C
Cipher
تواصل صوتي ونصّي مشفّر طرف-لطرف
الخصوصية هي الأساس
سياسة الخصوصية
آخر تحديث: 10 يوليو 2026
Cipher تطبيق للتواصل الخاص. رسائلك النصّية ومكالماتك الصوتية مشفّرة طرف-لطرف
(End-to-End)، بمعنى أنها تُشفّر على جهازك ولا تُفكّ إلا على جهاز الطرف الآخر —
لا نستطيع نحن قراءتها أو الاستماع إليها. هذه السياسة توضّح البيانات
القليلة التي نحتاجها لتشغيل الخدمة، وكيف نتعامل معها.
١. البيانات التي نجمعها
معلومات الحساب
- البريد الإلكتروني — لإنشاء حسابك وتسجيل الدخول واستعادة كلمة السر.
- كلمة السر — تُخزَّن مُجزّأة (hashed) لدى مزوّد المصادقة ولا نراها كنصّ.
- رمز الهوية (PIN) والمفتاح العام — رمز قصير ومفتاح تشفير عام يسمحان لأصدقائك بإضافتك والتواصل معك بأمان. المفتاح الخاص لا يغادر جهازك أبداً.
- الاسم المعروض والصورة (اختياري) — إن أضفتها.
محتواك (رسائل ومكالمات)
- نصّ الرسائل والمكالمات الصوتية: مشفّرة طرف-لطرف. تمرّ عبر خوادمنا كنصّ مُشفَّر فقط ولا يمكننا فكّها.
- الوسائط (صور، رسائل صوتية): تُنقل عبر اتصال مشفّر (TLS) وتُخزَّن على خوادمنا لتوصيلها للطرف الآخر، ثم تُدار حسب إعدادات الاختفاء.
- لا نبيع محتواك، ولا نستخدمه للإعلانات، ولا نحلّله.
ما لا نجمعه
- لا نجمع موقعك الجغرافي.
- لا نستخدم أدوات تتبّع إعلاني ولا نتتبّعك عبر تطبيقات أو مواقع أخرى.
- لا نطلب دفتر جهات اتصالك — تضيف أصدقاءك برمز PIN أو QR فقط.
٢. كيف نستخدم البيانات
- لتشغيل حسابك وتسجيل دخولك واستعادة كلمة سرّك.
- لتوصيل رسائلك ومكالماتك بين الأجهزة.
- لإرسال إشعارات الرسائل والمكالمات (عبر خدمة الإشعارات).
- للحفاظ على أمان الخدمة ومنع الإساءة (مثل الحظر والإبلاغ الذي تبدؤه أنت).
٣. مقدّمو الخدمة
نعتمد على مزوّدين موثوقين لتشغيل التطبيق، ويصلون فقط للبيانات اللازمة لأداء مهامهم:
- Supabase — قاعدة البيانات، المصادقة، التخزين، وتبادل إشارات المكالمات. يخزّن حسابك ومحتواك المُشفَّر.
- خادم التحويل (TURN) — يُمرّر بيانات المكالمة عند تعذّر الاتصال المباشر؛ يرى حِزماً مشفّرة فقط ولا يستطيع فكّها.
- خدمة الإشعارات (Expo / Apple) — لإيصال تنبيهات الرسائل والمكالمات.
- App Store (Apple) — لتوزيع التطبيق.
٤. الاحتفاظ بالبيانات وحذفها
- نحتفظ ببيانات حسابك ما دام حسابك فعّالاً.
- يمكنك حذف حسابك ومحتواك المرتبط به بمراسلتنا على nahlah@nahlah.io.
- الرسائل ذات الاختفاء التلقائي تُحذف حسب المدة التي تختارها.
٥. أمان البيانات
نستخدم التشفير طرف-لطرف للنصّ والمكالمات، والتشفير أثناء النقل (TLS) لكل الاتصالات مع خوادمنا.
مفتاحك الخاص محفوظ في المخزن الآمن للجهاز (Keychain) ولا يُرفع إلى خوادمنا. لا يوجد نظام آمن
بنسبة 100٪، لكننا نصمّم Cipher بحيث يبقى محتواك غير مقروء لنا بحكم البنية نفسها.
٦. الأطفال
Cipher غير موجّه للأطفال دون 13 عاماً، ولا نجمع بياناتهم عن قصد.
٧. التغييرات على هذه السياسة
قد نحدّث هذه السياسة، وسننشر التحديث هنا مع تعديل تاريخ «آخر تحديث».
٨. تواصل معنا
لأي سؤال عن الخصوصية أو لطلب حذف بياناتك: nahlah@nahlah.io
Privacy by design
Privacy Policy
Last updated: July 10, 2026
Cipher is a private communication app. Your message text and voice calls are
end-to-end encrypted — encrypted on your device and only decrypted on
your contact's device, so we cannot read or listen to them. This policy
explains the limited data we need to run the service and how we handle it.
1. Data We Collect
Account information
- Email address — to create your account, sign in, and recover your password.
- Password — stored hashed by our authentication provider; we never see it in plain text.
- PIN & public key — a short identifier and a public encryption key so contacts can add and message you securely. Your private key never leaves your device.
- Display name & photo (optional) — if you add them.
Your content (messages & calls)
- Message text and voice calls: end-to-end encrypted. They pass through our servers only as ciphertext that we cannot decrypt.
- Media (images, voice notes): sent over an encrypted connection (TLS) and stored on our servers to deliver them, then handled according to your disappearing-message settings.
- We do not sell your content, use it for advertising, or analyze it.
What we do not collect
- We do not collect your location.
- We do not use advertising trackers or track you across other apps or websites.
- We do not request your address book — you add friends by PIN or QR only.
2. How We Use Data
- To operate your account, sign-in, and password recovery.
- To deliver your messages and calls between devices.
- To send message and call notifications (via a push service).
- To keep the service safe and prevent abuse (e.g. the block/report tools you initiate).
3. Service Providers
We rely on trusted providers to run the app; they access only the data needed for their function:
- Supabase — database, authentication, storage, and call signaling. Stores your account and your encrypted content.
- TURN relay server — relays call data when a direct connection isn't possible; it only sees encrypted packets and cannot decrypt them.
- Push service (Expo / Apple) — to deliver message and call alerts.
- App Store (Apple) — to distribute the app.
4. Data Retention & Deletion
- We keep your account data while your account is active.
- You can delete your account and associated content by emailing nahlah@nahlah.io.
- Disappearing messages are deleted according to the timer you set.
5. Data Security
We use end-to-end encryption for text and calls, and encryption in transit (TLS) for all
communication with our servers. Your private key is stored in your device's secure Keychain
and is never uploaded to our servers. No system is 100% secure, but Cipher is designed so
that your content stays unreadable to us by architecture.
6. Children
Cipher is not directed to children under 13, and we do not knowingly collect their data.
7. Changes to This Policy
We may update this policy and will post changes here with a revised "Last updated" date.
8. Contact
For any privacy question or a data-deletion request: nahlah@nahlah.io