Privacy Policy
Effective 15 August 2026 · Last updated 16 August 2026
SunniHub is a network for the Ahle Sunnat Wal Jamaat community. This notice says what we collect, why we collect it, who else ever sees it, how long we keep it, and how you take it back. It describes what the platform actually does — not what it might one day do.
What we collect
What you give us
- Your Google account. Signing in is the only way to join, and when you do, Google tells us three things: a permanent identifier for your account, your email address, and your name and profile picture. Nothing else. We never see your Google password, and we cannot read anything else in your Google account — not your contacts, not your mail, not your files.
- Your email address is kept so we can reach you about your account. It is never shown to other members and is never used to advertise to you. Your name and picture become the starting point for your profile, and you can change or remove either straight away.
- A password, only if you add one. You may set one in your settings so you can still get in if you lose access to your Google account. It is stored by Google’s Firebase service against the same account — never by us. We cannot read it, and there is no password of ours to leak.
- Your profile. Display name, handle, role (Mufti, Aalim, Hafiz-e-Quran, Talabah or Community Member), institution, credentials, specialisations, languages, location, country, headline and website. Every field except your name and handle is optional.
- What you post. Text, images, audio recordings, polls, event announcements, comments, reactions, saved items and the folders you file them in — and the questions you send to the Darul Ifta.
- Verification applications. If you apply for the verified mark, what you submit in support of it and the moderator’s decision.
- Reports you file. About a post, a comment or a member, so a moderator can act on them.
What the platform records as you use it
- Sessions. One record per signed-in device, so you can see your own devices and end any of them. It holds the browser and device description, when it was last used, and a hash of the session secret — never the secret itself.
- Post views. That a post was seen, and by whom, so an author can see how their writing travelled. Counted once per person per post.
- A record of every change to your email address — the old value, the new one, and when. You cannot change it here: it comes from your Google account. This exists because it can therefore change without anyone telling you, and you deserve a date rather than a mystery.
- A sign-in record. That a sign-in happened, when, and from which network address. It holds no credential of any kind — only the fact that the check happened, which is what stops the same sign-in being replayed. It is deleted automatically after about ninety minutes.
- Rate-limit counters. Short-lived counts of requests, to stop abuse of sign-in and posting.
What we do not collect
No advertising identifiers. No third-party analytics or tracking scripts. No location beyond the country and city you choose to put on your profile. No contact-list upload. No phone number — we do not ask for one and there is nowhere to put one. We never see your Google password, and the only thing Google shares with us is the small profile described above.
Why we collect it
Each item above exists for one of four reasons, and nothing is collected for a reason that is not on this list:
- To let you in and keep the account yours — your Google identity, the optional password you may add, and your sessions.
- To provide what the platform is for — your profile, your posts, your connections, your saved items.
- To keep the community safe — reports, blocks, mutes, moderation decisions and verification.
- To keep the service working — rate limits, delivery receipts and error records.
We do not sell your data, we do not share it with advertisers, and we do not show advertising of any kind. There is no interest-based advertising on SunniHub and there will not be.
What is public, and what is not
Public: your display name, handle, profile picture, role, institution and other profile fields you fill in, and anything you publish — posts, comments, reactions, and the circles and hashtags you file them under. A post you share by link can be read by anyone holding that link, including people without an account.
Not public: your email address, your saved items and folders, your drafts, your blocks and mutes, the questions you send to the Darul Ifta, your sessions, and your follower, following and connection lists — those three are visible to you alone.
How long we keep it
- Sign-in records are kept for about ninety minutes, long enough to stop a sign-in being replayed, and then deleted automatically.
- Sessions end when you sign out, when you end them from your device list, or when they expire.
- Your account and what you posted are kept until you delete them.
- A released handle is reserved for 30 days after you change it, and the record that it once belonged to you outlives the change. This is deliberate: on a network where a scholar’s name carries weight, a freed handle is a ready-made disguise.
- Moderation records — a report and the decision made on it — are kept after the matter is closed, so a pattern of behaviour remains visible to moderators.
Your rights, and how to use them
Under India’s Digital Personal Data Protection Act, 2023, and as a matter of how this platform is built, you can do each of these yourself from within your account:
- See and correct what we hold. Your profile is editable at any time.
- Take a copy. Settings → your account → export. You receive everything you wrote as plain JSON: your account, posts, comments, votes, saved items, endorsements and uploads. It deliberately leaves out other people’s words and names, because those are not yours to take.
- Delete your account. Settings → your account → delete. This removes your profile, posts, comments, reactions, votes, saved items, notifications and uploaded files.
- End a session. Any signed-in device can be signed out on its own, from your device list.
What survives deletion, and why. A comment of yours that somebody has replied to cannot simply vanish without taking their reply with it, so its words are erased and your name detached — the empty place in the thread remains. The record that your handle once existed is kept for the impersonation reason above. Nothing else is retained.
Deletion is immediate and cannot be undone. Removing your account here does not touch your Google account. If you cannot reach your account, write to us at the address below from the email address on it and we will act on the request.
How it is protected
No password is stored here, which removes an entire category of risk: no password database of ours to breach, and no reset links of ours to forge. If you add a password, Google holds it. Session secrets are stored only as a SHA-256 hash, so reading our database does not yield a usable credential, and every refresh rotates the session — a copied one is detected and the whole device is signed out. What we receive from Google is a signed statement, which we check against Google’s own keys, accept exactly once, and refuse if the sign-in behind it is more than a few minutes old. Deleting your account requires you to sign in again first, so a stolen session cannot destroy it. Traffic is encrypted in transit.
No system is perfect. If we ever discover a breach affecting your personal data, we will tell you and the Data Protection Board as the law requires.
Age
SunniHub is intended for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will remove it.
Changes
If this notice changes in a way that affects you, we will say so on the platform before the change takes effect, and the date at the top will move. Continuing to use SunniHub after that means the updated notice applies.
Contact
Questions about this notice, or about your data, go to privacy@sunnihub.com. We answer requests about your own data within 30 days.
If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
