Daanish Alumni

Privacy Policy

Last updated: October 9, 2026

1. About This Policy

Daanish Alumni is a community app for alumni and current students of Daanish Schools. It offers profiles, posts, comments, shared images and PDF resources, follows, direct messages, notifications, a Help Center and community moderation. This policy explains, in plain language, what information the Android app collects, why it is needed, where it is stored, who can see it, how long it is kept, how it is protected and how you can access, correct or delete it. It applies to the app and to the services that run it. It does not apply to websites you open from links that members share. By creating an account you confirm that you have read this policy. If you do not agree with it, please do not register.

2. Who Can Use the App

The app is intended for people aged 13 and older who studied or are studying at a Daanish School. If you are under 18, please use the app with the knowledge of a parent or guardian. We do not knowingly collect personal data from children under 13; if you believe a child under 13 has registered, tell us through the Help Center and we will delete the account.

3. Information You Give Us When You Register

Registration has two parts. • Sign-in details: your email address and a password, or your Google account (we request only your email address and basic profile from Google). • Verification: you must confirm BOTH your email address, by opening a link we send, and your Pakistani mobile number, by entering a 6-digit code we send by SMS. Each email address and each mobile number can belong to one account only. The SMS is sent by Firebase Authentication on our behalf. Your account is created as soon as both are verified. There is no manual approval step, but administrators can still restrict or remove accounts that break the rules. We do not ask for, collect or store your CNIC number. Accounts created by earlier versions of the app may still hold a one-way hash and a masked form of a CNIC in their private record; these are never shown to other members and are removed when the account is deleted.

4. Your Profile

Your profile can include your name, role (alumni or student), campus, batch number, entry number, graduation year, roll number, university and study status, semester, class, field of interest, current work, a short biography and a profile photo. The app also keeps your post, follower and following counts, the date your account was created, your last-seen time and your account status, together with moderation fields such as a warning count or a restriction reason. Your campus, batch and graduation details, and your verified mobile number, cannot be changed after registration. Your name, biography, photo and the other education and work details can be edited at any time from Edit Profile.

5. Contact Details Are Private

Your email address, verified mobile number, notification settings and push-notification token are kept in a separate private record. Only you and administrators can read it; other members never see your email or phone number. Firebase security rules enforce this on the server, not just in the app.

6. Posts, Comments, Images and PDFs

We store the posts, links, comments, replies, likes, saves and follows you create, and the images and PDF files you attach. • Images are resized and compressed on your phone before they are uploaded (about 1440 pixels on the long side for posts and 512 pixels for profile photos), and location and camera details (EXIF data) are removed. • PDF files of up to 5 MB are uploaded as they are. • Images and PDFs are stored in Cloudflare R2 through our upload service. The service checks that you are signed in, that your account is active and that the file is really an image or a PDF before storing it. Each file gets a long, random address that is only shared inside the app. Posts, comments and follows are visible to signed-in members only. When you delete a post its attached files are removed; copies held in network caches expire within about an hour, and members who already opened the file may still have a copy on their own phone.

7. Direct Messages

Direct messages are text of up to 1,000 characters between two members. Message text, delivery and read status and the "typing" indicator are stored in Firebase Realtime Database; the list of conversations (participants, a short preview of the last message and its time) is stored in Cloud Firestore. Database rules allow only the two people in a conversation to read it, and the admin panel does not display message text. Messages are encrypted while they travel over the internet (HTTPS/TLS), but they are not end-to-end encrypted, which means they are stored on our service providers' servers in a form the service can process. Please do not send passwords, codes or other secrets in messages. Your online status and last-seen time are visible to other signed-in members.

8. Notifications

When someone follows you, comments on your post, replies to your comment or sends you a message, an in-app notification is saved for your account. To show a pop-up on your phone, the sender's app asks our notification service to deliver it through Firebase Cloud Messaging, using the push token stored in your private record. The notification service checks that the notification is real, recent and sent by the person named in it, delivers each one at most once and respects your notification settings. Message pop-ups never contain the text of the message — only "Name sent you a message." You can turn notification types off in Settings or in Android's app settings.

9. Reports, Help Requests and Appeals

When you report a post or comment we store the report, the reason and your user ID; reports are visible only to administrators. Help Center requests store the name, email address, optional phone number, category and description you enter, and can be sent without signing in. Appeals store your user ID and the explanation you write. Administrators also keep records of warnings and restrictions and an audit log of administrative actions, so that moderation is accountable.

10. Technical Information

Like any internet service, our providers process technical information such as your IP address, device type, operating system version and app version in order to deliver the service and protect it against abuse (for example, Google Play Integrity and Firebase App Check confirm that requests come from the genuine app). The app does not contain advertising, Google Analytics for Firebase, Crashlytics or any other analytics or tracking SDK. It does not access your contacts, location, microphone or advertising ID. Photos are chosen with Android's own photo picker, so the app only receives the pictures you select.

11. Information Kept on Your Phone

The app keeps some settings on your phone: theme, whether you have seen the introduction, your saved email for "Remember me", notification toggles, members you have muted, conversations you have hidden, cached images and timestamps used to slow down repeated sign-in, code and posting attempts. This information never leaves your phone and is deleted when you clear the app's data or uninstall it. Muting is private to your phone; the muted person is not told.

12. How We Use Information

We use information only to run the community: • create and secure accounts and verify email and phone; • prevent duplicate, fake and banned accounts; • show profiles, posts, comments and files to members; • deliver messages and notifications; • handle reports, appeals and Help Center requests; • enforce the Community Guidelines and Terms; and • keep the service working, fast and secure. We do not sell personal data, do not use it for advertising and do not build advertising profiles.

13. Service Providers and Where Data Is Stored

The app runs on these providers, who process data for us under their own terms and privacy policies: • Google Firebase — Authentication (including SMS verification), Cloud Firestore, Realtime Database, Cloud Messaging and App Check; • Google Sign-In, if you choose it; • Cloudflare — Workers and R2, which store uploaded images and PDFs, deliver push notifications and carry out account deletion. Data may be stored and processed in data centres outside your country, including in Asia, Europe and North America. We do not share personal data with anyone else except when the law requires it, or to protect the safety of members.

14. Who Can See What

• Other signed-in members: your public profile (name, photo, role, campus, batch and the education and work details you add), your posts, comments, likes counts and follows, and your online status. • Only the other person in a conversation: your direct messages. • Only you and administrators: your email address, mobile number, notification settings and push token. • Only administrators: reports, appeals, Help Center requests, warnings, restrictions and the moderation audit log. • Nobody outside the app: the app shows no content to people who are not signed in.

15. How Information Is Protected

• All traffic is encrypted with HTTPS/TLS and the app refuses unencrypted connections. • Server-side security rules decide who can read and write each record; they are tested against hundreds of attack cases. • The upload and notification service verifies your sign-in on every request, checks file types and sizes, limits how fast an account can upload or send notifications, and caps how much each account can store. • Contact details are kept in a private per-user record. • Android backup of app data is disabled, and release builds are obfuscated and checked for tampering. • Deleting your account requires you to confirm your sign-in again. No system is perfectly secure, and we cannot promise absolute security. If you notice a problem, please tell us through the Help Center.

16. How Long We Keep Information

We keep your information for as long as your account exists. When you delete your account, everything listed in section 17 is removed. We keep a small amount of information after deletion to protect the community: warnings, restrictions and the administrative audit log; reports other members made about you or your content; and Help Center requests sent without signing in. If an account was banned or suspended when it was deleted, we keep a one-way hash of its email address and of its mobile number so that the same person cannot immediately register again; the hash cannot be turned back into the email or number. Deleted data may also remain for a limited time in our providers' backups before it is overwritten.

17. Deleting Your Account

In the app, open Settings → Account Actions → Delete Account and confirm your password or Google sign-in. Deletion is permanent and cannot be undone. It removes: • your sign-in account, profile and private record; • your posts and their images and PDFs, and the comments on them; • your comments and replies on other posts; • your likes, saves and follows (other members' counts are corrected); • every conversation you took part in, for both people; • your notifications, reports, appeals and signed-in Help Center requests; and • your profile photos and all other files you uploaded. If you cannot open the app, request deletion at the account deletion page on this website (/account-deletion). An administrator will confirm that you own the account before deleting it.

18. Your Choices and Rights

You can view and edit your profile, change notification settings, mute members, hide conversations, report content, submit an appeal and delete your account at any time from inside the app. You may also ask us for a copy of your personal data, ask us to correct or delete it, or object to how we use it, by contacting us (section 20). We will answer within 30 days. The rights available to you depend on the law that applies where you live.

19. Cookies and Tracking

The Android app does not use cookies, web trackers, advertising identifiers or embedded web pages. Links you open are handled by your browser and are governed by the website you visit.

20. Changes to This Policy and How to Contact Us

We will update this policy whenever the app's data practices change and revise the date at the top. For important changes we will also show a notice in the app. For privacy questions or requests, use the in-app Help Center. Please never send a password or a verification code to anyone, including us.