Privacy Policy — Tahavol (تحول)
Version 1 · Effective date: 2026-08-04 (۱۴۰۵/۰۵/۱۳ in the Iranian calendar)
Unofficial translation. This English text is a courtesy translation provided for convenience only. The Persian version at https://legal.tahavolapp.com/fa/privacy.html is the sole binding and governing text; in the event of any discrepancy, the Persian text prevails in matters of interpretation and enforcement. The factual disclosures below — data collected, processors, retention, and your options — describe exactly the same practices as the Persian text.
This document explains what the Tahavol habit app collects about you, why, who it is shared with, how long it is kept, and what control you have. Every statement here is written against the actual behaviour of the software; where the service has a limitation, the limitation is stated plainly.
1) Data controller and contact
- Provider: Masoud Saeedi (natural person, sole proprietor)
- Provider identifier: O2784359
- Address: Attaran, Qom, Iran
- Privacy contact: tahavolapp.com@gmail.com
- Support: tahavolapp.com@gmail.com · +989040683023 · Saturday to Thursday, 09:00-20:00 Iran time
2) Honest summary — eight things to know before you sign up
- Sign-in is by mobile phone number and a one-time code only. The phone number is the single mandatory piece of account data.
- The "backup" feature means you give us another person's phone number and we send them SMS. Read section 4 in full.
- Your habit titles can be included in that SMS to the third party. Read section 5 in full.
- Your profile picture is stored at a public, stable URL. Section 6.
- Scheduled automatic deletion applies to three technical data categories only; everything else is kept while the account exists. Section 10.
- Account deletion has no automatic in-app path; it is performed manually on your request. Section 13.
- "Delete habit" in the app is actually an archive — that habit's history stays in your account. Section 12.
- There is no automated data-export tool today; export requests are fulfilled manually. Section 12.
3) Data we collect
3-1) Data you enter
| Category | Items | Mandatory | Purpose |
|---|---|---|---|
| Account identity | Mobile phone number in international format | Yes | The only account identifier and the only way to sign in |
| Profile | First name, last name, email, gender, birth date, occupation, education level, profile picture | No | Personalisation and the profile-completion reward |
| Time zone | Device time-zone identifier | Yes | Computing the daily deadline and the logging window |
| Habit content | Title, description, schedule, duration, daily log notes | Yes for every habit you create | The core function of the service |
| Backup contact | A third party's mobile number and an optional name | Only if you enable it | Section 4 |
| Support | Ticket subject and body, attachments including images, audio, video and documents | Only if you open a ticket | Answering and tracking your issue |
3-2) Data the service generates while running
| Category | Items | Purpose |
|---|---|---|
| Financial | Wallet balance, the coin transaction ledger, coin purchase records including the store receipt token, gateway payment records including the reference id, discount-code use | An auditable record of every coin movement and dispute resolution |
| Sign-in and sessions | One-time-code request records containing the phone number, a keyed hash of the code and the attempt count; hashes of session tokens together with a device identifier | Sign-in security, abuse detection, sign-out from all devices |
| Device technical | App version, platform, device identifier, requested language | Version support, mandatory updates, diagnostics |
| Notifications | Device notification token and the text of notifications generated for you | Delivering notifications and showing your notification inbox |
| Integrity signals | Device boot-session identifier, device-uptime delta, client timestamp | Preventing device-clock manipulation used to log fake progress |
| Service technical | Duplicate-request prevention keys — the scope of such a key can be your phone number, and the stored response can contain your profile | Preventing a financial operation from being recorded twice |
3-3) IP address
Your IP address is not stored in the Tahavol database; it is used only as a temporary in-memory partition key for request rate limiting. It may be recorded briefly in server and hosting-proxy technical logs for diagnostics and security. Technical logs are rotated and purged periodically.
4) Backup contact — third-party personal data
The "backup" feature lets you enter another person's mobile number so that they are informed if you fail to keep your commitment. This is the most sensitive data flow in the whole service.
4-1) What is stored
- The backup's contact number and name are stored encrypted with AES-GCM.
- A keyed blind index is stored alongside so the service can tell whether a contact was already used, without decrypting it.
- The backup's contact details are never returned to you by the service; the app only knows that a backup is active.
4-2) What the SMS reveals
Three kinds of message may be sent: an invitation the first time, a missed-day warning on the day your absence begins, and a failure notice on the eighth day. Their text discloses to the recipient:
- Your name — and if you have not entered a name, your mobile phone number in local form
- That you use Tahavol
- Up to two of your habit titles, plus a count of the remainder if there are more
- That you did not keep your commitment today, or that your commitment has failed
4-3) Four limitations you must know
- A backup is permanent. Once enabled there is no in-app path to remove or replace it.
- Their consent is not recorded. The service does not verify the number or the consent of its owner; obtaining permission is solely your responsibility.
- The SMS carries no unsubscribe keyword. There is no stop keyword and no suppression list. The only route is for them to contact us — section 17.
- No correction SMS is sent. If a missed day of yours is later restored under the in-app force-majeure rule, the message already sent to your backup is not corrected or retracted.
4-4) If you were made someone's backup and object
If you received an SMS from Tahavol and do not want to be anyone's backup, tell us at tahavolapp.com@gmail.com or +989040683023. We will remove your number from the backup list and no further message will be sent to you. You do not need to be our user for this.
5) Important warning about habit titles
The title you give a habit is free text and may be sent verbatim in the backup SMS to a third party. Each habit has a "hide the title in SMS" option which makes that habit only ever counted, never named — but that option is off by default.
So if a habit relates to a medical, pharmaceutical, religious, financial or otherwise private matter, either do not put that in the title, or turn the hide-title option on before enabling a backup.
6) Your profile picture is at a public URL
The profile picture you upload is stored in cloud object storage at a stable, unsigned URL that anyone can read. Anyone who has that URL can view the image, even if they are not an app user. Using "remove picture" in the app genuinely deletes the stored object, but a cached copy may persist in content-delivery networks for a while.
Support-ticket attachments, unlike avatars, are private and are only retrievable through a short-lived signed URL.
7) What we do not collect
- National ID, card numbers or any banking credentials — payments happen on the payment gateway and your card details never reach our servers
- Your device contacts, your messages, your browsing history
- Location
- Biometric data such as fingerprint or face
- Advertising identifiers; the app contains no advertising SDK and no third-party analytics tracker
8) Sharing with processors
Your data is not sold and is not made available to anyone for advertising. It is shared only with these processors, only to operate the service:
| Processor | What reaches them | Why |
|---|---|---|
| Kavenegar — SMS provider | The recipient number and the one-time code; and for a backup SMS: the backup's number, your name or number, and your habit titles | Delivering the sign-in code and the backup SMS |
| ArvanCloud — cloud object storage | The files you upload and their original filenames | Storing profile pictures and attachments |
| Cafe Bazaar and Myket | The product identifier and the purchase receipt token | Verifying in-app purchases |
| ZarinPal — payment gateway | Merchant id, amount, currency, a static description, the return URL. Your phone number, email and national ID are not sent | Payment in the direct-install build |
| Google and Apple — push services | The device notification token and the notification text. This traffic passes through an egress proxy | Delivering notifications. Push notifications are not enabled in the current Iranian-market build |
| Technical monitoring service | Logs and request traces. When monitoring is enabled, some log lines can contain a phone number | Diagnostics and service-health monitoring |
In addition, information is provided where a competent judicial authority lawfully requires it.
9) Where data is held
The primary database and file storage for the Iranian build are hosted on cloud infrastructure inside Iran. The exceptions — data that leaves the country — are the Google and Apple push services together with their egress proxy, and, when enabled, the technical monitoring service.
10) Retention
Scheduled automatic deletion applies today to these three categories only:
| Data | Retention |
|---|---|
| One-time-code request records | One hour after expiry |
| Duplicate-request prevention keys | 24 hours |
| Sent outbound message-queue rows | Seven days |
- Everything else — profile, habits and performance history, the wallet ledger, purchase records, tickets and attachments, notification tokens — is retained while the account exists, and is deleted or anonymised on account deletion under section 13.
- Financial and payment records are kept for up to one year even after account deletion, for accounting obligations and dispute resolution.
- If an SMS permanently fails to send, its queue row remains for manual review.
- Database backups may contain a copy of deleted data until their normal rotation.
11) Security
- All traffic between the app and the server is protected with TLS.
- One-time codes are stored as a keyed hash with a server-side pepper; the raw code is never stored.
- Session tokens are stored hashed, and if one token is reused the whole session family for that device is revoked.
- Access tokens are short-lived and must be refreshed frequently.
- Backup contact details are encrypted with AES-GCM and their lookup index is hashed with a derived key.
- Every money path acquires a per-user exclusive lock before reading a balance, so two concurrent operations cannot corrupt it.
- Rate limiting is applied to sign-in, code requests and other sensitive paths.
- External providers such as SMS and payments are fail-closed in production: if they are not configured the operation is rejected, never silently skipped.
- Administrative access is separated from ordinary user access and sensitive roles are restricted.
No system is perfectly secure. If you see any sign of unauthorised access to your account, sign out of all devices immediately and tell us at tahavolapp.com@gmail.com.
12) Your rights and how to exercise them
| Right | How it works today |
|---|---|
| See your account data | The profile screen in the app |
| Correct it | Profile editing in the app |
| Clear optional fields | Edit your profile and leave optional fields empty. Saving a profile is a full replacement, so a field you send empty is cleared |
| Remove your profile picture | "Remove picture" in the app — the stored object is genuinely deleted |
| Stop notifications | Remove the device from the notification list in the app, or turn off app notifications in your device settings |
| Set a habit aside | "Delete habit" in the app is actually an archive: it leaves the active list, but its history, performance records and backup details stay in the account. Full erasure happens only through account deletion |
| Get a copy of your data | No automated tool exists. On a support request, a list of your account data is compiled manually and delivered to the registered phone number |
| Delete your account | Section 13 |
Note: a habit that carries an active stake cannot be archived; you must first exit that contract.
13) Account deletion
Account deletion has no automatic in-app path; it is performed manually on your request. The steps, prerequisites, timing and the exact table of what is deleted versus retained are on the account deletion page.
14) Children and teenagers
The minimum age for using Tahavol is 13, and financial actions in the app — buying coins and placing a stake — require being 18 or older. Because entering a birth date is optional, we do not verify your age and rely on your own declaration; if you do enter a birth date showing an age under 13, it is rejected.
If we learn that an account belongs to a child under 13, we disable the account and delete its data. Parents and guardians may request a review at tahavolapp.com@gmail.com.
15) Security incidents
If an incident affects your personal data, then after containing it and assessing its scope we will inform affected users through the app and the registered phone number, describing the nature of the incident, the data involved and the recommended action.
16) Changes to this policy
- Every material change is published with a new version number and effective date, and announced in the app.
- The current version is always at https://legal.tahavolapp.com/en/privacy.html.
- Superseded versions are kept in the archive area of the same address so you can tell which text governed on a given date.
17) Contact and complaints
- Privacy matters: tahavolapp.com@gmail.com
- General support: tahavolapp.com@gmail.com · +989040683023 · Saturday to Thursday, 09:00-20:00 Iran time
- Postal address: Attaran, Qom, Iran
Please ask us first. If our answer does not satisfy you, you may approach the competent supervisory bodies, including the consumer-protection organisation and the authority handling complaints about internet businesses.