Rihla

Privacy Policy

Last updated: 14 May 2026

This policy explains what Rihla collects, why, and what control you have over it. Rihla is operated as an individual project by the developer listed at the bottom of this page.

1. Anonymous by default, optional recovery email

Rihla does not require an email address, password, phone number, or any other identifier on first launch. The app creates an anonymous session in Firebase Authentication. If you choose to link an email in Settings, that email is attached to the same Firebase user only so you can recover the same Rihla identity on a new or reset device.

2. What we collect

Rihla does not collect your contacts, location, advertising identifier, microphone, or camera (other than when you explicitly attach a receipt photo).

3. How data is used

Group and expense data is used only to operate the app — keeping your groups in sync across the people you share them with. A linked email is used only to send and complete recovery links. We do not sell any data. We do not run ads. We do not use your data to train machine learning models.

4. Where data is stored

Data is stored in Google Firebase (Cloud Firestore, Cloud Functions, FCM) under the project rihla-safar. Firebase runs on Google Cloud infrastructure. Their privacy and security documentation is available at firebase.google.com/support/privacy. Crash reports are stored in Sentry — sentry.io/privacy.

5. How long data is kept

Group, event, and expense data is kept for as long as the group exists. Soft-deleted records (expenses you removed inside a group) are retained so other members can see the history. A linked recovery email is kept until the Firebase user is deleted. If you want everything attached to your Rihla identity removed, see Delete your data.

6. Children

Rihla is not directed at children under 13. If you believe a child has submitted data through the app, please contact us and we will remove it.

7. Your rights

Because Rihla does not collect any identifying information, the practical mechanism for exercising data rights is to request deletion. See Delete your data.

8. Changes

If this policy changes materially, the “Last updated” date at the top of the page will change. Significant changes will also be announced in the app.

9. Contact

For privacy questions or deletion requests, email nasserbusaidi@gmail.com.