Skip to content
CariDoa
BM

Privacy Notice

The du'a you write is a trust. This notice explains what we collect, why, how it is protected, and your rights under Malaysia's Personal Data Protection Act 2010.

In short

  • No ads, no third-party trackers and no selling of data.
  • Du'a, notes and messages are encrypted before they are stored. Your sign-in email is not, so that you can sign in with it.
  • Location is kept as a place label only; coordinates are discarded after the check.
  • You can download or delete your data at any time. Deleting locks the account at once and erases it after 7 days.
  1. 1.About this notice

    This notice applies to the CariDoa website and web app at caridoa.com. It explains how CariDoa processes your personal data under the Personal Data Protection Act 2010 (Act 709), including its 2024 amendments.

    By signing up, or by sending a form as a guest, you agree to the processing described here. Each form records which version of this notice you agreed to.

  2. 2.What we collect and why

    We collect only what is needed to run CariDoa. The last column says exactly how each item is stored. Encrypted means encrypted with AES-GCM by our application before it reaches the database. Hashed means turned into a one-way code that cannot be read back. As written means stored readable, for the reason given.

    • Account: email address, display name, password, age group (13 to 17, or 18 and over)

      Why
      To open and protect your account, and to send account emails
      How it is stored
      Email and display name as written: you sign in with your email, and your name is shown only where you choose. The password itself is never stored, only a slow one-way hash.
    • Public username

      Why
      Your journey addresses (caridoa.com/j/username/...) and Explore
      How it is stored
      As written, and public. A new account gets a random username such as jemaah-k3x9wd, never made from your name or email. You can change it in Settings.
    • Profile and settings: theme, text size, du'a languages, list size, email preferences, travel window (optional), profile photo (optional)

      Why
      To tailor CariDoa to your choices
      How it is stored
      As written. An uploaded photo is re-encoded in your browser, which removes its location data, and is kept in private storage.
    • Du'a requests and the notes members send back

      Why
      To pass your request to members who pray, and their notes back to you
      How it is stored
      Request text and notes encrypted. Theme, language and the place label of a note as written.
    • Du'a sent through Du'a Links: name and email (both optional), your own words, your message to the pilgrim, an attached catalogue du'a

      Why
      To deliver the du'a to the pilgrim and send you a memento
      How it is stored
      Name, email, your words and your message encrypted. Your email (or, without one, a mix of your IP address and browser) is also hashed to apply the sending limits. An attached catalogue du'a is stored only as a reference to the public catalogue.
    • Du'a Links and journeys: title, address, dates, message to senders, settings

      Why
      To run your link or journey
      How it is stored
      Message encrypted. Title, address, dates and settings as written. The private /s/ address is hashed for look-up, and an encrypted copy is kept so you can view it again.
    • Completions: place label, verified status, note, voice note

      Why
      To tell the sender their du'a has been read
      How it is stored
      Note encrypted; place label as written; voice note in private storage. The memento address is hashed for look-up, with an encrypted copy so the pilgrim can share it again.
    • Dedications: message and photo or audio attachments

      Why
      To pass a thank-you to the pilgrim
      How it is stored
      Message encrypted; attachments in private storage; photo location data removed in your browser
    • My Du'a list and catalogue suggestions

      Why
      To keep your chosen du'a and review suggestions
      How it is stored
      Your own du'a: title and text encrypted. A saved catalogue du'a: its public catalogue title as written.
    • Feedback

      Why
      To improve CariDoa and to answer you
      How it is stored
      Email (optional) encrypted. Name (optional) and message as written, after personal details are removed automatically. Linked to your account when you send it while signed in.
    • Reports

      Why
      To deal with reported content
      How it is stored
      Reason, and details (optional) as written after automatic redaction. Your account when you are signed in, and a hash of your IP address.
    • Technical data: IP address, browser, sign-in sessions, consent records, rate limits

      Why
      Security, preventing abuse and recording your consent
      How it is stored
      IP addresses are never stored, only a one-way HMAC hash. A sign-in session keeps your browser's description (user agent) as written.
    • Emails waiting to be sent

      Why
      To send account and notification emails
      How it is stored
      Address and content encrypted, and the address hashed. Emails carry links only, never du'a text.
    • Campaign and invite visits

      Why
      To count how often a campaign or invite link is opened
      How it is stored
      The code, the time and a hash of the IP address, at most once every 30 minutes. The cd_ref cookie links the code to a sign-up.
  3. 3.Sensitive data and explicit consent

    The du'a you write can reveal your religious beliefs and the health of you or others. Under Act 709 this is sensitive personal data. We process it only with your explicit consent, given through the consent box when you sign up and on every form that sends what you write: the request form, sending a du'a through a link, a dedication, feedback, and the details of a report. Each record keeps the version of this notice you agreed to and when.

    When this notice changes in a way that needs new consent, members are asked to agree again ("Our Privacy Notice has changed") before they can open member pages or write anything. Every consent you give is also kept in a history: the version, the time, how it was given and your age group, without your IP address.

    Please avoid writing full names, identity card numbers, phone numbers, addresses or details that identify other people. Our system removes details like these automatically, but it is better to be careful.

    You can withdraw consent at any time by deleting your content or your account (see Your rights). Withdrawing does not affect processing that has already taken place.

  4. 4.How we protect your data

    • Encryption in the application: du'a text, notes, messages, senders' names and emails, feedback emails and email content are encrypted with AES-GCM before they are stored, with the key kept apart from the database. What is stored as written, and why, is listed in What we collect.
    • One-way hashes: IP addresses are stored only as HMAC hashes. Private link and memento addresses are looked up by their hash; an encrypted copy is also kept so their owner can view and share them again. Email sign-in links are stored only as a hash.
    • Passwords: at least 10 and at most 128 characters. A password is refused if it is on a list of 10,000 common passwords or is a simple variation of one, a keyboard run, a repeated pattern, or your own name or email name. The check runs on our server; your password is never sent to any other service.
    • Sessions: after "Sign out of all devices", a password change or reset, or a suspension, the old sessions can no longer download your data, ask for or cancel deletion, change your password, passkeys or name, or use any admin function, at once. Other pages stop working on those devices within 60 seconds.
    • No copies in the browser cache: pages that can show du'a, report details, feedback or an email address are sent with "Cache-Control: private, no-store", so the browser does not keep them after you sign out on a shared device.
    • Secure connections: all traffic goes over HTTPS, with strict security headers.
    • Limited access: administrators see content only for moderation, reports and support, and every administrator action is recorded in an audit log.
    • Moderation: personal details such as phone numbers and identity card numbers are removed automatically before content is stored or shown.
  5. 5.Location: a label only

    When you mark a du'a as done, CariDoa can check whether your device is inside a holy-site area, such as Masjid al-Haram or Masjid an-Nabawi. The coordinates are used once for that check on our server, then discarded. We keep only the place label and whether it was verified.

    In reading mode without a connection, the coordinates wait on your device with the completion until it is sent, and are deleted with it. If the upload fails, they are dropped at once. Users under 18 are not offered the location check when they pray for a request.

    You can refuse location access and type the place yourself; the "verified" badge is then not shown. The badge is a sign of community trust, not absolute proof.

  6. 6.No trackers and no session recording

    CariDoa uses no third-party analytics, social media pixels, ads or session recording. We do not sell or rent your data, and we do not use it to train AI models. Fonts, scripts and images come from caridoa.com itself; the only other services your browser contacts are listed under Processors.

  7. 7.Cookies and device storage

    CariDoa uses only first-party cookies that it needs to work, and storage in your own browser. None of them follows you to other sites. On caridoa.com the four sign-in cookies (the names starting with "cd.") carry the extra prefix "__Secure-".

    • Cookie cd.session_token

      Purpose
      Keeps you signed in. HttpOnly, Secure, SameSite=Lax.
      How long
      30 days, extended while you use CariDoa; removed when you sign out
    • Cookie cd.session_data

      Purpose
      A signed copy of your session, including your name and email, so pages do not have to ask the database every time. HttpOnly.
      How long
      60 seconds
    • Cookie cd.better-auth-passkey

      Purpose
      Only while you add or use a passkey: the one-time challenge for that step
      How long
      5 minutes
    • Cookie cd.state

      Purpose
      Only with "Continue with Google": protects the sign-in round trip
      How long
      5 minutes
    • Cookie cd_ref

      Purpose
      Set by a campaign or invite link (/r/...) for visitors who are not signed in: which code brought you, so a sign-up can be counted. HttpOnly, SameSite=Lax. No personal data.
      How long
      30 days
    • Cookie cd_req_onb

      Purpose
      Remembers that the first-visit setup on My Home was saved or skipped in this browser. HttpOnly.
      How long
      1 year
    • Local storage cd:theme, cd:textSize

      Purpose
      Your theme and text size
      How long
      Until you clear them
    • Local storage cd:install-dismissed

      Purpose
      That you dismissed the install prompt
      How long
      The prompt stays hidden for 30 days
    • Local storage cd.saved-doa.v1

      Purpose
      Du'a you saved while signed out (catalogue addresses only, which can still show what you pray for). They move into your account, and leave the device, when you sign in.
      How long
      Until you sign in or clear them
    • Local storage cd:last-user

      Purpose
      The random id of the account last seen signed in on this browser (not your name or email), so offline copies of reading mode open only for that account. When a page finds you signed out, this id and every offline copy are deleted.
      How long
      Until you sign out
    • Session storage cd:toast, cd:thanks, cd:wizard:..., cd.send-return, cd.save-prompt, cd:read:...

      Purpose
      Short-lived state for one tab: a message for the next page, the result of a send, the send form's details (your name, email and words) while you look at a catalogue du'a, the page to go back to, whether the save prompt was shown, and which of your own du'a you have read in reading mode. For content reviewers only, cd.admin.reviewer keeps the reviewer's name and accreditation number.
      How long
      Until you close the tab
    • IndexedDB caridoa-reading

      Purpose
      Reading mode offline: a copy of a link's du'a (the senders' words, decrypted) and the completions waiting to be sent (note, voice note, place)
      How long
      The copy is deleted 7 days after the journey ends, or 30 days after it was downloaded when there is no end date, and when you sign out, another account signs in, or a page finds you signed out (including after "Sign out of all devices" on another device). Offline reading mode opens a copy only for the account in cd:last-user. Waiting completions stay until they are sent or you discard them.
    • Service worker caches cd-shell-..., cd-static-...

      Purpose
      The reading-mode page without any user data, and the site's static files, so reading mode opens offline
      How long
      Replaced with each new version of CariDoa

    We show no cookie banner because we use no tracking or advertising cookies. Clearing this site's data in your browser removes everything above; you then need to sign in again and to prepare reading mode for offline use again.

  8. 8.Who can see your data

    • Du'a requests: before it is shown, every new request is read by our moderation team. Then signed-in members who open Pray see a short excerpt of your request (after automatic redaction), with its theme and language; the member who carries it sees the full text. They see your first name only if you turn off "Anonymous".
    • Notes you write for a request: the requester sees your note and place label, and your first name only if you choose not to stay anonymous. Notes from users under 18 are always anonymous.
    • Du'a sent through links: the link owner sees your words, the attached catalogue du'a, your message, and your name unless you hide it. Your email is never shown to the owner.
    • Mementos: only whoever holds the private memento link. A memento never contains the link's private address. The pilgrim can revoke it.
    • Journeys and Explore: a journey page shows its title, dates and message, and its address carries your public username. Explore lists only journeys their owners choose to list, with the display name only when the owner chooses to show it.
    • "Prayed for" counts: the requester only.
    • Administrators: only for moderation, reports and support.
    • While an account is being deleted, or is suspended: its journeys leave Explore, its links stop accepting du'a, its profile photo is no longer shown, and mementos of du'a it read say "A pilgrim", with no note and no voice note.
  9. 9.Processors and cross-border transfers

    Cloudflare, Inc. runs CariDoa (Workers, the D1 database, R2 storage, Email Service and Turnstile) and processes data on our behalf on its global network. Your data is stored and processed by Cloudflare, including in data centres outside Malaysia. By giving consent, you understand that your data may be transferred outside Malaysia to run this service.

    • Cloudflare Turnstile checks that you are human using device signals, on sign-up, on sign-in after several failed password attempts for the same email, the request form, sending a du'a through a link, dedications, feedback and reports. It loads from challenges.cloudflare.com and is not used for advertising.
    • Google receives your sign-in request only if you choose "Continue with Google".
    • Quranic recitation, shown only when Quranic text is published, plays from AlQuran.cloud's audio server (cdn.islamic.network) when you press play.
    • Outside links such as quran.com, sunnah.com, hadeethenc.com and JAKIM Smart Quran follow their own privacy policies when you open them.
  10. 10.How long we keep data

    • Your account and its content: kept while your account is active. When you ask for deletion, the account is locked at once for a 7-day cooling-off period, and every other device is signed out: you can still sign in, but only to cancel, and everything else, including "Download my data", waits until you do. Cancelling within the 7 days restores everything as it was.
    • After 7 days, a daily job (03:00 Malaysia time) permanently deletes the profile, sign-in methods, sessions and passkeys; your requests and the notes they received; the notes you wrote for others; your links and journeys with every du'a, completion, voice note and dedication in them; your du'a list; the reports and feedback you sent; the dedications you posted; your unsubscribe records, the emails sent or queued for you, visits to your invite code and rate-limit records; and your stored files.
    • What stays, anonymised: du'a you sent through other people's links stay with the recipient as an amanah, with no account, name, email, sender key or IP hash. The administrator audit log keeps only actions, dates and pseudonymous ids, with their details erased, and the deletion itself is recorded with counts only. Site-wide totals do not change and cannot identify you.
    • Du'a received through links: deleted automatically 180 days after a link closes (completed, archived, cancelled or taken down by an administrator), counted from the later of its end date and its last status change, together with their mementos, dedications, voice notes and attachments. The link itself stays for you, and reopening it restarts the clock. A link that stays open keeps its du'a until you delete them.
    • Deleting things yourself: a link owner can delete any single du'a received, with its memento, dedications and voice note, or a whole link with everything in it. A requester can delete a request with its notes. Deleting cannot be undone. If you sent a du'a as a guest and want it removed sooner, contact us.
    • Unused uploads: a voice note or attachment that no completed du'a or posted dedication uses is deleted automatically once it is more than 24 hours old.
    • Email content: 30 days after an email is queued, its content and any error text are erased, whether it was sent or not, and an email still unsent by then is never sent. The record that it was sent (the encrypted and hashed address, the type and the status) stays to check delivery and respect unsubscribes.
    • Sign-in: a session lasts 30 days and is extended while you use CariDoa. Expired sessions, sign-in links and password reset links are deleted every night.
    • Rate-limit records: deleted after 2 days.
    • Feedback: feedback sent while signed in is kept as a support record and deleted with your account. Feedback sent without signing in (no account owns it) is deleted automatically 12 months after it was sent. Ask us if you want feedback you sent deleted sooner.
    • Reports: kept as moderation records. Once a report is resolved or dismissed, its details and the reporter's IP hash are erased automatically 12 months after it was filed; its target, reason and outcome stay for moderation statistics. Reports you sent while signed in are also deleted with your account. Ask us if you want a report you sent deleted sooner.
    • Visit counts: visits to your invite code are kept as campaign records and deleted with your account.
    • Administrator audit log: kept for security and accountability. When an account is deleted, the details of every entry about it are erased.
    • cd_ref cookie: expires after 30 days. Device storage follows the times in Cookies and device storage.

    The database has a disaster-recovery feature that keeps past states for a limited time (up to 30 days). After that, deleted data can no longer be restored.

  11. 11.Your rights and how to use them

    • Access and a copy of your data: in Settings, choose "Download my data" to get your data as one JSON file. The du'a text in it is decrypted, so keep the file somewhere safe.
    • Correction: update your name, username, preferences and settings in Settings at any time. An age group of 13 to 17 cannot be changed to 18 and over in Settings; ask us to correct it.
    • Deletion: delete particular content, or choose "Delete my account" in Settings.
    • Withdrawing consent: delete your content or account, or contact us.
    • Limiting processing: turn off particular emails or all email in Settings, or use the unsubscribe link in every email. The one-click unsubscribe button in mail apps only ever unsubscribes; subscribing again needs the button on the CariDoa page.
    • Data portability: the JSON export can be used elsewhere.

    For requests you cannot make in Settings, contact us through the feedback form. We answer data access requests within 21 days, and may need to confirm your identity first.

    If you are not satisfied, you have the right to complain to the Personal Data Protection Department (opens in a new tab).

  12. 12.Children and teenagers

    CariDoa is for users aged 13 and over. Users aged 13 to 17 can use CariDoa but cannot post anything publicly: they cannot post du'a requests to Pray, their journeys cannot be listed on Explore or take du'a from the public, and the notes they leave for requests are always anonymous, without a location check. We encourage parents and guardians to know how their children use it.

    An account confirmed as 13 to 17 stays in that group when consent is renewed; only a correction through us can change it. If we find an account belonging to a child under 13, it will be deleted.

  13. 13.If a data breach happens

    If a personal data breach happens, we will notify the Personal Data Protection Commissioner as soon as possible, within 72 hours. If the breach is likely to cause you significant harm, we will also tell you without undue delay, together with steps you can take.

  14. 14.Data Protection Officer

    Data Protection Officer (DPO): to be announced. Until then, contact us through the feedback form (choose "Question" and mention "privacy").

  15. 15.Changes to this notice

    We will update the effective date above when this notice changes. Significant changes will be announced on this page, in the Changelog and, if you have an account, by email. If a change needs new consent, we will ask for it before you can continue.

  16. 16.Contact us

    Questions about privacy? Contact us through the feedback form on any page.

This document is available in Malay and English. If they differ, the Malay version applies.