Hala Privacy Policy

Version: 0.1 (beta) · Effective: 2026-09-08 · Applies to: the Hala iOS beta distributed through TestFlight Contact: hala.support[at]gomoblaqo.com Online: https://myhala.app/privacy

Draft status. Written for the TestFlight beta and not reviewed by counsel.
The PDPA programme (register.md §6) is tagged [KV-GA] and remains open.
This document is what testers are entitled to now, not the final policy.

Who we are

Hala is a navigation app for drivers and motorcyclists in Malaysia, made by Faris Hassani. During the beta it is operated by one person, not a company.

What this covers

The Hala iOS app, the Hala service at alerts.gomoblaqo.com, and the pages at myhala.app. A trip you share is shown on a page at myhala.app, served by that same service.


What we collect

Your location. Hala reads your position while you use it. It keeps reading it in the background while it is guiding you or sharing your trip, which is what keeps directions and hazard warnings coming with the screen off. When you are doing neither, it stops. Your position draws you on the map, plans routes, and decides which alerts are ahead of you.

Your start and destination are sent to a routing engine, and points along your route are sent to a map-data service to look up speed cameras. Which engine depends on whether you are signed in. The section "Who else sees anything" below lists all of them.

Reports you make. When you report a hazard, a camera, an animal or an accident, we store what you reported and where. This is the point of the app: other riders are shown it.

Your account. Signing in with Apple is needed for weather along your route, for community alerts, and for reporting anything. The map, search and routing work without an account. Signed out, your routes are planned by a public community routing service rather than ours.

What we store is the identifier Apple gives us for this app, and nothing else: no name, no email address, and no password, which we never see in any case. That identifier is specific to Hala and cannot be used to recognise you in any other app.

It is pseudonymous rather than anonymous. We cannot tell who you are from it, but we can tell that the same account made two reports. If you would rather we could not, delete your data in Settings and the link goes with it.

Diagnostics. If a build crashes, iOS may send us a crash report. If you send feedback, we get what you wrote.

Ride logs, only if you switch them on. Settings → Record rides is off by default. When it is on, a detailed trace of your ride is written to your phone and is not sent anywhere. You can delete it in Settings.

Favourites stay on your phone, in a file the system cannot read while the phone is locked. They are sent to iCloud only if you turn on Settings → Sync favourites with iCloud, which is off by default. That copy goes to your own iCloud account, not to us.

Recent destinations also stay on your phone, but in ordinary app storage rather than the locked-file kind. They are protected by your passcode like the rest of the app's data, and no better than that. Clear them any time from the search screen. (Corrected 2026-09-08: an earlier version of this policy claimed they were in protected storage. They are not, and moving them is on the list.)

The names you give other riders stay on your phone and are never sent to us. Our record of a connection is two anonymous identifiers and a date.

What we do not do


Who else sees anything

Requests to our own server go over HTTPS. We have not yet signed data-processing agreements with these providers. That work is tagged [KV-GA] in our register and is not complete. You should weigh that before joining the beta.


How long we keep it

Your choices

Under Malaysia's Personal Data Protection Act 2010 you may ask what we hold about you, ask us to correct it, and ask us to delete it. Write to the address at the top, replacing [at] with @. It is written that way to keep the address away from scrapers, not from you. We will answer within 21 days.

Children

Hala is not for under-18s and we do not knowingly collect their data.

Changes

Beta testers will be told through TestFlight when this changes materially. The version and date at the top always say which policy is in force.