NisabifyTrack and purify
Legal

Privacy Policy

Effective October 4, 2026. Covers the Nisabify website at nisabify.com and the Nisabify apps for iPhone, iPad and Android.

The short version

1. Who we are

Nisabify is a personal-finance app for Muslims in the United States. It works out an estimate of your zakat under the school of fiqh you choose, sends you to a charity’s own website when you want to give, and keeps a record of your giving for your own use and for tax season.

In this policy, “Nisabify”, “we” and “us” mean the operator of the Nisabify website at nisabify.com and the Nisabify apps (app ID tech.mizan.app). For any privacy question or request, email info@mizanfintech.app.

Nisabify was called Mizan until October 4, 2026. Only the name changed: it is the same service, run by the same operator, and your account and records are the same.

2. What we collect

Every way of using Nisabify needs an account, so what we hold is the same whether you use the website or an app, apart from the differences noted below.

Using the website

Your account

You can create an account with an email address and a password, on the website and in both apps. You can also sign in with Google on the website and in both apps, and with Apple on iPhone and iPad only. Each option appears only once it has been switched on for Nisabify. Your account is identified by a random ID.

The confirmation and password-reset links open pages on nisabify.com (/auth/confirmed/ and /auth/reset/). Those pages save nothing in your browser. Each takes the sign-in details the link carries off the address bar as soon as it opens, and ends that sign-in once it has done its job. Saving a new password on the reset page also signs your account out everywhere else.

Supabase stores your email address and what it needs to check your password, if you use them, and the identity details your sign-in provider shares, along with the records needed to keep you signed in. If Nisabify has your email address, it shows it to you in Settings as “Signed in as”. Supabase also records, with each signed-in session, the IP address and the user-agent string of the browser or app that signed in. These are erased when you delete your account.

Your age

Nisabify is for adults 18 and over. Whichever way you sign in, the first setup step asks your date of birth, and nothing else in Nisabify is shown until it is answered.

Your school of fiqh (religious-belief information)

To work out your zakat and track your zakat year, Nisabify stores which school of fiqh you follow: Ḥanafī, Mālikī, Shāfiʿī or Ḥanbalī. This is information about your religious belief, and several US state privacy laws treat it as sensitive.

Financial information you enter

Nisabify stores on its servers what you enter:

Nisabify can see who you gave to. The recipient names in your giving record are stored in readable form. Nisabify can read them, and a valid legal order could require us to disclose them.

Removing an item is not the same as erasing it. A removed account, asset or debt is archived and keeps its value history. A voided gift stays on file, marked void. A changed balance is saved as a new entry beside the old one. Only deleting your account erases these.

Accounts you connect through Plaid

Connecting an account is optional. It is offered on the website and in the iPhone, iPad and Android apps, for US institutions and balances in US dollars. The connection is made by Plaid. It cannot connect a real account yet: for now it reaches only Plaid’s test institutions. Until that changes, Nisabify tells you so before it opens Plaid’s page, and what connects is Plaid’s sample bank, not yours. In test mode Nisabify keeps nothing from the sample bank: it is read once to show that the connection works, removed at Plaid straight away, and never added to your wealth. What is kept is your agreement and a record of the attempt. The rest of this section describes a real connection, for when that opens.

What stays on your device

When you email us

If you write to info@mizanfintech.app, we receive your email address and whatever you include in your message. Please never send bank logins, passwords or account numbers.

If you join a waitlist

If you join the Plus or Family waitlist on the website, we keep your email address, the plan you chose and when you joined. Nothing else: no name, no account, and it is not linked to an account if you have one. We use it only to email you about that plan’s launch and its founding price. To be removed, email info@mizanfintech.app.

What we do not collect

3. How we use it

We do not use your information for advertising, and we do not build profiles about you. The only marketing email we send is the launch email to people who joined a waitlist. The figures Nisabify shows are estimates for you to act on; Nisabify makes no decisions about you.

4. What we do not do

5. Who processes it

These companies process information for us so that Nisabify can run:

Supabase
Our database, sign-in and server functions, in the United States (US East region). Everything stored with your account is held here. Like our other providers, Supabase keeps technical logs of requests, which can include your IP address.
Plaid
Connecting accounts, only if you use it. See Accounts you connect through Plaid. What you enter on Plaid’s page, and what Plaid collects from your institution, is handled by Plaid under its own End User Privacy Policy.
Apple and Google
Whichever one you choose to sign in with: Google on the website and in both apps, Apple on iPhone and iPad only.
Cloudflare
Hosts the website and receives standard request information, such as your IP address and browser type, when your browser loads it. Your browser may also send Cloudflare reports about network errors.
Google Workspace
Sends Nisabify’s account emails (the link that confirms your address, and password-reset links) from info@mizanfintech.app, and delivers email sent to that address.

Charity websites, the IRS and ProPublica receive a visit only when you open one of their links, and they receive only what any website receives from a visitor.

We may also disclose information when the law requires it, for example in response to a valid legal order. If Nisabify is ever transferred to a new owner, your information would move only under this policy, and we would tell you before any different terms applied.

6. How long we keep it

7. Deleting your account

You can delete your account yourself while signed in:

When you confirm, Nisabify first asks Plaid to end every connection you made. If a connection could not be ended, email us and we will have it closed. Nisabify then erases your sign-in record (including your email address and password, if you used them) and everything attached to your account: your profile and school, the record that you confirmed your age, settings, agreements, accounts, assets, debts, balance history, zakat years, gifts and voids, calculations, and the records of your connected accounts, including the stored access tokens. This cannot be undone. The website and the apps then sign you out and remove the session from your device, and the website also removes its copy of your record from that browser, keeping only your theme choice.

What remains afterwards is listed under How long we keep it: the deletion record, Plaid’s records if you connected an account, a copy in any other browser where you were signed in until it is cleared there, service providers’ logs under their own retention rules, and backups until they expire. Removing the app from your device does not delete your account. If you signed in with Apple, Nisabify does not yet withdraw its access at Apple when you delete your account; you can remove Nisabify from the list of apps using Sign in with Apple in your Apple ID settings.

If you cannot sign in, or the deletion does not finish, email info@mizanfintech.app and we will delete the account for you after confirming that it is yours. If you signed in with Apple, Nisabify may hold no email address for you, so we may not be able to confirm the account from an email alone; delete it from inside the app whenever you can.

8. Security

Your data is not end-to-end encrypted: Nisabify can access what is stored on its servers. No system is perfectly secure. If you find a security problem, please tell us at info@mizanfintech.app.

9. Children

Nisabify is for adults: our Terms require you to be at least 18 to use it. Nisabify is not directed to children, and we do not knowingly collect personal information from children under 13. Once you have signed in, the first thing Nisabify asks is your date of birth. If your phone or browser finds you are under 18, it does not send the date, and Nisabify does not let you continue: it offers only to sign you out or to delete the account you signed in with. See Your age. If you believe someone under 18 has given us personal information, email us and we will delete it.

10. Your rights

Things you can do yourself

US state privacy rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with privacy laws may have the right to:

We honour these requests from anyone in the United States, whether or not their state’s law applies to us. Email info@mizanfintech.app. We may ask for information to confirm the request comes from you, and we will not ask for more than we need. You may use an authorized agent, and we may ask for proof that the agent acts for you. We will respond within 45 days. If we need longer, we will tell you why, and we will not take more than another 45 days. If we turn down your request, you can ask us to reconsider by replying to our answer; if you are still unsatisfied, you can contact your state attorney general.

Because Nisabify does not sell or share personal information or track you across websites, it behaves the same whether or not your browser sends a Global Privacy Control or Do Not Track signal. We do not disclose personal information to third parties for their own direct marketing.

Categories of personal information

Identifiers
Your account’s random ID; your email address, if you sign up with it or your sign-in provider shares it; and your sign-in identity. From you, and from Google or Apple if you sign in with them. Processed by Supabase; by Google Workspace for the emails Nisabify sends you; and by Plaid, which receives your account’s random ID if you connect an account.
Account log-in details
Your password, if you sign in with an email address. From you. Processed by Supabase, only to check it when you choose it and when you sign in.
Age
The date and time you confirmed you are 18 or over. Not your date of birth, which is not stored. From you. Processed by Supabase.
Sensitive personal information: religious beliefs
Your school of fiqh, and whether your gifts were zakat or sadaqah. From you, after you agree. Processed by Supabase.
Financial information
The accounts, balances, assets, debts, gifts and calculations described above. From you, and from Plaid if you connect an account. Processed by Supabase, and by Plaid for connected accounts.
Internet and device information
Your browser’s user-agent string, stored with the agreements you give on the website; the IP address and user-agent string Supabase records with each signed-in session; and the IP address and browser details our providers receive when you connect. Processed by Supabase and Cloudflare.

None of these categories is sold or shared for advertising.

11. Changes to this policy

If we change this policy, we will post the new version here with a new effective date. If a change affects how we use information you have already given us, we will tell you in the app or on the website before it takes effect, and ask for your agreement again where the law requires it.

12. Contact us

For any question about this policy or your information, or to make a request, email info@mizanfintech.app.