Privacy Policy
The short version
- Nisabify always needs an account, on the website and in the iPhone, iPad and Android apps. You sign in with an email address and a password, with Google once it is switched on for Nisabify, or, on iPhone and iPad only, with Apple.
- Your wealth, your giving record and your school of fiqh are stored on Nisabify’s servers in the United States.
- Nisabify is for adults 18 and over. We ask your date of birth once, to check that, and do not store it. We record only that you confirmed you are 18 or over.
- Your school of fiqh is information about your religious belief. We store it only after you agree, and we use it only to work out your zakat.
- Your data is not end-to-end encrypted. Nisabify can read what you store, including the names of the recipients you record gifts to.
- No ads, no analytics, no tracking. We do not sell your personal information or share it for advertising.
- You can delete your account from inside the website or either app at any time, or email us and we will delete it for you.
1. Who we are
Nisabify is a personal-finance app for Muslims in the United States. It works out an estimate of your zakat under the school of fiqh you choose, sends you to a charity’s own website when you want to give, and keeps a record of your giving for your own use and for tax season.
In this policy, “Nisabify”, “we” and “us” mean the operator of the Nisabify website at nisabify.com and the Nisabify apps (app ID tech.mizan.app). For any privacy question or request, email info@mizanfintech.app.
Nisabify was called Mizan until October 4, 2026. Only the name changed: it is the same service, run by the same operator, and your account and records are the same.
2. What we collect
Every way of using Nisabify needs an account, so what we hold is the same whether you use the website or an app, apart from the differences noted below.
Using the website
- The website at nisabify.com/app/ opens with a sign-in page, and nothing else in the app is shown until you sign in. To show that page, your browser asks our authentication provider, Supabase, which sign-in options are available.
- Your browser also keeps a copy of the website’s own files, so the site can still open if you lose your connection. Answers from Nisabify’s servers are never kept in that copy.
- Nisabify’s own code sets no cookies and contains no analytics.
- As with any website, our hosting provider receives technical information when your browser loads a page, such as your IP address and browser type. See Who processes it.
- What the website keeps in your browser, and when it is removed, is described under What stays on your device.
Your account
You can create an account with an email address and a password, on the website and in both apps. You can also sign in with Google on the website and in both apps, and with Apple on iPhone and iPad only. Each option appears only once it has been switched on for Nisabify. Your account is identified by a random ID.
- Email and password: Nisabify emails a link to your address, from info@mizanfintech.app, and you confirm the address before you can sign in. A password must be at least 8 characters, and Supabase refuses a new password that appears on a list of passwords known to have leaked. Your password goes over an encrypted connection to Supabase, which checks it when you sign in; Nisabify’s website and apps do not save it on your device. If you forget it, you can ask for a reset link, sent to the same address.
- Google on the website, iPhone and iPad: Nisabify sends you to Supabase and on to Google’s own sign-in page (on iPhone and iPad, inside a browser sheet). Google may share your email address, your name and your profile picture.
- Google on Android: Google’s sign-in sheet on your phone gives Nisabify a Google sign-in token, which normally includes your email address and may include your name and profile picture.
- Apple, on iPhone and iPad only: Nisabify uses Sign in with Apple and asks Apple for neither your name nor your email address.
The confirmation and password-reset links open pages on nisabify.com (/auth/confirmed/ and /auth/reset/). Those pages save nothing in your browser. Each takes the sign-in details the link carries off the address bar as soon as it opens, and ends that sign-in once it has done its job. Saving a new password on the reset page also signs your account out everywhere else.
Supabase stores your email address and what it needs to check your password, if you use them, and the identity details your sign-in provider shares, along with the records needed to keep you signed in. If Nisabify has your email address, it shows it to you in Settings as “Signed in as”. Supabase also records, with each signed-in session, the IP address and the user-agent string of the browser or app that signed in. These are erased when you delete your account.
Your age
Nisabify is for adults 18 and over. Whichever way you sign in, the first setup step asks your date of birth, and nothing else in Nisabify is shown until it is answered.
- Your phone or browser checks the date first. If it finds you are under 18, the date is not sent anywhere, and Nisabify offers only to sign you out or to delete your account.
- If you are 18 or over, the date is sent once, over an encrypted connection, to Nisabify’s server, which checks it again and records only the date and time you confirmed you are 18 or over.
- Your date of birth itself is not stored. No field in Nisabify’s database holds it, Nisabify’s website and apps do not keep it on your device, and Nisabify’s code does not write it to any log.
Your school of fiqh (religious-belief information)
To work out your zakat and track your zakat year, Nisabify stores which school of fiqh you follow: Ḥanafī, Mālikī, Shāfiʿī or Ḥanbalī. This is information about your religious belief, and several US state privacy laws treat it as sensitive.
- We ask first. On the website and in the iPhone, iPad and Android apps, the setup step where you choose your school asks for your agreement, and you cannot finish setup without ticking it. On the website, if your browser holds data entered before Nisabify had accounts, Nisabify shows you what would be uploaded and asks you to agree before any of it leaves the browser. Nisabify’s database refuses to save your chosen school to your profile, or to mark your setup complete, unless your agreement is on record. When an account is first created, this field holds a default value; that default is a placeholder, not a record of your choice.
- Where it appears. Your school is stored on your profile, on each zakat year, and in each saved calculation. Your giving record also shows whether each gift was zakat or sadaqah, which says something about your religious practice.
- How it is used. Only to decide which rulings apply to your wealth. Nisabify’s code does not send it to analytics (there are none) and does not write it to logs. It travels only inside encrypted requests, never in a web address.
- The record of your agreement. We keep a record of each agreement: what it was for, which version of the wording it refers to, whether you agreed, and the date. In the apps, changing your school in Settings adds a new agreement record under the wording you accepted during setup. On the website it also stores your browser’s user-agent string (the text that names your browser and operating system).
- Withdrawing. Today, you withdraw this agreement by deleting your account, which erases your school along with everything else.
Financial information you enter
Nisabify stores on its servers what you enter:
- Accounts: the name you give each one, the institution, the type (checking, savings, brokerage, retirement or crypto), details such as Roth or Traditional, and its balances over time.
- Other assets: the name you give each one, its kind (gold, silver, cash, business inventory, money owed to you, or other), its weight for gold and silver or its value over time for the rest, and whether an item is for personal use.
- Debts: a name, when each is due, and the amount.
- Gifts you record: the amount, the date, whether it was zakat or sadaqah, and the recipient’s name if you type one. That is usually an organization, but it can be a person. The apps also store which listed charity it was. If you void a gift in the apps, the reason you type is stored too.
- Settings and zakat year: your nisab standard, lunar or solar year, how retirement accounts count, the gold and silver prices you set, and the dates your zakat years start and close.
- Calculations: each time Nisabify works out your figure on its servers, it saves a permanent record of the result together with a copy of the inputs: account names, institutions and balances, assets, debts, the amounts and dates of your gifts, and your settings, including your school. In the apps this happens each time the app works out your figure. On the website it happens when you press Record this figure.
Nisabify can see who you gave to. The recipient names in your giving record are stored in readable form. Nisabify can read them, and a valid legal order could require us to disclose them.
Removing an item is not the same as erasing it. A removed account, asset or debt is archived and keeps its value history. A voided gift stays on file, marked void. A changed balance is saved as a new entry beside the old one. Only deleting your account erases these.
Accounts you connect through Plaid
Connecting an account is optional. It is offered on the website and in the iPhone, iPad and Android apps, for US institutions and balances in US dollars. The connection is made by Plaid. It cannot connect a real account yet: for now it reaches only Plaid’s test institutions. Until that changes, Nisabify tells you so before it opens Plaid’s page, and what connects is Plaid’s sample bank, not yours. In test mode Nisabify keeps nothing from the sample bank: it is read once to show that the connection works, removed at Plaid straight away, and never added to your wealth. What is kept is your agreement and a record of the attempt. The rest of this section describes a real connection, for when that opens.
- Before anything connects, Nisabify shows what it will read and asks you to agree. It records your agreement, the version of the wording and the date.
- You then sign in to your bank, card, loan or investment provider on a page run by Plaid. On the website your browser leaves Nisabify for that page and returns afterwards; Nisabify’s own pages load no code from Plaid. Your username and password go to Plaid, never to Nisabify.
- What Nisabify reads: your account balances; the holdings in your investment and retirement accounts; and your debts, meaning what you owe on credit cards and loans and the date the next payment is due.
- Transactions: the connection includes permission for your transactions. Nisabify does not read them yet. This policy will say so before that changes.
- Nisabify cannot move money. The connection is read-only. Nisabify does not ask for the permissions that payments, transfers or withdrawals need.
- What Nisabify keeps. For each institution you connect: its name, Plaid’s references for the connection and its accounts, when it was connected and last read, whether it is working, and the access token Plaid issues for it. That token is stored encrypted on Nisabify’s servers and is never sent to your browser or your phone. For each account: its name, its type, and its value in US dollars each time it is read. Nisabify values an investment or retirement account from its holdings and keeps the total. A credit card or a loan is kept as a debt, never as something you own, with the amount owed, its kind and the next payment date. An overdrawn bank account, or an investment account worth less than nothing, is kept as a debt due now. An account that is not in US dollars is skipped. Nisabify also keeps a record of each time you start connecting or reconnecting: when, whether from the website, the iPhone and iPad app or the Android app, and what it came to.
- What Nisabify sends Plaid: your Nisabify account’s random ID, not your name or email address. Plaid collects and keeps its own information about you and your accounts under its End User Privacy Policy.
- When it is read: when you connect; when you open your Wealth page and the last reading is more than 12 hours old; when you choose Update now on the website; and when Plaid tells Nisabify that something changed or that a connection needs your attention.
- Disconnecting: each connected institution has a Disconnect button on the Wealth page. It ends the connection at Plaid and removes that institution’s accounts and debts from your figures. They are archived with their value history, like anything else you remove, until you delete your account. Deleting your account disconnects every institution first.
What stays on your device
- Website: while you are signed in, your browser’s local storage, which Nisabify does not encrypt, holds a working copy of your whole record (accounts, balances, debts, gifts, your school and your settings) and a second copy of what your account last held, labelled with your account’s random ID. It also holds your sign-in session: the tokens, and the account details Supabase returns when you sign in, including your email address and any name, profile-picture link or account identifier your sign-in provider shared. Signing out, or deleting your account, removes all of this from that browser and keeps only your choice of light or dark theme. Settings → Your data → Clear everything signs you out and removes Nisabify’s data from the browser, the theme included. Copies can stay behind in four cases: in another browser where you were signed in, until you sign out there; in a browser whose session ended without you signing out (for example, because it expired), where the copy is kept so that changes not yet saved can be sent when you sign back in; data entered in a browser before Nisabify had accounts, until you upload it to your account; and a copy the website cannot read, because a newer version of Nisabify wrote it or it is damaged, which signing out and deleting your account leave in place. Clear everything, which you reach while signed in, or clearing that browser’s site data removes any of them. While you sign in with Google, the tab also keeps a one-time security code, which is removed when you come back and which the browser discards when the tab is closed. While you connect an account, the browser’s local storage also keeps a note of the connection you started: a random reference, your account’s random ID, the time, and the institution’s name if you are reconnecting one. It holds nothing from your bank. It is removed when Nisabify learns what the connection came to or when you sign out, and is ignored after six hours.
- iPhone and iPad: the app keeps your sign-in session (tokens, your account ID and your email address, if Nisabify has one) in the iOS Keychain. The item stays on this device: it is not synced to iCloud and does not move to a new device. Deleting the app does not necessarily remove this item; sign out first if you want it gone. The app does not write your financial data to files of its own; it loads it from your account. iOS may keep a temporary cache of recent responses from Nisabify’s servers inside the app’s own storage, which is removed when you delete the app.
- Android: the app keeps your sign-in session (tokens, your account ID and your email address, if Nisabify has one) in encrypted storage. Cloud backup of the app’s data is turned off. The app does not save your financial data to its own storage.
When you email us
If you write to info@mizanfintech.app, we receive your email address and whatever you include in your message. Please never send bank logins, passwords or account numbers.
If you join a waitlist
If you join the Plus or Family waitlist on the website, we keep your email address, the plan you chose and when you joined. Nothing else: no name, no account, and it is not linked to an account if you have one. We use it only to email you about that plan’s launch and its founding price. To be removed, email info@mizanfintech.app.
What we do not collect
- Your location, contacts, photos, or access to your camera or microphone.
- Advertising identifiers, device identifiers or push-notification tokens.
- Your bank transactions, full account numbers or bank login.
- Your date of birth: it is checked and not stored. See Your age.
3. How we use it
- To work out your zakat estimate under the school and settings you chose, and to show how each figure was reached.
- To track your zakat year, keep your giving record, and keep your data in step across your devices.
- To show the balances, holdings and debts of accounts you connected.
- To keep a fixed record of each calculation, so a figure you acted on can be reproduced later.
- To record the agreements you give us.
- To check that you are 18 or over, and to record that you confirmed it.
- To sign you in, keep your account secure and run the service.
- To send you emails about your account: the link that confirms your address, and a password-reset link when you ask for one.
- To answer you when you contact us.
- If you joined a waitlist, to email you about that plan’s launch.
- To comply with the law, including a valid legal order.
We do not use your information for advertising, and we do not build profiles about you. The only marketing email we send is the launch email to people who joined a waitlist. The figures Nisabify shows are estimates for you to act on; Nisabify makes no decisions about you.
4. What we do not do
- We do not sell your personal information, and we do not share it for targeted advertising.
- No ads, analytics or tracking. Nisabify’s website and apps contain no advertising, analytics, tracking or crash-reporting code, and send nothing to advertising networks or data brokers. Nisabify’s pages load no outside code. To connect an account your browser goes to a page run by Plaid, and Plaid handles what you enter there under its own privacy policy.
- We never handle your money. When you give, Nisabify opens the charity’s own website. The charity takes the payment and issues your receipt. Nisabify adds nothing to the link: no amount, no ID, and on the website no referring address. Recording a gift only saves your own note of it in Nisabify.
- We cannot move money from your bank. Nisabify does not request the permission that would allow it.
5. Who processes it
These companies process information for us so that Nisabify can run:
- Supabase
- Our database, sign-in and server functions, in the United States (US East region). Everything stored with your account is held here. Like our other providers, Supabase keeps technical logs of requests, which can include your IP address.
- Plaid
- Connecting accounts, only if you use it. See Accounts you connect through Plaid. What you enter on Plaid’s page, and what Plaid collects from your institution, is handled by Plaid under its own End User Privacy Policy.
- Apple and Google
- Whichever one you choose to sign in with: Google on the website and in both apps, Apple on iPhone and iPad only.
- Cloudflare
- Hosts the website and receives standard request information, such as your IP address and browser type, when your browser loads it. Your browser may also send Cloudflare reports about network errors.
- Google Workspace
- Sends Nisabify’s account emails (the link that confirms your address, and password-reset links) from info@mizanfintech.app, and delivers email sent to that address.
Charity websites, the IRS and ProPublica receive a visit only when you open one of their links, and they receive only what any website receives from a visitor.
We may also disclose information when the law requires it, for example in response to a valid legal order. If Nisabify is ever transferred to a new owner, your information would move only under this policy, and we would tell you before any different terms applied.
6. How long we keep it
- Your account data (sign-in details, profile, the record that you confirmed you are 18 or over, school, settings, agreements, accounts, assets, debts, balance history, zakat years, gifts and calculations) is kept until you delete your account. Nisabify does not yet delete older records automatically. If we introduce time limits, we will update this policy first.
- The copy in your browser is removed when you sign out there, delete your account there, or use Clear everything. The cases where a copy stays behind are listed under What stays on your device.
- After you delete your account, we keep a record that the deletion was requested and completed: your account’s random ID and the dates and, only if a connection could not be ended at Plaid, Plaid’s reference for that connection, kept so that it can be closed. It contains no name, email address or financial data. We keep it to show that the deletion happened.
- Plaid’s records (only if you connected an account) are kept by Plaid under its own privacy policy. Disconnecting an institution, or deleting your Nisabify account, ends Nisabify’s access to it; it does not delete what Plaid holds. Plaid’s privacy policy says how to ask Plaid for that.
- Backups. Deleted data can remain in our database provider’s backups until those backups expire. We have not yet confirmed the length of that window. We will state it here once we have.
- Service providers’ logs are kept under each provider’s own retention rules.
- Emails you send us are kept as long as we need them to deal with your request.
- Waitlist sign-ups are kept until the plan launches and we have emailed you, or until you ask us to remove them, whichever comes first.
7. Deleting your account
You can delete your account yourself while signed in:
- Website: Settings → Your account → Delete account. If the website shows an error, email us and we will delete the account for you.
- iPhone and iPad: Settings → Your account → Delete account.
- Android: Settings → Your account → Delete account.
- At the age question: if Nisabify stops you because you are under 18, it offers Delete my account on the website and in both apps.
When you confirm, Nisabify first asks Plaid to end every connection you made. If a connection could not be ended, email us and we will have it closed. Nisabify then erases your sign-in record (including your email address and password, if you used them) and everything attached to your account: your profile and school, the record that you confirmed your age, settings, agreements, accounts, assets, debts, balance history, zakat years, gifts and voids, calculations, and the records of your connected accounts, including the stored access tokens. This cannot be undone. The website and the apps then sign you out and remove the session from your device, and the website also removes its copy of your record from that browser, keeping only your theme choice.
What remains afterwards is listed under How long we keep it: the deletion record, Plaid’s records if you connected an account, a copy in any other browser where you were signed in until it is cleared there, service providers’ logs under their own retention rules, and backups until they expire. Removing the app from your device does not delete your account. If you signed in with Apple, Nisabify does not yet withdraw its access at Apple when you delete your account; you can remove Nisabify from the list of apps using Sign in with Apple in your Apple ID settings.
If you cannot sign in, or the deletion does not finish, email info@mizanfintech.app and we will delete the account for you after confirming that it is yours. If you signed in with Apple, Nisabify may hold no email address for you, so we may not be able to confirm the account from an email alone; delete it from inside the app whenever you can.
8. Security
- Every connection the website and the apps make to Nisabify’s servers is encrypted (HTTPS).
- The database lets each person read and change only their own records. Internal records are not reachable from the internet, and Nisabify’s server functions refuse any request without a valid sign-in. There are two exceptions: the waitlist form on the home page, and the notices Plaid sends about a connection, which are accepted only with Plaid’s signature.
- Gifts, agreements and calculations cannot be edited after they are saved. Mistakes are corrected by adding a new entry, so your record cannot be changed silently.
- The iPhone and iPad app keeps your session in the iOS Keychain. The Android app keeps it in encrypted storage. The website keeps it in your browser’s local storage, which Nisabify does not encrypt, so protect the device, and sign out when you finish on a shared computer.
- Your bank login never reaches Nisabify, and Nisabify holds no permission to move money.
Your data is not end-to-end encrypted: Nisabify can access what is stored on its servers. No system is perfectly secure. If you find a security problem, please tell us at info@mizanfintech.app.
9. Children
Nisabify is for adults: our Terms require you to be at least 18 to use it. Nisabify is not directed to children, and we do not knowingly collect personal information from children under 13. Once you have signed in, the first thing Nisabify asks is your date of birth. If your phone or browser finds you are under 18, it does not send the date, and Nisabify does not let you continue: it offers only to sign you out or to delete the account you signed in with. See Your age. If you believe someone under 18 has given us personal information, email us and we will delete it.
10. Your rights
Things you can do yourself
- Get a copy. On the website, Export JSON (Settings → Your data) downloads the copy of your record held in that browser, and Export CSV (Records) downloads your giving record. In the apps, Export CSV on the Records tab shares your giving record. For a copy of everything on your account, including calculations and agreement records, email us.
- Correct it. Edit your accounts, assets, debts and settings in the app. A gift is corrected by voiding it and recording it again.
- Delete it. Delete your account as described in Deleting your account.
- Withdraw your agreement to Nisabify storing your school by deleting your account.
- Disconnect an institution with its Disconnect button on the Wealth page. Deleting your account disconnects every institution. You can also email us.
US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with privacy laws may have the right to:
- know what personal information we collect, use and disclose, and get a copy of it;
- correct information that is wrong;
- delete it;
- receive it in a portable format;
- opt out of the sale or sharing of personal information, targeted advertising and profiling (we do none of these, so there is nothing to opt out of);
- limit the use of sensitive personal information (we use your school of fiqh only to provide the service you asked for); and
- not be treated differently for using these rights.
We honour these requests from anyone in the United States, whether or not their state’s law applies to us. Email info@mizanfintech.app. We may ask for information to confirm the request comes from you, and we will not ask for more than we need. You may use an authorized agent, and we may ask for proof that the agent acts for you. We will respond within 45 days. If we need longer, we will tell you why, and we will not take more than another 45 days. If we turn down your request, you can ask us to reconsider by replying to our answer; if you are still unsatisfied, you can contact your state attorney general.
Because Nisabify does not sell or share personal information or track you across websites, it behaves the same whether or not your browser sends a Global Privacy Control or Do Not Track signal. We do not disclose personal information to third parties for their own direct marketing.
Categories of personal information
- Identifiers
- Your account’s random ID; your email address, if you sign up with it or your sign-in provider shares it; and your sign-in identity. From you, and from Google or Apple if you sign in with them. Processed by Supabase; by Google Workspace for the emails Nisabify sends you; and by Plaid, which receives your account’s random ID if you connect an account.
- Account log-in details
- Your password, if you sign in with an email address. From you. Processed by Supabase, only to check it when you choose it and when you sign in.
- Age
- The date and time you confirmed you are 18 or over. Not your date of birth, which is not stored. From you. Processed by Supabase.
- Sensitive personal information: religious beliefs
- Your school of fiqh, and whether your gifts were zakat or sadaqah. From you, after you agree. Processed by Supabase.
- Financial information
- The accounts, balances, assets, debts, gifts and calculations described above. From you, and from Plaid if you connect an account. Processed by Supabase, and by Plaid for connected accounts.
- Internet and device information
- Your browser’s user-agent string, stored with the agreements you give on the website; the IP address and user-agent string Supabase records with each signed-in session; and the IP address and browser details our providers receive when you connect. Processed by Supabase and Cloudflare.
None of these categories is sold or shared for advertising.
11. Changes to this policy
If we change this policy, we will post the new version here with a new effective date. If a change affects how we use information you have already given us, we will tell you in the app or on the website before it takes effect, and ask for your agreement again where the law requires it.
12. Contact us
For any question about this policy or your information, or to make a request, email info@mizanfintech.app.