What data we collect, why we need it, who we share it with and how to delete it.
23 August 2026
1. Who processes the data
The data controller is the owner of the Umma Nikah service, available at nikah.ummalife.com and through the Telegram bot @nikahappbot — Isa Dagestani (1sa.me). The Service is part of the Umma Life ecosystem.
2. What data we collect
From Telegram at sign-in: numeric identifier, first name, username and profile photograph if it is public.
When signing in by other means: the email address and name from a Google account, the email address when signing in by code, the phone number when signing in by SMS. A confirmed address links different means of signing in to one profile.
From your profile: gender, age and date of birth, height, country and city, ethnicity, education, occupation, marital status, children, plans for marriage, your description of yourself, photographs.
Information about religious practice: prayer and Quran reading, performance of hajj, wearing hijab, presence of a mahram.
Phone number — if you have provided one voluntarily.
Approximate location (country, city and the coordinates of the locality) — to suggest profiles nearby.
Correspondence with other users — stored so that you can see your message history. Conversations are visible to the Service’s moderators: not only when a complaint is examined, but as part of ordinary oversight — this is what the promise of conversation in the presence of witnesses rests on. If a woman has her own guardian, he sees the conversation too; if she has none, a moderator acts as the witness, and both sides are told so.
The appeal to the guardian written before a conversation begins — what a man said about himself, about why he chose her, and about his intentions. It is seen by the guardian and by the person it concerns.
Profile and message texts — for machine translation into the other person’s language. Translation is performed by a third-party service; translated texts are stored so that the same text is not translated twice.
Images sent in a conversation — they are checked automatically for hidden contacts (a number or username captured in a screenshot).
Technical information: IP address, device and browser type, request times, error logs.
Payment information: amount, date, status and the provider’s transaction identifier.
We neither receive nor store bank card details: payment takes place on the payment provider’s side.
3. Special category data
Information about religion and religious practice is a special category of personal data. We process it solely because it is the essence of the Service — matching a spouse by faith — and only with your consent, which you give by filling in the relevant profile fields. Being a Muslim is confirmed as a requirement, without which the Service has no meaning; the remaining fields about practice may be left empty, and the information given may be changed or deleted at any time.
4. Why we process the data
to show your profile to other users and to suggest suitable profiles to you;
to enable messaging, notifications and the guardian and witness features;
to accept payment and keep account of your balance and purchases;
to handle complaints, detect violations and block bad-faith users;
to maintain security: detecting password guessing, automated and fraudulent activity;
to fix errors and improve the Service.
5. Who we share data with
Other users of the Service — the information in your profile and your photographs. Profiles are not indexed by search engines and are not visible without signing in.
Telegram — to the extent necessary for authentication and delivery of notifications.
Payment providers — the amount and transaction identifier needed to process a payment.
The hosting provider — by virtue of where the servers are located.
A third-party machine-translation and image-checking service — the text of a message or profile and the image itself, without your name or any other details about you.
An SMS provider — the phone number you asked us to send a sign-in code to. The code itself is unknown to the Service: the provider creates and verifies it.
Competent authorities — only upon a lawful request.
We do not sell personal data and do not pass it to third parties for advertising.
6. How long we keep data
Profile data is kept for as long as your account exists. Deletion happens in two steps: the profile leaves the search and becomes unavailable to others at once, while the data itself is kept for a further 30 days — the account can be restored at any point in that period, and a reminder is sent as the deadline nears. Once it expires the information is erased or anonymised; payment records are retained to the extent required for accounting and tax purposes. Technical logs are kept for a limited period and deleted automatically.
One case is separate: a profile deleted by moderation for breaking the rules. The profile, photographs and chats are erased in the same way, but the sign-in identifiers — Telegram id, email address, phone number, Google id — are kept indefinitely and stored apart from everything else. That record holds no name, no profile and no messages: it exists so that closed access cannot be reopened by creating a new profile, and it protects the other users. The record is removed on request to support if the decision is reversed.
7. Your rights
to find out what data about you is processed;
to correct inaccurate data — most fields can be edited directly in the app;
to delete your profile and the data associated with it;
to withdraw consent to processing — this entails deletion of the profile, since the Service cannot operate without this data;
to lodge a complaint with the competent data protection authority.
8. How we protect data
The connection to the Service is encrypted (HTTPS), and outdated encryption versions are disabled. The database can be reached only from the server itself and is closed from outside. Administrator passwords are stored as irreversible hashes.
Photographs are not served from direct addresses: a link to a photo is signed and valid for a limited time, and before a mutual like the other side sees only a blurred preview. The moderation team’s access to the console is protected by a separate, revocable session with a limited lifetime; sign-ins to it are monitored and automated password guessing is blocked. Backup copies of data are kept encrypted. Staff access to personal data is granted only to the extent their duties require.
9. Minors
The Service is intended for persons over 18. We do not knowingly collect data about minors. If such a profile is found, it will be deleted.
10. Changes to this Policy
We may update this Policy. The current version is always published on this page, with the update date shown below.
11. Contacts
For questions about the processing of personal data and to exercise your rights, contact support on Telegram: @NikahApp_support