Privacy Policy — Our Jamia
Effective date: 20 June 2026 ·
App: com.ourjamia.companion
This policy describes how the Our Jamia Android
application (the “App”) handles your personal information. The App is a
companion to your Madarsa institute's existing administration system
and is intended for use by enrolled students' parents and by institute
staff. The App is operated by Our Jamia (Madarsa software platform).
1. Information we collect
-
Mobile number. When you sign in, the App reads
the mobile number associated with the SIM in your device so it
can match your number to a record your institute already keeps
(parent or staff). The number is sent to our server only at the
moment of sign-in.
-
One-time passwords (OTP) sent and received via SMS.
The App sends a short code from your device to your own number
and reads the matching incoming SMS to confirm you control the
SIM. The OTP message body is read only to extract the code; no
other SMS content is read or transmitted.
-
Session token. After successful sign-in the
server sets an authenticated session cookie. The cookie is
stored on your device by the in-app browser component and is
used to keep you signed in.
-
App version & device platform. Sent in the
HTTP
User-Agent header so the server can enforce a
minimum supported version.
-
Records you choose to view or submit through the App
— for example: a parent viewing their child's attendance,
syllabus or leave records; a staff member marking attendance
or applying for leave. These records belong to the institute's
existing database and are accessed through the App only after
you sign in. The App itself does not create new datasets
outside what your institute already maintains.
-
Camera & images you capture or upload. Some
features use your device camera, and only when you start them:
scanning a QR code (decoded on-device to look up a student — the
image is not stored or transmitted), and — for staff — taking a
photo of an exam marks-slip. A marks-slip photo is uploaded to
your institute's server only when you choose to submit it, where
it is stored alongside the related exam record. You can also pick
an existing image from your device for these uploads. The App
never browses your photo gallery in the background; you select or
capture each image explicitly.
2. Information we do NOT collect
- We do not include any third-party advertising networks.
- We do not embed third-party analytics (no Google Analytics,
Firebase Analytics, Facebook SDK, AppsFlyer, etc.).
- We do not collect or transmit your location.
- We do not access your contacts or microphone, and we do not browse
your photo gallery in the background. The camera and image upload
are used only on the relevant screen when you start them, for QR
scanning and exam marks-slip photos (see section 1).
- We do not read SMS messages other than the specific OTP message
the App itself sent moments earlier.
- We do not share, sell, or rent your data to any third party.
3. Why we ask for sensitive permissions
-
SEND_SMS / READ_SMS / RECEIVE_SMS
— to send and read the OTP described above. The App reads only
the message it sent itself and does not scan the rest of your
inbox.
-
READ_PHONE_STATE / READ_PHONE_NUMBERS
— to detect the SIM's mobile number so the OTP loop can target
your own number (so you don't have to type a phone number to
sign in). The number is used at sign-in time only.
-
CAMERA — to scan a student's QR code and to let
staff photograph an exam marks-slip for upload. The camera is
activated only on the relevant screen, when you start it; there
is no microphone or video recording.
-
INTERNET / ACCESS_NETWORK_STATE — to
contact your institute's server.
4. How we store and protect data
Your records are stored on your institute's server. The transport
between the App and the server uses HTTPS. Authenticated sessions
are protected by a cookie tied to a server-side OTP proof. The App
keeps no plaintext password on the device.
5. Children
The App is not directed at children under 13. Parent accounts in
the App allow a parent or guardian to view their own child's
institute records — those records are entered by the institute,
not by the child. Staff accounts are restricted to adult institute
employees. We do not knowingly collect information directly from
children.
6. Data retention
Institute records (attendance, leaves, syllabus, etc.) are
retained according to your institute's own retention policy. To
request deletion of your account or your records, contact your
institute administration directly, or contact us at the address
below.
7. Your choices
- You may sign out at any time from the Profile screen of the App.
- You may revoke any of the SMS or phone permissions through your
device's system settings; sign-in will then require manual
entry of the OTP.
- You may uninstall the App; this removes all locally stored
session data.
- To request access, correction, or deletion of your data, contact
us at the address in section 9 — we'll forward the request to
your institute administration.
8. Changes to this policy
We may update this policy from time to time. The "Effective date"
at the top reflects the latest revision. Significant changes will
be announced through the App.
9. Contact
Questions or requests regarding this policy:
Our Jamia (Madarsa software platform)
Email: abdullahmadani78682@gmail.com
This page is hosted by your institute's Madarsa platform and is
public — you do not need to be signed in to view it.