What we collect
Last updated
These are the fields used for app analytics, generated from the software definitions. See Privacy for the separate data needed to process sessions, recover transcripts and manage your allowance.
When something breaks
On unless you turn it off, in Settings. A fault report contains a standard error category, screen and technical metadata listed below. It contains no error message, stack trace or session content.
- The name of an error
- The type of fault only, such as TypeError. Never the message, and never anything you or the speaker said. For example: TypeError
- Which screen it happened on
- The area of the app, so a fault can be found. Errors on the reading screen carry less than this, never more. For example: archive
- Whether the app had to stop
- Whether the fault ended your session or the app carried on. For example: the app carried on
Relay diagnostic summaries
The same Report faults switch allows a compatible app to send diagnosticsAllowed. Missing or false disables identifiable diagnostic collection. Summaries contain: diagnostic id; session and device association; created/updated expiry timestamps; schema and capability versions; input sample count, duration, RMS/peak dBFS, zero/clipped ratios, six energy buckets, malformed-byte count, chunks and longest arrival gap; at most eight provider attempts with model, opaque id, provider Begin id, connection latency, accepted/sent/padding bytes, queue maxima, send failures, raw partial/final/empty/rejected counts, source-final and delivered counts, translation started/succeeded/failed counts, provider durations when available, termination signals/reason/code; omitted-attempt count, output counts, classification and completion status.
These private records expire after 24 hours, are limited to 16 KiB each and 2,000 records, and are excluded from third-party monitoring and usage rollups. Turning the switch off clears the active session summary. Data export uses a separate private credential stored securely on native devices; its hash is stored with the record. Delete everything removes these records. See Privacy.
Relay operations
Constant-size process counters count starts, counting requests, successful/failed analytics writes, silent-session alerts, rescues and capacity refusals; active sessions/jobs and provider occupancy are gauges. They have no device/session identifiers or individual event history and run regardless of app consent. Daily totals of session starts, application HTTP requests, health/admin requests, and live audio duration are stored for 90 days in UTC buckets. Other counters reset on process restart.
Counting whether the app is used
Off until you say yes. If you have not agreed to this, none of the following is stored for session analytics.
- When a session ran
- The date and how long it lasted. Not what was said. For example: 2026-09-04, 38 minutes
- Reading language
- The language you chose to read in. For example: Hindi
- Platform
- Whether the app was running on an iPhone or an Android phone. For example: iOS
- App version
- Which build of Manarah you were running, so a fault can be tied to a release. For example: 1.0.3
- Time zone
- The time zone your phone is set to. This is a rough stand-in for where Manarah is used, not your location: it is what the phone is configured to, it never involves your IP address, and a traveller carries their home zone with them. For example: Asia/Dubai
- How the session ended
- Whether it finished normally or something went wrong, and which named fault it was. For example: uplink-dropped
- A random identifier for this install
- The same one used to count your free monthly session. It is not derived from you or your device, and reinstalling makes a new one. For example: a random string
What analytics never includes
- Anything the khateeb said, or anything Manarah transcribed or translated.
- Your audio. Separate temporary audio processing and recovery are described in Privacy.
- Your IP address or precise location. The time zone above is the phone setting; it can reveal a broad region and may change when you travel.
- Your name, email, or phone number.
- Third-party tracking identifiers. There is no third-party analytics in this app.
How long it is kept
Session detail is kept for 90 days. After that it is reduced to monthly totals — how many sessions, in which language, on which platform — with no identifier of any kind. Anything too rare to be anonymous in those totals is dropped rather than kept. Fault reports are deleted after 90 days. Cleanup waits for idle time, so it may be delayed during live work.
Getting rid of it
Settings › Your data › Delete everything removes all of the above from our server while it is still linked to your installation. Anonymous monthly totals have no installation identifier and cannot be removed by an individual deletion request. Turning counting off stops new session analytics; turning fault reporting off also discards unsent fault reports on your phone.
Contact
Northstar Engineering Ltd
hello@northstarengineering.mu