Sobah Privacy Policy

Effective: September 7, 2026

Sobah is a wake aid for Fajr. This policy explains what the app stores, what our service providers receive, and the choices available to you.

Data kept on your iPhone

Sobah stores alarm settings, onboarding answers, any required regional analytics choice, wake and mission progress, prayer check-in answers, and a random analytics identifier on your device. Approximate location is used on-device to calculate Fajr. Motion readings are processed on-device to count movement during the optional Squats and Steps missions.

During a Squats mission, the app keeps only the latest 30 seconds of motion readings in memory. If detection fails, it may temporarily save that diagnostic trace on your iPhone so you can review whether to share it. The trace leaves your device only if you explicitly choose to share it through the system share sheet. It is deleted when you decline or dismiss sharing and expires after 24 hours. Location and motion readings are not sent to Clerk or PostHog. Deleting your account in the app deletes the account and the app data held on your iPhone. Deleting the app also removes its local data.

Optional account data

You do not need an account to schedule or use alarms. If you choose to create an account, Clerk processes the identity information required for the sign-in method you select, such as your email address, identity-provider account identifier, and provider profile name when the provider supplies one. Sobah requests only email access from Sign in with Apple. Sobah does not attach your Clerk identity, email address, or name to product analytics. You can delete your account inside the app. Account data is retained until you delete the account, subject to Clerk’s legal obligations as a service provider.

App product analytics

After you select an adult age range during onboarding, product analytics starts automatically when the privacy rules for your region allow it. Analytics remains off for users who select under 18 and while a required regional choice is unresolved. If your region requires prior consent or an analytics opt-out, Sobah shows that specific regional choice and honors refusal or withdrawal. There is no general product-analytics preference outside those required regional controls. Analytics is not required to use any alarm feature.

For eligible adults, PostHog receives a random installation identifier and a manually allowlisted set of product events. These include the onboarding answers you select—missed-Fajr frequency, usual wake-up failure mode, age range, and gender response—as well as onboarding cohort start, first alarm scheduling, observed alarm firing, mission completion, prayer check-in presentation and answer, day-seven alarm activity, coarse Squats preview, completion, sensor-failure recovery, and disable outcomes, and coarse Steps completion. Other properties are limited to app build, random wake identifiers, and elapsed-time, attempt-count, or configured-repetition buckets.

The random installation identifier supports a pseudonymous PostHog person profile so events from one app installation can be analyzed together. It is never replaced with or connected to your Clerk identity, email address, or name. PostHog does not receive coordinates, motion readings, diagnostic traces, exact Fajr or alarm times, prayer text, free text, audio, or session recordings. Automatic app event capture, automatic lifecycle or screen capture, feature flags, and session replay are disabled for this release.

A legally required regional refusal or withdrawal stops future collection, removes queued events, and removes the random identifier from the app. Deleting your account or local app data does the same locally. Events already received by PostHog are retained for up to 12 months and then expire. Because the analytics identifier is deliberately not linked to your account or contact details, we cannot locate an individual’s existing analytics events from an email request.

Website analytics

On sobah.app, PostHog loads automatically and uses first-party storage with a separate random website identifier. It collects page views, page-leave events, automatically captured interactions, and a cta_clicked event containing the button location, destination when applicable, and surface: web. These events may be grouped in a pseudonymous website person profile. The website does not connect this identifier to the app identifier, Clerk identity, email address, or name. Session replay, exception autocapture, surveys, campaign attribution, referrer capture, and feature flags are disabled.

Website analytics starts automatically when the privacy rules for your region allow it. If your region requires prior consent or an analytics opt-out, the website shows that specific regional choice. Refusal or withdrawal stops future collection and resets the website identifier. If Sobah cannot resolve the applicable regional policy, analytics stays off while the website remains available. Website analytics is retained for up to 12 months.

Android waitlist

If you join the Android waitlist on sobah.app, Cloudflare processes your signup request and Resend stores your email address and Android waitlist membership so we can send an Android launch notification. Signup does not create an app account. We do not connect your email address to website or app analytics, and the waitlist form is excluded from automatic interaction capture. No confirmation email is sent. Existing unsubscribe preferences remain in effect. We retain your waitlist entry until the launch notification has been sent or you request removal. To request removal, email umar@sobah.app. Launch emails include an unsubscribe link.

Sharing, sales, and purpose

We use Resend to manage the Android waitlist and send its launch notification, Cloudflare to host the website and process waitlist requests, Clerk only to provide optional authentication and PostHog only to understand onboarding, website interest, and whether the alarm journey works. We do not sell personal data, use it for third-party advertising, or track activity across other companies’ apps or websites.

Support and privacy requests

For privacy questions or general support, email umar@sobah.app.