Privacy Policy
Last updated: 2026-05-01 — SA Arabic
SA Arabic Meetings (the "app") helps members reserve weekly meetings, exchange messages in private chat groups, and place audio / video calls. This policy describes what data we collect, why we collect it, how we use it, and the choices you have. Using the app means you accept the practices below.
1. Information we collect
- Account data. Username (staff) or email and display name (chat users), password (stored as a salted bcrypt hash — we never see the plaintext), assigned role.
- Contact data. Phone number for meeting reservations and chat-account verification.
- User-generated content. Chat messages, voice recordings, photo and PDF attachments, read receipts, presence (online / offline / on-call), typing indicators.
- Call signaling data. Caller and callee identity, call start / end times, and minimal WebRTC signaling needed to establish 1:1 and group audio / video calls. Call media is peer-to-peer and is not stored on our servers.
- Push tokens. Apple APNs and Firebase Cloud Messaging device tokens are stored against the chat account for the lifetime of the install, so we can deliver chat and call notifications.
- Diagnostic data. Server-side error logs that may include the request path and a generated user identifier. We do not collect device advertising identifiers and do not perform third-party analytics or tracking.
2. How we use the data
- Authenticate you and authorize access to features.
- Manage meeting reservations and waiting lists.
- Deliver chat messages, attachments, and audio / video call invitations to the right device.
- Send transactional email (verification, password reset) and push notifications.
- Investigate abuse, fix bugs, and keep the service reliable.
3. Permissions on your device
- Microphone — voice messages and audio / video calls.
- Camera — taking new photos for chat and video calls.
- Photo library — picking existing photos to attach, and saving photos you receive.
- Notifications — incoming messages and incoming calls.
Each permission is requested only when the related feature is first used and can be revoked from the operating-system Settings at any time.
4. How data is stored and shared
Application data lives in a managed Postgres database. Attachments are stored in Vercel Blob with private URLs gated by your session. All traffic is encrypted in transit over HTTPS / TLS. Push messages are delivered through Apple APNs and Firebase Cloud Messaging. Email is delivered via SMTP. We do not sell, rent, or share your data with third parties for advertising. Data is shared only with subprocessors strictly necessary to operate the app (database host, blob storage host, push-notification provider, email-delivery provider).
5. Retention
Account, message, attachment, and reservation data are retained for as long as the account is active. Push tokens are retained for the lifetime of the install and removed when the OS reports the token as expired. You can request deletion of your account and content at any time (see Contact below); on confirmed request we remove personal data within 30 days, except where we are required to keep a record for legal purposes.
6. Children
The app is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it.
7. Your rights
You can access, correct, or delete your account data, and revoke notification / camera / microphone / photo permissions from the operating-system Settings. To exercise rights or ask a question, contact us at the address below.
8. Changes to this policy
When we make material changes we update the "Last updated" date at the top of this page and, where appropriate, notify you in-app.
9. Contact
Questions or deletion requests: omar.alhannash@gmail.com.