أولاً: السياسة باللغة العربية
١. من المسؤول عن بياناتك؟
مقدم الخدمة والمتحكم في البيانات هو:
شادي الحروب (Shadi Al Hroub) — مطوّر فرد، وليس شركة أو كياناً مسجّلاً.
الإمارات العربية المتحدة
قناة التواصل الرسمية الوحيدة، وللمراسلات القانونية وطلبات حقوق البيانات: support@taakad.app
نردّ على طلبات حقوق البيانات خلال 30 يوماً كحد أقصى.
تُقدَّم خدمة TAAKAD عبر تطبيقها للهواتف وموقعها taakad.app (ويُشار إليها بـ«تأكّد» أو «نحن»).
٢. ماذا يقدم التطبيق؟
يساعد تأكّد المستخدم على فحص محتوى يختار إرساله — رسائل، نصوص، روابط، أرقام هواتف، صور ولقطات شاشة — ثم يعرض مؤشرات وتحليلاً إرشادياً آلياً عن احتمال وجود احتيال.
- الفيديو: فحص الفيديو برابط مجاني ويُعامل كرابط عادي. أمّا اختيار ملف فيديو من جهازك فميزة «برو»، ويعالَج الملف محلياً على جهازك: يستخرج التطبيق مشهداً ممثِّلاً واحداً على الجهاز، ولا يُرفع ملف الفيديو الكامل إلى تأكّد أبداً. المشهد المستخرج قد يُرسل إلى خوادمنا ومزوّدي الذكاء الاصطناعي ويُعامل كأي صورة مرسلة. مشهد واحد قد لا يمثّل كل ما في الفيديو، والصوت لا يُفحص، ولا نعد بتحليل كامل الفيديو أو كل مشاهده أو سياقه.
- حماية هوية المتصل (مجانية لحسابك المسجَّل): تعرّف أرقاماً مبلّغاً عنها أو موثّقة أثناء المكالمات الواردة اعتماداً على قائمة تُزامَن إلى جهازك، وتُفصَّل في البند 7.
التطبيق أداة مساعدة آلية ولا يضمن صحة أي نتيجة (انظر شروط الاستخدام).
٣. البيانات التي نعالجها
نعالج البيانات اللازمة لتقديم الخدمة وتشغيل الحساب والاشتراك والحماية من إساءة الاستخدام:
| الفئة | أمثلة | الغرض |
|---|---|---|
| بيانات الحساب | البريد الإلكتروني (الدخول يكون برمز لمرة واحدة إلى بريدك، أو بالدخول بجوجل، أو عبر Sign in with Apple)، معرّف المستخدم، بيانات تسجيل الدخول الفنية، ورمز تحديث آبل (Apple refresh token) الذي يُحفظ خادمياً لإبطال تفويض Sign in with Apple عند حذف حسابك | إنشاء الحساب، المصادقة، الدعم، الحذف والتصدير |
| بيانات مزوّد الدخول (Google / Apple) | الاسم المعروض ورابط الصورة الشخصية إن قدّمهما المزوّد. يُحفظان على جهازك فقط ولا يصلان خوادمنا. لا تقدّم Apple صورة، وتقدّم الاسم مرة واحدة عند أول تفويض فقط. عند اختيارك «إخفاء بريدي» لدى Apple نتلقى عنوان تحويل ولا نعرف عنوانك الحقيقي | عرض اسمك وصورتك داخل التطبيق |
| المحتوى المرسل للفحص | النصوص، الرسائل، الروابط، أرقام الهاتف، الصور ولقطات الشاشة، واللقطة المستخرجة محلياً من فيديو | إجراء الفحص المطلوب وعرض النتيجة — لا يُخزَّن المحتوى الأصلي في قاعدة بيانات التطبيق بعد اكتمال الفحص (انظر البند 9) |
| سجل الفحوصات (بيانات وصفية فقط) | نوع الفحص، الحكم، درجة الثقة، نمط الاحتيال، اللغة، البلد، محرك التحليل وحالته، نسخة كتالوج الحماية، التوقيت، وتغذيتك الراجعة على النتيجة | إتاحة السجل والتصدير واتساق الخدمة — بلا محتوى أصلي |
| مؤشرات التهديد المستخرجة | أرقام وروابط ونطاقات مستخرجة من محتوى صُنّف احتيالياً، ونمط الاحتيال وعدد المبلّغين المتمايزين | بناء قاعدة تهديدات مشتركة تحمي المستخدمين (انظر البند 10) |
| معرّفات تقنية | معرّف عشوائي لتثبيت التطبيق يُحوَّل بتجزئة مفتاحية ويُعامل كبيان مستعار الهوية (يرتبط بحسابك ما دام الجهاز موصولاً به)، رمز جلسة الحساب، رمز الإشعارات، منصة الجهاز وإصدار التطبيق | منع إساءة الاستخدام، حدود الاستخدام، المصادقة، الإشعارات |
| بيانات الاشتراك | منصة المتجر، معرّف المنتج، معرّفات المعاملة/الطلب، معرّفات أحداث المزوّد، حالة الاشتراك، تواريخ الشراء والتجديد والإلغاء والانتهاء والاسترداد والسماح والإبطال، وبصمات (hashes) للإيصالات ورموز الشراء، وما يلزم للتحقق من الأحقية ومنع إعادة استخدام الإيصالات | تفعيل مزايا «برو» خادمياً وإدارة الاشتراك — لا نستلم ولا نخزّن أرقام بطاقات دفع كاملة أبداً |
| موافقات التنبيهات | موافقة التنبيهات وتفضيلاتها (احتيال/أخبار) واللغة والبلد | إرسال تنبيهات اخترتَها صراحة |
| البلد أو المنطقة | اختيارك أو إعداد منطقة/لغة الجهاز | قنوات إبلاغ ومعلومات مناسبة لبلدك |
| سجلات تشغيل وأمان | وقت الطلب، المسار الفني، حالة الاستجابة، عنوان IP، إصدار التطبيق | الأمان واكتشاف الأعطال ومنع إساءة الاستخدام — بلا محتوى مستخدم (انظر البند 9) |
معرّف التثبيت المجزّأ بيان مستعار الهوية وليس مجهّلاً — إعادة تثبيت التطبيق تولّد معرّفاً جديداً. لا نستخدم معرّفات إعلانية ولا نتتبعك عبر تطبيقات أو مواقع أخرى.
لا يطلب التطبيق الوصول إلى جهات اتصالك أو سجل مكالماتك أو رسائلك المخزنة أو موقع GPS الدقيق.
٤. المحتوى المرسل ومزوّدو الذكاء الاصطناعي
قبل أول فحص سحابي يعرض التطبيق إفصاحاً واضحاً ويطلب موافقتك الصريحة على إرسال المحتوى الذي تختاره إلى مزوّدي التحليل. بدون الموافقة لا يُرسل المحتوى ولا يتاح الفحص السحابي.
يُرسل المحتوى إلى Anthropic (المزوّد الأساسي) وOpenAI (المزوّد الاحتياطي عند الحاجة).
التمييز المهم بين بنيتنا ومزوّدي الذكاء الاصطناعي:
- بنية تأكّد: لا يُخزَّن المحتوى الأصلي في قاعدة بيانات التطبيق بعد اكتمال الفحص، وسجلاتنا التشغيلية المؤقتة تخضع لسياستنا المنفصلة (انظر البند 11) — وهذه السياسة لا تحكم مزوّدي الذكاء الاصطناعي.
- المزوّدون: وفق الإعدادات القياسية الحالية، قد تحتفظ Anthropic وOpenAI بمدخلات ومخرجات API لمدة تصل إلى 30 يوماً لأغراض السلامة ومراقبة إساءة الاستخدام، وقد تطول المدة استثناءً حيث يوجبه القانون أو إنفاذه أو رُصدت إساءة استخدام، وقد يختلف السلوك باختلاف نقطة النهاية أو الميزة. لا توجد حالياً اتفاقية Zero Data Retention نافذة خاصة بتأكّد مع أي منهما. كون البيانات لا تُستخدم للتدريب لا يعني أنها لا تُحتفظ مؤقتاً.
لذلك لا ترسل كلمات مرور أو أرقام بطاقات أو وثائق هوية أو معلومات طبية/مالية غير ضرورية أو بيانات شخص آخر ما لم تكن مخوّلاً.
مراجع سياسات المزوّدين:
٥. مزوّدو الخدمة
| المزوّد | الخدمة | البيانات المعنية |
|---|---|---|
| Anthropic | التحليل الأساسي | المحتوى الذي تختاره والنتيجة |
| OpenAI | التحليل الاحتياطي | المحتوى الذي تختاره والنتيجة عند المسار الاحتياطي |
| Supabase | الحسابات وقاعدة البيانات والتخزين الفني | بيانات الحساب، البيانات الوصفية للسجل، المعرّفات، مؤشرات التهديد، بيانات الاشتراك |
| Render | استضافة الخادم | الطلبات والبيانات المارة أثناء الفحص |
| Apple وGoogle | توزيع التطبيق، تسليم الإشعارات، ومعالجة مدفوعات الاشتراك | بيانات المتجر، رموز الإشعارات، وبيانات الفوترة وفق شروط المنصة |
لا نبيع بياناتك ولا نشاركها للإعلانات ولا نبني بها ملفات إعلانية. قد تُعالَج البيانات أو تُنقل خارج بلد إقامتك حيث يعمل مزوّدونا (بما في ذلك الولايات المتحدة وأوروبا)، مع الضمانات المناسبة وبالقدر الذي يسمح به القانون.
٦. الإشعارات والتنبيهات (Push)
- يُطلب إذن الإشعارات عند تفعيلك التنبيهات بنفسك، لا تلقائياً عند فتح التطبيق.
- التسليم عبر Apple APNs أو Google FCM بحسب جهازك، ونعالج لذلك: رمز الإشعارات، المنصة، إصدار التطبيق، لغة التنبيه المفضلة، وموافقتك وتفضيلاتك.
- يمكنك إيقاف الإشعارات من التطبيق أو من إعدادات النظام في أي وقت. عند سحب الموافقة أو تسجيل الخروج أو حذف الحساب أو ورود رد من المنصة بأن الرمز باطل، يُحذف الرمز المخزّن أو يُبطل خلال المهلة الفنية المعتادة.
- عند حذف حسابك تُسحب موافقة التنبيهات وتُحذف رموز الإشعارات لأجهزة الحساب، وتتوقف تنبيهات تأكّد حتى تفعّلها صراحة من جديد.
- لا يعرض محتوى الإشعار تفاصيل فحوصاتك الحساسة على شاشة القفل، ولا تُستخدم رموز الإشعارات للإعلان أو للتتبع خارج التطبيق.
٧. حماية هوية المتصل (مجانية لكل حساب مسجَّل)
- الميزة مجانية لكل حساب مسجَّل — لا تتطلب اشتراكاً.
- بطاقة التعريف فوق شاشة المكالمة (أندرويد): عند تفعيلك الميزة يعرض التطبيق بطاقة تعريف فوق شاشة المكالمة الواردة عند مطابقة الرقم للقائمة المحفوظة على جهازك، بإذن «العرض فوق التطبيقات» الذي تمنحه أنت من إعدادات النظام وتسحبه متى شئت. لا يصلنا رقم المتصل ولا أي معلومة عن مكالماتك. على iOS يعرض النظام نفسه التسمية على شاشة المكالمة.
- سجل المكالمات التي جرى التحقق منها (أندرويد): يُحفظ على جهازك وحده ولا يغادره إطلاقاً، ويُمحى مع القائمة عند إطفاء الميزة أو الخروج. على iOS لا يوجد هذا السجل لأن النظام لا يُبلّغ التطبيقات بالمكالمات.
- المطابقة محلية بالكامل: يُنزّل التطبيق قائمة حماية (أرقام مبلّغ عنها من المجتمع وأرقام رسمية موثّقة) إلى جهازك — وتُحدَّث تلقائياً عند فتح التطبيق — ويجري التعرف على الرقم الوارد على الجهاز عبر آليات نظام التشغيل وقت المكالمة. بيانات المكالمة المستخدمة للتعرف تُعالَج محلياً على جهازك ولا تُرسل إلى خوادم تأكّد.
- لا يصل إلى تأكّد عبر هذه الميزة: صوت المكالمة، ولا سجل مكالماتك، ولا هوية من يتصل بك. طلب مزامنة القائمة لا يتضمن أي رقم متصل.
- غياب رقم عن القائمة لا يعني أنه آمن، والأرقام قابلة للانتحال (spoofing).
- عمل الميزة يعتمد على دعم نظام التشغيل وإعدادات الجهاز والأذونات والأدوار ونجاح المزامنة، وقد لا تتوفر على كل الأجهزة.
- لا يوجد حظر تلقائي للمكالمات في هذا الإصدار إطلاقاً. زر «حظر» في شاشة النتيجة يفتح إرشادات الحظر اليدوي عبر إعدادات نظام هاتفك، ولا يحظر تأكّد أي رقم نيابةً عنك. الميزة تعرّف الأرقام فقط: موثّق، أو مبلَّغ عنه، أو غير معروف.
- الميزة ليست حماية كاملة من المكالمات الاحتيالية.
- تُحذف القائمة من جهازك بعد تسجيل الخروج أو تبديل الحساب أو فشل التخويل.
٨. البطاقات الترويجية والمحتوى المدعوم
قد يعرض تأكّد بطاقات ترويجية أو محتوى برعاية تقدّمه علامات تجارية مباشرة، مع تمييزه بوضوح بعبارة «إعلان» أو «محتوى برعاية» (أو "Advertisement"/"Sponsored").
قواعد صارمة تفصل الإعلان عن الحماية:
- لا شبكة إعلانات خارجية في هذا الإصدار، ولا تتبع إعلاني عبر التطبيقات أو المواقع.
- لا استهداف بناءً على محتوى فحوصاتك، ولا يصل محتوى فحوصاتك إلى أي معلن.
- لا يؤثر أي معلن على الأحكام أو درجات الثقة أو إدخالات الكتالوج أو التحذيرات أو تصنيفات الخطر، ولا يمكن للدفع أن يجعل أي علامة أو نطاق أو رقم أو متجر أو منتج «آمناً».
- المحتوى المدعوم مميز بصرياً عن نتائج الفحص ونصائح الحماية، والإعلان ليس توثيقاً أمنياً ولا ضماناً من تأكّد.
- روابط الرعاة الخارجية تحكمها شروط وخصوصية أصحابها.
- لا يجمع نظام البطاقات الحالي أي قياس: لا مرات ظهور ولا نقرات ولا تحويلات ولا ربط بحسابك — بيانات البطاقة المخزنة هي محتواها الترويجي فقط. أي قياس إعلاني مستقبلي يتطلب تحديث هذه السياسة وإفصاحات المتجرين قبل تفعيله.
٩. ماذا يُخزَّن فعلاً من فحوصاتك؟
بدقة، وفق تصميم قاعدة البيانات الفعلي:
- لا يُخزَّن: نص رسالتك، الصورة أو اللقطة المرسلة، ولا أي محتوى أصلي — قاعدة بيانات التطبيق مصممة بلا أعمدة محتوى، ولا يظهر محتوى المستخدم في سجلاتنا التشغيلية.
- يُخزَّن (بيانات وصفية): نوع الفحص، الحكم، الثقة، نمط الاحتيال، اللغة، البلد، محرك التحليل وحالته، نسخة الكتالوج، التوقيت، معرّف التثبيت المجزّأ، وتغذيتك الراجعة إن قدمتها.
- يُستخرج ويُخزَّن كمؤشر تهديد: رقم أو رابط أو نطاق ورد داخل محتوى صُنّف احتيالياً (انظر البند 10).
- تُقلَّل البيانات الوصفية للملفات (metadata) حيث يكون ذلك منفذاً تقنياً، ولا نقدّم وعداً بالحذف الدائم لدى كل مزوّد ما لم يكن مؤكداً تعاقدياً.
١٠. قاعدة التهديدات والاعتراض
المؤشرات المستخرجة (أرقام/روابط/نطاقات المحتالين) إشارات خطر قابلة للمراجعة لا اتهامات نهائية، وقد يكون المؤشر بياناً شخصياً أو يخص ضحية انتحال، فلا نعامله كمجهّل تلقائياً. لطلب مراجعة أو تصحيح أو حذف رقم أو رابط أو نطاق أو نتيجة: support@taakad.app. تقديم الاعتراض لا يغيّر النتيجة تلقائياً؛ التصحيح يمر بمراجعة أدلة وعملية كتالوج محكومة.
١١. مدة الاحتفاظ
| البيانات | المدة |
|---|---|
| المحتوى الأصلي المرسل في قاعدة تطبيق تأكّد | لا يُخزَّن بعد اكتمال الفحص |
| ملفات الفيديو | لا تُرفع أصلاً — تُستخرج لقطة على جهازك |
| المحتوى لدى Anthropic/OpenAI | حتى 30 يوماً وفق شروطهما القياسية الحالية، مع الاستثناءات المذكورة في البند 4 |
| سجلات تأكّد التشغيلية | لأقصر مدة لازمة للأمان واكتشاف الأعطال؛ سجلاتنا داخل القاعدة (مثل عدّادات حدود الاستخدام) تُدوَّر خلال ~24 ساعة. وسجلات التشغيل لدى مزوّد الاستضافة تُحفظ سبعة أيام كحدٍّ أقصى ثم تُحذف نهائياً. وسجلات طلبات HTTP — وهي وحدها التي تحمل عنوان IP — غير مُفعَّلة على خطة استضافتنا، فلا تُولَّد أصلاً |
| الحساب | حتى تحذفه |
| البيانات الوصفية لسجل الفحوصات | مع الحساب — تُحذف صفوف سجل أجهزة حسابك عند حذف الحساب |
| رمز الإشعارات وموافقة التنبيهات | حتى الإيقاف من التطبيق أو النظام، أو حذف الحساب |
| قائمة حماية هوية المتصل على جهازك · وسجل المكالمات المفحوصة (أندرويد) | حتى إطفاء الميزة أو الخروج أو تبديل الحساب، فتُحذف من الجهاز |
| سجل الجهاز غير المرتبط بهوية بعد الحذف (لحدود الاستخدام ومنع الإساءة) | 90 يوماً كحد أقصى من آخر استخدام، ثم يُحذف آلياً. لا يحتوي حساباً ولا رمز إشعارات ولا موافقات ولا سجل فحوصات، وإعادة تثبيت التطبيق تولّد معرّفاً جديداً فلا يتتبعك عبر التثبيتات |
| سجلات الاشتراك وبصمات الإيصالات | مدة الاشتراك وبعدها بالقدر اللازم للالتزامات الضريبية والمحاسبية ومنع الاحتيال |
| مؤشرات التهديد | ما دامت ضرورية ومتناسبة للحماية، مع مراجعة وتصحيح وحذف عند ثبوت الخطأ |
| النسخ الاحتياطية | وفق دورة النسخ الآمنة لدى مزوّد الاستضافة، للاستعادة من الأعطال فقط |
١٢. التصدير والحذف
- التصدير من داخل التطبيق يعيد إليك: بيانات أجهزتك (منصة، إصدار، آخر ظهور، بلد)، اشتراكاتك (الحالة والتواريخ)، موافقات التنبيهات، والبيانات الوصفية لفحوصاتك (التاريخ، النوع، الحكم، الثقة، النمط، اللغة، البلد، تغذيتك الراجعة). لن تجد فيه محتوى فحوصاتك الأصلي لأنه غير مخزّن أصلاً.
- الحذف من داخل التطبيق عملية حذف فورية محدودة الإتمام: يُحذف مستخدم المصادقة وبيانات حسابك واشتراكاتك، ويُحذف سجل فحوصات أجهزة حسابك، وتُسحب موافقات التنبيهات وتُحذف رموز الإشعارات لتلك الأجهزة، وتُحذف قائمة حماية هوية المتصل من جهازك — فوراً، وبإتمام كامل من الأنظمة النشطة خلال 30 يوماً كحد أقصى ما لم يوجب القانون أو الأمن احتفاظاً محدوداً. ما قد يبقى: بصمات الإيصالات ومعرّفات المعاملات مفصولةً عن هويتك (منع الاحتيال وإعادة الاستخدام والالتزامات الضريبية)، سجل جهاز غير مرتبط بهوية لحدود الاستخدام (يُحذف آلياً بعد 90 يوماً من آخر استخدام كحد أقصى)، سجلات أمنية، نسخ احتياطية معزولة حتى انتهاء دورتها، وبيانات لدى المزوّدين وفق شروطهم.
- تتوفر أيضاً صفحة حذف خارجية عامة على taakad.app/account-deletion لمن لا يستطيع الدخول إلى التطبيق.
- حذف حساب تأكّد لا يلغي اشتراك Apple أو Google تلقائياً — أدر الاشتراك أو ألغه من حساب المتجر نفسه.
١٣. حقوقك
بحسب القانون المطبق في بلدك، لك حقوق الوصول والتصحيح والحذف وتقیید المعالجة والاعتراض عليها ونقل البيانات وسحب الموافقة (دون أثر على قانونية المعالجة السابقة)، وتقديم شكوى إلى جهة حماية البيانات المختصة حيث يتاح ذلك. لأي طلب لا تنفذه من التطبيق: support@taakad.app، وقد نطلب معلومات محدودة للتحقق من هويتك.
أسس المعالجة حيث يتطلبها القانون: تنفيذ العقد (الفحص والحساب والاشتراك)، موافقتك الصريحة (إرسال المحتوى للمزوّدين، التنبيهات)، مصالحنا المشروعة (حماية المستخدمين ومنع إساءة الاستخدام وتأمين الخدمة بما لا يتغلب على حقوقك)، والالتزام القانوني.
١٤. الأطفال والأهلية
إنشاء الحساب والشراء يتطلبان أهلية قانونية للتعاقد. على القاصر استخدام الخدمة عبر ولي أمر أو وصي حيث يوجب قانونه المحلي ذلك، ويمكن للآباء والأوصياء استخدام تأكّد لحماية أسرهم. لا نتعمد جمع بيانات شخصية غير ضرورية من الأطفال، ونحترم قوانين خصوصية الأطفال المحلية المطبقة.
إذا تعلّق المحتوى بخطر مباشر أو ابتزاز أو استغلال قاصر فتواصل فوراً مع ولي أمر موثوق والشرطة؛ تأكّد ليس جهة طوارئ ولا يبلّغ نيابة عنك.
١٥. الأمن
نطبّق تدابير معقولة: تقليل البيانات، عدم تخزين المحتوى الأصلي حيث صُمم ذلك، تقييد الوصول، تشفير النقل، تجزئة المعرّفات، فرض الأحقية والحدود خادمياً، منع إعادة استخدام الإيصالات، إبعاد الأسرار ومحتوى المستخدم عن السجلات. لا توجد وسيلة آمنة 100%، فلا نضمن منع كل الحوادث، لكننا نتصرف بتناسب ونخطر الجهات والأشخاص حيث يوجب القانون.
١٦. التغييرات والتواصل
قد نحدّث هذه السياسة عند تغير التطبيق أو القانون أو المزوّدين، مع إشعار مناسب قبل التغيير الجوهري حيث يلزم، ودون استخدام موافقة سابقة لغرض جديد غير متوافق بلا أساس قانوني. التواصل والطلبات والاعتراضات: support@taakad.app
Part Two: Privacy Policy in English
1. Who controls your data?
The service provider and data controller is:
Shadi Al Hroub — an individual developer, not a company or registered entity.
United Arab Emirates
Sole official contact channel, including legal notices and data-rights requests: support@taakad.app
Data-rights requests are answered within 30 days at the latest.
The TAAKAD service is provided through its mobile application and its website taakad.app ("TAAKAD", "we", "us").
2. What the app does
TAAKAD helps users check content they choose to submit — messages, text, links, phone numbers, images, and screenshots — and returns automated, indicative fraud-risk analysis.
- Video: checking a video by link is free and is treated as an ordinary link. Choosing a video FILE from your device is a Pro feature, and the file is processed locally on your device: the app takes a single representative scene on the device, and the full video file is never uploaded to TAAKAD. The extracted scene may be transmitted to our servers and AI providers and is handled like any submitted image. A single scene may not represent everything in the video, the sound is not examined, and we do not promise analysis of the full video, every scene, or its full context.
- Caller ID protection (free, signed-in): identifies reported or verified numbers during incoming calls using a list synced to your device, detailed in Section 7.
TAAKAD is an automated assistive tool and does not guarantee that any result is correct (see the Terms of Use).
3. Data we process
We process the data necessary to provide the service, run the account and subscription, and protect against misuse:
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email address (sign-in is by a one-time code to your email, by Google sign-in, or by Sign in with Apple), user ID, technical authentication data, and the Apple refresh token stored server-side to revoke the Sign in with Apple authorization when you delete your account | Account creation, authentication, support, deletion, export |
| Sign-in provider data (Google / Apple) | Display name and profile-picture link if the provider supplies them. Stored on your device only and never reach our servers. Apple supplies no picture and supplies the name once, at first authorization only. If you choose Apple's "Hide My Email", we receive a relay address and never learn your real one | Showing your name and picture inside the app |
| Content submitted for a check | Text, messages, links, phone numbers, images, screenshots, and the locally extracted video frame | Perform the requested check and return a result — original content is not stored in the app's database after the check completes (Section 9) |
| Check history (metadata only) | Check type, verdict, confidence, scam pattern, language, country, analysis engine and its status, protection-catalog version, timestamps, and your feedback on a result | History, export, service consistency — no original content |
| Extracted threat indicators | Numbers, links, and domains extracted from content classified as fraudulent, plus scam pattern and distinct-reporter counts | A shared threat database protecting users (Section 10) |
| Technical identifiers | A random app-installation identifier transformed using a keyed hash and treated as pseudonymous data (linkable to your account while the device is linked to it), account session token, push token, device platform, and app build | Abuse prevention, usage limits, authentication, notifications |
| Subscription data | Store platform, product identifier, transaction/order identifiers, provider event identifiers, subscription status, purchase/renewal/cancellation/expiration/refund/grace/revocation dates, receipt and purchase-token hashes, and what is needed to verify entitlement and prevent receipt replay | Server-side Pro entitlement and subscription management — we never receive or store full payment-card numbers |
| Alert consents | Alert consent and preferences (scam/news), language, country | Alerts you explicitly opted into |
| Country or region | Your selection or device region/language setting | Country-appropriate reporting channels and information |
| Operational and security logs | Request time, technical route, response status, IP address, app version | Security, troubleshooting, abuse prevention — no user content (Section 9) |
The hashed installation identifier is pseudonymous, not anonymous — reinstalling the app generates a new one. We use no advertising identifiers and do not track you across other apps or websites.
The app does not request access to contacts, call history, stored messages, or precise GPS location.
4. Submitted content and third-party AI
Before the first cloud-based check, the app presents a prominent disclosure and asks for explicit permission to send content you select to the analysis providers. Without permission, content is not sent and cloud analysis is unavailable.
Content is sent to Anthropic (primary provider) and OpenAI (fallback provider when needed).
The important distinction between our infrastructure and the AI providers:
- TAAKAD's infrastructure: original content is not stored in the app's database after the check completes, and our temporary operational logs follow our separate policy (Section 11) — that policy does not govern the AI providers.
- The providers: under current standard settings, Anthropic and OpenAI may retain API inputs and outputs for up to 30 days for safety and abuse monitoring, with possible longer retention where legally required, for law enforcement, or where misuse is detected, and behavior may differ by endpoint or feature. TAAKAD currently has no operative Zero Data Retention agreement with either provider. That data is not used for training does not mean it is not temporarily retained.
Therefore do not submit passwords, card numbers, identity documents, unnecessary medical or financial information, or another person's data unless authorised.
Provider policy references:
5. Service providers
| Provider | Service | Relevant data |
|---|---|---|
| Anthropic | Primary analysis | User-selected content and the output |
| OpenAI | Fallback analysis | User-selected content and output on the fallback path |
| Supabase | Accounts, database, technical storage | Account data, history metadata, identifiers, threat indicators, subscription data |
| Render | API hosting | Requests and data in transit during a check |
| Apple and Google | App distribution, push delivery, and subscription billing | Store data, push tokens, and billing data under the platform's terms |
We do not sell personal data, share it for advertising, or build advertising profiles. Data may be processed or transferred outside your country where our providers operate (including the United States and Europe), subject to appropriate safeguards and applicable law.
6. Push notifications
- Notification permission is requested when you activate alerts yourself, never automatically at startup.
- Delivery uses Apple APNs or Google FCM as applicable; for this we process: push token, platform, app build, preferred alert language, and your consent and preferences.
- You can disable alerts in the app or in system settings at any time. On opt-out, logout, account deletion, or a platform response showing the token is invalid, the stored token is removed or invalidated within normal technical processing time.
- On account deletion, alert consent is withdrawn and push tokens are removed for the account's devices; TAAKAD notifications stop until you explicitly opt in again.
- Notification content does not expose your sensitive check details on a locked screen, and push tokens are never used for advertising or cross-app tracking.
7. Caller ID protection (free for every signed-in account)
- The feature is free for every signed-in account — no subscription required.
- Identification card over the call screen (Android): when you enable the feature, the app shows an identification card over the incoming-call screen for numbers matching the list stored on your device, using the "Display over other apps" permission you grant in system settings and can withdraw at any time. The caller's number and any information about your calls never reach us. On iOS the system itself renders the label on the call screen.
- Checked-calls log (Android): kept on your device only and never leaves it; it is erased together with the list when the feature is turned off or you sign out. On iOS there is no such log because the system does not report calls to apps.
- Matching is entirely local: the app syncs a protection list (community-reported numbers and verified official numbers) to your device, and incoming-number identification happens on the device through the operating system's own mechanisms at call time. Call information used for number identification is processed locally on your device and is not transmitted to TAAKAD's servers.
- TAAKAD does not receive through this feature: call audio, your call history, or the identity of who calls you. The list-sync request contains no caller numbers.
- Absence of a number from the list does not mean it is safe, and numbers can be spoofed.
- The feature depends on OS support, device settings, permissions, roles, and successful synchronization, and may be unavailable on some devices.
- There is no automatic call blocking in this release, at all. The "Block" option on a result opens your phone's own manual blocking instructions; TAAKAD never blocks a number on your behalf. The feature identifies numbers only: verified, reported, or unknown.
- The feature is not complete protection against fraudulent calls.
- The list is deleted from your device after logout, account switching, or authorization failure.
8. Promotional cards and sponsored content
TAAKAD may display clearly labelled promotional cards or sponsored content provided directly by brands, identified as "Advertisement", "Sponsored", «إعلان», or «محتوى برعاية», as appropriate.
Strict separation between advertising and protection:
- No external advertising network in this release, and no cross-app or cross-site advertising tracking.
- No targeting based on your submitted check content, and no advertiser ever receives your check content.
- No advertiser influences verdicts, confidence levels, catalog entries, warnings, or risk classifications, and payment can never cause any brand, domain, number, store, or product to be classified as safe.
- Sponsored content is visually distinct from scan results and protection advice; an advertisement is not a security endorsement, verification, or guarantee by TAAKAD.
- External sponsor destinations are governed by the third party's own terms and privacy practices.
- The current card system collects no measurement: no impressions, clicks, or conversions, and nothing is linked to your account — the stored ad data is the promotional content itself. Any future advertising measurement requires updating this Policy and the store disclosures before activation.
9. What is actually stored from your checks?
Precisely, per the actual database design:
- Not stored: your message text, the submitted image or frame, or any original content — the app's database has no content columns, and user content never appears in our operational logs.
- Stored (metadata): check type, verdict, confidence, scam pattern, language, country, analysis engine and status, catalog version, timestamps, the keyed-hash installation identifier, and your feedback if given.
- Extracted and stored as threat indicators: a number, link, or domain that appeared inside content classified as fraudulent (Section 10).
- File metadata is minimized where technically implemented; we make no permanent-deletion promise about every provider unless contractually confirmed.
10. Threat database and challenges
Extracted indicators (scammers' numbers/links/domains) are reviewable risk signals, not final accusations; an indicator may still be personal data or belong to an impersonation victim, so we do not automatically treat it as anonymous. To request review, correction, or removal of a number, link, domain, or result: support@taakad.app. Submitting a challenge does not automatically change a verdict; corrections follow evidence review and the controlled catalog process.
11. Retention
| Data | Period |
|---|---|
| Original submitted content in TAAKAD's app database | Not stored after the check completes |
| Video files | Never uploaded — a frame is extracted on your device |
| Content at Anthropic/OpenAI | Up to 30 days under their current standard terms, with the Section 4 exceptions |
| TAAKAD operational logs | For the shortest period needed for security and troubleshooting; our in-database records (e.g. rate-limit counters) rotate within ~24 hours. Operational logs at our hosting provider are retained for at most seven days and are then permanently deleted. HTTP request logs — the only logs that carry an IP address — are not enabled on our hosting plan, so they are never generated |
| Account | Until you delete it |
| Check-history metadata | With the account — your account's device-linked history rows are deleted on account deletion |
| Push token and alert consent | Until disabled in the app or OS, or the account is deleted |
| Caller ID protection list on your device · checked-calls log (Android) | Until the feature is turned off, logout, or account switch, then deleted from the device |
| Identity-unlinked device record kept after deletion (usage limits, abuse prevention) | 90 days maximum from last use, then deleted automatically. It holds no account, no push token, no consents, and no check history, and reinstalling the app generates a new identifier so it cannot track you across installs |
| Subscription records and receipt fingerprints | For the subscription's life plus what tax, accounting, and fraud-prevention obligations require |
| Threat indicators | While necessary and proportionate for protection, with review, correction, and removal where inaccurate |
| Backups | Under the hosting provider's secure cycle, for disaster recovery only |
12. Export and deletion
- Export (in-app) returns: your devices (platform, build, last seen, country), your subscriptions (status and dates), alert consents, and your check-history metadata (date, type, verdict, confidence, pattern, language, country, your feedback). It will not contain your original check content, because that content is not stored.
- Deletion (in-app) is an immediate deletion process with bounded completion: the authentication user, your account data, and your subscriptions are deleted; your account's device-linked check history is deleted; alert consents are withdrawn and push tokens removed for those devices; and the Caller ID protection list is cleared from your device — immediately, with full completion from active systems within 30 days at most unless law or security requires limited retention. What may remain: receipt fingerprints and transaction identifiers detached from your identity (fraud/replay prevention, tax obligations), an identity-unlinked device record for usage limits (automatically deleted after at most 90 days from last use), security records, isolated backups until their cycle expires, and provider-held data under their terms.
- A public external deletion page is also available at taakad.app/account-deletion for anyone unable to access the app.
- Deleting a TAAKAD account does not automatically cancel an Apple or Google subscription — manage or cancel it in your store account.
13. Your rights
Depending on your country's applicable law, you have rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent (without affecting prior lawful processing), and complaint to a competent data-protection authority where available. For any request you cannot complete in-app: support@taakad.app; we may ask for limited information to verify identity.
Legal bases where required: contract performance (checks, account, subscription), explicit consent (sending content to providers, notifications), legitimate interests (protecting users, preventing abuse, securing the service, without overriding your rights), and legal obligation.
14. Children and capacity
Account creation and purchases require legal capacity to contract. A minor should use the service through a parent or legal guardian where their local law requires it, and parents and guardians may use TAAKAD to protect their families. We do not knowingly collect unnecessary personal data from children and respect applicable local children's-privacy laws.
Where content involves immediate danger, extortion, or exploitation of a minor, contact a trusted guardian and the police immediately; TAAKAD is not an emergency service and does not report on your behalf.
15. Security
We apply reasonable safeguards: data minimization, no original-content storage where so designed, restricted access, encrypted transport, hashed identifiers, server-side entitlement and rate controls, receipt-replay prevention, and keeping secrets and user content out of logs. No electronic system is 100% secure; we cannot guarantee prevention of every incident, but we act proportionately and notify authorities and individuals where the law requires.
16. Changes and contact
We may update this Policy when the app, the law, or the providers change, with appropriate notice before material changes where required, and without relying on earlier consent for an incompatible new purpose without a proper legal basis. Contact, requests, and challenges: support@taakad.app