Privacy policy
Last updated: 10 September 2026
This is a translation for convenience. The Arabic version of this page is the binding one; if the two differ, the Arabic text prevails.
Reading on Mulhm needs no account and is not recorded under your name. What we collect when you create an account is set out here in full — including what stays in your browser alone and never reaches us.
The short version
- Reading without an account collects nothing about you — no network address and no browser fingerprint.
- We do not sell your data, do not share it for marketing, and do not hand it to an advertising broker.
- There are no ads on the platform, so there are no ad trackers and no ad broker.
- Visit measurement does not run without your consent, and one press declines it — and you may change your mind at any time.
- Your account is deleted on your request, and with it your saved stories, your likes, your ratings, and your submissions.
- Your password never reaches us at all — we neither see it nor store it.
Reading without an account
You open pages, read, print, download a copy, and play the audio, and we link none of that to your name. Visit measurement does not run until you consent to it — the detail is under “Visit measurement” below.
The only thing counted is the story’s read counter: a single number on the story itself that goes up by one. Nothing is stored with it about who read, or when, or from where, and it cannot be traced back to a person. Your browser stores a temporary marker so that one story is not counted twice in a session — that marker is in your browser, not with us, and it disappears when you close the tab.
When you create an account
Accounts are managed by Firebase Authentication from Google. If you register with an email address and a password, the password goes to them directly, hashed; it does not pass through us and we cannot read it. If you sign in with a Google account, there is no password here at all: we receive your email address and your display name from Google.
Facebook sign-in will be added, and it works the same way as Google: we receive your email address and display name from the provider and nothing else. We do not ask for your friend list, your posts, or your photos, and we write nothing to your account there.
In the Mulhm database we keep one row for you: your Firebase identifier, your display name, your role (reader or editor), and the date the row was created. That row holds no email address, no password, and no photo.
What is saved by your own action
- Saved stories — that your account saved this story and when, so you find it on all your devices. No one else sees them.
- Likes — that your account liked this title. Liking is for signed-in readers only, so someone reading without an account sees the count but cannot like.
- Ratings and reviews — your stars and your text if you wrote one, with its date and its status.
- Submissions — the story you wrote, with your name, your email address, the section you chose, and your attachment if you added one.
- A message from the contact page — your name, your email address, and the text of your message.
None of this is gathered automatically: every item is something you do by hand and see on the screen.
Likes — and what was removed
Liking is now an account feature rather than a visitor action, and the key that prevents duplicates is your account identifier. So we store nothing in your browser for it, and we do not touch your network address.
It was open to visitors in an earlier version, and a random token was stored in the browser alongside a hashed fingerprint of the network address. Both are gone: no token remains in your browser, and no network address is counted in a new like. The older like rows remain, because they are counts readers see on the stories, and they are attributed to no one.
Reviews — read before they are published
The text of a review is read by an editor before it appears to people, and so is your rating if you send them together. The reason is that many of our stories are religious or historical, and a text published unread may attribute to the faith what is not sound.
You always see your review and its status on the story page, and you may edit it or delete it. Deleting it removes its row from the database and takes your rating out of the story average.
Submissions and attachments
A submission requires an account, and its author is read from the session rather than from a form field. We keep its row with its status — under review, accepted, or rejected — because your page cannot tell you “rejected, and here is why” about a row that has been removed. The row stays so that you can see it, not so that we can.
The attachment is kept in a private store that can only be read through a short-lived signed link the server issues when it is opened in the editing panel — so it has no permanent link, and it does not reach anyone without permission.
We tell you the decision on your submission by email: accepted, or rejected with its reason, and likewise the outcome of a withdrawal request.
The email newsletter
Subscription is immediate: whoever enters an email address in the newsletter form is subscribed at that moment, with no confirmation email. Every message carries an unsubscribe link of your own that works at once and without signing in.
Unsubscribing deletes your row rather than merely flagging it: keeping an address in our table after its owner asked for it to be removed cannot be justified.
The subscription form does not disclose the state of an address: its reply is the same whether you are subscribed or not — so that it cannot become a tool for finding out who subscribed.
Visit measurement
We want to know which stories are read and where readers arrive from, so that we write more of what helps. For that we use Google Analytics — with your consent alone.
Before you consent, nothing of it is loaded at all: no script, no cookie, and no network request to Google. That is stricter than the “consent mode” many sites run in a denied state, where the script still runs on the page of someone who declined.
If you do consent, what reaches Google is:
- The pages you opened, their order, and how long you stayed on them.
- Where you arrived from — a search engine, a link on another site, or a direct visit.
- Your device type, browser, and language, and your approximate country and city from your network address.
- A cookie in your browser that recognises you as the same visitor between one page and the next and between one visit and another.
What does not reach it is your name, your email address, your saved stories, or anything you wrote, and we do not link what it measures to your account with us. We ask it to mask the last part of your network address (anonymize_ip). We do not use it for advertising and we do not sell what is in it.
And you may withdraw your consent whenever you wish — from here, or by clearing this site’s data from your browser. Declining takes nothing away from the site: reading, accounts, saved stories, and the newsletter are unchanged.
The story read counter you see on the page has nothing to do with this: it is counted on our own server, and it works whether you consented or declined — and it is a number that traces back to no one.
What stays in your browser
- Your sign-in session — managed by Firebase. If you ticked “remember me” it persists between visits; otherwise it ends when you close the tab.
- Your choice of dark or light mode.
- A marker for a story read in this session — so the counter is not counted twice. It disappears when you close the tab.
- Your answer to the measurement question — “accepted” or “declined”, so the question is not asked again on every page.
- Your language choice (`mulhm_lang`) — two letters and nothing more, `ar` or `en`, so that the site opens in the language you chose on your next visit. It lasts a year, and one press of the language button changes it.
- And if you consented: the Google Analytics cookie (`_ga`) — which is the only thing that reaches Google.
Your measurement answer is kept in local storage, not in a cookie: a cookie is sent to the server with every request, while local storage never leaves your device. Everything in this list is removed by clearing the site’s data.
Your language choice, however, has to be a cookie: our server reads it before any JavaScript loads, so that it knows which language to serve, and local storage never leaves your device so it cannot be read there. It is sent only to our own domains ( mulhm.com and its subdomains), never to a third party, and it carries nothing but the two letters of the language — no identifier, no tracking token, and nothing about you.
Where the data is stored
On Google Cloud: the database on Cloud SQL and the files on Cloud Storage, both in the europe-west1 — Belgium, European Union region. Account data (the email address and the hashed password) is held by Google through Firebase Authentication.
The database has no public address on the internet: only our own server connects to it, over an internal socket, so no one reaches it from the network even holding the password. A daily backup is taken.
Email is sent through Resend, so the address and the message text pass through them for the purpose of sending alone.
Search
Search runs over the stories’ texts, titles, and keywords inside our own database. We index nothing from reader data, and we do not keep what you searched for nor link it to your account.
How long data is kept
- Anything tied to your account stays as long as the account does — and is deleted with it.
- Messages from the contact page stay as long as a reply and its follow-up are needed.
- Your newsletter row stays until you unsubscribe, and is then deleted.
- Published stories remain: they are editorial content that people read, not personal data.
Deleting your account — exactly what is deleted
Deleting your account removes your row from our database, along with your saved stories, your likes, your ratings, your reviews, and the submissions that were not published, and it removes your account from Firebase.
It is in your hands, from the “Delete account” card on your account page, and it happens at once. The steps and exactly what is removed are set out on the data deletion page.
Published stories remain, along with the author name stored on them — separated from an account that is gone. A published story was edited by an editor, attributed to its source, and is read by people; deleting it would break published links and erase someone else’s work.
Your rights
- To request a copy of the data we hold about you.
- To correct your display name from your account page, and your email address from your Google account or through password recovery.
- To delete your account at any time from the “Delete account” card on your account page.
- To unsubscribe from the newsletter from any message you received.
- To object to anything on this page, or to ask about it.
To make a request, write to us from the contact page. We reply within a reasonable time.
Children
Mulhm has a section of children’s stories, and reading it needs no account — so your child can read without creating anything. Accounts are for adults, or under a guardian’s supervision.
We do not knowingly collect data from children. If you learn that an account was created in your child’s name, tell us and we will delete it.
Data security
The connection to the site is encrypted throughout, editing permissions are verified on the server on every request rather than in the browser, and your role is read from the database every time — so revoking a permission takes effect at once. We do not promise absolute security: no one can promise that honestly.
Changes to this policy
If we change what we collect or where we store it, we change this page and update its date above. A substantial change is announced to newsletter subscribers.
A question about this page? Contact us.