← UmmahCity
Privacy Policy
Ummah Media Group LLC: covering UmmahCity (ummah.city) and its Districts: UmmahPass identity, ummah.email, UmmahChat, UmmahPlaces, UmmahCauses, UmmahArmy, UmmahJobs, MuslimTorrents, UmmahBuzz, UmmahSocial, ummah.me, and related UMG sites.
Last updated: October 5, 2026
We built this place so the Muslim internet doesn’t have to run on surveillance advertising. We don’t sell your data, we don’t build worship trackers or “religious scores,” and we will never turn your charity into a product. We do run a first-party system that links your activity across UMG sites to improve the product — full disclosure of what it collects and a real off-switch are both in section 1 below. We collect what we need to run the services you signed up for, and we tell you honestly exactly what that is — including the places where our protections are ordinary rather than extraordinary. Where something is not end-to-end encrypted, this policy says so plainly instead of hiding behind the word “secure.”
1. What we collect, and why
Most of this page is about people who made an account. One site, Ummah Directory, also holds entries about people who did not.
If you start claiming a name and do not confirm, we keep the name you tried, a one-way hash of the email, and the time, for 30 days, to count and fix the join flow. Then it is deleted. A professional sign-up that is not finished is deleted after 7 days.
- Your UmmahPass account: email address, your chosen screenname, and a password (hashed using industry-standard methods — never stored in plain text). This is one identity across all UMG Districts, so you sign in once instead of creating an account on each of our 14 platforms.
- Organisations (masjids, Muslim charities, and Muslim orgs or practices, since Sep 2026): if you set up an organisation, we store its name, its type (masjid, charity, or organisation), and its web address (a slug you pick, which also names its Meet room). We store who created it. Every member can see the names, screennames and roles (owner, admin, or member) of every other member of that same organisation, and when they joined; nobody outside the organisation can see any of this. If you invite someone by email, we store the email address you invited so the organisation's admins can see who was asked to join and by whom. An invite link stops working after 14 days if nobody accepts it, but today we keep the invite record, including that email address, indefinitely rather than deleting it automatically; closing that gap is on our roadmap. Signing in to your organisation's Meet room tells the room who you are and which organisation you belong to, so the right person is recognised as its host.
- Two kinds of activity tracking — and they are different:
(1) Aggregate, self-hosted traffic analytics: see section 3.
(2) A first-party behavioral system that links your activity across UMG sites to build a profile used today only to power product improvements, and gated before any future ad use. It runs on these sites, and only these:
- UmmahCity (ummah.city)
- UmmahPass (ummahpass.io)
- ummah.email
- UmmahPlaces (ummahplaces.com)
- UmmahCauses (ummahcauses.org)
- UmmahArmy (ummah.army)
- UmmahBuzz (ummahbuzz.com)
- ummah.me
- UmmahLocal (ummahlocal.com)
- MuslimTorrents (muslimtorrents.com)
The profile includes signals inferred from what you engage with — including religious-content signals (for example, whether you engage with prayer or Quran content) and giving/spending signals. This tracking is off until you turn it on for your account; turning it on starts collection from that moment. You can turn it off any time in your UmmahPass privacy settings, and turning it off deletes your existing profile, not just future collection. No profile data is sold or shared externally, and none is exported to any ad platform today — if that ever changes, it will only include members who separately opt in to ad personalization. Every site that runs this system says so on its own privacy page — you should never have to come here to find out that a page you are on is part of it.
- Payment records: if you become a paying member or donate, Stripe (our payment processor) handles your card. We never see or store your card number. We keep the records Stripe gives us: what you paid, when, and for which membership or donation, so we can honor your membership and your receipts.
- Email you host with us (ummah.email) — your messages are stored on our own servers so we can deliver them to you. See section 5 for exactly what that means.
- Chat: messages you send in UmmahChat. See section 6 for what is and isn’t end-to-end encrypted.
- Site search: when you search on one of our sites, we keep the words you typed, the number of results, a one-way hash of your IP address and a session token, for 30 days. We use it to see what people look for and to make search better. It is not linked to your account, and the hashes use a key that changes daily and is never written down, so past searches cannot be traced back to you or joined together later. Live today on UmmahArt and UmmahPlaces, and on the professionals directory search on UmmahPlaces (searching by profession and city), under the same 30-day, hashed-IP terms.
- Professional profile: if you choose to add one: your profession, a headline, your city, region and country, your years of experience, and any credentials you list. Since Sep 25 2026 this can also include a short "how I work" description, the languages you serve clients in, whether you also serve clients remotely, a link to your own external booking page, up to 8 services with a price you write yourself (never a quote), the year you started practising, an optional gender field that we show only if you choose to fill it in, and, also since Sep 25 2026, your education (school, degree, field of study, years), a list of skills, and any certifications you list (name, issuer, year). Credentials, education, skills and certifications are all self-reported: we do not check a licence, a degree or a certification before it is shown. You control an open-for-clients toggle, off by default; the profile stays private until you turn it on, and turning it on makes the profile public. A "Go live as a professional" button turns your page, the open-for-clients toggle and the contact relay on together, in one action, and only ever turns things on, never off. You can delete the whole professional profile at any time in one click, and deleting it hides it at once. A page you claimed on Ummah Directory stays until you ask us to remove it. New profiles do not appear in the professionals directory until the account's email is verified and the account is at least 24 hours old, or a staff member clears it sooner; a profile whose text looks like an unrelated advertisement is held back from the directory for a person to look at, which never affects the member's own page.
- Import from LinkedIn (since Sep 25 2026): if you choose to, you may upload the data archive LinkedIn gives you when you request a copy of your own data. We read only your Profile, Positions, Education, Skills, Certifications and Languages files from that archive. We never open any file about other people in that archive, including your connections, messages, invitations or endorsements, and our code cannot read those files even if you upload them. We keep no copy of the file you upload: it is read in memory to pre-fill a review screen and deleted immediately after. Nothing from the import is saved to your profile until you review it and confirm, field by field; anything you already filled in by hand is never overwritten by an import.
- The "I serve clients" / "I run a business" checkbox: when you join, we ask this once. It is stored on your account. You can leave it blank; a blank answer is never treated as a "no".
- A page on Ummah Directory: a member's profile is listed there only when the member has turned on "open for clients" and has ticked "I am Muslim" themselves. A page we built for you becomes yours when you claim it.
- Contact relay: a message a visitor types to a professional through their listing or profile is relayed to that professional by email, to their verified address only. We do not store what the visitor typed. The relay is on when you set up a professional profile; you can turn it off at any time in your profile settings. Sending is capped by a global hourly limit, not a per-visitor one, so the cap protects the system without singling anyone out.
- Ummah Directory (ummah.directory): we list some professionals before they join. We did not ask them first. Each entry says why it is listed. The reason is one of these: a public page (the person's own, their practice's, or a professional body or directory that lists them); a link to the Muslim community that their own page shows, such as work at a masjid clinic or an Islamic center; or a recommendation from someone who knows them. Being listed does not say that a person is Muslim. When an entry comes from a public page, we keep one quote from that page. When someone recommends a person, we keep the recommender's name and never show it. To remove an entry, use "Ask us to remove it" on its page. It is free and needs no account. What that site holds, and how to remove an entry, is at ummah.directory/privacy, and that page applies where the two differ.
- Content you post: reviews, listings, missions, feed posts, profile information you choose to make public.
- Web-push subscriptions: only if you turn notifications on. Stored keyed to your account so we can deliver to your devices, deleted when the subscription dies or you turn them off. Notifications are limited by policy to things a human sent you or things you asked for; mail notifications are deliberately generic (they do not include the sender or subject line in the push payload).
- Server logs: like every website, our web servers log requests (IP address, page, time, browser type) for security, abuse prevention (e.g. blocking brute-force login attempts), and debugging. These are kept for a limited period for security and debugging, then deleted or anonymized.
- Newsletter: only if you sign up in the site footer, and only your email address, how often you asked to hear from us, and where on the site you signed up. Confirmation is double opt-in — we send one link, and nothing else goes out until you click it. Every email after that carries an unsubscribe link; an unsubscribed address is kept only so we don’t email it again, and you can ask us to delete it entirely (section 18). We don’t track opens or clicks in these emails — see section 3.
- Where you came from: when you create an account we keep the page and campaign link you arrived from (for example, which part of UmmahCity sent you) so we can see which doors work. We never buy or sell this and it is not shared with advertisers.
2. What we will NEVER do
These are commitments, not marketing:
- We never sell your data. Not to advertisers, not to data brokers, not to anyone.
- We run ads through EPOM, our ad server, on pages that carry ad slots. Some paid campaigns run a Google Campaign Manager 360 (DoubleClick) tag inside the ad. EPOM and Google may set their own cookies on those pages, and read your device, browser and IP address to serve and measure the ad. This runs on UmmahCity, UmmahArmy, UmmahBuzz, UmmahSocial, UmmahPlaces, UmmahCauses, UmmahArt and Ummah Directory. You can block third-party cookies in your browser to limit it. We do not control how Google uses data its own tag collects. Google's own privacy policy governs that. We still use no Google Analytics and no Meta pixel.
- We never read or scan your email to target ads at you. Your inbox is not an advertising asset.
- We will never build prayer trackers, worship streaks, or “religious scores” into our products. We never sell religious-signal data. We never share it either, with one exception you control: when you donate, you can tick a box to share your name and email with the charity you gave to, so they can thank you. That covers that one donation only. No box ticked, nothing shared. The charity gets no feed, no list, and no profile — one thank-you for one gift. Being listed on Ummah Directory does not say that a person is Muslim. On some entries nobody has claimed, the page shows the person's own words from their own or their practice's page, or their role in an association of Muslims, with the page they are on. Where a person ticked "I am Muslim" themselves, we keep that tick private and never show it. We do not sell any of this. Our behavioral system (section 1) does infer some religious-content engagement signals — always disclosed, always yours to turn off and erase.
- We never sell donor data, and donor identity — who you give to — is walled off from every commercial use, permanently. A thank-you from the charity you chose (the tick-box above) is the only exception, and it is not a commercial use. Religious-content engagement signals are handled exactly as section 1 describes: used only for product improvement today, never sold, never shared outside UMG.
- A masjid's or organisation's member list stays theirs. We never market to it, never sell it, and never use it to target ads, the same rule we hold for UmmahPass member data generally (section 4). Only that organisation's own members can see who belongs to it (section 1).
- We never generate fake activity: reviews, donor counts, member counts. What you see on our surfaces is real or clearly labeled.
Google code does not run on our pages directly. It runs only inside an ad slot, when a paid campaign using Google's ad tag fills that slot. That is the one place Google code touches our sites, and we name it here instead of hiding it.
3. Analytics — self-hosted, first-party
We measure our own sites with Matomo, running on our own servers (analytics.ummahmediagroup.com). Nothing about your visit is sent to Google, Meta, or any analytics company — the data stays on infrastructure we own. We use it to answer questions like “is the signup page broken?” and “which pages do people actually use?”, with known bots excluded from the counts.
We also record some first-party product events (e.g. “a signup was completed”) in our own databases to run and improve the products. This is first-party only — it is never shared with or sold to anyone.
On the sign-up pages and the plan page, our page counter also counts which button was pressed, such as the yearly or the monthly price. It does not record what you type, your name, your email or your account.
Member pages make very few third-party network requests: a font file from Bunny Fonts on every page, and, if you look up a city, a request to OpenStreetMap Nominatim. The complete list is in the third-party table in section 16.
4. Advertising — contextual, never surveillance
Some UMG surfaces show ads; advertising is how much of this stays free. Our rule on member surfaces is simple: ads are matched to what a page is about, never to who you are. Ads run through EPOM, our ad server. EPOM sets its own cookie. Some paid campaigns run inside a Google Campaign Manager 360 (DoubleClick) tag. That tag can call googletagservices.com, ad.doubleclick.net and s0.2mdn.net, and send measurement beacons to pagead2.googlesyndication.com and googleads4.g.doubleclick.net. It may set a Google cookie. We do not control what Google does with data its own tag collects. You can block third-party cookies in your browser to limit this. A halal restaurant ad appears on a food page because it is a food page — not because we tracked you across the internet. We do no cross-site tracking of members ourselves, though Google's tag may when it loads inside a paid ad. No demographic profiles of members, no individual ad targeting of members by us.
On our own ad marketplace we count “ad views” (an ad unit rendering) and we tell advertisers exactly that — never “people reached.” Our ad server sets its own cookies, kept for up to 400 days. One of them, UUID, is a number for your browser. The ad server reads it on every site that shows our ads. We do not use it to choose ads from your UmmahPass account, and we give the ad server nothing from your account.
This policy covers UmmahCity and its member Districts. Our advertising business, MuslimReach, places ads on partner publisher websites and on UmmahCity’s content pages. Ads never appear on prayer, dua, giving, or wall pages, and they never use your member data.
5. Email hosting — honest about what it is
Your ummah.email mailbox lives on servers we rent in Europe and run ourselves. Honestly stated:
- Mail travels encrypted in transit (TLS) between servers and to your devices.
- Mail is not end-to-end encrypted at rest. Like almost every email provider on earth (including the big ones), messages are stored in a form our systems can read — that is what makes spam filtering and search work.
- The difference between us and the big ones is what we do with that: we do not scan, mine, or analyze your mail for advertising or profiling. Ever. Access to stored mail is restricted to what is required to operate the service (e.g. delivery, spam filtering, a support issue you ask us to look at).
6. Chat: what’s encrypted and what isn’t
- Direct messages (DMs) in UmmahChat are end-to-end encrypted: encrypted on your device, readable only by you and the person you’re messaging.
- Group Rooms are NOT end-to-end encrypted — by design. Rooms are moderated community spaces; moderation requires that moderators can see messages. We say this plainly instead of implying everything is private.
- Voice/video calls run on our own servers (“owned, not Meta”) but are not end-to-end encrypted.
- Online status. When you have UmmahChat open, people who share a direct message, a Room or a Circle with you can see whether you are online, idle or offline, and roughly how long ago you were last active. Every new member joins the #lobby Room, so most members can see your status there. A Circle's link is open to anyone who has it. You cannot turn this off yet.
7. UmmahSocial — your page, and who can see it
UmmahSocial (ummahsocial.com) is a place to post. What follows describes only that District.
Posts are public by default — you pick the audience each time
When you post, the audience picker defaults to Anyone: a public post that anyone on the internet can read, with or without an account. You can change it on every post: Members (any signed-in UmmahCity account) or Just this link (only people who have the link; it never appears in feeds or on your page). Replies never become more visible than the post they answer. Public posts may also appear in search engines and on your ummah.me page, and are shown in the UmmahCity “Today” feed to people who follow you. Posts that are not public are marked so search engines do not index them.
If you post a link, our server fetches that page once to build the preview card, and we store a copy of the preview image ourselves — so the site you linked to never learns who read your post.
Photos: location data is stripped before anyone can see them
Photos you attach are re-encoded before they are shown to anyone. That re-encoding removes the hidden camera metadata photos carry — including GPS location, device details and timestamps. The uploaded original is held in a non-public staging area only while this happens, then deleted; if a photo cannot be processed, it is dropped entirely rather than shown unprocessed.
Who can see your follow graph
How many people follow you is your information: it shows on your page only if you turn it on in Settings, and it is off by default. The list of who follows you is visible only to you, always — it names other people, so it is never public. The list of accounts you follow becomes visible only if you turn the same setting on. If your account is set to approve followers, new followers need your approval before they see your posts.
What a report contains, and that every decision is logged
When you report a post, we store which post, your account, the reason you chose, and the report’s status while a person reviews it. Reports are read by named people on our team — not by software. The person you reported is not told who reported them. Every moderation decision — hiding a post, removing it, removing photos, dismissing a report — is written to an internal log with who acted and why, so decisions can be audited.
Deleting posts, and leaving UmmahSocial
Deleting a post removes it immediately from every page, feed and count, its link stops working, and any photos on it are erased from our storage — not just hidden from view. Leaving UmmahSocial (Settings, then deactivate) does this for all your posts at once, removes your likes, clears your follow connections, and takes your page offline — your UmmahCity account, email and everything else in the city are untouched. If you come back, your page reopens; removed posts stay removed.
8. The public activity page
We publish a public activity page, and a short strip of it in the footer of our sites. It shows real things people did across UmmahCity - somebody joined, somebody claimed their @name, somebody wrote a review, somebody published an artwork, somebody joined a mission, somebody checked in at a place with a QR code, somebody liked a post, somebody set aside a gift for a cause. Every line is a real event with the real time it happened, and if a week is quiet the page says so rather than filling itself in. Section 2 already commits us to never generating fake activity; this page is the surface where that commitment gets tested most often.
What it never shows. It carries the kind of thing that happened, which site it happened on, when, and a link. It does not carry anything you wrote - no post text, no review text, no titles. Donations never carry a name, whatever your settings say. Staff, test and automated-feed activity is left off it entirely. Some things on it were done by people with no account at all - a check-in is a QR code scanned at a shop or a masjid, and a gift can be given without signing up. Those lines say someone, not a member, because we have no relationship with that person and will not imply one.
The numbers under it. Below the activity we show a few counts: how many places are published, how many reviews we hold, how many members there are, and how many visits our sites recorded in the last 30 days. The visits figure comes from our own Matomo, described in section 3, and it is a count and nothing else. It carries no country, no city, no page, and nothing about any single visit. We call them recorded visits on purpose, because anything our analytics could not see is not in the number.
Your @name on it, and the control you have
Showing your @name is off until you turn it on, in your UmmahPass privacy settings. With it on, your activity reads @yourname. With it off, we shorten your @name instead - am*********d rather than the whole thing.
We want to be straight about what that shortening buys you. It makes you harder to spot at a glance. It does not hide who you are. We measured it: across our members, most shortened @names still point to exactly one person, and somebody who already knows your @name can recognise the shortened form. So we describe it as what it is - a softening - and nothing stronger.
If you want to be left off the page completely, email salaam@ummah.city and we will take you off it. That is a real switch on our side, not a queue.
Some activity is left off for you even when your @name is shortened. Anything that names another person in the event itself - claiming an @name, following somebody - is dropped rather than shortened, because shortening the person who acted does nothing to hide the person named.
9. Payments — Stripe processes, we don’t hold cards
All payments (memberships, donations, business services) are processed by Stripe on Stripe-hosted payment pages. Your card number goes to Stripe, not to us — we never receive or store it. We keep transaction records (amount, date, product) to honor your membership, provide receipts, and meet accounting obligations. Stripe’s own privacy policy governs the data they process: stripe.com/privacy
10. Security — the honest version
- Everything is encrypted in transit (TLS) between you and our servers.
- We run on servers we lease and operate ourselves, located in Europe — not Big Tech cloud infrastructure.
- We use standard protections: firewalled services, automatic security patching, brute-force login blocking, and optional two-factor authentication on your account.
- We do not use words like “military-grade,” “bank-level,” or “zero-knowledge,” because we have not earned them and most companies who use them haven’t either. What is end-to-end encrypted here is exactly what section 6 says — no more.
- Stored data is protected by access controls and server security, not disk-level encryption: closing that gap is on our roadmap.
- If we experience a data breach affecting your personal information, we will notify affected users as required by applicable law.
11. Staff access and “Help Mode”
If you ask for help with your UmmahPlaces business dashboard, a UMG admin can view it as you see it through Help Mode: a deliberately constrained tool: sessions are time-limited (20 minutes), every use is logged, and you are notified within minutes that it happened. We built it this way so support never means silent access to your account.
12. Data retention and deletion
- We keep your data while your account is active.
- Search words in our search log are deleted after 30 days. Our page counter keeps the address of a search page, which can hold the words, with no end date today.
- You can ask us to delete your account and data at any time by emailing salaam@ummah.city. We will delete your data from our live systems on request and confirm when it’s done. Today this is handled by a person on our team, not an automated system — expect it to take a few business days, not seconds. Backup copies are removed on our normal backup-rotation schedule and are not kept indefinitely.
- If you use the tracking off-switch described in section 1, that alone deletes your behavioral profile and anonymizes your past events immediately — you don’t need to request a full account deletion just to stop that.
- We are required to keep some records even after deletion: payment and donation records for as long as tax and accounting law requires, and records needed to prevent abuse (e.g. a ban evasion list) for as long as needed to keep the community safe.
- You can also ask us what data we have about you, or ask us to correct it, the same way: email salaam@ummah.city.
- Leaving or being removed from an organisation takes effect immediately: the moment it happens, that person's access to the organisation and its Meet room ends, everywhere. There is currently no way to close or delete an organisation itself once it's created; if you need one closed, email salaam@ummah.city and we will do it by hand.
13. Legal process
We may also disclose information without your consent when required by law — for example, in response to a valid subpoena, court order, or other legal process, or where necessary to protect the safety of a person, prevent fraud, or protect our legal rights.
14. Business transfers
If UMG is ever involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will require any successor to honor the commitments in this policy, including the “What we will never do” section.
15. Children
Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact us and we will delete it.
16. Third parties we rely on
The short list of outside services that touch member data, and why:
| Service | What it gets | Why |
| Stripe | Payment details you enter on their pages | Payment processing |
| Bunny Fonts | A font-file request (no cookies) | Web fonts without Google |
| Apple / Google / Mozilla push services | The push payload (a notification’s text), never your account credentials | Required by web standards to deliver a push notification to your device — every website’s push goes through the browser vendor’s own service, not just ours |
| Other mail providers | Your message content, in transit | When you email someone off our network (e.g. a Gmail address), it necessarily passes through their mail servers to be delivered — normal for all email, everywhere |
| nominatim.openstreetmap.org | The city name you type, or your coordinates for reverse lookup | Only when you type a city name or use reverse lookup in Prayer or Places search. We store nothing from the lookup itself, and Prayer-times coordinates are never stored. What you type into a search box is covered in section 1. |
| EPOM | Sets a cookie on .aj2742.top; device, browser and IP | Serves and measures ads on ad-supported UMG sites |
| Google Campaign Manager 360 (DoubleClick) | May set a cookie through its own domains; device, browser and IP | Loads inside some paid ads on ad-supported UMG sites; we do not control Google's use of this data |
| YouTube (youtube-nocookie.com) | IP address and browser data, only after you tap play on a video | Plays the video you chose |
What is deliberately absent from this table: Google Analytics, Meta/Facebook and TikTok. We run none of the three, anywhere. The one location service above, OpenStreetMap Nominatim, is used for location context only, never to build a profile to target you with ads.
The anonymous prayer-time line shown before you set a city looks up your approximate city from your IP using our own self-hosted database on our own server — no third party is called, and nothing is stored.
At signup and login, UmmahPass looks up your approximate country, region and city from your IP in the same self-hosted database. If you have not turned off the system in section 1, it also adds that approximate location to behavioral events. No third party is called. Since October 5, 2026, your IP address is no longer sent to ip-api.com.
If you tap play on a YouTube video on UmmahSocial, YouTube (Google) loads the video and receives your IP address and browser data. Nothing loads from YouTube until you tap play.
17. Changes to this policy
If we change this policy, we will post the new version here with a new date, and for meaningful changes we will tell you (a notice on the site or an email) before they take effect, except where an immediate change is required for security or legal-compliance reasons. We will never use a policy change to quietly start doing something section 2 says we never do — those commitments are the point of this document.