Miraj Privacy Policy

Miraj Privacy Policy

Last updated: May 8, 2026

This Privacy Policy describes how Miraj Collective ("Miraj", "we", "us") collects, uses, and shares information when you use the Miraj mobile application (the "App") and the related services available at mirajcollective.com (together, the "Services").

The App is a private member experience for Miraj Collective members. It helps Muslim professionals develop spiritual practice through journaling (Wird, Inner Work), dhikr counting, habit tracking, and a guided curriculum.

If you have questions about this policy, contact us at privacy@mirajcollective.com.

1. Information We Collect

We collect only what is necessary to operate the App and verify your membership.

1.1 Information you give us

  • Account identifier: your email address. This is also used to verify your active Miraj Collective membership.
  • Password: stored only as a salted bcrypt hash. We never store or have access to your plaintext password.
  • Profile: display name (optional).
  • Practice content you create in the App:
    • Wird daily journal entries and muhasaba (evening review) responses.
    • Inner Work daily reflection text and pattern tags.
    • Threshold check-in answers.
    • Dhikr phrases and tap counts.
    • Habit definitions, check-ins, streaks, and tawbah ("reset") timestamps.
    • Diagnostic responses and your resulting Two-Axis Map / Composite Zone reading.
    • Curriculum module progress.

This content is private to your account. Founders / staff do not read it except where strictly necessary to investigate a bug you reported or to enforce these terms.

1.2 Information collected automatically

  • Device timezone (IANA name, e.g. America/New_York) and UTC offset, sent on each API request so that "today" is computed in your local time for streaks, daily entries, and exports. Stored on your user record and updated opportunistically.
  • Authentication session: a JWT issued at sign-in, stored on the device. Server logs include the request IP address and a short-lived rate-limit counter for abuse prevention; these are not used to build a behavioural profile.
  • Push notification token (only if you grant notification permission), used to deliver the reminders you have scheduled in the App (e.g. dhikr reminder, evening muhasaba). You can revoke this at any time from your device settings.

1.3 What we do not collect

  • We do not access your camera, microphone, photo library, contacts, precise or coarse location, calendar, SMS, call logs, or files on device.
  • We do not use third-party advertising SDKs or analytics SDKs that build cross-app profiles.
  • We do not use tracking identifiers (no AAID / IDFA tracking).

2. How We Use Your Information

  • Provide the Service: store and display the practice content you enter, calculate streaks, render your Two-Axis Map, generate your Inner Work pattern view, and deliver curriculum progress.
  • Authenticate you: verify email/password, issue session tokens, send password-reset deep links.
  • Verify membership: check on every sign-in (and on a daily server sweep) that the email is associated with an active Miraj Collective membership in either Stripe or GoHighLevel. Accounts without an active membership are suspended from accessing the App.