Own Hub Get the app العربية

Privacy Policy

Version: 3.0
Effective date: the day this version of the app is released
Applies to: Own Hub for iOS and Android, bundle id com.ownhub.app, and this website.

If the English and Arabic versions of this policy differ, the Arabic version applies.

The short version#

  • Own Hub is a fitness app for women in Egypt aged 18 and over. Membership is for women only, for women’s safety and privacy. To keep it that way, we check your Egyptian national ID card and a live selfie once, when you join.
  • The photographs of your card and your face are never stored. Our server in Frankfurt, Germany reads them in memory and discards them when the check ends. We keep the result for 180 days. We also keep a keyed code made from your ID number, so that one card cannot open two accounts.
  • Your cycle, check-ins, measurements, weight, pregnancy or postpartum stage and allergies stay on your phone, unless you turn on health backup yourself.
  • Once you are verified, your workouts and meals are copied to Google Cloud in Frankfurt, so a new phone does not mean starting again. No other member can see them.
  • To send your sign-in code, your phone number goes to Google Firebase in the United States.
  • We do not sell your data. There are no adverts and no tracking. Usage statistics and crash reports are each sent only if you allow them, and never include your health information.
  • We never use your data to train AI, ours or anyone’s.
  • You can delete your account in the app at any time, and ask us for a copy of your data.

1. Who is responsible for your data#

Controller
Mahmoud Reda, an individual publishing Own Hub in his own name. He is personally responsible for complying with the law.
Address
Egypt
Privacy contact
info@own-hub.app
Personal Data Protection Centre permit
Not yet issued. We will publish the permit number and its expiry date here as soon as the Personal Data Protection Centre issues it.
Data protection officer
Mahmoud Reda acts as data protection officer himself, as the law requires of an individual who holds a permit. Contact: info@own-hub.app

Rahma Mohsen is Own Hub’s founder and coach, and the face of the brand. She is not the controller of your data and has no access to your account data.

The women who review verification cases act on the controller’s instructions and are bound by a written confidentiality agreement.

2. Who can use Own Hub, and why it is for women only#

Own Hub is for women aged 18 or over who hold an Egyptian national ID card. It is a women-only space for one reason: so that women in Egypt can train, follow their bodies and their cycles, and look after their health somewhere they feel safe and their privacy is protected. This reflects the Constitution’s protection of women, of private life, of health and of everyone’s right to sport (Articles 11, 18, 57, 59 and 84). It is not a judgement about anyone else.

Your sex and your age are read from the digits of your national ID number. We never guess them from your face.

We do not knowingly collect data from anyone under 18. If the check shows that you are under 18, your application is refused. The refusal is kept as section 6 describes.

3. What we collect, why, and on what basis#

Each basis below is one that Egypt’s Personal Data Protection Law allows (Law 151/2020, Articles 2, 6 and 12).

3.1 Your account#

  • Your mobile number. Used to create your account and sign you in with a code sent by SMS, and to phone you if you ask a woman reviewer to check you.
  • An account identifier we generate. Used to link your data to your account.
  • Your language, settings and setup answers. This covers your privacy switches, notification preferences and quiet hours, your goal, where you train, your equipment, your training days and minutes, and your dietary preferences. Used to run the app the way you set it.
  • Basis: performing our agreement with you (the Terms of Use).

3.2 Your agreements#

When you sign up, we record which versions of the Terms of Use and this policy you accepted, in which language, from which app version, and when. We keep a similar record for each separate consent you give: the identity check, health backup and a review by a woman.

  • Basis: a legal obligation. The Executive Regulations of the Personal Data Protection Law require us to keep a record of each consent, with its date and form.

3.3 Checking that you are a woman aged 18 or over#

This happens once, when you join, and only after you have read a separate screen and agreed to it. The camera does not start until our server has recorded that agreement. The camera is the only way to take the photographs: the app cannot upload a picture that is already on your phone.

  • Photographs of the front and back of your ID card. Sent over an encrypted connection to our server in Frankfurt, Germany. Google Cloud Vision reads the text on the card through its European Union endpoint. The images are not stored anywhere.
  • A short live selfie, taken while you follow prompts chosen by our server. It checks that a live person is present and that the face matches the portrait on the card. The comparison runs on our own server, with no outside face recognition service. We do not store the selfie or any face measurement.
  • Your national ID number. Used to confirm your sex (from the digit the Civil Status authority sets in the number) and your age (from the birth date encoded in it). It is then turned into a one-way keyed code, with a secret key held separately in Google Secret Manager. The number itself is not stored.
  • Your name and date of birth as printed on the card. Read only to cross-check the number, and not stored.
  • The result: approved, refused, or sent to a woman reviewer. It comes with reason codes, coarse score bands (never raw scores), the attempt number and the dates. The app shows you whether your check is pending, approved, refused or ready to try again.
  • Fraud signals: a count of failed attempts for each ID code; and a scrambled code for the app installation, together with the last ID codes tried from it, so that one installation trying many cards can be noticed.
  • Basis: your explicit consent, given in writing on the screen before the camera opens. The face match is biometric data, which the law treats as sensitive. Because a face match is sensitive data, the law also requires a permit from the Personal Data Protection Centre. Ours is shown in section 1.
  • You can refuse. If you do, you can still ask a woman reviewer to check you (section 3.4). Without a check you cannot open a verified account, because a women-only membership is the purpose of the service.

3.4 Review by a woman#

Your case goes to a woman reviewer in four situations: the automatic check is unsure; you wear niqab and prefer a woman reviewer; you decline the camera; or the check cannot run for a technical reason.

  • Your request. When you ask for this, we record your request and the route you chose (section 3.2).
  • The queue. The review queue holds reason codes and score bands. It never holds a photograph or your phone number.
  • The contact. A woman from Own Hub reviews your case. When she is ready to contact you, she looks up your number at that moment. Each lookup is recorded with the reviewer and the time. She phones you within 72 hours of your request to finish your check with you. There is no video call.
  • Nothing is recorded. The check is not recorded, and the reviewer writes down only her decision and the date.
  • Your ID number. If your case has no ID code yet, the reviewer may ask you to read out your ID number. It is turned into the keyed code at once, and is never stored or written to a log.
  • Our team’s alert. When a case enters the queue, our team gets an alert containing only the case number and the reason codes. It is sent through a team chat service.
  • Basis: your consent, given when you ask for the review.

3.5 Your training and meals#

Workouts, sets, weights and repetitions, weekly goals, personal bests, the meals you log, your usual plates, your protein target and your meal plans stay on your phone. Once your account is verified, a copy is also kept in Google Cloud Firestore in Frankfurt, Germany, so that it survives a lost or replaced phone. Server security rules let only your own verified account read it. No other member can see it.

Your Ramadan setting stays on your phone only.

If you add an Own Hub widget to your Home Screen or Lock Screen, it shows how many sessions you have done this week, whether today’s workout is done and whether you have logged a meal, and nothing else. The widget reads this from your phone. It never shows your cycle, pregnancy or postpartum stage, weight, measurements or allergies, and nothing is sent anywhere. Signing out or deleting your account clears it.

  • Basis: performing our agreement with you.

3.6 Your health information stays on your phone#

By default, these are kept on your phone only: your cycle settings and period days; your daily check-ins (for example energy, sleep, bloating, pain and bleeding); your body measurements and weight; your life stage (pregnancy, postpartum or training around an injury); and the allergies you tell us about.

You can choose to back them up. In Profile, then Privacy, Back up my health data asks for a separate consent. That consent names this information and the countries where it would be stored. Nothing is copied until our server has recorded the consent, and our server’s security rules refuse the copy without it. If you turn backup off, we delete the copy on our servers straight away. The copy on your phone stays.

Your cycle and health information is never used for advertising or marketing, never sold, never sent to any analytics service, and never used to train AI.

  • Basis: your explicit consent, given in writing in the app, which the law requires for health data, and our permit from the Centre (section 1).

3.7 Technical data#

  • Sign-in security. When you sign in, Google Firebase Authentication receives your IP address and device details. To stop abuse of text messages, Firebase may confirm that the request comes from a real device, using Google Play Integrity, an Apple push notification, or a reCAPTCHA check page.
  • Genuine-app check. From the first time you open the app, Firebase App Check uses Google Play Integrity (Android) or Apple App Attest (iOS) to confirm that requests come from the real Own Hub app. Firebase gives the installation a random identifier for this.
  • Selfie guidance. Google ML Kit detects your face on the phone to guide the selfie camera. Your images do not leave the phone through ML Kit. ML Kit sends Google the device model, operating system, app version, an installation identifier and performance events.
  • Crash reports, only if you allow them. You can allow them on the sign-up screen, or later in Profile, then Privacy. They are off until you do. What Firebase Crashlytics receives when the app crashes: the type of error and where in the code it happened, the screen it happened on (shown as “private” for screens about your body or your cycle), your device model, operating system, app version, free memory and storage, and an installation identifier. It also receives a report when one of our servers fails in a way that is our fault, with only the error’s status code. If you have also turned on usage statistics, the last screens and steps you used are shown with the report. What is never attached: your account identifier, your name, your phone number, or the text of any error. If you turn them off, reports waiting on your phone are deleted.
  • Usage statistics (“Help improve Own Hub”), only if you allow them. A separate switch on the sign-up screen and in Profile, then Privacy. Off until you turn it on. When it is on, Google Analytics for Firebase receives which screens you open (by a short screen code such as “T01”) and which steps you reach: the tour, each sign-up step, whether the ID check started, went to a reviewer, asked for new photos, let you in or was refused (one word, never why), your first workout and meal, reaching your weekly target, coming back after a week or more away, and your language and kitten settings. Google adds a random app instance identifier, your device model, operating system and app version, and an approximate location it works out from your IP address. It never receives your health information, cycle, body measurements, weight, life stage, pregnancy, allergies, name, phone number, ID number, anything you type, or the names of recipes or programmes. We do not give it your account identifier and do not link what it receives to your account. We never use it for advertising: there is no advertising identifier, and advertising uses are switched off. If you turn it off, collection stops at once and the identifier on your phone is reset, so what was sent before cannot be joined to anything sent later.
  • Our server logs. These record outcomes and reason codes. They never record your phone number or your ID number, and they never place your account identifier beside an outcome.
  • Basis: keeping the service secure and working, which the law allows (Law 151/2020, Article 6, point 4), except crash reports and usage statistics, which each need your consent. ML Kit runs only on the selfie screen, after you have agreed to the check.

3.8 Artificial intelligence#

  • We never use your data to train AI models, ours or anyone’s.
  • Google Cloud Vision reads the text on your ID card only to run the check. It reads the card in memory and does not keep the image. Under Google Cloud’s terms, Google may not use that data to train its own models.
  • The face comparison uses open-source models that run on our own server. Their authors trained them before Own Hub existed. They are not trained or adjusted with your face.
  • There is no AI assistant in this version of Own Hub. If we add one, we will ask for your separate agreement first, naming the provider, before anything is sent to it.

3.9 Messages you send us#

If you write to us, we keep your message and your email address so that we can answer you. These are deleted 1 year after the conversation ends.

3.10 The waitlist and this website#

If you joined the waitlist on this website, we keep the mobile number or email address you gave, the language you chose, your agreement and the date you joined.

  • We use it for one thing: to message you once. If you are among the first 100 to join, the message invites you to try Own Hub before it opens to everyone; otherwise it tells you the day it opens. Then we delete it.
  • If that has not happened, it is deleted automatically 180 days after you joined.
  • So that we can prove you agreed, we keep a keyed code made from your contact, the version of the wording you agreed to, and the date, for 3 years after the last message we send you.
  • To protect the form from abuse, we keep a keyed code made from your internet address (never the address itself) and a count of attempts from it. Both are deleted after two days.
  • It is all stored in Google Cloud Firestore in Frankfurt, Germany. To leave the waitlist sooner, write to info@own-hub.app.

This website sets no cookies, runs no scripts and counts no visits. The company that hosts it, listed in section 4, receives the standard data any website receives, such as your IP address and browser type, in order to deliver the pages.

4. Who handles your data, and where#

We do not sell your data, and we do not share it with advertisers, data brokers or marketing companies. The service providers below process data only on our instructions. Google processes data for us under the Google Cloud Data Processing Addendum and the Firebase Data Processing and Security Terms. Google Analytics processes usage statistics for us under the Google Ads Data Processing Terms, with data sharing with Google, Google signals and advertising links all switched off.

  • Google Firebase Authentication

    Handles
    Your phone number, IP address and device details
    Where
    United States
  • Your mobile operator and Google’s SMS partners

    Handles
    Your phone number and the sign-in code
    Where
    Egypt, and the route Google uses
  • Google Cloud Firestore, Cloud Functions, Cloud Storage and Secret Manager

    Handles
    Your account, training and meals, health information if you turn on backup, verification results and the keyed ID code
    Where
    Frankfurt, Germany (europe-west3)
  • Google Cloud Vision

    Handles
    The text on your ID card, during the check only
    Where
    European Union
  • Google Play Integrity, Apple App Attest, reCAPTCHA, Firebase App Check

    Handles
    Confirmation that the app and the device are genuine
    Where
    Google data centres worldwide, which include the United States, and Apple servers for App Attest
  • Google ML Kit

    Handles
    Device and performance data (section 3.7)
    Where
    Google data centres worldwide, which include the United States
  • Firebase Crashlytics, only if you allow it

    Handles
    Crash data (section 3.7)
    Where
    Google data centres worldwide, which include the United States
  • Google Analytics for Firebase, only if you allow it

    Handles
    Usage statistics (section 3.7)
    Where
    Google data centres worldwide, which include the United States
  • A team chat service

    Handles
    A case number and reason codes only
    Where
    the chat service's servers, which may be outside Egypt
  • Zoho Mail (Zoho Corporation)

    Handles
    Messages you send us
    Where
    Zoho data centres, which are outside Egypt
  • Cloudflare Pages (Cloudflare, Inc.)

    Handles
    Standard website request data
    Where
    Cloudflare's global network of data centres, which includes the United States

We may also disclose data where Egyptian law requires it, for example in answer to a lawful order from a court or a competent authority. If Own Hub is ever transferred to another publisher, we will tell you in the app before it happens, ask for your consent where the law requires it, and the new publisher will need its own permit from the Personal Data Protection Centre.

5. Transfers outside Egypt#

Your data is stored and processed outside Egypt:

  • Germany and the European Union: your account, your training and meals, any health backup, and your verification.
  • The United States: your phone number, for sign-in.
  • Google data centres worldwide, which include the United States: the device checks, ML Kit performance data, crash reports if you allow them, and usage statistics if you allow them. Google does not let us choose one country for these.

Egypt’s Personal Data Protection Law No. 151 of 2020 allows transfers abroad only under a permit from the Personal Data Protection Centre, and with your consent. We ask for that consent on the sign-up screen, naming these countries, before your phone number is sent. We ask again, separately, before any health information is backed up. Usage statistics have their own consent, the “Help improve Own Hub” switch, which names Google Analytics and says the data may be processed outside Egypt. Nothing is sent before you turn it on.

Permit: Not yet issued. We will publish the permit number and its expiry date here as soon as the Personal Data Protection Centre issues it.

Safeguards: Germany and the European Union: Google Cloud in Frankfurt (europe-west3) and the Cloud Vision EU endpoint, where Google stores and processes data only in the EU. The United States: Firebase Authentication, which Google runs only from US data centres. Google data centres worldwide, which include the United States: Firebase App Check, Google ML Kit performance data, Firebase Crashlytics if you allow it, and Google Analytics for Firebase if you allow it. Google does not let us choose one country for these. Also outside Egypt: Zoho Mail keeps the emails you send to info@own-hub.app or support@own-hub.app in Zoho data centres, and Cloudflare serves this website from its global network, which includes the United States. Each transfer needs your consent, which we ask for before it happens, and our transfer permit from the Personal Data Protection Centre. Google acts only on our instructions under its data processing terms, encrypts the data in transit and at rest, and may not use it to train AI models. The Centre has not yet published a list of countries it considers adequate.

6. How long we keep it#

ID card photographs, selfie, name and date of birth from the card, your raw ID number
Never stored. Discarded from memory when the check ends, whatever the result.
The single-use selfie session
5 minutes, then deleted automatically
Verification result and review case
180 days after the case is decided, or earlier if you delete your account. A case still waiting for review is kept until it is decided.
The keyed code of your ID number
While your account exists. After you delete your account it is closed, not deleted: it is no longer linked to any account, it is kept with no end date, and the same card cannot be used to open a new account.
Count of failed attempts per ID code, and the scrambled installation record
180 days after the last attempt. Not linked to your account.
Reviewer access log (which reviewer opened which case, and when)
1 year. It holds no photograph, phone number or ID number.
Your account, settings, training, meals, any health backup and your consent records
Until you delete them or delete your account
The record that a deletion was carried out (status and dates only)
3 years, as proof that your request was honoured
Daily totals of verifications, with no link to any person
Kept
Our server logs
30 days
Crash reports, if you allow them
90 days, after which Google starts removing them from its live and backup systems
Usage statistics, if you allow them
2 months for anything tied to the app instance identifier, the shortest Google Analytics allows, then deleted automatically. Counts that are not linked to any person, such as how many people finished the tour, are kept.
Messages you send us
1 year
Waitlist contact
180 days at most. The proof that you agreed is kept for 3 years after the last message we send you (section 3.10).
Backups held by Google
Removed within about 6 months (180 days) of deletion

7. Deleting your account#

In the app: Profile, then Your data, then Delete everything. You do not need to be verified to do this.

  • Our server locks your sign-in first.
  • It then deletes your account and the data in section 3, and deletes your sign-in record, including your phone number, last.
  • Your phone is cleared at the same time.
  • It usually takes under a minute. If anything interrupts it, it finishes on its own within the hour.

Without the app: use the deletion page on this website. It explains how to ask by email. We confirm that the request comes from the owner of the number on the account (a one-time code we send by SMS to that number, which you send back to us), then delete within 6 working days of your request and confirm in writing.

What remains after deletion, on purpose:

  • the closed keyed code of your ID number (section 6);
  • the failed-attempt count and the installation record, until their 180 days end, linked to no account;
  • reviewer access log entries for your case, until their year ends;
  • the record that the deletion was carried out.

Crash reports, usage statistics and ML Kit data are never linked to your account. Deleting everything also turns usage statistics off and resets the identifier on your phone. Google deletes this data on the schedule in section 6.

Deleting only part of your data:

  • turn off health backup (this deletes the cloud copy);
  • delete your cycle data on its own, from cycle settings;
  • remove items from a day’s log, and delete individual measurements.

8. Your rights#

Under Egypt’s Personal Data Protection Law No. 151 of 2020, you have the right to:

  • know what personal data we hold about you, and get a copy of it;
  • have it corrected or completed;
  • have it erased;
  • withdraw your consent at any time, without affecting processing that took place before. You can turn off crash reports, usage statistics and health backup yourself in Profile, then Privacy;
  • object to processing, or ask us to restrict it;
  • be told of any breach of your personal data.

A copy of your data:

  • How to ask: in the app (Profile, then Your data, then Ask for a copy), or write to info@own-hub.app.
  • What you get: a file a computer can read, plus a summary in your language.
  • How you get it: by email to the address you wrote from, as a password-protected file. We send the password separately, by SMS to the number on the account.
  • Health information that is only on your phone is not held by us. You can see it in the app.

Response time: we answer every request within 6 working days. Requests are free.

Complaints: if you are not satisfied with our answer, you can complain to Egypt’s Personal Data Protection Centre: Website portal.pdpc.gov.eg · email info@pdpc.gov.eg · hotline 17372.

9. Security#

  • Sign-in uses a one-time code sent to your phone. There is no password to steal.
  • Data travels over encrypted connections, and Google encrypts it where it is stored.
  • Server rules let your account read only your own data, and the app cannot mark itself as verified. Only our server can do that.
  • We never write verification images to disk, logs or storage.
  • The secret key behind the ID code is held in Google Secret Manager, separate from the database.
  • Access to our systems is limited to the people who run Own Hub, and every lookup of a phone number for a review is recorded.
  • No system is perfectly secure. If a breach affects your personal data, we will notify the Personal Data Protection Centre within 72 hours of becoming aware of it, and tell you within three working days after that, by SMS or email.
  • The publisher, who runs Own Hub’s systems, can technically reach stored data. He opens an individual account’s data only to answer your request, to fix a fault, to investigate misuse, or when the law requires it.

10. What Own Hub does not do#

  • No adverts, no advertising identifiers, and no tracking across other apps or websites.
  • No analytics unless you turn on usage statistics, and never of your health information.
  • No sale of your data.
  • No training of AI on your data.
  • No access to your contacts, location, photo library, microphone, text messages, or Apple Health or Health Connect. The app itself never uses your microphone, and there is no video review.
  • Nothing that guesses your sex, age or anything else about you from your face.

11. Children#

Own Hub is not for anyone under 18. We do not knowingly keep data about children. If you believe a child has an account, write to us and we will delete it.

12. Changes to this policy#

We publish every change here, with its date and version.

  • Material changes require your agreement in the app before they apply to you. A material change is one that collects something new, uses your data for a new purpose, adds a new country or a new kind of provider, or reduces your rights.
  • Other changes are announced in the app.

Version history:

  • 3.0, update before release: usage statistics with Google Analytics for Firebase, only with your separate consent (“Help improve Own Hub”), and more detail on what a crash report carries.
  • 3.0, minor update: section 3.5 now describes the Own Hub widgets. They collect nothing new, so you are not asked to accept again.
  • 3.0, the day this version of the app is released: acceptance recorded at sign-up, crash reports by consent, AI statement, full retention periods, copy of your data on request.
  • 2.0, 24 September 2026: accounts and the women-only check.

13. Language#

This policy is published in Arabic and English. If they differ, the Arabic version applies.

14. Contact#

info@own-hub.app · Mahmoud Reda, Egypt