Privacy Policy

Last updated: May 2026

1. Information We Collect

We collect information you provide directly, including your name, email address, and financial data you enter into the app (precious metals holdings, cash accounts, liabilities, goals, etc.). We also collect device information and usage analytics to improve the app.

2. How We Use Your Information

Your information is used to calculate Zakah, generate financial reports, send notifications you've opted into, and provide customer support. We do not sell your personal information to third parties.

3. Data Storage and Security

Your data is stored securely on Google Firebase servers with industry-standard encryption. We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, or destruction.

4. Data Sharing

We do not share your personal or financial data with third parties except as required by law or with your explicit consent. The Legacy Data feature allows you to share specific data with designated beneficiaries at your discretion.

5. Your Rights

You have the right to access, update, or delete your personal information at any time through the app settings. You can also request a complete deletion of your account and all associated data by contacting support.

6. Cookies and Analytics

The web version of Maaly may use cookies for authentication and session management. We use analytics to understand app usage patterns and improve our services.

7. Changes to Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes through the app or via email.

8. Contact

If you have questions about this Privacy Policy, please contact us through the app's Contact Us page.

9. Local Storage Mode

If you choose Local storage mode, your financial data is stored only on this device and is never transmitted to our servers. We do not have access to data kept in Local mode, which also means we cannot recover it if your device is lost, reset, damaged, or the app is uninstalled. We do not back up Local data, do not analyze it, and cannot include it in any account-deletion request because it never reaches us. When you switch from Local to Cloud, your local data is uploaded to your authenticated cloud store and the on-device copy is cleared so the cloud becomes the sole source of truth. When you switch from Cloud to Local, the cloud data is copied down and any prior local data is replaced. Account-level information (email, authentication, subscription status) is always processed in Cloud regardless of storage mode.