meem Join the founding circle

Legal

Meem Privacy Policy

Last updated: July 14, 2026 · Effective: July 14, 2026

This Privacy Policy explains how FI Halal Circle ("Meem," "we," "us," "our"), the operator of the Meem mobile application and joinmeem.com (together, the "Service"), collects, uses, shares, and protects your personal information, and the rights you have over it. We are based in Bangalore, India and offer the Service to users worldwide.

For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), the data controller is FI Halal Circle, Bangalore, Karnataka, India. For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the data fiduciary.

1. Scope and who this Service is for

In short: This policy covers the Meem app and joinmeem.com. You must be 16 or older to use Meem.

This policy applies to the Meem app and joinmeem.com. It does not apply to third-party websites or services we link to, which have their own privacy policies.

The Service is intended for users 16 years of age and older. We do not knowingly collect personal information from anyone under 16. If we learn that a user is under 16, we will delete the account and associated data. See Section 12 for region-specific age rules.

2. A note on religious affiliation (sensitive data)

In short: Meem is a community app for Muslims, so simply having an account can indicate your religious beliefs. Laws like the GDPR treat this as specially protected data, and we treat it that way too: we never sell it, never share it in identifiable form, and never use it for advertising.

Because Meem is a Muslim community app, your membership and activity may reveal or imply your religious beliefs. Under the GDPR this is "special category" data (Article 9), and under some US state laws (such as the California Privacy Rights Act) it is "sensitive personal information."

  • We process this information only to provide the Service you signed up for, a faith-centered community you chose to join.
  • Where the GDPR applies, we rely on your explicit consent, given when you create an account, as the legal basis for processing data that reveals religious beliefs. You may withdraw consent at any time by deleting your account.
  • We do not use sensitive personal information for advertising, profiling for advertising, or any purpose other than operating the Service, and we do not sell or share it.

3. Information we collect

In short: We collect your email and sign-in details, the profile you build, the content you post, your poll answers, your Meems activity, and a push-notification token if you turn notifications on. Prayer/Qibla location stays on your device and never reaches our servers.

Information you give us

  • Account information: email address or phone number; if you sign in with Google or Apple, the name and email that provider shares with us.
  • Profile information: username, display name, avatar photo, and city/country if you choose to add them.
  • Content you create: posts, comments, Majlis discussions, "Moments" (photos that expire after 24 hours), reactions, bookmarks, Circle memberships, and reports you file.
  • Poll and survey responses: your answers to polls and research questions. These are the basis of our consumer-research business, see Section 5 for exactly how they are and are not used.

Information generated by your use of the Service

  • Rewards activity: your Meems points ledger, redemption history, daily check-ins, and achievements.
  • Push notification token: if you enable notifications, a device token used to deliver them via Google's Firebase Cloud Messaging.
  • Basic technical data: data inherent to operating a networked service (such as IP addresses in transient server logs maintained by our infrastructure provider).

Location, on-device only

  • If you enable prayer times or the Qibla compass, your device's GPS coordinates are used to calculate prayer times and Qibla direction on your device. We do not transmit your live location to our servers for this feature. Your last-known coordinates are cached locally on your device (not on our servers) so these features work offline.

Crash and usage analytics (not yet live)

  • A future release will add Firebase Crashlytics (crash reports) and Firebase Analytics limited to a short list of product events (sign-up, poll completed, post created, check-in, redemption, circle joined). We will not collect advertising identifiers. This policy will be updated when that release ships.

4. What we do NOT collect or do

In short: No contact-book access, no ads, no ad tracking, no selling your personal data, ever.
  • We never access your phone's contact book. There is no contact sync, this is a permanent product commitment, not a current limitation.
  • We do not run third-party advertising and do not embed third-party advertising or ad-tracking SDKs.
  • We do not sell, rent, or trade your personal data to anyone.
  • We never disclose identifiable member data to brands or research buyers, see Section 5.
  • The app has no private messaging (no DMs), so there is no private-message content to collect.

5. Consumer research and aggregated insights (how Meem makes money)

In short: Brands pay us for anonymous, aggregated insights, for example, "62% of respondents preferred X." They never receive your name, email, account, or any data that could identify you.

Meem is also a consumer research panel. When you answer polls or research questions, we may combine your responses with those of other members and provide the aggregated, anonymized results to brands and research buyers. Before any insight leaves the platform:

  • All direct identifiers (name, username, email, account ID) are removed;
  • Results are aggregated across groups of respondents, never reported at the level of an individual member;
  • Demographic breakdowns (e.g., by country) are only provided at group level.

Sponsored polls are always labeled "Sponsored" in the app. Answering any poll is optional. Aggregated results are no longer personal data once they cannot reasonably be linked back to you.

6. Why we process your data and our legal bases

In short: We use your data to run your account and the community, pay out Meems fairly, send notifications you asked for, keep the community safe, and produce anonymous research insights.

We process personal data for the following purposes. Where the GDPR applies, the legal basis for each is noted.

  • Providing the Service: operating your account, Circles, Majlis, Moments, polls, and rewards (GDPR: performance of a contract, Art. 6(1)(b); for data revealing religious beliefs, explicit consent, Art. 9(2)(a)).
  • Meems and rewards integrity: maintaining the points ledger and processing redemptions; the ledger design prevents points from being silently edited (contract, Art. 6(1)(b)).
  • Notifications: delivering push notifications you have enabled (consent, Art. 6(1)(a); withdrawable in Settings at any time).
  • Safety and moderation: detecting spam, abuse, and policy violations and acting on member reports (legitimate interests, Art. 6(1)(f), in keeping the community safe).
  • Aggregated research insights: producing the anonymized insights described in Section 5 (legitimate interests, Art. 6(1)(f), in operating our research business; only anonymized outputs leave the platform).
  • Legal compliance: responding to lawful requests and meeting record-keeping obligations (legal obligation, Art. 6(1)(c)).

7. Who we share data with

In short: Only the service providers that run the app, our database/host (Supabase), Google (push notifications and sign-in), and Apple (sign-in). No data brokers, no advertisers.

We share personal data only with the processors below, only so they can provide their service to us, and never for their own advertising:

  • Supabase: our database, authentication, file storage, and realtime backend, running on cloud infrastructure. All member data is stored here.
  • Google Firebase Cloud Messaging: delivers push notifications. Google receives your device push token, not your account content.
  • Google / Apple sign-in: if you choose them, they handle that authentication step under their own privacy policies.
  • Resend: delivers our transactional email (such as sign-in codes, password resets, and account notices). Resend receives your email address and the content of those messages, nothing else.
  • Firebase Crashlytics / Analytics: once live (see Section 3), crash reports and the limited event list.

We may also disclose personal data if required by law, court order, or governmental authority, or to protect the rights, safety, or property of Meem, our members, or the public, and, in the event of a merger, acquisition, or asset sale, to the successor entity, with notice to you.

8. International data transfers

In short: We operate from India and our servers run on Supabase's cloud infrastructure hosted on Amazon Web Services in Tokyo, Japan. Legal safeguards apply to these transfers.

We are based in India, our members are worldwide, and our infrastructure provider (Supabase) hosts data on Amazon Web Services cloud infrastructure in Tokyo, Japan (AWS region ap-northeast-1). Your personal data will therefore be transferred across borders. Where the GDPR applies, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses as incorporated in our processors' data processing agreements, and note that Japan holds a European Commission adequacy decision.

9. Data retention

In short: We keep your data while your account is active. Delete your account and it's removed; Moments auto-delete after 24 hours regardless.
  • Account and content data are retained while your account is active.
  • Deleting your account removes your login, profile, posts, comments, Circle memberships, and related content, see our Data Deletion page for the exact scope and what may briefly remain in routine backups.
  • "Moments" are automatically deleted from our database and file storage after they expire (24 hours), regardless of account status.
  • Aggregated, anonymized research results may be retained indefinitely, since they can no longer be linked to you.
  • We may retain limited records where required by law (e.g., records of deletion requests).

10. Security

In short: Encrypted connections, database-level access rules so members can't read each other's private data, and locked-down server functions for anything touching points. If a breach affects you, we'll tell you.

We use encrypted connections (TLS/HTTPS), database Row Level Security so one member's session can never directly read another member's private data, and narrow, audited server-side functions for any operation that affects Meems points or redemptions. No system is perfectly secure; if we discover a personal data breach affecting you, we will notify you and the relevant authorities as required by applicable law.

11. Your rights and choices

In short: You can see, fix, and delete your data. Depending on where you live you have specific legal rights (listed below), email support@joinmeem.com to use any of them.

Everyone, everywhere:

  • Access & correction: edit your profile, username, and settings in the app at any time.
  • Deletion: delete your account and data at any time in-app (Settings → Account → Delete Account) or via the Data Deletion page.
  • Notifications: per-type toggles and a nightly mute window in Settings → Notifications.
  • Any privacy request: email support@joinmeem.com. We will verify your identity and respond within the timeframe applicable law requires (and in any event within 30 days unless the law allows longer).

European Economic Area, United Kingdom, and Switzerland (GDPR/UK GDPR)

  • Right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests.
  • Right to withdraw consent at any time (without affecting prior processing), including the explicit consent described in Section 2, by deleting your account.
  • Right to lodge a complaint with your local supervisory authority.
  • We do not make automated decisions with legal or similarly significant effects.

United States state privacy laws (California CCPA/CPRA, and similar laws in Virginia, Colorado, Connecticut, Texas, and other states)

  • Right to know/access: the categories and specific pieces of personal information we collect (Section 3), the purposes (Section 6), and the parties we share with (Section 7).
  • Right to delete and right to correct your personal information.
  • Right to opt out of sale or sharing: we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. We treat aggregated, anonymized research insights (Section 5) as outside the definition of "sale" because they are not personal information; if that ever changed, we would provide an opt-out first.
  • Sensitive personal information: we use it only to provide the Service (see Section 2) and do not sell or share it.
  • Non-discrimination: we will never degrade your Service for exercising a privacy right.
  • Submit requests to support@joinmeem.com. You may use an authorized agent; we will verify the request as the law allows.

India (Digital Personal Data Protection Act, 2023)

  • Right to access a summary of your personal data and processing activities.
  • Right to correction, completion, updating, and erasure of your data.
  • Right to grievance redressal: contact our Grievance Officer (below) and we will respond within the period prescribed under the DPDP Act and its rules.
  • Right to nominate another individual to exercise your rights in the event of death or incapacity.
  • If unsatisfied with our response, you may complain to the Data Protection Board of India.
  • Grievance Officer: Grievance Officer, FI Halal Circle, Bangalore, Karnataka, India, support@joinmeem.com.

12. Children's privacy

In short: Meem is for ages 16+. If you're a parent and believe your under-16 child has an account, email us and we'll remove it.

The Service is not directed at children under 16, and we do not knowingly collect their personal data. Parents or guardians who believe a child under 16 has created an account should contact support@joinmeem.com and we will delete it. Additional age rules may apply in your region (see the note in Section 1 regarding India).

13. Changes to this policy

In short: We'll update the date at the top, and for big changes we'll tell you in the app before they take effect.

We will update the "Last updated" date above when this policy changes. For material changes, we will provide notice in the app before the changes take effect and, where required by law, seek fresh consent.

14. Contact us

FI Halal Circle
Bangalore, Karnataka, India
Privacy requests and general support: support@joinmeem.com

Privacy· Terms· Guidelines· Data Deletion
© 2026 Meem · joinmeem.com Instagram / X / YouTube: @joinmeem