privacy policy
last updated: 5 july 2026 . last reviewed: 8 july 2026
this explains what mahfah collects, why, the legal basis for it, who it goes to, how long we keep it, and your rights. plain language, no tricks.
who runs mahfah
mahfah is operated by an individual (a sole operator), who is the data controller for the personal data described here. contact for any privacy question or request: support@mahfah.app. we have not appointed a data protection officer (we are not required to).
what we collect
- email address (only if you sign up with email)
- google or apple account identifier (only if you use social login)
- date of birth (for the 18+ age gate. we store the date only, never an ID document)
- username and the profile photo you upload
- your lore (the statements you write) and the judgments you make
- your aura score and badges (derived from how you play)
- device push notification token (only if you turn notifications on)
- your device's time-zone offset from UTC (a number of minutes, not a location). we use it so a daily streak rolls over at your midnight and a reminder arrives in your evening rather than ours. it is not shared, and it is not GPS or a precise location.
- reports you file and users you block
why we use it, and our legal basis
each purpose has a legal basis under the EU/UK GDPR:
- running the app (account, profile, photo display, lore, votes, aura, badges): contract (art 6(1)(b)). we can't provide mahfah without this.
- safety and moderation (photo + text checks, handling reports, blocking abuse, security): legitimate interest (art 6(1)(f)) in a safe community.
- age gate (date of birth): keeping mahfah 18+ (legitimate interest / legal duty). we ask your date of birth once, during sign-up, before a profile exists. if it says you are under 18 we do not create a profile, we delete the sign-in account that was just created, and the app stays closed on that device. if that deletion cannot be completed there and then, the app tells you so and gives you an address to write to.
- push notifications: opt-in only (consent, art 6(1)(a)), withdrawable any time.
- analytics and crash reporting: keeping the app working and improving it (legitimate interest). we do not run advertising or cross-app tracking, and we never sell your data. analytics are pseudonymous rather than truly anonymous: the analytics tool assigns your install a random id so repeat events from one device can be counted, and crash reports are tagged with your account id so we can tell whether a bug hit one person or everyone. neither is linked to your name or email by us. you can turn product analytics off in the app (profile → usage analytics, available to guests too). switching it off stops collection on that device straight away and stays off after you close the app; the analytics tool is not started at all on the next launch. crash reporting is separate and stays on, because it is how a crash on your phone becomes a bug we can fix.
where we rely on legitimate interest, you can object (see your rights).
your photo, and automated moderation
is your face treated as biometric data? no. mahfah does not use facial recognition. we do not build faceprints or face templates, and we never use your photo to identify, match, or recognise you. under EU law a face photo is only special-category "biometric" data when it is run through technology built to uniquely identify a person, and we do none of that. your photo is ordinary personal data: we use it to show your profile and to keep the app safe.
photos and lore are checked automatically before they go live. these checks run without a human and can reject content on their own. the logic, plainly: if an automated safety score crosses our threshold, the content is rejected and we fail closed (if a check can't run, the upload is blocked). a rejected photo or line of lore is simply not published and you're asked to submit a different one. it does not affect your account standing or scores.
your right to a human. if you think a rejection was wrong, email support@mahfah.app and a person will review it, hear your view, and can overturn it.
where your data goes (international transfers)
your account and content are stored on supabase in the EU (stockholm), and pseudonymous product analytics on posthog in the EU. some processing happens in the united states, and how long each of those holds anything differs: openai (automated moderation) processes the content and does not store it; expo (push delivery and builds) and resend (only used to email ourselves if you flag child-safety content) handle a message in transit; vercel (the mahfah.app web pages) keeps short-term request logs; sentry (crash diagnostics) retains error reports for around 90 days. the per-processor detail is in the list below. when data leaves the EU we rely on the EU-US data privacy framework where the processor is certified, and on the european commission's standard contractual clauses as a fallback. email us for detail on any specific processor.
third parties
- supabase. database, auth, storage (EU)
- openai. automated photo + text moderation for lore and comments (US; processed, not stored)
- expo. push notification delivery and build infrastructure (US)
- vercel. hosting for the mahfah.app web pages + share links (US). vercel logs each request (including your IP address, browser user-agent, and the path you visited) to keep the site secure and mitigate DDoS attacks; these logs are kept short-term per vercel's standard retention.
- sentry. crash and error diagnostics so we can fix bugs (US). crash reports are tagged with your account id (a random uuid, never your name or email) so we can tell one person's bug from everyone's. error logs can include device data and your IP address (only from internal "trace" test builds), retained around 90 days.
- resend. transactional email, used only to alert us if you flag child-safety content (US). the alert email contains only what was reported and who reported it (identifiers), never the content itself; the content stays in our own systems for the review.
- posthog. product analytics, hosted in the EU. no autocapture, no session recording, and we never call their identify feature, so your account is not named to them. posthog does assign your install a random device id and records standard technical event metadata (app version, device model, os, locale). a handful of events only (a judgment made, signed up, a share attempt, a sign-up prompt) plus app-open. you can switch this off in the app (profile → usage analytics); with it off, the posthog sdk is not started and nothing is sent to them from your device.
- google / apple. sign-in, only if you use social login
each is contractually bound to protect your data as described here.
for transparency: we previously used sightengine (photo moderation) and anthropic (claim suggestions). both have been removed and no longer receive any of your data.
how long we keep it
- account data (profile, photo, lore, votes, aura, badges): kept while your account is active. when you delete your account the database records go straight away. photo files are removed in the same operation; if a storage error stops that, the app tells you at the time and an automatic sweep clears whatever is left, usually within a couple of hours and at the latest within 24.
- date of birth: kept as proof of age while your account is active; deleted with your account.
- lore you wrote about other people: a line you added to someone else's lore stays on their profile after you leave, but de-identified (your authorship removed). a crowd claim you posted about someone is deleted outright with your account, not kept.
- reports you file and moderation records: kept de-identified for up to 12 months for safety.
- content a moderator removes: it stops being shown in the app immediately, and the photo file itself is deleted once the period for reversing the decision has passed: 7 days when a single post was removed, 30 days when it was removed as part of an account-level restriction. until then the file still exists, so a direct link to it that someone already had may still work; after it is deleted, that link stops working and the removal can no longer be undone. the record that the content existed and was removed is kept for safety, as above.
- content we are legally required to preserve (for example, material reported for child safety) may be retained and disclosed to law enforcement as required by law, even after you delete your account (GDPR art 17(3)(b)). everything else above is either deleted or de-identified; this is the only thing that can still be tied to you after you delete.
- product analytics (posthog): a handful of events keyed to a random install id, never to your name or email. because they were never linked to your account, we have no way to find them by it, and deleting your account does not remove them. turning usage analytics off stops any further events from your device, but for the same reason it cannot retrieve the ones already sent.
- crash logs (sentry): around 90 days, then deleted.
when a file is deleted, by you or by us after a moderator removal, cached copies on content-delivery networks can take up to 72 hours to expire, so a copy may briefly be served from a cache after the file itself is gone. our database provider keeps automatic daily backups for a short rolling window (currently seven days) for disaster recovery. we do not restore from them to recover a deleted account, and each backup ages out on its own, so your records are gone from the last of them within a week of deletion.
guests (anonymous mode)
you can use mahfah as a guest without an account. we create an anonymous session and keep your progress on your own device. we don't collect your email or identity as a guest. anything you upload still goes through the same safety moderation. if you create an account later, your guest progress transfers to it. deleting the app clears your local guest data.
your rights
under the EU/UK GDPR you can, at any time:
- access. get a copy of the data we hold about you.
- delete. erase your account and all associated data (in-app, or by emailing us).
- correct. fix data that's wrong (rectification).
- restrict. ask us to pause processing while a dispute is sorted.
- port. get the data you gave us in a portable, machine-readable form.
- object. object to any processing we base on legitimate interest. for product analytics you do not have to ask us: the switch is in the app under profile → usage analytics.
- withdraw consent. turn off push, turn off usage analytics, or withdraw any consent at any time, without affecting what came before.
- complain. lodge a complaint with your local data protection authority. in the EU, find yours at edpb.europa.eu; UK users can contact the ICO.
for any right that isn't a button in the app, email support@mahfah.app. we respond within one month.
age
mahfah is for users aged 18 and over. we ask for your date of birth at signup, before any profile is created. if it says you are under 18, the app closes there: no profile is made, the sign-in account created moments earlier is deleted, and that device stays locked out. mahfah is not directed to children, and if we otherwise find that a user is under 18 we delete their account. we ask for a date, not an ID document, so this is a self-declared check: it stops a stated minor, and it cannot detect a false date.
deleting your account
you can delete your account and all associated data at any time. how to delete your account. our community rules are in the terms.
changes to this policy
if we change this policy in a way that materially affects you, we'll update the date above and surface a notice in the app before the change takes effect.
contact
questions? email support@mahfah.app.