يعمل تطبيق «جبتها منين؟» محليًا من دون حساب إجباري أو إعلانات،
ويستخدم Firebase Remote Config تلقائيًا لفحص معلومات إصدار التطبيق.
تشرح هذه السياسة ما يحدث لبياناتك عند الاستخدام وعند اختيارك ربط
Google Drive للنسخ الاحتياطي.
آخر تحديث: 9 أغسطس 2026الإصدار المشمول: 1.0.0
1 نطاق هذه السياسة
تنطبق هذه السياسة على تطبيق «جبتها منين؟» (WhereFrom)، ومعرّف الحزمة
com.iaraby.wherefrom، الذي يطوره Karam Araby. لا تنطبق
على مواقع أو تطبيقات أو خدمات تابعة لجهات أخرى قد تفتحها باختيارك من
داخل التطبيق.
2 البيانات التي يحفظها التطبيق محليًا
يتيح التطبيق لك حفظ معلومات تختار إدخالها عن مشترياتك، وقد تشمل:
اسم الغرض والتصنيف والمتجر أو المصدر.
رابط المصدر أو رقم هاتف المتجر، إذا أضفتهما.
السعر والعملة وتاريخ الشراء.
التفاصيل والملاحظات ورأيك في إعادة الشراء والمفضلة.
صورة تختارها من جهازك.
إعدادات التطبيق، مثل اللغة والمظهر.
تُحفظ هذه البيانات في مساحة التطبيق الخاصة على جهازك. لا يشغّل
المطور خادمًا خاصًا لتلقي سجلات المشتريات أو الصور. قد تدرج خدمة
النسخ الاحتياطي الخاصة بنظام التشغيل بيانات التطبيق المحلية ضمن نسخة
جهازك، وفق إعدادات جهازك وسياسات Google أو Apple.
3 فحص التحديث وFirebase Remote Config
عند تشغيل التطبيق، يتصل Firebase Remote Config تلقائيًا للتحقق من
رقم الإصدار المطلوب، وما إذا كان التحديث اختياريًا أو إلزاميًا، ورابط
المتجر المناسب. وقد يستقبل التطبيق تحديثات لهذه القيم أثناء عمله.
لا تتضمن هذه الطلبات سجلات مشترياتك أو صورها أو ملاحظاتك.
يعتمد Remote Config على Firebase Installations، ولذلك تنشئ Firebase
معرّف تثبيت عشوائيًا خاصًا بهذه النسخة من التطبيق
(Firebase Installation ID) ورمز مصادقة مرتبطًا به. وقد تُرسل أيضًا
بيانات التطبيق والجهاز اللازمة لاختيار الإعداد المناسب، ومنها معرّف
التطبيق واسم الحزمة وإصدار التطبيق ورقم البناء وإصدار SDK، واللغة أو
إعداد المنطقة ورمز البلد/المنطقة المضبوط على الجهاز (وقد يكون مجرد
مؤشر تقريبي للبلد)، والمنطقة الزمنية، والمنصة وإصدار نظام التشغيل.
تتلقى Google كذلك عنوان IP وبيانات الطلب وسجلات الأمان أو الأخطاء
المعتادة عند الاتصال بخوادمها.
لا يطلب التطبيق موقع GPS أو موقعًا دقيقًا لهذه الوظيفة. معرّف التثبيت
ليس معرّف إعلانات ولا معرّف حساب Firebase، ولا نضيف إشارات مخصصة أو
خصائص تحليلات إلى Remote Config، ولا نستخدمه للإعلانات أو تتبع سلوك
الشراء.
4 تسجيل Google والنسخ الاحتياطي الاختياري
تستطيع استخدام التطبيق من دون تسجيل الدخول. إذا اخترت ربط Google
Drive، يستخدم التطبيق Google Sign-In وFirebase Authentication
للتحقق من حسابك. وقد تعالج هذه الخدمات معرّف مستخدم Firebase ومعرّف
حساب Google أو مزود تسجيل الدخول، وعنوان بريد Google، واسم العرض، ورابط
صورة الحساب إن كانت متاحة، ورموز المصادقة، وبيانات أساسية عن إنشاء
الحساب وآخر تسجيل دخول. يبقى سجل Firebase Authentication بعد تسجيل
الخروج أو إلغاء وصول Google إلى أن يُحذف وفق الخطوات أدناه.
يطلب التطبيق نطاق الوصول
drive.appdata فقط. يسمح هذا النطاق للتطبيق بإنشاء وقراءة
وحذف نسخه الاحتياطية داخل مجلد بيانات خاص ومخفي في Google Drive، ولا
يسمح له بالاطلاع على ملفات Drive الأخرى. تحتوي النسخة على حقول سجلات
مشترياتك التي أدخلتها، مثل الاسم والمصدر والرابط أو الهاتف والسعر
والعملة والتواريخ والتصنيف والتفاصيل والملاحظات والمفضلة ورأي إعادة
الشراء، إضافة إلى الصور الموجودة التي اخترتها، وبيان تقني يتضمن وقت
إنشاء النسخة وإصدار التطبيق ومخطط النسخة والأعداد وقيم التحقق. لا
تتضمن النسخة إعداد اللغة أو المظهر.
صُمم التطبيق للاحتفاظ بأحدث ثلاث نسخ بعد الرفع وحذف الأقدم. عملية
التنظيف هذه بأفضل جهد؛ فإذا تعذرت، قد تبقى نسخ إضافية إلى أن تحذفها
بنفسك أو تنجح عملية تنظيف لاحقة.
تنبيه أمني مهم
يحمي Google Drive النسخة وفق أمان حساب Google، لكن التطبيق لا يضيف
حاليًا تشفيرًا من طرف إلى طرف أو كلمة مرور مستقلة إلى ملف النسخة
الاحتياطية.
5 كيف نستخدم البيانات
تُستخدم البيانات فقط لتقديم الوظائف التي تطلبها، مثل:
عرض سجلات المشتريات والبحث فيها وتصفيتها وتعديلها.
فتح رابط المصدر أو رقم الهاتف عند اختيارك.
مشاركة المعلومات عبر التطبيقات التي تحددها على جهازك.
جلب إعداد الإصدار والتحديث المناسب من Firebase Remote Config.
مصادقة حساب Google الذي تختار استخدامه للنسخ السحابي.
إنشاء نسخة احتياطية أو استعادتها أو حذفها من Google Drive.
الحفاظ على اللغة والمظهر والتفضيلات التي اخترتها.
لا نستخدم بياناتك للإعلانات المخصصة، أو إنشاء ملفات تعريف تسويقية، أو
بيعها، أو تدريب نماذج ذكاء اصطناعي.
6 المشاركة والخدمات التابعة لأطراف ثالثة
لا يشارك التطبيق بيانات مشترياتك مع المطور أو وسطاء بيانات. تعالج
Google وFirebase تلقائيًا بيانات التثبيت والبيانات التقنية اللازمة
لـRemote Config. وعندما تختار تسجيل Google والنسخ السحابي، تعالجان
أيضًا معلومات المصادقة وتفويض Drive وتخزين النسخ اللازمة لتقديم هذه
الوظائف، وفق سياساتهما وشروطهما.
يلتزم استخدام التطبيق للمعلومات المستلمة من Google APIs بسياسة بيانات
مستخدمي خدمات Google API، بما في ذلك متطلبات الاستخدام المحدود.
عند فتح رابط أو إجراء مكالمة أو مشاركة محتوى، تنتقل المعلومات التي
اخترتها إلى المتصفح أو تطبيق الهاتف أو تطبيق المشاركة الذي حددته،
وتخضع بعد ذلك لسياسة ذلك التطبيق.
7 الأمان والاحتفاظ بالبيانات
نستخدم وسائل الحماية التي توفرها أنظمة Android وiOS لمساحة التطبيق
الخاصة، ونستخدم تدفقات OAuth الرسمية من Google للوصول المحدود إلى
Drive. ومع ذلك، لا توجد وسيلة تخزين أو نقل مضمونة الأمان بنسبة 100%.
احمِ جهازك وحساب Google بقفل شاشة وكلمة مرور قوية والتحقق بخطوتين.
تبقى البيانات المحلية حتى تحذف السجل، أو تمسح بيانات التطبيق، أو تزيل
التطبيق، مع مراعاة أي نسخ يحتفظ بها نظام التشغيل. يحذف التطبيق ملفات
العمل المؤقتة للنسخ عند اكتمال العملية بصورة طبيعية؛ وإذا انقطعت، قد
تبقى الملفات في مساحة النظام المؤقتة إلى أن ينظفها النظام. تبقى نسخ
Drive حتى تحذفها من شاشة النسخ أو تحذف بيانات التطبيق المخفية من
إعدادات Google Drive؛ وحذف حساب المصادقة لا يحذف هذه النسخ تلقائيًا.
يحتفظ Firebase بسجل المصادقة الاختياري حتى حذفه، وفقًا لسياسات
الاحتفاظ والنسخ الاحتياطي لدى Google. يبقى معرّف Firebase Installations
مخزنًا محليًا ما دامت نسخة التطبيق وبياناتها موجودة؛ يؤدي مسح بيانات
التطبيق أو إزالته عادةً إلى إعادة ضبط حالة التثبيت المحلية بحسب
المنصة، وقد يُنشأ معرّف جديد عند الاستخدام التالي أو إعادة التثبيت.
تحتفظ Google بالسجلات الفنية
والأمنية ونسخها الاحتياطية وتحذفها وفق سياساتها والتزاماتها القانونية.
8 حذف الحساب والبيانات — خطوات الطلب
طلب حذف حساب «جبتها منين؟»
إذا استخدمت تسجيل Google، يمكنك طلب حذف سجل حسابك الاختياري في
Firebase Authentication. لا يوجد حساب Firebase Authentication
لحذفه إذا لم تسجل الدخول أصلًا.
قبل إرسال الطلب، احذف كل نسخة Drive تريد إزالتها من شاشة النسخ
الاحتياطي (يمكنك تكرار حذف أحدث نسخة)، أو احذف بيانات التطبيق المخفية
من إعدادات Google Drive. لا يستطيع المطور فتح ملفات Drive الخاصة بك
أو حذفها بمجرد رسالة بريد، وحذف حساب Firebase لا يحذفها تلقائيًا.
احذف السجلات المحلية من داخل التطبيق، أو امسح بيانات التطبيق من
إعدادات الجهاز، أو أزل التطبيق إذا أردت حذف كل البيانات المحلية.
أرسل من عنوان Google المرتبط بالتطبيق رسالة بعنوان
«WhereFrom account deletion request» إلى
karam.araby@gmail.com
واذكر أنك تطلب حذف حساب تطبيق الحزمة
com.iaraby.wherefrom.
نتحقق من الملكية باستخدام عنوان المرسل، وقد نطلب تأكيدًا محدودًا.
نعالج الطلب المؤكد عادةً ونرسل تأكيد الإكمال خلال 30 يومًا.
يشمل الحذف سجل Firebase Authentication الواقع تحت سيطرتنا، بما فيه
معرّف Firebase والارتباط بمزود Google والبريد والاسم ورابط الصورة
وبيانات المصادقة الأساسية المرتبطة. لا يحذف ذلك حساب Google نفسه.
قد تحتفظ Google ببيانات محدودة في سجلات الأمان أو النسخ الاحتياطية
للفترة التي تفرضها سياساتها أو القوانين. نحتفظ بمراسلات الطلب فقط للمدة
اللازمة لتنفيذه وتوثيقه ومنع إساءة الاستخدام أو الوفاء بالتزام قانوني.
تسجيل الخروج أو إلغاء الإذن لا يساوي حذف الحساب. يمكنك إلغاء وصول
التطبيق بصورة منفصلة من
صفحة التطبيقات المرتبطة بحساب Google
.
معرّف Firebase Installations خاص بالتثبيت وليس حسابًا؛ يؤدي مسح بيانات
التطبيق أو إزالته عادةً إلى إعادة ضبط حالته المحلية بحسب المنصة، وقد
تنطبق على سجله لدى Google مدد الاحتفاظ الخاصة بخدمات Firebase.
9 خصوصية الأطفال
التطبيق أداة عامة لتذكر المشتريات، وليس موجهًا خصيصًا للأطفال دون 13
عامًا أو السن الأدنى المعمول به في بلدهم. لا يجمع المطور عن قصد بيانات
شخصية من الأطفال. إذا اعتقد ولي أمر أن طفلًا قد أرسل بيانات عبر ميزة
Google الاختيارية، يمكنه التواصل معنا لطلب المساعدة.
10 التغييرات على السياسة
قد نحدّث هذه السياسة عند تغيير وظائف التطبيق أو المتطلبات القانونية.
سنحدّث تاريخ «آخر تحديث» في أعلى الصفحة، وقد نعرض إشعارًا داخل التطبيق
عندما يكون التغيير جوهريًا.
11 التواصل
للأسئلة المتعلقة بالخصوصية أو طلبات الحذف، تواصل مع مطور التطبيق:
WhereFrom works locally without a required account or ads and uses
Firebase Remote Config automatically to check app-version
information. This policy explains what happens to your information
when you use the app and optionally connect Google Drive for backup.
Last updated: August 9, 2026Covered version: 1.0.0
1 Scope
This policy applies to the WhereFrom mobile application, package ID
com.iaraby.wherefrom, developed by Karam Araby. It does
not apply to third-party websites, apps, or services that you choose
to open from WhereFrom.
2 Information stored locally
WhereFrom lets you save information that you choose to enter about
purchases. This may include:
Item name, category, shop, or source.
A source link or optional shop phone number.
Price, currency, and purchase date.
Details, notes, buy-again opinion, and favorite status.
A photo that you select from your device.
App preferences such as language and appearance.
This information is stored in the app's private area on your device.
The developer does not operate a proprietary server that receives
your purchase records or photos. Your operating system's device
backup service may include local app data depending on your device
settings and Google or Apple policies.
3 Update checks and Firebase Remote Config
When the app starts, Firebase Remote Config connects automatically
to check the target version, whether an update is optional or
required, and the appropriate store URL. The app may also receive
updates to these values while it is running. These requests do not
include your purchase records, photos, or notes.
Remote Config relies on Firebase Installations, so Firebase creates
a random identifier for this installation of the app (a Firebase
Installation ID) and an associated authentication token. Firebase
may also receive app and device data needed to select the right
configuration, including the app ID and package name, app version
and build number, SDK version, language or locale, the country or
region code configured on the device (which may only approximate
your country), time zone, platform, and operating-system version.
Google also receives the IP address, request data, and ordinary
service security or error logs when the app connects to its servers.
WhereFrom does not request GPS or precise location for this feature.
The installation ID is neither an advertising ID nor a Firebase
account ID. We do not add custom signals or analytics properties to
Remote Config, and we do not use it for advertising or purchase
behavior tracking.
4 Optional Google sign-in and backup
You can use WhereFrom without signing in. If you choose to connect
Google Drive, the app uses Google Sign-In and Firebase Authentication
to verify your account. These services may process a Firebase user
ID, the Google Account or sign-in-provider ID, your Google email
address, display name, profile-photo URL when available,
authentication tokens, and basic account-creation and last-sign-in
metadata. The Firebase Authentication record remains after sign-out
or revoking Google access until it is deleted using the steps below.
WhereFrom requests only the drive.appdata scope. This
lets the app create, read, and delete its own backups in Google
Drive's hidden app-data folder; it does not allow WhereFrom to read
your other Drive files. A backup contains the purchase-record fields
you entered, such as item and source names, link or phone number,
price, currency, dates, category, details, notes, favorite status,
and buy-again choice. It also contains the existing photos you
selected and a technical manifest with the creation time, app and
backup-schema versions, counts, and checksums. It does not contain
your language or appearance setting.
The app is designed to keep the latest three backups after upload
and delete older ones. That cleanup is best effort; if it fails,
extra copies may remain until you delete them or a later cleanup
succeeds.
Important security note
Google Drive protects the backup under your Google Account's
security. WhereFrom does not currently add end-to-end encryption
or a separate password to the backup archive.
5 How information is used
Information is used only to provide features you request, such as:
Displaying, searching, filtering, and editing purchase records.
Opening a source link or phone number when you choose to do so.
Sharing information through apps you select on your device.
Fetching the appropriate version and update configuration.
Authenticating the Google Account you choose for cloud backup.
Creating, restoring, or deleting a Google Drive backup.
Remembering your language, appearance, and other preferences.
We do not use your information for personalized ads, marketing
profiles, sale, or training artificial intelligence models.
6 Sharing and third-party services
WhereFrom does not share your purchase information with the developer
or data brokers. Google and Firebase automatically process the
installation and technical data needed for Remote Config. When you
choose Google sign-in and cloud backup, they also process the
authentication, Drive authorization, and backup-storage information
needed to provide those features under their policies and terms.
WhereFrom's use and transfer of information received from Google APIs
adheres to the Google API Services User Data Policy, including the
Limited Use requirements.
If you open a link, place a call, or share content, the information
you select is passed to the browser, phone app, or sharing app you
choose and is then governed by that app's privacy practices.
7 Security and retention
We rely on Android and iOS protections for private app storage and
use Google's official OAuth flows for limited Drive access. No method
of storage or transmission is guaranteed to be 100% secure. Protect
your device and Google Account with a screen lock, a strong password,
and two-step verification.
Local information remains until you delete a record, clear app data,
or uninstall the app, subject to any backups retained by your
operating system. The app removes temporary backup work files when
an operation completes normally; if interrupted, files may remain in
system temporary storage until the operating system cleans them up.
Drive backups remain until you delete them from the backup screen or
remove the app's hidden data through Google Drive settings; deleting
the authentication account does not delete those backups automatically.
Firebase retains the optional authentication record until it is
deleted, subject to Google's retention and backup practices. The
Firebase Installation ID remains stored locally while that app
installation and its data remain. Clearing app data or uninstalling
normally resets local installation state depending on the platform,
and a new ID may be created on the next use or reinstall. Google
retains and deletes technical and security logs and backup copies
under its policies and legal obligations.
8 Account and data deletion — request steps
Request deletion of your WhereFrom account
If you used Google sign-in, you can request deletion of your
optional Firebase Authentication account record. There is no
Firebase Authentication account to delete if you never signed in.
Before sending the request, delete every Drive copy you want
removed from the backup screen (you can repeatedly delete the
latest copy), or delete the app's hidden data in Google Drive
settings. The developer cannot open or delete your private Drive
files from an email request, and deleting Firebase Authentication
does not remove them automatically.
Delete local records in the app, clear the app's data in device
settings, or uninstall it if you want to remove all local data.
From the Google email address linked to the app, send an email with
the subject “WhereFrom account deletion request” to
karam.araby@gmail.com
and state that you want the account for package
com.iaraby.wherefrom deleted.
We verify ownership using the sender address and may request a
limited confirmation. We normally process a verified request and
send completion confirmation within 30 days.
Deletion covers the Firebase Authentication record under our control,
including the Firebase ID, Google provider link, email, name,
photo URL, and associated basic authentication metadata. It does not
delete your Google Account. Google may retain limited data in security
logs or backups for periods required by its policies or by law. We
retain request correspondence only as long as needed to complete and
document the request, prevent abuse, or meet a legal obligation.
Signing out or revoking permission is not account deletion. You can
separately revoke app access on your
Google Account connections page
.
The Firebase Installation ID is installation-scoped, not an account;
clearing app data or uninstalling normally resets its local state,
depending on the platform, while Google's Firebase-service retention
periods may still apply to its server-side record.
9 Children's privacy
WhereFrom is a general purchase-memory tool and is not specifically
directed to children under 13 or the applicable minimum age in their
country. The developer does not knowingly collect children's personal
information. A parent or guardian who believes a child submitted
information through the optional Google feature may contact us for
assistance.
10 Changes to this policy
We may update this policy when the app's features or legal
requirements change. We will update the “Last updated” date above and
may provide an in-app notice when a change is material.
11 Contact
For privacy questions or deletion requests, contact the developer: