Privacy Policy
Last updated: 14 May 2026
This policy explains what Rihla collects, why, and what control you have over it. Rihla is operated as an individual project by the developer listed at the bottom of this page.
1. Anonymous by default, optional recovery email
Rihla does not require an email address, password, phone number, or any other identifier on first launch. The app creates an anonymous session in Firebase Authentication. If you choose to link an email in Settings, that email is attached to the same Firebase user only so you can recover the same Rihla identity on a new or reset device.
2. What we collect
- Anonymous user ID. A random identifier issued by Firebase Authentication when the app first runs. Stored on your device and on our backend so we can fetch your groups and expenses.
- Optional recovery email. If you choose to link an email, Firebase Authentication stores it so email-link recovery can return you to the same anonymous UID. Rihla does not use it for marketing.
- Display name. The name you enter when creating or joining a group. Visible to the other members of that group. You choose this — it does not have to be your real name.
- Group & expense data. Group names, event names, currencies, expense amounts, descriptions, notes, categories, settlements, and any optional receipt photos you attach. Visible to members of the same group.
- Push notification token. A Firebase Cloud Messaging (FCM) token so the app can notify you when something happens in a group you are part of. You can disable notifications in your device settings at any time.
- Crash & error reports. When the app crashes or encounters an unexpected error, technical details (stack trace, device model, OS version) are sent to Sentry so we can fix it. These reports do not include your group data or display name.
Rihla does not collect your contacts, location, advertising identifier, microphone, or camera (other than when you explicitly attach a receipt photo).
3. How data is used
Group and expense data is used only to operate the app — keeping your groups in sync across the people you share them with. A linked email is used only to send and complete recovery links. We do not sell any data. We do not run ads. We do not use your data to train machine learning models.
4. Where data is stored
Data is stored in Google Firebase (Cloud Firestore, Cloud Functions, FCM)
under the project rihla-safar. Firebase runs on Google Cloud
infrastructure. Their privacy and security documentation is available at
firebase.google.com/support/privacy.
Crash reports are stored in Sentry —
sentry.io/privacy.
5. How long data is kept
Group, event, and expense data is kept for as long as the group exists. Soft-deleted records (expenses you removed inside a group) are retained so other members can see the history. A linked recovery email is kept until the Firebase user is deleted. If you want everything attached to your Rihla identity removed, see Delete your data.
6. Children
Rihla is not directed at children under 13. If you believe a child has submitted data through the app, please contact us and we will remove it.
7. Your rights
Because Rihla does not collect any identifying information, the practical mechanism for exercising data rights is to request deletion. See Delete your data.
8. Changes
If this policy changes materially, the “Last updated” date at the top of the page will change. Significant changes will also be announced in the app.
9. Contact
For privacy questions or deletion requests, email nasserbusaidi@gmail.com.