Last updated: 1 Sha'ban 1447 AH. This is a plain-language summary. The full legal policy is available on request.
What we collect
- · Your email and name, via Clerk (our auth provider).
- · Lesson progress and notes you write.
- · Push notification preferences if you enable them.
- · Anonymous usage analytics (which pages, how long), via Vercel.
What we don't do
- · We don't sell your data. Not to advertisers, not to anyone.
- · We don't share your notes or progress with other members.
- · We don't track you across other sites.
- · We don't use your data to train AI models.
Your rights
You can request an export of all your data, or delete your account entirely, at any time by emailing privacy@theislaminstitute.com. We'll honour the request within 30 days. EU and UK members have GDPR rights, California members have CCPA rights, and we extend the same to everyone regardless of jurisdiction.
Where data lives
Member data is stored on Neon (Postgres) in the US-East region. Auth is managed by Clerk. Push subscriptions are stored alongside member data. Email goes through Resend. Payments go through Stripe: we store only their customer id and subscription id on our side. We never see or store your card number, CVV, or expiry. Refunds, invoices, and payment method changes all happen on Stripe's hosted portal.
Questions
Write to privacy@theislaminstitute.com. We reply.