Privacy at UmmahPass

Last updated: July 31, 2026

The short version

Jump to the off-switch →

What UmmahPass collects

If you start claiming a name and do not confirm, we keep the name you tried, a one-way hash of the email, and the time, for 30 days, to count and fix the join flow. Then it is deleted.

  • Your account - your name, your email address, and your password, which is stored only as a bcrypt hash. We never store or see the plain text.
  • Passkeys - if you add a passkey, we store a public key, the device name you typed, and when it was last used. A public key cannot sign you in on its own. We never receive your fingerprint or your face: those stay on your device and are never sent to us.
  • What you choose to add - screenname, profile photo, additional email addresses, and verification documents if you apply for Muslim verification.
  • Payments - if you become a paying member, Stripe handles your card. We never see or store your card number; we keep what you paid, when, and for which membership, so we can honour it.
  • Server logs - like every website, our servers log requests (IP address, page, time, browser) for security, abuse prevention, and debugging, and keep them for a limited period.
  • Where you came from - when you create an account we keep the page and campaign link you arrived from (for example, which part of UmmahCity sent you) so we can see which doors work. We never buy or sell this and it is not shared with advertisers.

Stories (Sands)

A story is a photo or a short video you post from UmmahPass, with an optional caption. This section exists because we were capturing all of it and this page did not say so.

  • What we keep while it is live - the image or video file, the caption you typed, the picture's size and the video's length, when you posted it, when it is due to disappear, and whether you chose to keep it. If you tag someone, we keep who you tagged.
  • It disappears after 24 hours unless you press Keep. A job runs every five minutes, deletes the file, then re-requests the public link over the internet and requires it to be dead before it will mark the story deleted. If that check does not come back dead, the story is not marked deleted and the job tries again. We would rather retry than record a deletion we cannot prove.
  • We do not record who watched your story. There is no viewer list and no view count, because we do not store one. Salaams are the only response a story can receive, they carry no text, and they are deleted with the story.
  • If someone reports your story, we keep the report and we hide the story rather than letting it disappear on its timer, so the evidence still exists while it is read. A named list of people on our team reads it - not everyone on staff, and not a machine. If the report was wrong we put the story back and its own timer resumes. If it was right the story stays hidden and we delete the file after 90 days, using the same check as every other deletion: delete the file, re-request the public link, and require it to be dead. The report itself is deleted with the story it was about, so it never outlives the thing it was evidence of. Every time one of those people opens reported media we record who did it and when, so the access is reviewable too.
  • Taking a story down yourself is permanent. It goes into the same deletion job, and the file is gone within a few minutes. We cannot bring it back.

The cross-site activity system reports here

UmmahPass is not just another site that runs UMG's first-party activity system - it is the site that hosts it. The script the other UMG sites load is served from ummahpass.io, and the events it sends land in our database here, attached to your UmmahPass account. That is why the switch is on this site and nowhere else.

It is off until you turn it on for your account, and the profile it builds is used to recommend content, businesses and missions across the ecosystem. Turning it on starts collection from that moment; turning it off deletes the profile you already have. It is never sold and never shared outside Ummah Media Group. Every site that runs it says so on its own privacy page, and the complete audited list is published in one place: the sites that run it.

When you sign in to another app with UmmahPass

Some apps let you sign in with your UmmahPass account instead of making a new password. When you do, we send that app some of your information. This section exists because we were doing that and this page did not say so.

  • You choose, on a screen we show you first. Before anything is sent, we show you the app's name, the internet address it will send you to, and a list of what it is asking for. Nothing is sent if you press Cancel.
  • Every app gets your account number. That is a number, not your name and not your @handle. An app that asks for nothing else gets nothing else.
  • If you agree to "profile", the app also gets your name, your @handle, your member number, and where you are: your city, your region, your country and your community. It also learns whether you have Muslim verification.
  • If you agree to "membership", the app gets your Ummah One status and tier, and whether you have ever given through UmmahCauses. We are naming that plainly because giving is private, and a line about membership status is not where you would expect to find it.
  • If you agree to "email", the app gets your email address and whether it is confirmed.
  • We are not paid for this and we never sell it. The app receives it because you said yes, and for no other reason.

You can take it back. Apps you have connected lists every app you have said yes to and lets you disconnect one. Disconnecting stops it reading anything new; it does not delete what the app already saved, so contact the app for that. Being straight about one thing: anyone can build an app that connects to UmmahPass, we do not check them, and the sign-in screen says so. Only continue if you know whose app it is.

Apps we run ourselves, inside Ummah City, do not show you that screen, because you are already signed in to us.

Turn it off - and erase what is already there

The switch is Data & Consent → Cross-Platform Personalization in your profile. Turning it off does three things:

  • - your past events are unlinked from your account;
  • - your behavioural profile is deleted;
  • - your segment memberships are deleted.

Honestly stated: switching it back on later does not re-link the old events - that link is gone for good. Operational records (signups, payments, security events) are kept either way; they are what makes the service work and what the law requires of us.

Open my privacy settings →

You will be asked to sign in first; the page then opens on the Data & Consent section.

The umg_id cookie, in full

This is the one page in the ecosystem that documents this cookie - the canonical policy links here for it.

  • When you sign in, we set a cookie named umg_id on .ummahpass.io. It holds a signed token (a JWT) carrying your UmmahPass user ID, your screenname, your membership tier, and which memberships are currently active. It carries no payment details, no contact details, and no message content.
  • It expires after 30 days and is sent only over HTTPS. It is deliberately readable by JavaScript on our own domains - that is what makes the next point work.
  • Other UMG sites recognise you by reading it through a small page we serve at https://ummahpass.io/identity-bridge.html, loaded in a hidden frame. Only origins we have explicitly allow-listed can read a result from it.
  • Signing out clears it immediately, and signing out of the ecosystem clears it everywhere. You can also delete it in your browser at any time.
  • Your browser also stores two anonymous identifiers - up_anon_id (localStorage) and up_session_id (sessionStorage) - which stitch a single visit together before and after you sign in.

Your rights, and "Do Not Sell or Share"

We do not sell or share your personal information with third parties for money or other valuable consideration - there is nothing here to opt out of, because we do not do it. Your rights to know, access, correct, delete and port your data, and to opt out of the activity system, are set out in full in the canonical policy; the controls themselves are in your profile. To exercise any of them, use those controls or email privacy@ummahpass.io - we answer within 30 days.

One commitment, quoted exactly

"We never sell your data. Not to advertisers, not to data brokers, not to anyone."

- quoted verbatim from section 2, What we will NEVER do. Every commitment in that list binds UmmahPass too.

UmmahPass is part of the UmmahCity ecosystem and runs on a shared UmmahPass account. This site loads the UmmahPass behavioral tracking script, which links your activity across UMG sites to a profile you can turn off and erase at any time in your UmmahPass privacy settings.

Everything ecosystem-wide - the full description of that system and its off-switch, our self-hosted analytics, payments, security, data deletion, and the complete list of what we will never do - lives in one canonical policy at ummah.city/privacy, which governs this site too. This page covers only what is specific to UmmahPass; the canonical policy and this page's site-specific facts together are the whole truth.

The canonical policy at ummah.city/privacy, section 1, now also covers: a professional profile (profession, headline, self-reported credentials, an open-for-clients toggle, and since Sep 25 2026 a "how I work" description, languages, remote availability, your own booking link, up to 8 services with a price you write, a practising-since year, an optional gender field shown only if you set it, and self-reported education, skills and certifications), the "Go live as a professional" control, why we do not create a practice listing for you on UmmahPlaces unless you attach one you already own, the professionals directory search, the directory's verified-email-and-24-hours (or staff-cleared) visibility rule, the contact relay to a professional's verified email, and, since Sep 25 2026, the "Import from LinkedIn" tool: what it reads from a data archive you request from LinkedIn yourself (your own Profile, Positions, Education, Skills, Certifications and Languages files only, never a file about other people such as connections or messages), that we keep no copy of the file you upload, and that nothing saves until you review and confirm it.

Contact

Ummah Media Group LLC
California, United States

Privacy: privacy@ummahpass.io
Support: salaam@ummahpass.io