سياسة الخصوصيةPrivacy Policy
آخر تحديث: ١٥ سبتمبر ٢٠٢٦ · الجهة المشغّلة: MA Productions AE، دبي، الإمارات · تنطبق على موقع وتطبيق صيّادLast updated: 15 September 2026 · Operated by MA Productions AE, Dubai, UAE · Applies to the Sayyad website and app
باختصار — قبل التفاصيلThe short version — before the details
حين تفحص رسالة، يُرسل نصّها إلى خوادمنا لتحليلها، يُحجَب نصّ رسالتك على خوادمنا لحظة وصوله — قبل أن يُخزَّن، وقبل إرسال أي جزء منه إلى أي جهة. ولا يصل مزوّدَ الذكاء الاصطناعي إلا الشكل المحجوب، ومعه وصفُ ما حُجب: نوعُه وعددُه، وبلدُ الرقم دون الرقم. أمّا الشكل غير المحجوب فلا يُكتب في قاعدة بياناتنا، ولا في سجلّاتنا، ولا في تقارير الأعطال. يبقى في الذاكرة ما دام فحصك يعمل، ثمّ يزول معه — ولا يُكتب في أيّ مكانٍ دائم. في التطبيق، صورك لا تغادر جهازك. على الموقع، نرسل الصورة لقراءة نصّها — لا نحتفظ بالصورة ولا بنصّها. الفحص يعمل دون حساب. لا نبيع بياناتك أبداً ولا نعرض إعلانات.When you scan a message, its text is sent to our servers for analysis. Your message text is masked on our servers the moment it arrives — before it is stored, and before any of it is sent onward. Only the masked form reaches our AI provider, together with a description of what was masked: its type and count, and the number's country, not the number. The unmasked form is not written to our database, not to our logs, and not to error reports. It exists in memory for as long as your scan runs, then goes with it — and is not written to any permanent place. In the app, your images never leave your device. On the website, we send the image to have its text read — we keep neither the image nor its text. Scanning works without an account. We never sell your data and we show no ads.
١. من نحن1. Who we are
MA Productions AE، دبي، الإمارات العربية المتحدة. للتواصل: privacy@sayyad.aeMA Productions AE, Dubai, United Arab Emirates. Contact: privacy@sayyad.ae
٢. ما الذي نجمعه، ولماذا2. What we collect, and why
عند الفحص:When you scan something:
- نص الرسالة. وتُحجب الأرقام الحسّاسة على خوادمنا لحظة وصولها، قبل أن تُخزَّن، ولا يُرسَل إلى مزوّد التحليل إلا الشكل المحجوب، ومعه وصفُ ما حُجب لا قيمتُه. نحتاجه لتحليله.The message text. Sensitive numbers are masked on our servers the moment they arrive, before it is stored, and only the masked form is sent to the analysis provider, together with a description of what was masked — its type and count, and the number's country, not the number. We need it to analyse it.
- نوع الفحص (نص، صورة، رابط، QR) واللغة التي تستخدمها.The type of scan (text, image, link, QR) and the language you're using.
- النتيجة — الدرجة، والفئة، والإشارات التي اشتعلت.The result — the score, the category, and which signals fired.
نصّ الفحص لا يُحفَظ مرتبطاً بك افتراضياً. يُستخدَم لإنتاج النتيجة ثم لا يُحتفَظ به منسوباً إليك. و«سجلّ الفحوصات» مُعطَّل افتراضياً؛ إن فعّلتَه بنفسك حفظنا في حسابك نسخةً محجوبة من الرسالة — تفاصيلها الحسّاسة (الرموز، الآيبان، أرقام الهواتف) مخفيّةٌ مسبقاً — لتراجعها لاحقاً، وتبقى حتى تحذفها أنت أو تحذف حسابك.By default, the text of a scan is not kept linked to you. It is used to produce the result and is not retained against your identity. Scan History is off by default; if you switch it on yourself, we keep a masked copy of the message in your account — its sensitive details (codes, IBANs, phone numbers) hidden in advance — so you can review it later, and it stays until you delete it or delete your account.
في التطبيق تُقرأ الصورة على جهازك ولا تغادره. على الموقع نرسلها لقراءة نصّها، والنص وحده هو الذي يدخل الفحص. لا نحفظ الصورة ولا نسجّلها.In the app the image is read on your device and never leaves it. On the website we send it to have its text read; only that text goes into the scan. We do not keep the image and we do not log it.
عند إنشاء حساب:When you create an account:
- بريدك الإلكتروني، لتسجيل الدخول فقط. نستخدم رموزاً لمرة واحدة بدل كلمات المرور.Your email address, used only to sign you in. We use one-time codes rather than passwords.
عند تفعيل الإشعارات:If you enable notifications:
- رمز إشعارات الجهاز، لتوصيل التنبيهات — تنبيهات الحماية العائلية وإشعارات تأكيد حذف الحساب. يعرّف الجهاز لا شخصك.A device push token, so we can deliver alerts — Guardian Mode alerts and account-deletion confirmations. It identifies a device, not you.
تلقائياً:Automatically:
- بيانات تقنية لتشغيل الخدمة ومنع إساءة الاستخدام: عنوان IP (لتحديد المعدّل)، إصدار التطبيق، نوع الجهاز إجمالاً، والتوقيتات.Technical data needed to run the service and prevent abuse: IP address (for rate limiting), app version, coarse device type, and timestamps.
لا نجمع جهات اتصالك، ولا موقعك، ولا رسائلك الأخرى، ولا أي شيء من هاتفك لم تفحصه بنفسك.We do not collect your contacts, your location, your other messages, or anything from your phone that you have not scanned.
٢ب. معلومات الآخرين داخل ما تفحصه2b. Other people's information inside what you scan
الرسالة المفحوصة تحتوي عادةً تفاصيل عن شخص آخر — رقم المرسل، اسم، رابط. نعالج هذه التفاصيل لغرض واحد فقط: تقييم ما إذا كانت الرسالة احتيالاً. لا نستخدمها للتعرّف على أحد أو تصنيفه أو الاتصال به، ولا يُبلَّغ المرسل.A scanned message usually contains details about someone else — the sender's number, a name, a link. We process those details for one purpose only: assessing whether the message is a scam. We do not use them to identify, profile or contact anyone, and the sender is not notified.
٢ج. على الموقع: النماذج ولوحة الصدارة2c. On the website: forms and the leaderboard
البريد في نماذج الموقع: حين تكتب بريدك في نموذج «أبلغني عند الإطلاق» أو نموذج النصائح، يُحفَظ لدى خدمة النماذج التي نستخدمها لغرضٍ واحد فقط: إخبارك بإطلاق التطبيق أو إرسال نصائح أمان مختصرة. لا نربطه بأي فحص أجريته، ولا نبيعه، ولا نستخدمه لغرضٍ آخر، ويمكنك طلب حذفه متى شئت.Email in the site's forms: when you enter your email in the launch-notification form or the tips form, it is stored with our forms provider for one purpose only: to tell you the app has launched, or to send brief security tips. We do not link it to any scan you ran, do not sell it, do not use it for anything else, and you can ask us to delete it at any time.
لوحة الصدارة (لعبة صيّاد): اللعب لا يتطلّب نشر أي شيء. إن اخترتَ نشر نتيجتك، يُحفَظ اسمك المستعار ونقاطك فقط للعرض العام. وإن كنت مسجّل الدخول ربطنا النتيجة بحسابك لتوحيدها عبر أجهزتك — والمعروض للناس يبقى الاسم المستعار وحده.The leaderboard (Sayyad game): playing does not require publishing anything. If you choose to publish your score, only your nickname and points are saved for public display. If you are signed in we link the score to your account so it is consistent across your devices — what is shown publicly is still only the nickname.
٣. ما الذي لا نفعله أبدًا3. What we never do
- لا نبيع بياناتك ولا نشاركها مع معلنين أو وسطاء بيانات. هذا يختلف عن مزوّدي الخدمة الذين نحتاجهم لتشغيل التطبيق — وهم مذكورون بالاسم في القسم ٤، ومنهم مزوّد التحليل الذي يصله نصّ رسالتك.We do not sell your data or share it with advertisers or data brokers. That is a different thing from the service providers we need in order to run the app — they are named in section 4, including the analysis provider that receives your message text.
- لا نعرض إعلانات ولا نستخدم أدوات تتبع إعلاني.We do not show ads or use ad-tracking tools.
- على الموقع، نرسل الصورة إلى نموذج قراءة النصوص، ولا نرسل معها اسمك ولا بريدك ولا ما يعرّفك. لا نحفظها ولا نسجّلها، ونحذفها من طرفنا فور قراءة نصّها. في التطبيق لا نرسلها أصلاً.On the website, we send the image to a text-reading model. We do not send your name, your email, or anything that identifies you along with it. We do not keep it and we do not log it; we delete it on our side as soon as its text has been read. In the app we do not send it at all.
- لا نفتح الروابط المفحوصة — لا على جهازك ولا على خوادمنا. الفحص الوحيد هو التحقّق من وجود النطاق وعمره، كما في القسم ٤ب.We do not open scanned links — not on your device and not on our servers. The only external check is whether the domain exists and how old it is, as described in section 4b.
- لا نطلب أبداً الرابط الموجود داخل رسالةٍ فحصتَها. لا نفتحه، ولا نجلب أيقونته، ولا نتتبّع تحويلاته، ولا نطلب منه معاينةً — فلو فعلنا لأخبرنا خادمَ المحتال أن رسالته وصلت إلى فاحصٍ في توقيتٍ مرتبطٍ بقراءتك لها، ولو حمل الرابط رمزاً خاصاً بك لأكّدنا له وصولها إليك أنت تحديداً.We never request the link found inside a message you scanned. We do not open it, fetch its icon, follow its redirects, or ask it for a preview — because doing so would tell the scammer's server that their message reached a scanner at a time correlated with your reading it, and if the link carried a token unique to you, it would confirm delivery to you specifically.
- لا نربط بريدك في نماذج الموقع بأي فحص أجريته.We do not link your site-form email to any scan you performed.
- لا نرسل رسائل تسويقية ولا نستخدم بياناتك للإعلان. لو تغيّر ذلك يوماً، سيكون باشتراك اختياري ويُطلب منك على حدة.We do not send marketing messages and we do not use your data for advertising. If that ever changes, it will be opt-in and asked separately.
- لا نضع أي كوكيز على الموقع، ولا يستقبل أي مزوّد خطوط زياراتك — الخطوط تُقدَّم من موقعنا. على الموقع، تُرسل الصورة إلى نموذج قراءة النصوص عندنا — وهذا المسار الوحيد. وإن لم تنجح القراءة، ما نفحص، ونقول لك ذلك. في التطبيق، تُقرأ الصورة على جهازك ولا تغادره.We set no cookies on the website, and no font provider receives your visits — fonts are served from our own site. On the website, the image is sent to our text-reading model — that is the only path. If the read does not succeed, we do not scan, and we tell you so. In the app, the image is read on your device and never leaves it.
٤. إلى من تصل بياناتك4. Who your data reaches
لا نبيع بياناتك ولا نشاركها للإعلان. أهمّ ما في هذا القسم سطرٌ واحد، فنبدأ به بدل أن ندفنه في قائمة:We do not sell your data and we do not share it for advertising. The most important thing in this section is one fact, so we lead with it instead of burying it in a list:
نصّ الرسالة التي تفحصها يُرسَل إلى خدمة تحليل نصوص بالذكاء الاصطناعي خارج الإمارات ليُحلَّل. يحدث هذا في كل فحصٍ جديد، وتُحجب التفاصيل الحسّاسة (أرقام البطاقات، الآيبان، الهوية، أرقام الهواتف) على خوادمنا قبل إرسال أي شيء إلى تلك الخدمة — فلا يصلها إلا الشكل المحجوب، ومعه وصفُ ما حُجب — نوعُه وعددُه، وبلدُ الرقم لا الرقمُ نفسه. هذا أكبر ما يغادر خوادمنا على الإطلاق، وأكبر بكثير من رمز الإشعارات أو اسم النطاق المذكورَين أدناه. تعالج الخدمة النص لتعيد لنا تقييماً، وشروط استخدامها التجاري المنشورة تنصّ على ألا تستخدمه لتدريب نماذجها.The text of the message you scan is sent to an AI text-analysis service outside the UAE to be analysed. This happens on every new scan. Sensitive details (card numbers, IBANs, ID numbers, phone numbers) are masked on our servers before anything is sent to that service — it receives the masked form only, together with a description of what was masked — its type and count, and the number's country, not the number itself. This is by far the largest thing that leaves our servers — far larger than the push token or the domain name listed below. The service processes the text to return an assessment to us, and its published commercial terms state that it will not be used to train their models.
إن كان هذا وحده يزعجك، فهو سببٌ وجيه لعدم لصق رسالةٍ تحوي ما لا تريد أن يقرأه طرفٌ ثالث — والحجب على الجهاز يقلّل الضرر ولا يُلغيه.If that alone bothers you, it is a good reason not to paste a message containing something you would not want a third party to process — on-device masking reduces the exposure, it does not remove it.
ولتشغيل بقيّة الخدمة نستعين بالجهات التالية. كلُّ سطرٍ يذكر ما يصل الجهة، وإلى أين يذهب بعدها — أو أنه يتوقّف عندها:To run the rest of the service we use the parties below. Each line says what reaches them and where it goes next — or that it stops there:
- استضافة سحابية وقاعدة بيانات — نص الرسالة، نتائج الفحص، بيانات الحساب. ثم: رسائل رموز الدخول تُسلَّم عبر خدمة إرسال بريد ومنها إلى مزوّد بريدك الإلكتروني. أمّا التخزين وبيانات الحساب فيتوقّفان عند تلك الاستضافة.Cloud hosting and database — message text, scan results, account data. Then onward: sign-in code emails are delivered through an email delivery service and from there to your own email provider. Storage and account data stop with that host.
- توصيل الإشعارات — رمز إشعارات جهازك ومحتوى التنبيه. ثم: تُسلَّم عبر شبكة الإشعارات الخاصة بنظام هاتفك ومنها إلى الجهاز. أي أن مشغّل تلك الشبكة يستقبل التنبيه أيضاً — بعد خدمة التوصيل لا بدلاً منها. يُستخدم هذا المسار لتنبيهات الحماية العائلية ولإشعار حذف الحساب.Push-notification delivery — your device push token and the alert content. Then onward: delivered over your phone platform's push network and from there to the device. So that network's operator receives the alert too — after the delivery service, not instead of it. This path is used for Guardian alerts and for account-deletion notices.
- استعلام DNS — اسم النطاق وحده، من خوادمنا لا من جهازك. ثم: قد يسأل المحلِّل خادمَ أسماء النطاق نفسه — فيرى ذلك الخادم أن أحداً سأل عن نطاقه، دون أن يعرف من. تفاصيل القسم ٤ب.DNS lookup — the domain name only, from our servers rather than your device. Then onward: the resolver may in turn query the domain's own name server, which sees that someone asked about it — without learning who. Details in section 4b.
- سجلّات النطاقات — اسم النطاق وحده، للاستعلام عن عمره. نسأل السجلّ المسؤول عن امتداد ذلك النطاق، ولا يسافر مع السؤال أيُّ شيءٍ عنك.Domain registries — the domain name only, to ask how old it is. We ask the registry responsible for that domain extension, and nothing about you travels with the question.
- تقارير الأعطال — لا تحتوي نص رسائلك. تتوقّف عند مزوّد الخدمة ولا تُمرَّر إلى أحد.Crash reporting — crash reports, containing none of your message text. Stops with that provider and is passed to no one.
- استضافة الموقع ونماذجه — الموقع ونماذج البريد. ثم: ما تكتبه في نموذج الموقع يُحفظ لدى مزوّد الاستضافة ويُرسَل إشعارٌ به إلى بريدنا. لا يُربط بأي فحص أجريته.Website hosting and forms — the site and its email forms. Then onward: what you submit in a site form is stored by that host and a notification is emailed to us. It is never linked to any scan you performed.
وخدمة التحليل بالذكاء الاصطناعي المذكورة أعلاه: يصلها نصّ رسالتك المحجوبة. تعالجه على بنيتها التحتية ومزوّديها، ولا نستطيع تعدادهم لك واحداً واحداً — نذكرهم كفئة بدل أن نُوهمك بأن السلسلة تنتهي عندنا.And the AI text-analysis service named above: your masked message text reaches them. They process it on their own infrastructure and their own providers, which we cannot enumerate for you one by one — we name them as a class rather than let you assume the chain ends with us.
خدمة قراءة النصوص من الصور: تستقبل الصورة فقط عند الفحص من الموقع، لا من التطبيق (انظر ٤أ).Image text-reading service: receives the image only for scans from the website, never from the app (see 4a).
وما لا يصله شيء عنك: تغذية النطاقات الخبيثة تصل إلينا ولا نرسل إليها شيئاً — لا يغادر خوادمنا أي نطاقٍ فحصتَه في اتجاهها إطلاقاً.And one that receives nothing about you: the malicious-domain feed travels to us; we send nothing to it. No domain you scanned ever leaves our servers in its direction.
الاتصال مشفّر بالكامل (HTTPS/TLS)، والبيانات مشفّرة أثناء النقل وفي التخزين.Connections are fully encrypted (HTTPS/TLS), and data is encrypted in transit and at rest.
٤أ. قارئ النصوص في تجربة الموقع4a. The text reader in the website demo
على الموقع تُرسل الصورة لقراءة نصّها، ثم تُحذف من طرفنا فور القراءة. مزوّد قراءة الصور يحتفظ بها وفق سياسته المنشورة ولا يستخدمها لتدريب نماذجه. ما فيه مسار بديل. وتطبيق الهاتف مختلف تماماً: يحمل كل ملفات القراءة بداخله، ولا يتصل بأي جهة خارجية أثناء قراءة صورة.On the website the image is sent to have its text read, then deleted on our side the moment it is read. The image-reading provider retains it under its published policy and does not use it to train its models. There is no alternative path. The mobile app is different: it carries all of its reading files inside the app and contacts no outside party while reading an image.
٤ب. فحص النطاقات — من الذي يسأل؟4b. Domain checks — who does the asking?
حين تحتوي رسالة رابطاً، نتحقّق من أن نطاقه موجود فعلاً وكم عمره. هذا الاستعلام تُجريه خوادمنا، لا هاتفك. فمزوّد استعلام الـDNS وسجلّ النطاق يريان عنوان خادمنا واسم النطاق المسؤول عنه — ولا يريان عنوانك ولا أي معرّف لك. ولا يُرسَل نصّ الرسالة إلى أيٍّ منهما إطلاقاً؛ اسم النطاق وحده.When a message contains a link, we check that its domain really exists and how old it is. That lookup is made by our servers, not by your phone. So the DNS lookup provider and the domain registry see our server's address and the domain being asked about — they do not see your address or any identifier for you. Neither of them ever receives the message text; only the domain name.
وما يبقى صحيحاً رغم ذلك: النطاق ووقت السؤال يصلان إلى جهةٍ خارجية. هذا سجلٌّ جزئيّ لِما يُفحَص — لا لِمَن يفحص. نذكره لأنه صحيح، لا لأنه مطلوب: لو أُجري الفحص من جهازك لكان عنوانك جزءاً من ذلك السجلّ، وهذا هو الفرق الذي يستحقّ أن يُقال.What remains true even so: the domain and the time of the question do reach an outside party. That is a partial record of what is being scanned — not of who is scanning it. We say this because it is true, not because we are required to: had the check been made from your device, your address would have been part of that record, and that difference is the part worth stating.
ونحدّ منه بنيويًّا: يُسأل فقط عن النطاقات التي لم نسأل عنها من قبل، وبحدٍّ أقصى أربعة نطاقات لكل فحص، ولا يُسأل إطلاقاً عن نطاقٍ نعرفه أصلاً.We also limit it structurally: only domains we have not asked about before are looked up, at most four per scan, and a domain we already know is never asked about again.
٤ج. الكوكيز والتخزين في المتصفح4c. Cookies and storage on our website
موقعنا لا يضع أي كوكيز ولا يستخدم أدوات تتبع إعلانية أو تحليلية. يستخدم تخزين المتصفح لخمسة أشياء فقط: تفضيل اللغة، واسمك في اللوحة وأفضل نتيجة لك، وجلسة دخولك إن سجّلت، ومعرّف مُبلِّغ مجهول — معرّف عشوائي يُنشأ في متصفحك حتى لا تتكرّر بلاغات الروابط دون الحاجة لحساب. هو عشوائي، غير مشتق منك أو من جهازك، لا يُستخدم للإعلان، ويُحذف بمسح بيانات الموقع من متصفحك.Our website sets no cookies and uses no advertising or analytics trackers. It uses browser storage for five things only: your language preference, your leaderboard name and best score, your signed-in session if you log in, and an anonymous reporter ID — a random identifier created in your browser so community link reports can be de-duplicated without an account. It is random, not derived from you or your device, never used for advertising, and clearing your browser's site data deletes it.
٥. مدة الاحتفاظ5. How long we keep things
- سجل الفحوصات: مُعطَّل افتراضياً؛ وإن فعّلتَه بقيت النسخة المحجوبة حتى تحذفها. حذفها يزيلها من أنظمتنا.Scan history: off by default; if you enable it, the masked copy is kept until you delete it. Deleting removes it from our systems.
- ذاكرة التحليل المؤقتة: نسخة قصيرة العمر تمنع إعادة تحليل الرسالة نفسها. لا تحمل هوية ولا نصًّا، وتنتهي صلاحيتها خلال سبعة أيام على الأكثر ولا تُقدَّم بعدها.Analysis cache: a short-lived copy that prevents re-analysing the same message. It carries no identity and no text, expires within seven days at most, and is never served after that.
- الحساب: يبقى حتى تحذفه. يُنفَّذ الحذف خلال ٤٨ ساعة، وبكل الأحوال في مدة لا تتجاوز ٣٠ يوماً.Account: kept until you delete your account. Deletion is processed within 48 hours, and in any case no later than 30 days.
- رموز الإشعارات: تُزال عندما يتوقف تسجيل الجهاز.Push tokens: removed when a device stops being registered.
- نتائج اللوحة المنشورة: تبقى معروضة بالاسم المستعار حتى تطلب إزالتها.Published leaderboard results: they remain displayed under the nickname until you request their removal.
- البريد في نماذج الموقع: يبقى حتى تطلب حذفه أو ينتهي الغرض منه.Email in site forms: it remains until you request its deletion or its purpose ends.
٥ب. ماذا يحدث فعلياً عند حذف حسابك5b. What actually happens when you delete your account
تحذف حسابك بنفسك من داخل التطبيق. تبدأ بعدها مهلة ٤٨ ساعة يمكنك خلالها التراجع وإلغاء الطلب؛ فإن مضت دون إلغاء، يُحذف حسابك نهائياً ومعه سجلّ فحوصاتك وملفك الشخصي.You delete your account yourself from inside the app. A 48-hour window then begins in which you can cancel the request; if it passes without cancellation, your account is permanently deleted, along with your scan history and your profile.
وروابط الحماية العائلية تنتهي — سواء كنت تحمي أحداً أو يحميك أحد — ويُبلَّغ الطرف الآخر بأن الرابط انتهى. نذكر ذلك لأنه إشعارٌ يصل شخصاً آخر بسبب فعلٍ قمتَ به، ومن حقّه أن يعرف أن الحماية توقّفت بدل أن يظنّها قائمة.Guardian links end — whether you protect someone or someone protects you — and the other person is notified that the link has ended. We mention it because it is a notification reaching another person as a result of something you did, and they deserve to know the protection stopped rather than assume it is still running.
ونتائجك المنشورة في لوحة الصدارة تُحذَف حذفاً كاملاً، لا تُجهَّل فقط: يُزال الصفّ نفسه، فلا يبقى أثرٌ باسمٍ مستعارٍ معلّق.Your published leaderboard results are deleted outright, not merely stripped of your name: the row itself is removed, so no orphaned nickname entry is left behind.
٦. الحماية العائلية6. Guardian Mode
عند تفعيل الحماية العائلية، يصل شخصٌ تختاره تنبيهٌ حين تفحص شيئاً نصنّفه خطيراً. وهذا يعني أن شيئاً عنك يُرسَل فعلاً: أن هذا الشخص المحدَّد قابل شيئاً خطيراً، ووقت ذلك، ونوعه، إضافةً إلى رمز إشعارات جهاز حارسك.If you enable Guardian Mode, a person you choose receives an alert when you scan something we classify as dangerous. That means something about you really is transmitted: that this specific person encountered something dangerous, when it happened, and what kind it was — along with your guardian's device push token.
قُلها كما هي: مع الوقت، تُكوّن هذه التنبيهات سِجلّاً سلوكيّاً عن شخصٍ معروف بالاسم — متى يتعرّض للاحتيال، وكم مرّة. وجزءٌ منه يمرّ بمزوّد إشعارات خارجي. الاستخدام الشائع لهذه الميزة هو ابنٌ أو ابنة يطمئنّ على والدٍ مسنّ، ونرى أن على الطرفين معرفة ذلك بهذه الصراحة قبل تفعيلها.Stated plainly: over time these alerts build a behavioural record about a named individual — when they encounter scams, and how often. Part of that passes through an external notification provider. The common use of this feature is an adult child keeping an eye on an elderly parent, and we think both people should know this in these terms before it is switched on.
ما لا يُرسَل: نصّ الرسالة لا يصل حارسك ولا مزوّد الإشعارات إطلاقاً. حارسك يرى أن فحصاً خطيراً وقع — لا ما الذي كان مكتوباً فيه.What is not sent: the message text never reaches your guardian or the notification provider. Your guardian sees that a dangerous scan happened — not what it said.
الميزة تتطلّب موافقة الطرفين، ويمكنك إيقافها في أي وقت، وعندها تتوقّف التنبيهات فوراً. ويُخبَر حارسك بما يستطيع رؤيته وما لا يستطيع.The feature requires both people to agree, you can turn it off at any time, and alerts stop immediately when you do. Your guardian is told what they can and cannot see.
كيف يصل التنبيه: يُسلَّم عبر خدمة إشعارات خارجية (خدمة توصيل، ثم شبكة إشعارات نظام هاتفك، ومنها إلى الجهاز). يمرّ بها رمز إشعارات جهاز حارسك ومحتوى التنبيه الوصفي — أي أن فحصاً خطيراً وقع ونوعه — ولا يمرّ بها نص رسالتك إطلاقاً. وهذه القناة ليست خاصّة بالحماية العائلية وحدها: إشعار تأكيد حذف الحساب يسلكها أيضاً، فتفعيلُ الحماية ليس الشرط الوحيد لاستخدامها.How the alert travels: it is delivered through an external notification service (a delivery service, then your phone platform's push network, then the device). Your guardian's device push token and the alert's metadata — that a dangerous scan occurred, and its type — pass through it. Your message text never does. This channel is not exclusive to Guardian Mode: account-deletion confirmations travel the same way, so enabling Guardian is not the only thing that uses it.
يمكن للحارس فتح قائمة بآخر ٥٠ حدثًا (الحكم · الفئة · درجة الخطر · الوقت) — بدون نص الرسالة، وتُغلق القائمة عند إيقاف التنبيهات.A guardian can open a list of the last 50 events (verdict · category · risk · time) — never the message text — and the list closes when alerts are switched off.
٧. الإبلاغ عن النتائج والروابط7. Reporting results and links
عند إبلاغك عن رابط مشبوه أو نتيجة خاطئة، نستقبل: الرابط بعد إزالة معاملاته التتبعية، ونطاقه، وتصنيف البلاغ، ونتيجة الفحص، ونسخة من النص بعد إخفاء كل البيانات الحساسة تلقائياً (الرموز، أرقام البطاقات، الهواتف، الهويات — تُستبدل بأنواعها لا قيمها)، وملاحظتك الاختيارية بعد تنقيتها.When you report a suspicious link or a wrong result, we receive: the link with its tracking parameters removed, its domain, the report category, the scan result, a copy of the text with all sensitive data automatically masked (codes, card numbers, phone numbers, IDs — replaced by their types, not their values), and your optional note after sanitization.
البلاغات لا ترتبط بحسابك ولا بهويتك. تُوسم ببصمة مشفّرة غير قابلة للعكس تُشتق من معرّف مجهول — أو عند غيابه من عنوان الاتصال وبيانات الجهاز بعد تمليحها وتشفيرها، دون تخزين أي منها خاماً — وغرضها الوحيد منع إساءة استخدام البلاغات. ولأن البلاغات غير مرتبطة بك، فهي لا تُحذف مع حسابك ولا نستطيع التعرّف عليها لحذفها.Reports are not linked to your account or your identity. Each is tagged with an irreversible cryptographic fingerprint derived from an anonymous identifier — or, when that is absent, from the connection address and device data after salting and hashing, with none of it stored raw — for the sole purpose of preventing report abuse. Because reports are not linked to you, they are not deleted when you delete your account, and we cannot identify them in order to delete them.
٧ب. إشعار حذف الحساب — تناقضٌ ظاهريّ نوضّحه7b. The account-deletion notice — an apparent contradiction, explained
حين تطلب حذف حسابك نرسل إشعاراً إلى جهازك يؤكّد أن الطلب سُجِّل ومتى يُنفَّذ. وهذا الإشعار يسلك القناة نفسها التي تسلكها تنبيهات الحماية العائلية: خدمة التوصيل، ثم شبكة إشعارات نظام هاتفك، ثم جهازك. أي أنه في اللحظة التي تتصرّف فيها لإيقاف تدفّق بياناتك إلى الخارج، يمرّ إشعارٌ بذلك التصرّف عبر طرفين خارجيّين. نقولها صراحةً لأنها تبدو تناقضاً لمن يقرأ بانتباه، وهي تستحقّ تفسيراً لا ذِكراً عابراً.When you ask us to delete your account we send a notification to your device confirming the request was recorded and when it will run. That notification travels the same chain as Guardian alerts: the delivery service, then your phone platform's push network, then your device. So at the very moment you act to stop your data flowing outward, a notification about that act passes through two third parties. We say so plainly because it looks like a contradiction to anyone reading carefully, and it deserves an explanation rather than a passing mention.
ما يمرّ بهما: رمز إشعارات جهازك ونصّ التأكيد. لا يمرّ بريدك، ولا أيّ فحصٍ أجريته، ولا سببُ الحذف. ولماذا نرسله أصلاً: الحذف مؤجَّل لا فوريّ — وهي مهلةٌ عمداً حتى يمكنك التراجع — فلو لم نؤكّد شيئاً لما عرفتَ أن الطلب سُجِّل، ولا متى ينفَّذ، ولا كيف تُلغيه. إشعارٌ يمرّ بطرفين أقلُّ ضرراً من حذفٍ صامتٍ لا تعرف إن كان يجري.What passes through them: your device's push token and the confirmation text. Not your email, not any scan you ran, not a reason for the deletion. And why we send it at all: deletion is delayed rather than immediate — deliberately, so you can undo it — so without a confirmation you would not know the request was recorded, when it will run, or how to cancel it. A notice that passes two parties does less harm than a silent deletion you cannot tell is happening.
وإن كنت تفضّل ألّا يصلك هذا الإشعار، فإيقاف إشعارات التطبيق من إعدادات جهازك يمنعه — ويبقى طلب الحذف قائماً ويُنفَّذ في موعده.If you would rather not receive it, turning off the app's notifications in your device settings prevents it — and your deletion request still stands and still runs on schedule.
٨. حقوقك8. Your rights
بموجب قانون حماية البيانات الإماراتي، يمكنك أن تطلب منّا: نسخة من بياناتك؛ تصحيحها؛ حذفها؛ تقييد المعالجة أو إيقافها؛ أو الاعتراض على القرارات الآلية. راسلنا على privacy@sayyad.ae وسنردّ خلال ٣٠ يوماً.Under UAE data protection law you may ask us to: give you a copy of your data; correct it; delete it; restrict or stop processing it; or object to automated decision-making. Write to privacy@sayyad.ae and we will respond within 30 days.
٩. التحليل الآلي9. Automated analysis
يقيّم صيّاد الرسائل آلياً بقواعد وطبقة ذكاء اصطناعي. النتيجة مؤشّر لا حكم عليك. لا تُنشئ سجلاً قانونياً عنك. ومَن يصله شيءٌ عن فحصك موصوفٌ في القسم ٤ وفروعه وفي القسم ٦ — ولا أحدَ سواهم. ويمكنك دائماً طلب مراجعة بشرية لنتيجة ترى أنها خاطئة.Sayyad scores messages automatically, using rules and an AI layer. The result is an indicator, not a determination about you. It does not create a legal record about you. Whoever receives anything about your scan is described in section 4 and its subsections, and in section 6 — and no one else. You may always ask a human to review a result you think is wrong.
١٠. الأطفال10. Children
صيّاد لمن أعمارهم ١٨ سنة فأكثر. تتطلّب الحماية العائلية أن يكون الطرفان بالغين. إن كنت ترى أن طفلاً زوّدنا ببيانات، راسلنا على privacy@sayyad.ae وسنحذفها.Sayyad is for users aged 18 and over. Guardian Mode requires both people to be 18 or over. If you believe a child has given us data, write to privacy@sayyad.ae and we will delete it.
١١. الأمان11. Security
نستخدم التشفير أثناء النقل وفي التخزين، ونقيّد الوصول إلى أنظمتنا، ولا نخزّن نص رسالتك الخام غير المُقنّع. لا يوجد نظام آمن تماماً؛ وإن وقع خرق يمسّك سنبلغك ونبلغ الجهة التنظيمية بحسب المطلوب.We use encryption in transit and at rest, restrict access to our systems, and do not store your raw unmasked message text. No system is perfectly secure; if a breach affects you we will notify you and the regulator as required.
١٢. التغييرات والتواصل12. Changes and contact
سننشر أي تغييرات هنا، وسنُعلمك داخل التطبيق بالتغييرات الجوهرية. للتواصل أو الشكاوى: privacy@sayyad.ae. ولك أيضاً حق التقدّم بشكوى إلى مكتب البيانات الإماراتي.We will post changes here and, for significant ones, notify you in the app. Contact or complaints: privacy@sayyad.ae. You also have the right to complain to the UAE Data Office.