Manarah

What we collect

Last updated

These are the fields used for app analytics, generated from the software definitions. See Privacy for the separate data needed to process sessions, recover transcripts and manage your allowance.

When something breaks

On unless you turn it off, in Settings. A fault report contains a standard error category, screen and technical metadata listed below. It contains no error message, stack trace or session content.

The name of an error
The type of fault only, such as TypeError. Never the message, and never anything you or the speaker said. For example: TypeError
Which screen it happened on
The area of the app, so a fault can be found. Errors on the reading screen carry less than this, never more. For example: archive
Whether the app had to stop
Whether the fault ended your session or the app carried on. For example: the app carried on

Relay diagnostic summaries

The same Report faults switch allows a compatible app to send diagnosticsAllowed. Missing or false disables identifiable diagnostic collection. Summaries contain: diagnostic id; session and device association; created/updated expiry timestamps; schema and capability versions; input sample count, duration, RMS/peak dBFS, zero/clipped ratios, six energy buckets, malformed-byte count, chunks and longest arrival gap; at most eight provider attempts with model, opaque id, provider Begin id, connection latency, accepted/sent/padding bytes, queue maxima, send failures, raw partial/final/empty/rejected counts, source-final and delivered counts, translation started/succeeded/failed counts, provider durations when available, termination signals/reason/code; omitted-attempt count, output counts, classification and completion status.

These private records expire after 24 hours, are limited to 16 KiB each and 2,000 records, and are excluded from third-party monitoring and usage rollups. Turning the switch off clears the active session summary. Data export uses a separate private credential stored securely on native devices; its hash is stored with the record. Delete everything removes these records. See Privacy.

Relay operations

Constant-size process counters count starts, counting requests, successful/failed analytics writes, silent-session alerts, rescues and capacity refusals; active sessions/jobs and provider occupancy are gauges. They have no device/session identifiers or individual event history and run regardless of app consent. Daily totals of session starts, application HTTP requests, health/admin requests, and live audio duration are stored for 90 days in UTC buckets. Other counters reset on process restart.

Counting whether the app is used

Off until you say yes. If you have not agreed to this, none of the following is stored for session analytics.

When a session ran
The date and how long it lasted. Not what was said. For example: 2026-09-04, 38 minutes
Reading language
The language you chose to read in. For example: Hindi
Platform
Whether the app was running on an iPhone or an Android phone. For example: iOS
App version
Which build of Manarah you were running, so a fault can be tied to a release. For example: 1.0.3
Time zone
The time zone your phone is set to. This is a rough stand-in for where Manarah is used, not your location: it is what the phone is configured to, it never involves your IP address, and a traveller carries their home zone with them. For example: Asia/Dubai
How the session ended
Whether it finished normally or something went wrong, and which named fault it was. For example: uplink-dropped
A random identifier for this install
The same one used to count your free monthly session. It is not derived from you or your device, and reinstalling makes a new one. For example: a random string

What analytics never includes

How long it is kept

Session detail is kept for 90 days. After that it is reduced to monthly totals — how many sessions, in which language, on which platform — with no identifier of any kind. Anything too rare to be anonymous in those totals is dropped rather than kept. Fault reports are deleted after 90 days. Cleanup waits for idle time, so it may be delayed during live work.

Getting rid of it

Settings › Your data › Delete everything removes all of the above from our server while it is still linked to your installation. Anonymous monthly totals have no installation identifier and cannot be removed by an individual deletion request. Turning counting off stops new session analytics; turning fault reporting off also discards unsent fault reports on your phone.

Contact

Northstar Engineering Ltd
hello@northstarengineering.mu