Meem Privacy Policy

Last updated: July 14, 2026 · Effective: July 14, 2026

This Privacy Policy explains how FI Halal Circle ("Meem," "we," "us," "our"), the operator of the Meem mobile application and joinmeem.com (together, the "Service"), collects, uses, shares, and protects your personal information, and the rights you have over it. We are based in Bangalore, India and offer the Service to users worldwide.

For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), the data controller is FI Halal Circle, Bangalore, Karnataka, India. For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the data fiduciary.

1. Scope and who this Service is for

In short: This policy covers the Meem app and joinmeem.com. You must be 16 or older to use Meem.

This policy applies to the Meem app and joinmeem.com. It does not apply to third-party websites or services we link to, which have their own privacy policies.

The Service is intended for users 16 years of age and older. We do not knowingly collect personal information from anyone under 16. If we learn that a user is under 16, we will delete the account and associated data. See Section 12 for region-specific age rules.

2. A note on religious affiliation (sensitive data)

In short: Meem is a community app for Muslims, so simply having an account can indicate your religious beliefs. Laws like the GDPR treat this as specially protected data, and we treat it that way too: we never sell it, never share it in identifiable form, and never use it for advertising.

Because Meem is a Muslim community app, your membership and activity may reveal or imply your religious beliefs. Under the GDPR this is "special category" data (Article 9), and under some US state laws (such as the California Privacy Rights Act) it is "sensitive personal information."

3. Information we collect

In short: We collect your email and sign-in details, the profile you build, the content you post, your poll answers, your Meems activity, and a push-notification token if you turn notifications on. Prayer/Qibla location stays on your device and never reaches our servers.

Information you give us

Information generated by your use of the Service

Location - on-device only

Crash and usage analytics (not yet live)

4. What we do NOT collect or do

In short: No contact-book access, no ads, no ad tracking, no selling your personal data - ever.

5. Consumer research and aggregated insights (how Meem makes money)

In short: Brands pay us for anonymous, aggregated insights - for example, "62% of respondents preferred X." They never receive your name, email, account, or any data that could identify you.

Meem is also a consumer research panel. When you answer polls or research questions, we may combine your responses with those of other members and provide the aggregated, anonymized results to brands and research buyers. Before any insight leaves the platform:

Sponsored polls are always labeled "Sponsored" in the app. Answering any poll is optional. Aggregated results are no longer personal data once they cannot reasonably be linked back to you.

6. Why we process your data and our legal bases

In short: We use your data to run your account and the community, pay out Meems fairly, send notifications you asked for, keep the community safe, and produce anonymous research insights.

We process personal data for the following purposes. Where the GDPR applies, the legal basis for each is noted.

7. Who we share data with

In short: Only the service providers that run the app - our database/host (Supabase), Google (push notifications and sign-in), and Apple (sign-in). No data brokers, no advertisers.

We share personal data only with the processors below, only so they can provide their service to us, and never for their own advertising:

We may also disclose personal data if required by law, court order, or governmental authority, or to protect the rights, safety, or property of Meem, our members, or the public - and, in the event of a merger, acquisition, or asset sale, to the successor entity, with notice to you.

8. International data transfers

In short: We operate from India and our servers run on Supabase's cloud infrastructure hosted on Amazon Web Services in Tokyo, Japan. Legal safeguards apply to these transfers.

We are based in India, our members are worldwide, and our infrastructure provider (Supabase) hosts data on Amazon Web Services cloud infrastructure in Tokyo, Japan (AWS region ap-northeast-1). Your personal data will therefore be transferred across borders. Where the GDPR applies, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses as incorporated in our processors' data processing agreements, and note that Japan holds a European Commission adequacy decision.

9. Data retention

In short: We keep your data while your account is active. Delete your account and it's removed; Moments auto-delete after 24 hours regardless.

10. Security

In short: Encrypted connections, database-level access rules so members can't read each other's private data, and locked-down server functions for anything touching points. If a breach affects you, we'll tell you.

We use encrypted connections (TLS/HTTPS), database Row Level Security so one member's session can never directly read another member's private data, and narrow, audited server-side functions for any operation that affects Meems points or redemptions. No system is perfectly secure; if we discover a personal data breach affecting you, we will notify you and the relevant authorities as required by applicable law.

11. Your rights and choices

In short: You can see, fix, and delete your data. Depending on where you live you have specific legal rights (listed below) - email support@joinmeem.com to use any of them.

Everyone, everywhere:

European Economic Area, United Kingdom, and Switzerland (GDPR/UK GDPR)

United States state privacy laws (California CCPA/CPRA, and similar laws in Virginia, Colorado, Connecticut, Texas, and other states)

India (Digital Personal Data Protection Act, 2023)

12. Children's privacy

In short: Meem is for ages 16+. If you're a parent and believe your under-16 child has an account, email us and we'll remove it.

The Service is not directed at children under 16, and we do not knowingly collect their personal data. Parents or guardians who believe a child under 16 has created an account should contact support@joinmeem.com and we will delete it. Additional age rules may apply in your region (see the note in Section 1 regarding India).

13. Changes to this policy

In short: We'll update the date at the top, and for big changes we'll tell you in the app before they take effect.

We will update the "Last updated" date above when this policy changes. For material changes, we will provide notice in the app before the changes take effect and, where required by law, seek fresh consent.

14. Contact us

FI Halal Circle
Bangalore, Karnataka, India
Privacy requests and general support: support@joinmeem.com