Wasl وصل

Legal

Privacy policy

Last updated 30 September 2026 Applies to the Wasl mobile app and this website
The short version
  1. By default, everything you write stays on your device. We do not receive it.
  2. An account is optional. If you create one, each record is encrypted on your device before it is sent, so we hold ciphertext we cannot read. That encryption covers what is synced, not what sits on the phone.
  3. Cycle information is health data. It is treated as the most sensitive thing in the app.
  4. We do not sell or share your content, and there is no advertising in the app.
  5. You can export everything and you can delete everything, including the account.
  6. The one place we ask for a phone number is the follower offer, to stop the same person claiming it twice. It never reaches the app and is never used for marketing.

1. Who we are

Wasl is published by Wasl, based in Kingdom of Bahrain. For anything in this policy, write to privacy@wasl.love. We are the data controller for the limited information described in section 4.

2. What the app is

Wasl is a private app for one person. It suggests conversation questions, stores the answers and notes you choose to write, tracks dates that matter to you, and optionally records a menstrual cycle log with guidance for a partner. Your partner does not install anything and has no account.

3. Device-only mode, which is the default

When you first open the app you are not asked to sign up. In this mode:

  • Everything you write — saved answers, memories, notes, profile fields, lists, dates, photos, voice recordings and any cycle log — is stored only in the app's storage on your device.
  • None of it is transmitted to us or to anyone else. The app works fully offline.
  • We receive no analytics, no crash reports containing your content, no device identifier and no advertising identifier from this mode.
  • Because the data is on your device only, uninstalling the app or clearing its data deletes it permanently. Use Settings → Export backup before you switch phones.

To be exact about what protects it: content stored on the device relies on your phone's own storage protections — app data is private to the app, and a modern phone encrypts its storage at rest once you have a screen lock. The app does not add its own layer of encryption to what sits on the phone. Its encryption applies to records on their way to an account, which section 4 covers. The optional screen code and biometric unlock are access controls on the front of the app, not encryption; the app says so in Settings and we repeat it here so nobody is misled.

4. If you choose to create an account

An account exists for two purposes only: an encrypted backup, and getting your data onto a second device. It is entirely optional, and the app is fully functional without it. The first version of the app is device-only and does not offer accounts yet; this section describes how they will work when they arrive in an update.

What is encrypted, and when

If you create an account, each record is encrypted on your device, before it is sent, with a key that we never receive. That key is wrapped by your password and by a recovery key shown to you once at signup. The consequence is deliberate and worth stating plainly: if you lose both your password and your recovery key, your synced data cannot be recovered by anyone, including us. The signup screen tells you this before you commit.

Note what this does and does not cover. Encryption applies to records synced through an account, and not to the copy that stays on your phone. In device-only mode there is nothing in transit and nothing on a server, so there is no transport encryption to speak of — the protection there is that the data never leaves the device. And an exported backup file is written in readable form so that you can restore it anywhere, so store that file somewhere you trust.

What we can see with an account

DataWhyReadable by us
Email addressTo identify the account and let you sign inYes
Authentication records (hashed credentials, timestamps)To keep the account secureYes, as hashes
Your entries, photos, voice notes and cycle logBackup and multi-device restoreNo — ciphertext only
Record identifiers, timestamps and sizesSo sync knows what changedYes, as metadata

Account infrastructure is provided by Google Firebase (authentication, Cloud Firestore and Cloud Storage), acting as our processor. Encrypted content and the metadata above are stored on their infrastructure. Their handling is governed by Google's own terms; we configure the service so that only your account can read your own records.

5. Subscriptions

Purchases are handled by Apple or Google. We use RevenueCat, Inc. as our processor to confirm whether you have an active subscription. RevenueCat receives a random identifier created by the app, your purchase receipts and the store’s transaction details. It does not receive your name, your email address or anything you write in Wasl.

If you redeem a campaign code, the code, the email address it was issued to and that random identifier are sent to our server to check the code.

6. Cycle and health information

If you use the Cycle screen, the dates, symptoms and moods you log are health data and are the most sensitive category in the app. They are stored exactly like everything else: on your device by default, and encrypted before upload if you use an account. They are never used for advertising, never sold, never shared, and never used to train anything.

Two points of substance, not legal cover:

  • The predictions are estimates derived from what you log. They are not a contraceptive or a fertility treatment and must not be relied on to plan or prevent a pregnancy.
  • The information is usually about another person. Ask her before you log anything. Where the law where you live requires her consent for you to record her health information, obtaining it is your responsibility, and we ask you to treat it as an ethical requirement regardless.

7. Artificial intelligence features

Where the app offers an AI feature, it works only on what you type into that feature at that moment. It does not read your saved entries, your timeline, your partner profile or your cycle log, and those are not sent anywhere as part of it. If that ever changes, this policy changes first and the app will ask you before the feature behaves differently.

The assistant on this website is separate and simpler: it answers from a fixed list of prepared answers held in the page itself. What you type into it is not stored by us and is not used to train anything.

8. This website

  • The site sets no cookies and carries no advertising or social pixels. We count visits with Plausible Analytics, which is cookieless and does not identify you: it records the page, the referring site, and your broad country and device type, and nothing that follows you to other sites. It loads no external fonts.
  • If you submit the newsletter or contact form, we receive what you typed — your email address, and your message where there is one — in order to reply or to send you the weekly note. Forms are handled by our hosting provider on our behalf.
  • Newsletter emails carry an unsubscribe link, and one click is enough. We do not sell or rent the list.
  • Our host records standard server logs, including IP address and requested page, for security and to keep the site running. These are kept for a short period and not combined with anything else.

9. The follower offer, and the details it asks for

If you claim the follower offer on our claim page, we collect more than the app ever does, and only for that purpose. What you submit is: your first and last name, your email address, your mobile number with its country code, your gender, your handles on the two channels, and — where the follow cannot be checked automatically — the monthly campaign code and the screenshot you upload as proof.

Why we ask for a mobile number

The offer is limited to one claim per person. Holding that line needs something more durable than an email address, because anyone can make another of those. The number is what lets us recognise a repeat claim — including a claim made months later, once a first set of free months has run out.

Your number and your details never reach the app

This matters enough to state on its own. Everything on the claim form stays with the website. Your redemption code resolves to one thing only — two free months for the email address you registered — and the app receives nothing else. Your name, your mobile number and your gender are never sent to it, are not stored in your app data, and are not part of any account you create in the app. The app itself asks only for an email address and a password, exactly as its store listing declares.

What happens to it afterwards

  • Your number is used to check the claim is not a duplicate, and for nothing else. We do not text you, marketing or otherwise, and the number is not added to any list.
  • Once a claim is settled we keep your number and your email address only as hashes — one-way values that let us recognise a repeat claim without holding the originals. We keep that short list indefinitely, because the point of it is to catch a second claim long after the first has expired. It identifies nobody to anyone reading it and is used for no other purpose.
  • Your redemption code is bound to your email address, can be used once, and expires 30 days after we issue it.
  • Where a follow is checked automatically, that check happens through the platform's own sign-in and tells us one thing: whether you follow us. We do not read your account, your posts or your contacts.
  • Your screenshot is reviewed by a person, because most platforms offer no honest way to verify a follow automatically. It is deleted once the claim is settled.
  • Everything else — your name, your gender, the handles you gave — is deleted once the claim is settled.
  • Claim data is never combined with anything inside the app. There is no link between a claim and your entries, because we cannot read your entries.

You can ask us to delete a claim at any time at privacy@wasl.love. Withdrawing it before a code is issued means we cannot issue one.

10. What we never do

  • We do not sell, rent or share your content with anyone.
  • We do not show advertising in the app, and we do not include advertising SDKs.
  • We do not use your entries, photos, voice notes or cycle log to train machine-learning models.
  • We do not build profiles of you or your partner for any purpose beyond running the features you switched on.

11. How long things are kept

Device data stays until you delete it or remove the app. Claim data is covered in section 9. Account data stays until you delete your account, which the app does from Settings and which removes your authentication record and your stored ciphertext. Newsletter subscriptions last until you unsubscribe. Contact messages are kept while we deal with them and for a reasonable period afterwards.

12. Your rights

Depending on where you live you may have the right to access, correct, export or delete your information, to withdraw consent, and to complain to a data-protection authority. In practice the app gives you most of this directly: Export backup is a full copy, and deleting the app or the account is a full deletion. For anything you cannot do in the app, write to privacy@wasl.love and we will respond within 30 days.

Where we rely on a legal basis under the GDPR: performing the contract for account and sync features, consent for the newsletter and for health data, and legitimate interests for basic security logging.

13. Children

Wasl is intended for adults in a relationship and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, write to us and we will remove it.

14. International transfers

If you use an account, the encrypted records and account metadata described in section 4 may be processed on servers outside your country, on Google Cloud infrastructure. Because content is encrypted on your device before it is sent, what crosses a border is ciphertext we cannot read.

15. Security

We keep the attack surface small on purpose: no account by default, encryption before upload when there is one, server rules that permit only your own account to read your own records, and no third-party SDKs collecting data in the background. No system is perfect; if you find a problem, please tell us at privacy@wasl.love and we will act on it.

16. Changes to this policy

If we change it we will update the date at the top, and for anything that materially affects how your information is handled we will tell you in the app before the change takes effect.

17. Contact

Wasl, Kingdom of Bahrain. Privacy: privacy@wasl.love. Anything else: hello@wasl.love, or the contact page.