Privacy policy
Understand your data. Know your choices.
Last updated: September 27, 2026
Nasiha, Inc. (“Nasiha,” “we,” or “us”) provides the Nasiha app and nasiha.app. This policy explains how we handle information when you create an account, connect a brokerage, use stock screening, visit our website, join our waitlist, or contact us.
For privacy questions or requests, contact support@nasiha.app. You can use our public support page without signing in.
Information we use and why
- Account information. We use your email address, account identifier, authentication records, and any name supplied through sign-in to create and secure your account, restore access, and provide account-related messages. Sign in with Apple can supply a private relay address. Email passwords are handled by our authentication provider. Your preferred name and app settings can also be stored locally on your device.
- Brokerage connections. If you choose to connect an investment account through Plaid, we receive a connection identifier, institution information, connection status, and access tokens. Our backend stores the token in encrypted form so it can retrieve information you have authorized. Your brokerage login is entered through Plaid or your institution; Nasiha does not receive or store your brokerage password.
- Investment information. We retrieve the holdings available through your authorized connection, including security names and symbols, quantities, values, currency, and cost basis when available. We use this information to show your holdings, portfolio totals, and screening results. Our holdings endpoint processes this data for the response without saving a portfolio copy in our database. The app holds information needed to display the current session.
- Stock requests. We process company names or symbols you search for and the securities you open or screen. We store shared market and screening results to keep reports consistent and reduce repeated provider requests. Those shared records describe securities, rather than your holding quantities or balances.
- Website waitlist and communications. If you join the waitlist, we store your email, any name you provide, signup source and time, email-delivery status, and a hash derived from your IP address for abuse prevention. We use these records for requested access and product updates. If you contact us, we receive the information you include so we can respond.
- Operational information. Our infrastructure processes network information such as IP addresses, request times, authentication events, error information, and request or account identifiers to deliver the service, prevent abuse, enforce rate limits, and investigate problems. Optional website analytics are described separately below.
Brokerage linking is optional. In builds labeled “sandbox” or “demo,” displayed investment data may be test data; those labels do not authorize access to a real brokerage. Nasiha does not execute trades or move money.
Services that process information
We share the information necessary for the services below. Nasiha remains responsible for information processed on our behalf. We require providers handling that information for us to protect it at least to the same standard described in this policy and required by applicable privacy rules.
- Supabase provides account authentication, our database, and backend functions. It processes account details, connection records, and operational information. Our current primary database region is the eastern United States. See Supabase's privacy policy.
- Plaid connects the financial accounts you authorize and retrieves investment data. We send Plaid an opaque Nasiha account identifier to associate the connection with you. Plaid and your institution handle the connection and login flow and may process information you enter there, financial account data, and device or usage information described in Plaid's End User Privacy Policy. You can also manage eligible connections through Plaid Portal.
- Halal Terminal supplies stock-screening and market information. Our backend sends public security identifiers, such as a ticker symbol, for a stock you search for, open, or hold. These requests use Nasiha's provider account; they do not include your Nasiha user ID, brokerage account identifier or access token, holding quantity, balance, cost basis, or complete portfolio. See its privacy policy and terms.
- Apple provides Sign in with Apple if you choose it. Apple handles its authentication interface and shares the account details you authorize. See Apple's privacy information.
- Netlify and Resend provide website hosting and waitlist-email delivery, respectively. Netlify processes website requests and operational logs; Resend receives the recipient address and email content required to deliver our messages. See Netlify's privacy policy and Resend's privacy policy.
- Microsoft 365 and GoDaddy provide our support-email mailbox and its administration. They process sender addresses, message contents, attachments, and delivery information when you contact support. See the Microsoft Privacy Statement and GoDaddy privacy policy.
- Microsoft Clarity provides optional website analytics only after you allow it, as explained below. See the Microsoft Privacy Statement.
We may also disclose information when legally required, to address fraud or security incidents, to protect people's rights, or as part of a business transfer subject to applicable privacy obligations. We do not sell your personal information. The native Nasiha app does not use advertising SDKs or track you across other companies' apps or websites for advertising.
Website analytics and your choice
The marketing homepage offers Microsoft Clarity analytics. If you allow it, Clarity uses cookies, interaction events, heatmaps, and session recordings to help us understand website use and improve the page. It can process page and device information, clicks, scrolling, and network information. We do not send Clarity your Nasiha account identifier or brokerage holdings, and our waitlist form is masked for recordings.
We do not load Clarity before you allow analytics. We request analytics storage only and deny advertising storage. The privacy, support, admin, and demo pages do not load Clarity. We store your choice in this browser's local storage; it does not apply to other browsers or devices. You can change it here at any time. Declining stops future analytics on this browser; it does not automatically delete information previously received by Microsoft.
Website analytics: off until you choose.
If your browser sends Global Privacy Control or Do Not Track, optional analytics stay off even if you select Allow.
Browser privacy signals. We treat Global Privacy Control and Do Not Track signals as a choice to decline optional website analytics, including when this browser previously allowed it. Necessary hosting and security processing still occurs. When you allow Clarity without these signals, Microsoft receives the website activity described above under its own privacy policy; our consent choice denies advertising storage.
Necessary hosting, security, and delivery processing still occurs when analytics are declined. Browser settings can also limit cookies or clear locally stored choices.
Retention and deletion
- Account and connection records remain available while you use the account or connection. A successful disconnection revokes the connected Plaid Item and removes its connection credential from our active database. A successful account-deletion request revokes linked Plaid access and removes your Nasiha authentication account, associated profile, and brokerage connection records. Apple authorization is revoked through Apple confirmation, or you can explicitly choose to delete Nasiha and remove Apple authorization yourself as explained below.
- Holdings are retrieved on demand rather than retained as a portfolio history in our backend database. Shared stock-market information and screening assessments are not personal portfolio records and can remain after you delete your account.
- Waitlist records are separate from app accounts. We keep them to administer the requested waitlist and updates until you ask us to remove them or they are no longer needed for that purpose. Deleting an app account does not automatically remove a separately submitted waitlist email.
- Support, security logs, and backups may remain after active account deletion where needed to resolve a request, protect the service, comply with legal duties, or complete a backup-retention cycle. Backup and infrastructure-log lifetimes depend on the service and configuration; account deletion does not immediately erase every backup. Information retained for these limited purposes is not used to restore your access or send marketing.
We use the purpose of the information, an active support or security issue, applicable legal requirements, and provider retention settings to determine how long these remaining records are needed. Contact us for information about a specific deletion or retention request.
Your controls and requests
- Disconnect a brokerage: open More → Settings → Connected accounts, select Disconnect for the connection, and confirm. This does not close your brokerage account or sell investments.
- Delete your Nasiha account: open More → Settings → Your data → Delete account and follow the confirmation steps. If you used Sign in with Apple, confirm your Apple identity to revoke its authorization. If you cannot confirm, choose Delete without Apple confirmation and confirm deletion; you must then remove Nasiha under Sign in with Apple in your Apple Account settings or at account.apple.com. This alternative still disconnects linked Plaid accounts. Wait for completion. If the app reports an error, deletion is not confirmed; retry or contact us. See the complete deletion instructions and access-recovery help.
- Leave the waitlist: reply to a Nasiha waitlist email or email support@nasiha.app from the subscribed address and ask to stop updates and remove your waitlist record.
- Access, correct, or remove information: email support@nasiha.app. Depending on where you live, you may also have rights to a copy of your information, portability, restriction, objection, or withdrawal of consent. We may need to verify the request using your account or email and will explain any applicable limits. You may contact your local privacy regulator if you have a concern.
Withdrawing consent does not affect processing that already occurred. Information independently held by your brokerage, Apple, or Plaid is also subject to that provider's policies and request procedures. Uninstalling Nasiha alone does not delete your account or revoke a brokerage connection.
Security and device privacy
We use encrypted network connections, access controls, server-side credential handling, and encrypted storage for brokerage access tokens. No service can guarantee absolute security. Please do not send passwords, access tokens, full account numbers, or unredacted financial screenshots in support requests.
Face ID and device authentication are evaluated by iOS. Nasiha receives the authentication result and does not receive or store your biometric template. Preferences such as your chosen name, appearance, onboarding progress, and app-lock setting may be kept on your device.
International processing
Our providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws from where you live. Contact us with questions about the providers or transfer arrangements relevant to your information.
Children
Nasiha is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can investigate and remove it as appropriate.
Changes to this policy
We will post updates here and change the date above. Where required, we will give additional notice or ask for consent before materially changing how we use your information.
Let’s make it clear.
For help with your account or your information, contact our team.
support@nasiha.app