Privacy Policy
App: Warsh · Package: com.warsh.app · Developer: Umar Bin Akbar Ali · Last updated: September 11, 2026
1. Scope
This Privacy Policy explains how Warsh (“we,” “our,” or “us”) accesses, collects, uses, shares, retains, and deletes information when you use the Warsh mobile application and related services (the “Service”).
2. Information We Collect
- Account and authentication data: the name and email address you provide, an internal user ID, a securely hashed password, preferred language, learning goal, level, placement choice, and daily goal.
- Date of birth: asked once when you create an account (or on first launch for older accounts) so we can confirm you are old enough to use Warsh and apply the protections described in Section 9. It is never shown to other learners.
- Learning and app activity: lesson progress, answers and scores, XP, streaks, achievements, vocabulary and spaced-repetition history, Tadabbur progress, feature usage, and related app-interaction events.
- Ustaad Noor messages: messages you send to the AI tutor and its responses. Recent messages may be used as context so the conversation can continue across sessions.
- Purchase and entitlement data: Google Play product IDs, subscription status and expiry, purchase or order identifiers, a purchase-token value used to verify subscriptions, hashed one-time-purchase tokens, quantities, and credits granted. Google processes payment-card details; Warsh does not receive or store your full card number.
- Diagnostics, analytics, and device data: app version, operating system and device information, pseudonymous user ID, crash and performance diagnostics, IP/network information processed by hosting providers, and app-interaction events used to operate, secure, troubleshoot, and improve the Service.
- Support and security communications: information you include in support requests and records needed to send password-reset or account-security emails.
3. Microphone and Voice Recordings
Some speaking exercises request microphone permission after showing an in-app explanation. A voice recording created for shadow-speaking comparison remains in the app’s local storage, is used only for playback and comparison on that device, and is deleted when you discard it, restart the exercise, advance, or leave the exercise. Warsh does not upload that raw recording to our servers or analytics providers.
4. How We Use Information
- create and secure your account and provide the Service;
- personalize lessons and track learning progress;
- generate and preserve the visible Ustaad Noor conversation;
- verify Google Play purchases, grant entitlements or Noor credits, prevent duplicate grants, and support purchase restoration;
- send requested password-reset and account-security messages;
- measure feature usage, diagnose crashes, monitor performance, prevent abuse, and improve the Service; and
- comply with legal obligations and enforce our terms.
5. Service Providers and Data Sharing
We do not sell personal information and we do not use it for third-party advertising. We disclose data only as needed to operate the Service, process a user-requested feature, comply with law, or protect the Service. Our processors include:
- OpenAI: receives Ustaad Noor message content and recent conversation context to generate tutor responses.
- Mixpanel: receives a pseudonymous user ID, app-interaction events, and learning or subscription properties for product analytics. Raw Noor message text and voice recordings are not intentionally sent to Mixpanel.
- Sentry: receives a pseudonymous user ID, crash reports, performance traces, app/device context, and scrubbed diagnostic details. Warsh filters common credential, email, token, message, prompt, transcript, and text fields before sending events.
- Neon and Vercel: provide database, application hosting, network, and operational-log services.
- Cloudflare: provides content delivery and media hosting for lesson and vocabulary assets.
- Google Play: distributes the app, processes purchases, and provides purchase and subscription status used for verification.
- Resend: sends password-reset and account-security emails when those functions are used.
These providers may process technical information such as IP address, device/browser details, and request metadata as part of providing their services. They also apply their own privacy terms where they act independently.
6. Data Retention
Account, learning, Ustaad Noor conversation, and Warsh purchase-verification records are generally retained while your account is active so that progress, conversations, credits, and entitlements remain available across sessions. We may keep limited security, fraud-prevention, transaction, backup, or legal records for longer where reasonably necessary or required by law. Third-party providers retain data under their configured retention periods and applicable terms.
Local speaking-practice recordings are temporary and are deleted by the app as described in Section 3.
7. Account and Data Deletion
You can delete your Warsh account from within the app at Settings → Account → Delete account. You can also initiate an external deletion request at https://warsh.app/delete-account or contact support@warsh.app.
Deleting your Warsh account deletes the account and associated Warsh database records, including learning progress, vocabulary state, Ustaad Noor messages, achievements, subscription fields, and purchase-verification records. Data already retained independently by Google Play or another provider is governed by that provider’s policy. Deleting Warsh does not automatically cancel a Google Play subscription; subscription management remains available through Google Play.
8. Security
Warsh uses HTTPS/TLS for data in transit, hashes account passwords, restricts protected API access through authentication, and relies on cloud-provider encryption and access controls for stored data. No electronic system is completely secure, but we apply reasonable technical and organizational safeguards appropriate to the data we handle.
9. Children’s Privacy and Younger Learners
Warsh is for learners aged 13 and older. We ask everyone for their date of birth once, before an account is created, and we refuse to create an account for anyone under 13 without storing anything they entered. If you believe a child under 13 has an account, contact us so we can investigate and delete it.
For learners aged 13 to 17, Warsh applies additional protections: product analytics (Mixpanel) are switched off entirely, Ustaad Noor is instructed to keep every reply suitable for a young learner and never to ask for personal details, and the only emails we send are the account and password messages you request. Crash reporting (Sentry) remains on with personal data removed. Parents or guardians can ask us to delete a teen’s account at any time from warsh.app/delete-account.
10. Your Choices and Rights
Depending on your location, you may have rights to access, correct, obtain a copy of, object to certain processing of, or delete your personal information. You can disable microphone permission in Android settings and may contact us to exercise a data right.
11. Changes to This Policy
We may update this Privacy Policy when the Service or legal requirements change. We will update the date above and provide additional notice for material changes when required.
12. Contact
For privacy questions or requests, contact support@warsh.app.