Legal

Privacy policy.

Last updated 12 August 2026.

Keep It Halal is a marriage-intent introduction service operated by Keep It Halal Ltd ("we", "us"), registered address PO Box 6945, Unit 154629, London, W1A 6US, United Kingdom. This policy explains what we collect, why, how long we keep it, and how you get it back or delete it. It covers both the website at keepithalal.com and the Keep It Halal iOS and Android apps. We are the data controller, and all privacy and data-protection requests go to support@keepithalal.com.

Keep It Halal is for adults aged 18 and over. We do not knowingly collect data from anyone under 18, and we delete accounts we find to be under-age.

What we collect and why

  • Account details — email address, and phone number if you verify by SMS. Used to sign you in, secure the account and send service messages.
  • Profile content — nickname, age, approximate location, marital status, occupation, and the answers you choose to give (sect, personality, practice level and similar). Shown to potential matches within the rules of the product.
  • Photos and intro video — the media you upload. Your intro video's audio is part of that media. Photos stay hidden from a match until the reveal rules are met.
  • Verification media — a selfie and, where required, an ID check. Used only to confirm you are a real person. Never shown to matches.
  • Approximate location — used to work out distance for discovery. We do not store or display your precise coordinates, and we never show your location to another member.
  • Messages and activity — your conversations, matches, skips, reports and timers. Needed to run the 3-day rule, safety checks and support.
  • Purchases — what you bought and when, so entitlements unlock. Card details are handled by the payment provider and never reach us.
  • Device and diagnostic data — a push notification token if you opt in, plus basic crash and error logs so we can fix faults.

We do not track you across other apps or websites, and we run no advertising trackers.

Our legal bases (UK GDPR / EU GDPR)

We only use your data where we have a lawful basis to do so:

  • Contract — running your account, matching, chat, the 3-day rule, purchases and support. Without this data the service cannot work.
  • Legitimate interests — safety, moderation, fraud and abuse prevention, and keeping the platform secure and working. We balance these against your rights and keep the data to the minimum needed.
  • Consent — optional extras you switch on: location, contact blocking, push notifications, non-essential cookies, and your religious details on your profile. You can withdraw consent at any time in the app, and we stop using the data for that purpose.
  • Legal obligation — tax and accounting records, and responding to lawful requests.
  • Vital interests — rare cases where sharing is needed to protect someone from serious harm.

Religious details and verification media

Some of what you share is "special category" data under GDPR — in particular your faith, sect and practice level, and the selfie or ID used to prove you are a real person. We only handle it with your explicit consent, given when you choose to add it or start verification, and we use it for nothing else. Faith details are used to match you; verification media is used only to confirm identity and is never shown to another member. You can remove faith details from your profile, or ask us to delete verification media, at any time — deleting verification media means your verified status is removed.

Automated checks and human review

Photos, intro videos and messages are screened automatically before or as they become visible, and repeated flags can limit your account or block a message. These checks are not the final word: any outcome that affects your account — a warning, a block, a removed photo or a ban — is reviewed by a person before it stands, and you can challenge it by emailing support@keepithalal.com or using the in-app appeal. We do not use your data for advertising profiles or credit-style scoring.

Where your data is processed

The service is run from the UK and Europe, but some of our processors listed above operate in other countries, including the United States. Where data leaves the UK or EEA we rely on the transfer safeguards permitted by GDPR — an adequacy decision, or the UK International Data Transfer Addendum and the EU Standard Contractual Clauses — together with contract terms that limit each processor to acting on our instructions. Ask us for details of the safeguards for any specific processor.

Contacts blocking is hash-only

If you turn on contact blocking, your device converts each phone number into an irreversible SHA-256 hash and only those hashes are sent. We cannot read the numbers, names or anything else in your address book, and the hashes are used for one purpose: hiding your profile from people you already know. Turning the feature off deletes them.

Moderation of photos, video and chat

To keep the space safe, uploaded photos and intro videos are checked automatically before they become visible, and messages are screened for abuse and for attempts to move off-platform. This uses an automated service (Google Gemini) as a processor on our behalf; the content is not used to train anyone's models. Flagged items may be reviewed by our moderation team, and a Wali can read the conversations they are linked to.

Cookies and on-device storage

The website uses essential cookies for sign-in, security and remembering your cookie choice, plus optional analytics and marketing cookies that stay off until you switch them on. There are no advertising trackers and no cross-site tracking. Your choice is recorded with the time you made it — against your account if you are signed in, so it follows you across devices, otherwise on the device only — and you can change or withdraw it at any time. Full detail, including each cookie and how long it lasts, is in our cookie policy.

Who we share it with

We never sell your data. We use a small number of processors to run the service:

  • Supabase — database, authentication and file storage.
  • Cloudflare — hosting, media delivery and object storage.
  • Apple and Google — app distribution, in-app purchases and push delivery.
  • RevenueCat — purchase and entitlement records.
  • Stripe — payments made on the website.
  • Resend and Twilio — email and SMS you have asked for.
  • Google Gemini — automated safety checks described above.

We also disclose data where the law requires it, or where it is necessary to protect someone's safety.

How long we keep it

  • Profile, photos and messages — while your account is open.
  • Verification selfie and ID checks — deleted once verification is decided, and no later than 12 months.
  • Contact hashes — until you switch contact blocking off.
  • Deleted accounts — removed immediately, with backups rolling off within 30 days.
  • Reports, bans and payment records — kept as long as needed for safety and legal or tax obligations.

Your rights

You can access, correct, export or delete your data, object to processing, and withdraw consent for optional features such as location, contacts or notifications at any time in the app.

In full, you have the right to: be told what we hold, get a copy, have mistakes corrected, have data erased, restrict or object to how we use it, receive it in a portable format, withdraw consent, and not be subject to a decision made by automation alone.

Export: Profile → Danger zone → "Export my data" downloads everything we hold in one file.

Delete: Profile → Danger zone → "Delete my account" removes your account permanently — see the account deletion instructions. You can also email support@keepithalal.com.

Request deletion: Request that your account and associated data is deleted and we will email you a confirmation link before anything is removed.

Requests made by email are answered within one month. We may ask you to confirm you own the account before we act, and we never charge for a request.

If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ico.org.uk), or to your local supervisory authority if you are in the EU.

Security

Data is encrypted in transit and at rest, verification media is access-controlled, and screenshots are blocked or watermarked inside the app. No system is perfect, so please report anything that looks wrong to support@keepithalal.com.

If a breach ever put your rights at risk, we will tell the relevant regulator within 72 hours of becoming aware of it, and tell you directly where the law requires it.

Changes and contact

We will update this page when the product changes and move the date at the top. For privacy or data requests: support@keepithalal.com. For billing: billing@keepithalal.com.