remote Config, Cloud Messaging, App Check, Crashlytics, and aggregated counters. | Identifiers, interactions, push tokens, safety reports, app configuration, crash and diagnostic data, approximate region. |
| OpenAI | AI chat, text and image analysis, structured responses, and audio transcription where offered. | Prompts, text, images, audio, relevant recent conversation context, instructions, and limited technical metadata needed to process the request. |
| Usercentrics | Consent notices, regional rules, and preference management. | Consent status, device or app identifiers, region/ruleset, timestamp, and SDK diagnostics. |
| Meta / Facebook | App Events, analytics, attribution, and campaign measurement. | Device or advertising identifiers where allowed, product interactions, subscription events, and technical information. |
| Sentry | Error monitoring and diagnostics. | Crash/error information, app state, device and technical context configured for diagnostics. |
| Apple HealthKit | Optional on-device wellness estimates in apps that offer supported health features. | Only the health types you authorize; currently processed locally rather than uploaded by AppCLabs. |
| Google Sign-In / Sign in with Apple | Optional authentication where available. | Provider identifier, authentication token, and profile fields you authorize. |
| Firebase Hosting / FormSubmit / Google Gmail | Deliver this website and relay or receive support and legal messages. | Server/security logs and the contents of communications you send through a website form or email. |
OpenAI-powered features
When you affirmatively use an AI feature, the app sends the content needed for that request to OpenAI, L.L.C. or an applicable OpenAI affiliate through OpenAI's API. Depending on the feature, this can include the prompt you type, a meal description, an image, a voice recording, and limited recent conversation context. OpenAI processes that content to generate or transcribe the response, detect abuse, and operate and secure its API. AppCLabs does not opt API content into OpenAI model training or improvement programs without first providing separate notice and obtaining any consent required by law.
OpenAI states that API inputs and outputs are not used to train its models by default. Its standard abuse-monitoring logs may retain customer content for up to 30 days, unless longer retention is legally required or necessary to protect OpenAI's services or third parties; some API features can create additional application state subject to endpoint-specific controls. Do not submit information you do not want processed by OpenAI. See OpenAI's Privacy Policy and API data controls.
Consent-management configuration
Our Usercentrics configuration may contain services available across our products and campaigns, including Facebook SDK and App Events, TikTok, TikTok Advanced Matching and TikTok Advertising, Google Tag Manager, Google Ads, AppLovin, Firebase Cloud Messaging, Firebase/Google Analytics, Sentry, Firebase Crashlytics, Firebase Remote Config, Apple Search Ads, RevenueCat, Google Sign-In, Sign in with Apple, Firebase Firestore, AppsFlyer, and the Usercentrics platform itself. A service appearing in the configuration does not mean it runs in every app or on every device. Activation depends on actual integration, app version, platform, campaign, region, configuration, consent status, and platform permissions.
We may also disclose information to professional advisers, authorities, courts, or counterparties when reasonably necessary to comply with law, protect people or the Services, investigate abuse, establish or defend claims, or complete a merger, financing, acquisition, or transfer of assets. Any successor must honor this policy for information collected under it unless you are notified otherwise.
We assess providers before use and require them, through applicable contracts, data-protection terms, and platform controls, to protect personal information consistently with this policy and applicable law. We remain accountable for personal information transferred to processors. A separate controller remains responsible under its own privacy terms.
5. Consent, tracking, and advertising choices
In supported app versions, Usercentrics presents regional consent choices and a privacy-settings layer. On iOS, Apple’s App Tracking Transparency prompt separately controls access to IDFA and tracking across other companies’ apps and websites. You can change app permissions in system settings, reset or limit advertising identifiers through your platform, and revisit available consent choices in the app’s privacy or consent settings.
Before personal content is sent to OpenAI, the app must identify OpenAI, describe the content being sent and why, and request an affirmative choice where platform rules or law require it. Choosing “Not now” must leave the AI submission unprocessed. Withdrawing consent stops future consent-based processing but does not undo processing already completed; a feature that necessarily depends on OpenAI may no longer work. A privacy policy or acceptance of Terms does not replace this in-app disclosure and choice.
We do not sell personal information for money. Disclosures of identifiers or app interactions to advertising or attribution providers may be treated as “sharing,” “targeted advertising,” or a “sale” under certain US state laws even when no money is exchanged. Where applicable, you may opt out through the consent interface and platform settings or by emailing dpo@appclabs.com. We do not knowingly sell or share personal information of users under 16.
Mobile apps do not provide a uniform browser Global Privacy Control signal. If a supported platform-level opt-out signal becomes available for our apps, we will process it as required by applicable law. This website currently has no advertising or analytics trackers to opt out of.
6. International data transfers
We operate from Pakistan and use providers that may process information in the United States, European Economic Area, Canada, and other countries. These locations may have different data-protection laws. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, vendor transfer commitments, or another lawful transfer mechanism. You may request information about applicable safeguards by contacting the DPO address below.
7. Retention and deletion
- Local app data remains until you delete it in the app, clear app data, or uninstall, subject to device backups and synchronization you control.
- AI safety reports submitted through an AppCLabs app are retained for up to 90 days unless a longer period is reasonably required for an investigation or legal obligation.
- Support, privacy, and legal correspondence is generally retained for up to 24 months after the matter closes, or longer where legally required.
- Purchase, tax, dispute, and fraud-prevention records may be retained for the period required by law or reasonably needed to protect legal rights.
- OpenAI's standard API abuse-monitoring logs may retain request and response content for up to 30 days, subject to the exceptions and endpoint-specific state described in Section 4.
- Analytics, attribution, crash, and other provider-side data follows the provider configuration and retention rules applicable to the service.
When retention ends, we delete or de-identify information unless continued storage is legally required. Backup deletion may occur on a delayed cycle.
8. Security
We use reasonable technical and organizational safeguards appropriate to the nature of the information, including encrypted transport, platform access controls, consent gating, data minimization, and restricted administrative access. No transmission or storage system can be guaranteed completely secure. If you believe information has been compromised, email dpo@appclabs.com.
9. Your choices
- Decline or revoke camera, photos, microphone, location, notification, health, or tracking permissions in device settings.
- Change available consent choices through the in-app Usercentrics privacy settings.
- Clear app data or chat history using in-app controls where offered, or uninstall to stop future app collection.
- Use our Privacy Choices page to request an opt-out, withdraw consent, or exercise a regional right.
- Use our Account & Data Deletion page to initiate deletion from outside an app.
- Manage or cancel subscriptions through the Apple App Store or Google Play account used to purchase them.
- Avoid entering sensitive or confidential information in AI prompts, images, support messages, or meal descriptions.
10. Privacy rights by region
Subject to identity verification, exceptions, and the law that applies to you, you may have the following rights:
- EEA, UK, and Switzerland: access, correction, erasure, restriction, portability, objection, withdrawal of consent, and a complaint to your local supervisory authority.
- California and other applicable US states: know/access, correct, delete, obtain a portable copy, opt out of sale/sharing or targeted advertising, limit certain uses of sensitive personal information, and appeal a denied request where provided by law.
- Canada: know why information is collected, access and correct it, withdraw consent subject to legal or contractual restrictions, and complain to the Office of the Privacy Commissioner of Canada or an applicable provincial regulator.
- Other regions: any comparable rights provided by applicable privacy law.
Submit a request to dpo@appclabs.com and identify the relevant app, platform, approximate dates of use, and an app/device or purchase identifier if available. Do not send a password, complete payment-card number, or government ID unless we specifically and securely request proof needed for verification. We will respond within the time required by applicable law. Authorized agents may submit requests where law permits, subject to proof of authority. We do not discriminate against you for exercising a privacy right.
11. Supplemental US state privacy notice
For laws that require disclosure by statutory category, the table below summarizes personal information we collected and disclosed for business purposes during the preceding 12 months. The categories collected from any particular person depend on the app, features, permissions, region, subscription, configuration, and consent choices.
| Statutory category | Examples from our Services | Sources and recipients |
|---|---|---|
| Identifiers | Email, app-user ID, device/app-instance ID, vendor or advertising ID, push token, purchase identifier. | You, your device, app stores, sign-in providers; disclosed to hosting, authentication, subscription, analytics, attribution, consent, and support providers as applicable. |
| Commercial information | Subscription product, purchase, renewal, entitlement, restore, or refund status. | App stores and you; disclosed to RevenueCat, app stores, fraud/security providers, and advisers as required. |
| Internet or electronic activity | App interactions, screens, sessions, consent choices, ad or campaign interaction, crash and diagnostic events. | Your device and SDKs; disclosed to analytics, attribution, advertising, consent, crash, and infrastructure providers depending on consent and configuration. |
| Geolocation | Precise location you authorize for location-dependent features such as local prayer times; approximate location or region derived from IP or device settings. | You and your device; disclosed to providers needed for the requested feature, consent rules, security, analytics, or attribution as applicable. |
| Audio, visual, and user content | Meal photos, voice meal entries, AI chat images and text, support messages, and AI safety-report text. | You; disclosed to AI/transcription, Firebase, support, or moderation providers only as needed for the feature. |
| Sensitive personal information | Precise location, religious activity, and health or wellness inputs where those features are offered. | You and your device; used and disclosed to provide requested features, secure them, and comply with law—not to infer unrelated characteristics. |
| Inferences | Nutrition estimates, wellness estimates, product preferences, or aggregated predictions generated from information you provide. | Generated by the app or AI provider; disclosed to service providers only as needed to return or operate the feature. |
We collect these categories for the purposes in Section 3. We do not sell personal information for money. As described in Section 5, some advertising or attribution disclosures may be considered a sale, sharing, or targeted advertising under a particular state law; eligible users may opt out. We do not use or disclose sensitive personal information for purposes that require a separate right to limit under California law, such as inferring characteristics unrelated to the service you request.
12. Children
The Services are intended for a general audience and are not directed to children under 13. Where a higher minimum age applies to consent-based processing, parental authorization may be required. We do not knowingly collect personal information from children in violation of applicable law, permit interest-based advertising to users known to be under 16, or knowingly send a child's personal content to OpenAI without any consent required by law. If an app is ever directed to children or we learn that a child has provided personal information, we will apply the required age-screening, parental notice/consent, data-minimization, access, and deletion protections. Contact us so we can investigate and delete information where required.
13. AI, health, and religious information
AI outputs can be inaccurate, incomplete, or inappropriate. Nutrition and wellness estimates are not medical advice or diagnosis. Religious AI content is not a definitive religious ruling and does not replace qualified scholars. We do not use your AI, health, or religious information to determine eligibility for employment, housing, credit, insurance, health care, or other legally significant services.
We use sensitive health, precise-location, or religious information only for the feature you request, with explicit consent where required, and not for unrelated profiling or targeted advertising. Do not use an AI feature for emergencies or to submit protected health information intended for HIPAA-regulated treatment, payment, or health-care operations. In-app reporting tools, where offered, let you flag unsafe or inappropriate AI output for review.
14. Changes to this policy
We may update this policy when our Services, vendors, or legal obligations change. We will post the revised policy here and update the effective date. If a change materially affects your rights, we will provide additional notice or obtain consent when required.
15. Contact us
Controller: Muhammad Rabi, publishing under the AppCLabs brand
Location: Lahore, Punjab, Pakistan
Data Protection Officer / privacy requests: dpo@appclabs.com
General support: hi@appclabs.com
EEA and UK representative: none appointed as of the effective date. Until representative details are published here, direct questions and rights requests to the DPO contact above.