Last updated: Jul 22, 2026
Privacy Policy
Araby has no accounts and no server of ours. Everything you learn — your name, your answers, your progress — is stored on your device and stays there. We do receive a small amount of pseudonymous usage and crash data, tied to a random identifier for the installed app rather than to you. This policy explains exactly what that is.
The Install Identifier
When you first use Araby, the app generates a random 8-character code — something like ARB-7F3K-92QX. It is stored on your device and sent with analytics events and crash reports so that a series of events can be recognised as coming from the same installation. Nothing about you is encoded in it: it is not derived from your name, your device, your Apple ID, or anything you type. It identifies an installation of the app, not a person. Reinstalling the app, or tapping "Reset All Data" or "Delete Account" in Profile, clears it permanently and a new one is generated. Under UK and EU data protection law this is pseudonymous data, and we treat it as personal data even though it does not tell us who you are.
Your Name and Progress Stay on Your Device
The first name you enter during onboarding is used only to greet you in the app. It is stored on your device and is never transmitted to us or to anyone else. The same is true of your learning progress, your goal, your answers, and your review schedule: all of it lives in local storage on the device. We hold no copy and have no way to retrieve it.
What We Do Collect
Two services receive data from the app, and only in production builds:
- Analytics events — named events such as choosing a goal, starting or completing a lesson, or answering a practice item. They carry only non-identifying properties: a lesson identifier, a percentage complete, whether an answer was correct, the Arabic word being practised. No event carries your name, and no event carries free text you typed.
- Crash reports — when the app crashes or hits an error, a diagnostic report is sent, with the install identifier set as the user id and a trail of recent event names so the crash can be read in context. These reports may include device model, operating system version, and app version.
On-Device AI Grading
The "Araby AI Recall" feature grades the answers you type using Apple Intelligence, which is built into iOS and runs entirely on your iPhone. Your typed answers are not uploaded, not sent to us, and not sent to any third-party AI service. They never leave your iPhone.
Who Processes Your Data
We use the following services. Each has its own privacy policy:
- Vexo Analytics
- Product analytics — which lessons and features are used, so we know what to improve.
- Sentry
- Crash and error reporting, so we can find and fix bugs.
- RevenueCat
- Checks whether an Araby Pro subscription is active. Uses its own anonymous identifier, separate from ours.
- Apple
- App Store distribution, subscription billing, and the on-device Apple Intelligence models used for grading.
Subscriptions
Araby Pro is billed by Apple and managed through RevenueCat. RevenueCat issues its own separate anonymous identifier for the purchase. We deliberately do not link it to the install identifier, so that resetting your data in the app cannot destroy an active subscription. We never see or store your payment details — Apple handles all billing.
Notifications
Reminders are scheduled locally by the app on your device. No push token is registered and no notification server is contacted. You can turn reminders off in iOS Settings at any time.
Sending Feedback
If you tap "Send Feedback", the app opens a draft email pre-filled with the app version, your iOS version, your device name, the install identifier, and the RevenueCat identifier — details that help us reproduce a problem. Nothing is sent until you send it, and you can see and edit the whole draft first.
Development Builds
Analytics and crash reporting are disabled entirely in development builds. They run only in the version distributed through the App Store.
Legal Basis for Processing
Under the UK GDPR and EU GDPR, we process the install identifier, analytics events, and crash reports on the basis of our legitimate interests (Article 6(1)(f)) — namely understanding how the app is used and keeping it stable and free of bugs. We have weighed this against your interests: the data is pseudonymous, is limited to app usage, is not used for advertising or profiling, and is never sold or shared beyond the processors listed above. You can object to this processing at any time by contacting us or by deleting the app.
How Long We Keep It
Analytics events are retained for up to 14 months and then deleted. Crash reports are retained for up to 90 days. Data on your device is kept until you delete it. RevenueCat retains subscription records for as long as required for Apple billing and tax purposes.
Deleting Everything
Open Profile and tap "Reset All Data" or "Delete Account". This erases your name, your progress, and the install identifier from the device. Because there is no server copy, that is the complete forget-me path — after it, nothing we hold can be connected back to your installation. To have historical analytics or crash data associated with a specific install identifier erased from our processors, email us with that identifier and we will delete it.
Your Rights
If you are in the UK or the EEA you have the right to access, correct, erase, restrict, or object to the processing of your personal data, and to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner's Office). Because our data is pseudonymous, we may need the install identifier from your device in order to act on a request — without it, we cannot identify which records are yours.
International Transfers
Our processors may store and process data outside the UK and the EEA, including in the United States. Where they do, transfers are covered by the safeguards those providers offer, such as Standard Contractual Clauses.
Children's Privacy
We do not knowingly collect personal data from children under 13. Because the app collects no directly identifying information from anyone, we hold nothing that identifies a child. If you believe a child's data has reached us, contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted here with a new “Last Updated” date.
Contact Us
Questions about this Privacy Policy? bilalcagiran [at] gmail.com