Privacy policy
Masadir, the fatwa reference app. Last updated 9 October 2026.
The short version. This page describes the Masadir app for Android. "We" on this page means Masadir, the developer of the app (see Contact). Masadir works without an account: you can search, read, save rulings and ask a mufti without signing in. Signing in with Google is optional. It gives our accounts service your name, your email address and your Google account's identifier, and when you tap Sync it keeps a copy of your saved rulings and settings on our server, so that another phone can have them. You can delete that account from the app, or ask us by email to delete it. The books are searched on your phone, and while you are online your searches of the fatwa library are also sent to our server, which finds the pages that answer them. The app tells you so before your first search is sent. The other things that reach a server are the scanned pages and page texts the app fetches, downloading the library and the hadith collection, voice search, and a question you send to a mufti. There is no advertising, no analytics and no tracking of any kind. Apart from what you choose to share or email through your own apps, what the app sends goes only to our own servers and to the services named on this page that run the app for us.
What stays on your phone
- The library: the text and index of the books, downloaded so that searching and reading the text work with no connection, and the hadith collection, once you have opened the hadith section. Scanned pages are not downloaded ahead of time (see Pages, below).
- Copies of scanned pages you have opened, and of page texts the app fetched, kept by the web view the app runs in as its ordinary cache. A scan you open again can come from that copy instead of from our storage.
- Your saved rulings, your language, your theme, your Urdu text size, your tasbeeh counter, and your choice for the qibla, which is either a city you chose or a note that you use your own location. These stay on your phone unless you sign in and tap Sync, which also keeps a copy on our server (see Your account).
- Your place for the prayer times on the Home screen: a city you chose there, or the last position your phone gave the app, rounded to two decimal places (about a kilometre), with the time it was found. Also your adjustment to the Hijri date. These stay on your phone, and Sync does not copy them.
- Three counters shown on the Profile screen: how many rulings you saved, how many searches you have run, and how many you have shared.
- Your recent searches, so you can tap one again. Settings has a button that clears them.
- The text of pages the app fetched because your phone did not hold them yet, up to three hundred, and the text of each ruling you save on this phone, so that a saved ruling can be read with no connection. A ruling that arrives from another phone through Sync is kept the same way when it arrives. A ruling whose text is not on the phone and cannot be fetched at that moment stays in your saved list without that copy.
- The questions you sent to a mufti, their answers once they arrive, and for each question the secret key that lets this phone read its answer or delete it.
- If you sign in: your sign-in, which holds your account as our accounts service returns it, including your name and email address, and the keys that keep you signed in, so that you stay signed in and Settings and the Profile screen can show who is signed in. Signing out removes it from the phone. While you are signed in, the app also keeps a list of the saved rulings you remove, until the next Sync sends it. Signing out clears that list.
- A picture of a ruling with its citation, which you save with "Save" in Share as image. On Android 11 and later it goes to your phone's Documents folder as an ordinary file outside the app, which other apps you allow to read your files can open, and it stays there if you uninstall the app, until you delete it. On older versions of Android, Save needs a storage permission the app does not ask for, so it saves nothing: the screen says the picture could not be saved and points you to "Share", which works there too. "Share", here and for a hadith, puts a copy in the app's own cache to hand to the app you choose.
- A few notes the app keeps for itself: whether you chose "Sign in with Google" or "Use as guest" on the first screen, that you have seen the introduction and the notice about online searches, so that they are not shown again, and which edition of the library and of the hadith collection the phone holds.
- A short diagnostic trail of the last three hundred things the app did, kept so faults can be diagnosed. It records the shape of what happened, such as how many words a search had and how many results came back, never the words themselves and never which page you opened. It is overwritten as you keep using the app and is never sent anywhere.
Parts of the lists above are sent to us in these cases. If you sign in and tap Sync, your saved rulings, the ones you removed while signed in, and the settings named above are copied to our server (see Your account). While you are signed in, the keys of your sign-in go to our accounts service each time the app renews the sign-in, and with each Sync, with the deletion of your account and when you sign out. And the identifier and key of a question go to our server when My Questions checks for answers, when you delete that question, and, for every question in My Questions, when you delete your account (see Ask a Mufti). Using the app still reaches a server in the ways the next section describes, and some of them carry the same things: a search you run while online, for example, or the text of a ruling fetched when you save it. Uninstalling the app removes all of this from your phone, except a picture you saved from Share as image. It does not remove what is kept elsewhere: your account and what you synced, until you delete your account (see Deleting your account), and your questions to a mufti, which stay on our server until they expire unless you delete them first.
The app does not let Android's backup, or its transfer of apps to a new phone, copy any of this, apart from a picture saved to your Documents folder, which is an ordinary file outside the app. Keeping your saved rulings when you change phones is what signing in and Sync are for.
What leaves your phone, and when
- Pages. Every ruling can show the page it was printed on, and the scan comes from our storage provider, Cloudflare, when you open it (a scan you opened before can come from the phone's own copy instead). The text of a page also comes from there whenever your phone does not hold it yet, for example while the library is still downloading, for the pages of an online answer and the pages listed under it as "May also answer this question", and when you save a ruling. Cloudflare therefore receives the request: your IP address, the time, which page you asked for, as a scan or as its text, and the technical details every web request carries (see Permissions), and it may record that in its own logs. We keep no log of those requests ourselves. We do not use them to build any profile of you, and we do not connect them to anything else.
- The library and the hadith collection. The app downloads the fatwa library from our storage at Cloudflare, starting the first time it runs, over Wi-Fi or mobile data alike, and checks there for a newer edition each time you start the app. The first time you open the hadith section, it downloads the hadith collection, seven hadith books in Arabic, with a published Urdu translation beside the Arabic where the collection has one, from the same storage. After that it checks for a newer edition once each time you start the app and open the section, and downloads the collection again only when there is one. Both are searched on your phone, and a hadith search is never sent anywhere. Cloudflare sees these requests as it sees a page request: your IP address, the time, which file was asked for and the same technical details.
- The online search. Whenever you are online, your searches of the fatwa library are sent to our own server, which compares their meaning against all the books and returns the pages that answer the question, with other pages that may also answer it. When it answers, those pages are the list you see, and where no page qualifies the screen offers Ask a Mufti instead. While the online answer is on its way, the screen says that all the books are being searched online. If no usable answer comes while your phone is connected, the screen says "Search is temporarily unavailable. Retrying..." and the app sends the same search again by itself, first after three seconds and then at longer gaps of up to twenty seconds, until an answer comes, you search for something else or you leave the Search screen. It shows no list from your phone while it tries again. When your phone has no connection, nothing reaches our server. The screen then shows only the pages on your phone whose printed title states your question, under a line that says you are offline, or one sentence saying there is no exact match offline. If the connection returns while that search is still on the screen, the app sends it to the online search by itself, without another tap. What is sent is the search as the app understood it, sometimes with a few terms from the books that the app adds to it: for a question typed in Roman Urdu or in Hindi script, its Urdu form, and for a question in English, the Urdu the app puts it into where it can, and otherwise your own English words. A search in which the app could find no subject is not sent, and neither is a search that failed on the phone. Our server does not store or log what is sent. To compare meanings it passes the words to Cloudflare's AI service, which turns them into numbers. If that service does not answer, or its answer fails the check our server makes of it, our server passes the same words to a second service, DeepInfra, which does the same job. Only the numbers go on to the database the books are compared in. In the terms Google Play uses, this counts as data collected for the app to work, and we will declare it that way on Google Play. The app tells you that searches go online before your first search is sent. The last of the screens shown the first time you open the app says so. If you have not tapped "Start searching" on that screen, for example because you skipped those screens, the Search screen shows a notice that says the same before it sends a search, and it sends nothing until you tap "OK". Once you have tapped "Start searching" on that last screen, or "OK" on the notice, the app does not show it again on that phone.
- Ask a Mufti. If you send a question from the app, the question is stored on our server so that a mufti can read it and answer it, and so the answer can come back to your phone. What the app sends with it is stored too: when you ask from a search, the words you searched for (and their Urdu form) and which edition of the library was searched, and when you ask from a page, that page's reference. Our server gives the question a random identifier and a secret key, and your phone keeps both. Reading the answer or deleting the question needs that key, and our server keeps it only to check it: the muftis are not given it. We do not ask who you are, and a question is not linked to your account even when you are signed in. The muftis who answer questions can read every question held on our server, with what was sent with it, and so can we, who run it. A question is deleted from our server 30 days after it is answered (or after an answer is withdrawn). One still waiting for an answer is deleted 90 days after it was sent, and the 90 days start again each time a mufti takes it up or it is handed back. Deleting a question in My Questions asks our server to delete it too. If that does not work, for example because your phone is offline, the question still leaves My Questions, and the copy on our server stays until it expires. Deleting your account also asks our server to delete the questions still listed in My Questions on this phone. Separately, our server keeps for 400 days a record of each time a question is taken up, answered or has its answer withdrawn: the time, the question's identifier, who acted (for a mufti using one of our links, the name we gave that link, and for a mufti who signed in, the number of their account, not their email address), the answer's length and a fingerprint of it, and for a withdrawal, the name shown with the answer and a short note from us. The same record also notes when one of our mufti links is issued, first opened, reset or cancelled, and each refused attempt to open the mufti panel, with the country and the Cloudflare data centre the attempt came through. It holds no IP address, and it never holds the text of the question or the answer. Deleting a question does not delete that record.
- Voice search. If you tap the microphone, the clip you record is sent to our own server to be written down, and the words come back to your phone, where they are searched like typed words and kept in your recent searches, so while you are online they also go to the online search above. You are told this before your first recording, in the same way as for the online search: the notice also says that a spoken question is sent to be written down, and if you have not seen it yet, your first tap on the microphone shows it, and nothing is recorded until you tap "OK". While it records, and while it waits for the words, the screen says that your voice goes to our server. The clip is at most twelve seconds. Our server passes it to Cloudflare's AI service to be written down, and it does not store the clip or the words and does not log them. In the terms Google Play uses, this counts as data collected for the app to work, and we will declare it that way on Google Play. Typing the question instead sends no recording.
- Your account, only if you sign in. Signing in passes Google's confirmation of your account to our accounts service, Supabase, and while you stay signed in the app renews the sign-in there from time to time. Each tap on Sync sends your saved rulings, the ones you removed and your settings, deleting your account asks Supabase to delete it, and signing out tells Supabase that the sign-in on this phone has ended. What is kept, who can see it and how to delete it are under Your account and Deleting your account, below.
- What you send through your own apps. Sharing a ruling, or a picture of a ruling or of a hadith, reporting an error on a page, and asking a mufti by email instead of through the app each open your own share sheet or email app with the message written out. Nothing is sent until you send it, and it goes by the app you choose, not through our server. If you close the share sheet for a ruling without choosing an app, or it cannot open, the ruling's text is copied to your clipboard instead. An error report is also copied to your clipboard, in case email is not set up. An email sent this way carries your email address, like any email you send. The app addresses an error report to our address for corrections, and a question by email to our address for questions. Both addresses pass through Cloudflare, which forwards them to fatawa.library@gmail.com, a Gmail inbox, so Google holds what arrives there, and a reply comes from that address.
- Nothing else. The app has no analytics, crash-reporting or advertising library, it reads no advertising identifier, and nothing in our code reports on how you use it. The app also tells the Android web view it runs in not to send Google usage diagnostics for this app, and not to check the pages it opens with Google's Safe Browsing.
Your account
Signing in is optional. It is offered once, on a screen shown after the introduction the first time you open the app, beside "Use as guest", and after that only in Settings. Nothing in the app needs it except Sync. It uses Google: Android shows you Google's own account sheet, Google gives the app a signed confirmation of the account you chose, and the app passes that to our accounts service, Supabase, which makes your account from it. Google therefore knows that you used your Google account to sign in to Masadir.
What signing in gives us. Your name, your email address and the identifier Google gives your Google account, all from Google's confirmation, are stored with your account, which our accounts service also gives a number of its own. Our accounts service keeps Google's confirmation as it arrives, so where Google includes the web address of your Google profile picture, that is stored too. Like any sign-in service, it also records when you signed in, and for each sign-in the IP address and the description of the software it came from. While you stay signed in, the app renews the sign-in with Supabase from time to time.
What Sync sends. Signing in copies nothing by itself. When you tap "Sync saved fatawa and settings now" in Settings, the app sends to our server the rulings you have saved (for each one: which page it is, its title, book, volume, page and chapter, and when you saved it), the ones you removed while signed in, and these settings: your language, your theme, your Urdu text size, your tasbeeh counter (which dhikr, where you are in it, the count, the rounds and the target), whether the Qibla screen uses your location or a city, and the city you chose, with its name, country and position on the map. The same tap brings to this phone the saved rulings and settings your account holds that this phone does not have yet, and takes off this phone a ruling that was removed on another phone after it was saved here. Nothing is synced unless you tap it.
What is never sent to your account: your recent searches (our database refuses to store them), the diagnostic trail, the Profile counters, your questions to a mufti, and your phone's own location. The words of each online search still go to the online search as described above, and are not kept there either.
Removing a saved ruling. While you are signed in, the app remembers each saved ruling you remove, and the next Sync marks it as removed on our server, so that your other phones drop it at their own next Sync unless it was saved there again later. Our server keeps that mark, with which ruling it was, its title, book, volume, page and chapter, when you saved it and when you removed it, until you delete your account. A ruling removed while you are signed out is not remembered, so if our server already holds it, the next Sync brings it back to this phone. Removals not yet sent when you sign out are cleared from this phone, and such a ruling comes back the same way.
Who can see it. Only your own account can read or change your synced rulings and settings, and the database enforces that. We, who run the service, can see the accounts and what they hold in Supabase.
Signing out ends your sign-in on this phone only, removes it from this phone, and tells our accounts service that it has ended. Everything else on your phone stays as it is, and your account and what you synced stay on our server.
Deleting your account
In the app: Settings, Account, "Delete my account", then "Yes, delete". First the app asks our server to delete every question still listed in My Questions on this phone, and a question still waiting for an answer will then not be answered. Then it deletes your account from our accounts service, with your name, your email address and your Google account's identifier, and with it everything you synced, including the record of the rulings you removed. Then it signs you out on this phone. This cannot be undone. What is on your phone stays: your saved rulings, your settings, and your questions with their answers. Apart from your sign-in, which that sign-out removes, only the list of removals waiting for the next Sync is cleared.
If there is no connection, if our server cannot delete one of your questions, or if the account itself cannot be deleted, the screen says it could not delete, and you can try again. Because the questions go first, some or all of them may already be gone from our server by then. A question our server no longer holds, or whose key it does not recognise, does not stop the deletion, because trying again could not change that.
Questions no longer listed in My Questions on this phone, such as those sent from another phone or before the app was installed again, are not part of your account and are not deleted this way: delete them in My Questions on the phone that still lists them, or they are deleted when they expire, as described above. Deleting your account does not delete the 400-day record our server keeps of questions taken up, answered or withdrawn (see Ask a Mufti), which is not linked to your account. Nor does it delete email you have sent us, which is not part of your account. Removing Masadir from the apps connected to your Google account does not delete your account with us.
Without the app: write to fatawa.library@gmail.com from the email address of the Google account you signed in with, and ask for your account to be deleted. We delete it within 30 days of receiving your email. You can also install the app again, sign in with the same Google account, and delete the account from Settings as above. However your account is deleted, everything you synced is deleted with it, because our database removes it together with the account. Your questions to a mufti are not linked to your account, so they are not part of a deletion asked for by email: delete them in My Questions on a phone that still lists them, or they are deleted when they expire, as described above.
The same steps, and what is deleted and what is kept, are on masadir.in/delete.
The services that run the app for us
- Cloudflare stores the books, the scans and the downloads, runs our servers for the online search, voice search and Ask a Mufti, holds the questions sent to a mufti, and runs the AI service that turns searches into numbers and writes down voice clips. As it runs our servers, it receives your IP address with each request to them.
- DeepInfra is a second AI service, used only for the online search and only when Cloudflare's AI service does not answer a search or its answer fails our server's check. Our server then sends it the words of that search, with a fixed test sentence of our own, and it sends back the numbers. Our server passes on nothing else: not your IP address, nothing from your account, and nothing that says who asked or from which phone. It is never sent a voice clip or a question to a mufti.
- Supabase holds the database the online search compares against, which receives the numbers made from a search and never its words, and, only if you sign in, your account and what you sync. When you sign in, while you stay signed in, and when you Sync, delete your account or sign out, it receives your IP address with each of those requests.
- Google provides the sign-in, only if you use it. Google Play services on your phone is also one of the ways the Qibla screen and the prayer times card on the Home screen can get your position (see Permissions). And Google holds the email you send to our contact address, which is a Gmail inbox (see Contact).
This web page
This page loads its Arabic-script font from Google Fonts, so opening it sends your IP address to Google, whether you open it from the app's Settings, which opens it in your phone's browser, or from anywhere else. The app itself does not load fonts from the internet: they are part of the app.
Permissions
The Android app requests seven permissions. Android asks you before granting two of them, location and the microphone. The rest are granted when the app is installed, with no question. All seven are listed here so you can see why each one is there.
| Permission | Does it ask you? | What it is used for |
|---|---|---|
| Internet | No | Everything online described above: pages, the library and hadith downloads, the online search, voice search, Ask a Mufti, and sign-in and Sync if you use them |
| Network state | No | Telling whether the phone has a connection at all, so the library download waits for one and carries on when it returns, and so the Search screen knows whether to try the online search again or to show the offline matches |
| Vibration | No | The small tap you feel as you count on the tasbeeh, and when the qibla compass lines up |
| Approximate location | Yes. The Qibla screen asks for it when it opens without a chosen city. It is also asked for when you tap "Use my location" on the Qibla screen or on the prayer times card on the Home screen. The Home screen never asks by itself | Working out the direction of the Kaaba and the prayer times on the Home screen, and nothing else |
| Microphone | Yes, when you use the microphone on the Search screen | Recording your question so it can be written down. The recording is not kept |
| Audio settings | No | It comes with the microphone: the app's recording component will not record unless both are allowed |
| Masadir's own internal permission | No | Not a permission over your phone or your data. A standard Android library adds it to stop other apps sending messages into parts of Masadir that are meant only for Masadir |
The location permission is the approximate one, not the precise one: the app does not ask for precise location at all, so the system cannot give it. The position comes from your phone's own location services: the app asks Android's location service first, then Google Play services, and last the web view the app runs in, and uses the first answer it gets. How those services work out a position is up to them and to your phone's location settings, not to the app. The app uses the position on your phone to work out the direction of the Kaaba and the prayer times shown on the Home screen, and for nothing else. It keeps the last position your phone gave it, rounded to two decimal places (about a kilometre), with the time it was found, on your phone only, so that the Home screen can show prayer times without asking again. It stays there until a newer position replaces it or you uninstall the app. It is not written to the diagnostic trail, it is not copied to your account when you Sync, and the app does not send it to any server. If you decline, the Qibla screen and the prayer times work just as well by letting you choose your city. A city you choose on the Qibla screen is saved on your phone, and if you sign in and tap Sync, it is copied to your account with its name, country and position on the map. A city you choose for the prayer times on the Home screen, and your adjustment to the Hijri date, are saved on your phone only.
The app does not ask for your contacts, your photos, your files, your calendar or your precise location, and nothing in it reads the phone's advertising identifier. Unless you sign in, or write to us by email, nothing the app sends names you. Like any request over the internet, each one carries your phone's IP address, and a short description of the software that sent it, which can include your phone's model and Android version.
Children
Masadir is not directed at children. The app does not ask anyone's age. It works the same way for everyone, as this page describes, and nothing in it needs an account except Sync.
Changes
This policy changes when the app changes, and the date at the top is the date of the last change.
Contact
Masadir is the developer of this app. Questions about this policy or about your data, and requests to delete your account, go to fatawa.library@gmail.com. That is a Gmail inbox, so Google holds the email you send to it.