Privacy Policy

Last updated 27 September 2026 · Applies to the OneMessage mobile app and this website.

The short version. We collect what is needed to bring you food before Fajr and nothing else. There is no advertising, no analytics SDK, and no tracking of any kind in this app. We never sell your data. You can delete your account from inside the app at any time, and your phone number becomes free to use again immediately.

1. Who we are

OneMessage is a volunteer-run service that coordinates Sehri, the pre-dawn meal during Ramadan, for residents of the neighbourhoods we serve in Bangalore, India. The app lets residents say whether they need food each night, follow the delivery on a live map, read prayer times and Qur’an, and talk to their zone’s group.

In this policy, “we” and “us” mean the OneMessage volunteer team, who act as the controller of the personal data described below. You can reach us at onemessagedev@gmail.com.

2. What we collect and why

We collect only what a particular feature needs. If you never use a feature, we hold nothing from it.

WhatWhy we need it
Your name So your zone admin and the volunteer delivering to you know who you are, and so your name appears beside your messages in group chat.
Your mobile number It is how you sign in, and how we verify you are a real resident. A one-time passcode is sent to it.
Your password Stored only as a one-way bcrypt hash. We cannot read it, and neither can anyone with access to our database.
Your zone, building and address So the right amount of food is cooked for the right place, and so the volunteer knows which door to come to.
Gender and occupation Collected at registration so admins can allocate the correct accommodation zone (several of the zones we serve are single-gender hostels).
Your nightly answer (yes or no to Sehri) It is the entire point of the app. This is what tells the kitchen how much to cook.
Donations you record The amount and the payment screenshot you upload, so a super admin can verify it and it appears in your own donation history. We never see or store your card, bank or UPI credentials — the payment happens entirely in your own UPI app.
Feedback you send So your zone admin can read and act on it.
Chat messages So your zone’s group conversation works. See section 5.
A notification token So we can tell you the poll has opened or your food is close. See section 4.
Live GPS — delivery volunteers only See section 3. This applies only to volunteers who deliver, and only while a round is running.

What we deliberately do not collect

3. Location data

If you are a resident, the app never reads your device location. Your address comes from the building you pick at registration, nothing more. The live map you see during a delivery shows the volunteer moving toward your building — it does not track you.

If you are a delivery volunteer, the app shares your device location while you are on a round, so residents can see their food coming and get an accurate arrival time. Specifically:

4. Notifications

If you allow notifications, your device gives us a push token, which we store against your account. A token identifies a device for delivery purposes; it is not a tracking identifier and it tells us nothing about what you do on your phone.

We send notifications only for:

Tokens are passed to Expo’s push service, which hands them to Apple or Google to reach your device. Turning notifications off in your phone’s settings stops all of them; signing out removes the token from your account. We keep only the most recent device you signed in on.

5. Group chat, reporting and blocking

Each zone has a group. Messages are stored on our server so the conversation is there when you open the app, and are visible to the other members of that group and to admins. Chat is not end-to-end encrypted. Please treat it as a community noticeboard rather than a private channel.

Moderators may delete a reported message or stop a member posting in a group. See our Community Guidelines.

6. Who your data is shared with

We do not sell your data, and we do not share it for advertising. We use a small number of service providers, each for one job:

ProviderWhat it receivesWhy
MessageCentral Your mobile number To send the one-time passcode that verifies it
Google Maps Platform Building coordinates and the delivery volunteer’s position To draw the route and work out an arrival time
Expo Push → Apple APNs / Google FCM Your push token and the notification text To deliver notifications to your device
Cloudinary The donation screenshot you upload To store the image so an admin can verify your contribution

Prayer times and Qur’an and du’a content are fetched from public Islamic content sources and stored on our own server. No information about you is sent to them — not your location, not your identity, not the fact that you opened the page.

We may also disclose data if we are legally required to, or where it is necessary to protect someone’s safety.

7. How long we keep it

8. Deleting your account

Open the app and go to Profile → Delete account. It takes two confirmations and happens immediately — there is no waiting period and you do not have to email anyone. Full instructions, including how to request it if you can no longer sign in, are on the Delete Your Account page.

When you delete your account:

If you would prefer your past messages removed as well, tell us and we will delete them.

9. Your rights

You can, at any time:

We answer requests within 30 days, and usually much sooner.

10. How we protect your data

No service can promise perfect security. If a breach ever affects your data, we will tell you and the relevant authority without undue delay.

11. Children

OneMessage is not directed at children. You must be at least 13 to hold an account, and if you are under 18 you should have a parent or guardian’s permission. We do not knowingly collect data from children under 13. If you believe a child under 13 has registered, tell us and we will remove the account promptly.

Our approach to child safety in the parts of the app where people can talk to each other is set out in our Child Safety Standards.

12. Changes to this policy

If we change this policy we will update the date at the top of the page. If a change materially affects how your data is used, we will also tell you in the app before it takes effect.

13. Contact us

Email: onemessagedev@gmail.com

Post: OneMessage, Bangalore, Karnataka, India

For anything urgent, the fastest route is the support page.