Privacy Policy - Android
Privacy Policy – Sahan
Effective Date: 22 April 2025
Last Updated: 6 October 2025
Apps Foundry Labs Ltd (“we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use the Sahan mobile application (the “App”).
By using the App, you agree to this Privacy Policy. If you do not agree, please do not use the App.
1. Who We Are
Sahan is operated by:
Apps Foundry Labs Ltd
Company Number: 16288141
Incorporated: 3 March 2025
Company Type: Private limited company
Nature of Business (SIC): 58290 – Other software publishing
Registered Address: Unit 7, 97 Western Road, Southall, England, UB2 5HN
📧 Email: privacy@appsfoundrylabs.com
We are the Data Controller for the purposes of the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and applicable international privacy laws including the EU GDPR, California Consumer Privacy Act (CCPA), and Australian Privacy Act 1988.
2. Information We Collect
We collect and process the following categories of personal data.
a) Information You Provide
- Full name
- Username
- Email address
- Date of birth
- Gender
- Profile photo and verification selfie
- Bio and profile description
- Religious, lifestyle, educational, or marital preferences (optional)
- Profile visibility settings
- Messages, likes, matches, and other in-app interactions
b) Information We Collect Automatically
- IP address
- Device type and operating system version
- App version
- Activity logs (e.g. matches, messages, visits)
- Crash reports and diagnostics (e.g. via Firebase, Apple)
c) Face Data (Verification Selfie)
When you use the Selfie Match Verification feature:
- You capture a selfie image to confirm that your profile photos genuinely represent you.
- The App does not extract, map, or store facial geometry or biometric templates.
- The selfie is compared to your profile photos using secure, automated similarity checks.
- The image and comparison results are never shared with third parties and are used only to verify authenticity and maintain community safety.
- The selfie is encrypted, stored securely in Firebase, and deleted within 30 days of account deletion or when verification is no longer required.
3. How We Use Your Data
| Purpose | Explanation |
|---|---|
| Account management | To create and manage your account |
| Profile personalisation | To customise your experience |
| Matchmaking | To connect you with compatible users |
| Moderation and safety | To verify profiles, prevent impersonation, and detect harmful behaviour. Face data is never used for marketing, advertising, or analytics. |
| Communications | To notify you about matches and messages |
| Analytics | To improve and optimise performance |
| Legal compliance | To fulfil legal and regulatory obligations |
4. Legal Basis for Processing
| Basis | When We Use It |
|---|---|
| Contract | To provide core services such as registration and matchmaking |
| Legitimate interests | For security, fraud prevention, and product improvement |
| Consent | For optional features such as face verification and cultural identity tags |
| Legal obligation | When required by law or regulators |
5. Sharing Your Data
We do not sell or rent your data.
We share only with trusted service providers when necessary:
| Recipient | Purpose |
|---|---|
| Google Firebase | Authentication, hosting, storage, and analytics |
| Apple Services | Crash reporting and diagnostics (iOS only) |
| Support tools | To investigate complaints or provide support |
| Legal authorities | When required by law or court order |
6. International Data Transfers
Your data may be processed outside the UK.
We use appropriate safeguards such as:
- Adequacy decisions for approved countries
- Standard Contractual Clauses (SCCs) approved by the UK/EU
- EU-US Data Privacy Framework certified providers
7. Your Rights
Depending on your location, you may have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of your personal data |
| Correction | Ask us to update inaccurate information |
| Deletion | Request deletion of your account and related data |
| Withdraw consent | Withdraw consent for optional features |
| Object / Restrict | Object to or limit certain processing |
| Portability | Receive your data in machine-readable format |
| Non-discrimination (CCPA) | You won’t be treated differently for exercising your rights |
To exercise these rights, email privacy@appsfoundrylabs.com.
We may request proof of identity.
8. Data Retention
| Situation | Retention Period |
|---|---|
| Active account | Retained while account is active |
| Deleted account | Permanently deleted within 30 days |
| Verification selfies | Deleted within 30 days of account deletion or verification expiry |
| Inactive accounts | Removed after 3 years of inactivity |
| Anonymised logs | Retained for up to 12 months for analytics and security |
9. Data Security
We apply appropriate technical and organisational measures, including:
- End-to-end encryption in transit (TLS)
- Firebase Security Rules and role-based access controls
- Limited staff access under confidentiality agreements
- Regular security audits and monitoring
While we maintain robust security standards, no digital system is completely secure.
10. Children
Sahan is intended for users aged 18 and over.
We do not knowingly collect data from children.
If you believe a child has used our App, contact us and we will delete their data promptly.
11. Global Compliance
Sahan complies with major international privacy frameworks, including:
- UK GDPR & Data Protection Act 2018
- EU General Data Protection Regulation (EU GDPR)
- California Consumer Privacy Act (CCPA) / CPRA
- Australian Privacy Principles (APPs)
- Other applicable regional data protection regulations
Users outside the UK/EU may exercise equivalent rights consistent with these laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time.
The “Last Updated” date will be revised and users will be notified of material changes.
13. Contact Us
Apps Foundry Labs Ltd
Unit 7, 97 Western Road
Southall, England, UB2 5HN
📧 privacy@appsfoundrylabs.com
🇬🇧 ICO (UK): https://ico.org.uk/make-a-complaint/
14. Cultural Purpose of the App
Sahan is designed for the Somali community worldwide, offering a culturally relevant, respectful, and safe platform for matchmaking and introductions.
All personal data is handled with cultural sensitivity and care.
By using the App, you acknowledge that Sahan is intended for individuals who identify with or have a meaningful connection to Somali culture.
Face Data Disclosure Summary
Sahan collects a single selfie image solely for identity verification through the Selfie Match Verification feature. The selfie is compared to profile photos to confirm authenticity and prevent impersonation. No facial geometry or biometric templates are extracted or stored. The image is encrypted, never shared with third parties, and deleted within 30 days of account removal or verification expiry.