Privacy Policy
Effective Date: 2026-07-30
MostaGuide ("the App") is a touristic guide application. This Privacy Policy explains how we collect, use, and protect information when you use the App.
1. Information We Collect
- Account Information (optional): If you sign up or log in, we may collect your email address, name, and profile photo via email/password, Google Sign-In, or Apple Sign-In.
- User Content: Comments, favorites, and any touristic sites you create or submit.
- Media Content: Images and videos you choose to upload from your device to add to the App. These are processed by our third-party storage provider, Cloudinary, to optimize and deliver content.
- Location Data: Precise or approximate location, only if you grant permission. This data is processed ephemerally in real time to show nearby destinations and points of interest, and is not stored on our servers.
- App Information: App version and build number, used only for compatibility checks and bug fixes.
- Search Queries: Text you type into the search box is sent to our backend to return matching results. It is used only to run that search and is not stored.
- Reporting Data: When you report content, we record the reason you selected, any optional details you type, which content you reported, and a copy of that content as it appeared at the time (its text, image address, and the name of the account that posted it). If you are signed in, we record your account identifier. If you are not signed in, we instead attach a randomly generated identifier that the App creates and stores on your device. That identifier is not a hardware identifier, not an advertising identifier, and is not shared with anyone — it exists only so we can recognise repeated reports coming from the same installation. Reinstalling the App or clearing its data resets it.
- Moderation Data: If you block another user, we store the list of accounts you have blocked on your profile. If your account is suspended for violating these rules, we store that suspension along with its reason and date.
2. How We Use Information
- Provide and operate the App's core features.
- Display nearby places using your location when permitted.
- Allow you to upload and display media content.
- Let you open your device's dialer or maps app to contact or navigate to a place.
- Maintain security, prevent abuse, and moderate user-submitted content.
- Review reports of inappropriate content and act on them.
- Hide content from accounts you have chosen to block.
- Improve performance and fix bugs.
- Communicate with you about updates, support, and important notices.
3. Data Storage and Service Providers
We use trusted third-party services to operate the App:
- Firebase (Google): Authentication, and database services (Cloud Firestore).
- Supabase: Database and backend services.
- Cloudinary: Storage and optimization of user-uploaded images and videos.
- Hive (on-device local storage): Stores some data locally on your device for offline access and performance.
The App also keeps the following on your device only. This information is never transmitted to us:
- Your language preference.
- A list of the content you have already reported, so the App does not offer to report the same item twice.
- A cached copy of your own profile, so the App works while offline.
No analytics, advertising, or tracking. The App contains no analytics SDK, no crash-reporting SDK, no advertising SDK, and no third-party tracking software. We do not collect an advertising identifier, we do not build advertising profiles, and we do not track you across other apps or websites.
4. Permissions We Request
The App requests the following device permissions. Some are requested directly by the App, while others are added automatically by third-party libraries we use (such as Firebase and Google Sign-In) to enable their services:
- Location (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION): To show nearby destinations and points of interest on the map. You can deny this permission and still use the App with reduced functionality.
- Internet (INTERNET): Required to connect to our servers and display content.
- Network state (ACCESS_NETWORK_STATE): Added by the libraries we use to detect whether you are online, so requests can fail gracefully when you are not.
- Wake lock (WAKE_LOCK): Added by the video player, to keep the screen awake while a video is playing.
- Google Play License Check (com.android.vending.CHECK_LICENSE): A standard permission added automatically by Google Play to verify app licensing.
- Google Services Framework (READ_GSERVICES): Added automatically by the Google Sign-In library to access configuration data needed for Google authentication.
- App-Scoped Broadcast Permission (DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION): Added automatically by Firebase to securely receive internal broadcasts within the App itself. This permission is scoped to our App only and cannot be used by other apps to send it data.
The App also accesses your photos and videos in the following ways, which do not require declaring broad storage permissions:
- System Photo Picker (Android 13 and above): When you choose to upload an image or video, the App opens the operating system's built-in photo picker. You select exactly which file to share, and the App only receives access to that specific file — it cannot browse your full media library.
- Storage access (READ_EXTERNAL_STORAGE, Android 12 and below only): On older Android versions that do not support the system photo picker, the App requests this permission solely to let you select an existing photo or video to upload.
The App also uses the following capabilities, which do not require a runtime permission prompt:
- Phone dialer (tel: link): Tapping a phone number opens your device's default phone/dialer app with the number pre-filled. The App does not place calls automatically and does not access your call log or contacts.
- Maps (geo: link): Tapping a location can open your device's default maps application for directions.
5. Data Sharing
We do not sell or rent personal data. We share data only with the service providers listed above (Firebase, Supabase, Cloudinary) to enable core App functionality, subject to appropriate safeguards and their own privacy policies.
Reports are private. Submitted reports are visible only to our moderation team. If you report someone, they are not told who reported them. If you block someone, they are not notified.
6. Security
Data transmitted between the App and our servers is encrypted in transit using HTTPS/TLS. While no method is 100% secure, we take reasonable measures to protect your information.
7. Data Retention and Deletion
To delete your account or specific data, open Settings → Delete account in the App. This opens our secure deletion request page in your browser, where you choose between closing your entire account or removing selected data only (such as photos, comments, or submitted places), while keeping your account active.
We verify every request by email before deleting anything, to confirm it is really you. Verified requests are processed within 7–30 days. Selected data is removed from our active systems within 30 days after verification, and we do not keep it after that period unless a longer retention period is required by law, security, or fraud-prevention obligations.
Submitting the request form stores the email address and description you provide in our database, so that we can verify you own the account and act on the request. That record is deleted once the request has been completed.
Reports are retained. When content is reported, the report — including the copy of the reported content described in section 1 — is kept even after the original content has been deleted. We keep it to prevent abuse, to support the decision that was made, and to recognise repeat offenders. This applies whether the content was removed by us or deleted by the person who posted it.
Account & Data Deletion: Request deletion
8. Children's Privacy
The App is not directed to children under 13 years of age. If you believe we have collected personal information from a child under 13, contact us and we will delete it.
9. User-Generated Content, Reporting, and Moderation
Registered users may submit comments, media, and touristic site information. Inappropriate content, including nudity, sexually explicit material, graphic violence, hate speech, illegal content, or harassment is prohibited.
Reporting. The App includes a report feature that lets anyone viewing the App — including users browsing without an account — flag content they believe is inappropriate. You can report:
- A comment (for example, spam, harassment, or false information).
- A touristic site listing (for example, misleading information, inappropriate photos, or a duplicate entry). Photos and videos are reported as part of the listing they belong to.
Accounts are not reported directly. Where a comment is reported, our moderation team can act on the account that posted it.
To report content, open the menu next to a comment, or tap the flag icon on a site listing, select a reason, and optionally add details before submitting. No account is required to submit a report. Section 1 explains what a report records.
Blocking. If you are signed in, you can block another user from the menu next to one of their comments. Once blocked, their comments no longer appear for you. Blocking affects only your own view of the App — it is not a report, and the person you block is not notified. You can see everyone you have blocked, and unblock them at any time, under Settings → Blocked users.
Review and enforcement. Our team reviews submitted reports and may remove the violating content, suspend the account responsible, or both. A suspended account is signed out of the App and shown a notice explaining the suspension, and cannot sign back in. If you believe your account was suspended in error, contact us at the address in section 11.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted here with an updated Effective Date. Continued use of the App after changes indicates acceptance of the updated policy.
11. Contact Us
If you have questions or requests related to privacy, contact us at Dahozoheir1@gmail.com.
سياسة الخصوصية
تاريخ السريان: 2026-07-30
تطبيق "MostaGuide" ("التطبيق") هو تطبيق دليل سياحي. توضّح سياسة الخصوصية هذه كيفية جمعنا للمعلومات واستخدامها وحمايتها عند استخدامك للتطبيق.
1. المعلومات التي نجمعها
- معلومات الحساب (اختيارية): عند التسجيل أو تسجيل الدخول، قد نجمع بريدك الإلكتروني واسمك وصورتك الشخصية عبر البريد الإلكتروني وكلمة المرور، أو تسجيل الدخول عبر Google، أو تسجيل الدخول عبر Apple.
- محتوى المستخدم: التعليقات، والعناصر المفضّلة، وأي مواقع سياحية تنشئها أو ترسلها.
- المحتوى الإعلامي (الوسائط): الصور ومقاطع الفيديو التي تختار تحميلها من جهازك لإضافتها إلى التطبيق. تتم معالجة هذه الملفات بواسطة مزوّد التخزين الخارجي Cloudinary لتحسين المحتوى وتقديمه.
- بيانات الموقع: الموقع الدقيق أو التقريبي، فقط إذا منحت الإذن بذلك. تتم معالجة هذه البيانات مؤقتًا في الوقت الفعلي لعرض الوجهات ونقاط الاهتمام القريبة، ولا يتم تخزينها على خوادمنا.
- معلومات التطبيق: إصدار التطبيق ورقم البناء (build number)، وتُستخدم فقط للتحقق من التوافق وإصلاح الأخطاء.
- عمليات البحث: يُرسل النص الذي تكتبه في مربع البحث إلى خادمنا الخلفي لإرجاع النتائج المطابقة. يُستخدم فقط لتنفيذ عملية البحث تلك ولا يتم تخزينه.
- بيانات البلاغات: عندما تُبلغ عن محتوى ما، نسجّل السبب الذي اخترته، وأي تفاصيل اختيارية تكتبها، والمحتوى الذي أبلغت عنه، ونسخة من ذلك المحتوى كما كان وقت الإبلاغ (نصه، وعنوان الصورة، واسم الحساب الذي نشره). إذا كنت مسجّل الدخول، نسجّل معرّف حسابك. أما إذا لم تكن مسجّل الدخول، فنُرفق بدلًا من ذلك معرّفًا عشوائيًا ينشئه التطبيق ويخزّنه على جهازك. هذا المعرّف ليس معرّف جهاز، وليس معرّف إعلانات، ولا تتم مشاركته مع أي جهة — ويوجد فقط لتمكيننا من التعرّف على البلاغات المتكررة الصادرة من نفس عملية التثبيت. تؤدي إعادة تثبيت التطبيق أو مسح بياناته إلى إعادة تعيين هذا المعرّف.
- بيانات الإشراف: إذا حظرت مستخدمًا آخر، فإننا نخزّن قائمة الحسابات التي حظرتها على ملفك الشخصي. وإذا تم تعليق حسابك بسبب مخالفة هذه القواعد، فإننا نسجّل ذلك التعليق مع سببه وتاريخه.
2. كيف نستخدم المعلومات
- توفير الميزات الأساسية للتطبيق وتشغيلها.
- عرض الأماكن القريبة باستخدام موقعك عند السماح بذلك.
- السماح لك بتحميل المحتوى الإعلامي وعرضه.
- السماح لك بفتح تطبيق الاتصال أو الخرائط في جهازك للتواصل مع مكان ما أو التنقل إليه.
- الحفاظ على الأمان، ومنع إساءة الاستخدام، والإشراف على المحتوى الذي يرسله المستخدمون.
- مراجعة بلاغات المحتوى غير اللائق واتخاذ الإجراء المناسب بشأنها.
- إخفاء المحتوى الخاص بالحسابات التي اخترت حظرها.
- تحسين الأداء وإصلاح الأخطاء البرمجية.
- التواصل معك بشأن التحديثات، والدعم، والإشعارات المهمة.
3. تخزين البيانات ومزوّدو الخدمة
نستخدم خدمات موثوقة من أطراف خارجية لتشغيل التطبيق:
- Firebase (من Google): خدمات المصادقة وقاعدة البيانات (Cloud Firestore).
- Supabase: خدمات قاعدة البيانات والخلفية (backend).
- Cloudinary: تخزين وتحسين الصور ومقاطع الفيديو التي يرفعها المستخدمون.
- Hive (تخزين محلي على الجهاز): يخزّن بعض البيانات محليًا على جهازك للوصول دون اتصال بالإنترنت ولتحسين الأداء.
كما يحتفظ التطبيق بالبيانات التالية على جهازك فقط، ولا تُرسل هذه المعلومات إلينا أبدًا:
- تفضيل اللغة الخاص بك.
- قائمة بالمحتوى الذي سبق أن أبلغت عنه، حتى لا يعرض عليك التطبيق الإبلاغ عن العنصر نفسه مرتين.
- نسخة مخزّنة مؤقتًا من ملفك الشخصي، حتى يعمل التطبيق دون اتصال بالإنترنت.
لا تحليلات ولا إعلانات ولا تتبّع. لا يحتوي التطبيق على أي حزمة تحليلات (SDK)، ولا حزمة للإبلاغ عن الأعطال، ولا حزمة إعلانات، ولا أي برمجيات تتبّع من أطراف خارجية. نحن لا نجمع معرّف إعلانات، ولا ننشئ ملفات تعريف إعلانية، ولا نتتبعك عبر تطبيقات أو مواقع أخرى.
4. الأذونات التي يطلبها التطبيق
يطلب التطبيق أذونات الجهاز التالية. يطلب التطبيق بعض هذه الأذونات مباشرةً، بينما تُضيف مكتبات الأطراف الخارجية التي نستخدمها أذونات أخرى تلقائيًا (مثل Firebase وتسجيل الدخول عبر Google) لتمكين خدماتها:
- الموقع (ACCESS_FINE_LOCATION، ACCESS_COARSE_LOCATION): لعرض الوجهات ونقاط الاهتمام القريبة على الخريطة. يمكنك رفض هذا الإذن ومع ذلك الاستمرار في استخدام التطبيق بوظائف محدودة.
- الإنترنت (INTERNET): مطلوب للاتصال بخوادمنا وعرض المحتوى.
- حالة الشبكة (ACCESS_NETWORK_STATE): تضيفه المكتبات التي نستخدمها لتحديد ما إذا كنت متصلاً بالإنترنت، حتى تفشل الطلبات بشكل سلس عند عدم الاتصال.
- قفل الاستيقاظ (WAKE_LOCK): يضيفه مشغّل الفيديو للحفاظ على تشغيل الشاشة أثناء تشغيل مقطع فيديو.
- التحقق من ترخيص Google Play (com.android.vending.CHECK_LICENSE): إذن قياسي يضيفه Google Play تلقائيًا للتحقق من ترخيص التطبيق.
- إطار خدمات Google (READ_GSERVICES): تضيفه مكتبة تسجيل الدخول عبر Google تلقائيًا للوصول إلى بيانات الإعداد اللازمة للمصادقة عبر Google.
- إذن البث الخاص بالتطبيق (DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION): يضيفه Firebase تلقائيًا لتلقي عمليات البث الداخلية بأمان داخل التطبيق نفسه. يقتصر هذا الإذن على تطبيقنا فقط، ولا يمكن للتطبيقات الأخرى استخدامه لإرسال بيانات إليه.
كما يصل التطبيق إلى صورك ومقاطع الفيديو الخاصة بك بالطرق التالية، والتي لا تتطلب طلب أذونات تخزين واسعة:
- منتقي الصور الخاص بالنظام (Android 13 وما بعده): عند اختيارك تحميل صورة أو مقطع فيديو، يفتح التطبيق منتقي الصور المدمج في نظام التشغيل. أنت من يختار بالضبط الملف الذي تريد مشاركته، ولا يحصل التطبيق إلا على صلاحية الوصول إلى ذلك الملف تحديدًا — ولا يمكنه تصفح مكتبة الوسائط الخاصة بك بالكامل.
- الوصول إلى التخزين (READ_EXTERNAL_STORAGE، لإصدارات Android 12 وما قبله فقط): في إصدارات Android الأقدم التي لا تدعم منتقي الصور الخاص بالنظام، يطلب التطبيق هذا الإذن فقط للسماح لك باختيار صورة أو مقطع فيديو موجود مسبقًا لتحميله.
كما يستخدم التطبيق الإمكانيات التالية، والتي لا تتطلب طلب إذن أثناء التشغيل:
- تطبيق الاتصال (رابط tel:): يؤدي النقر على رقم هاتف إلى فتح تطبيق الهاتف/الاتصال الافتراضي في جهازك مع تعبئة الرقم تلقائيًا. لا يقوم التطبيق بإجراء المكالمات تلقائيًا، ولا يصل إلى سجل مكالماتك أو جهات اتصالك.
- الخرائط (رابط geo:): قد يؤدي النقر على موقع ما إلى فتح تطبيق الخرائط الافتراضي في جهازك للحصول على الاتجاهات.
5. مشاركة البيانات
لا نقوم ببيع أو تأجير البيانات الشخصية. نشارك البيانات فقط مع مزوّدي الخدمة المذكورين أعلاه (Firebase وSupabase وCloudinary) لتمكين الوظائف الأساسية للتطبيق، وذلك وفق ضمانات مناسبة وسياسات الخصوصية الخاصة بهم.
البلاغات سرّية. لا تكون البلاغات المُقدَّمة مرئية إلا لفريق الإشراف لدينا. إذا أبلغت عن شخص ما، فلن يُخبَر بهويّة من أبلغ عنه. وإذا حظرت شخصًا ما، فلن يتم إشعاره بذلك.
6. الأمان
يتم تشفير البيانات المتبادلة بين التطبيق وخوادمنا أثناء النقل باستخدام بروتوكول HTTPS/TLS. ورغم أنه لا توجد وسيلة آمنة بنسبة 100%، فإننا نتخذ تدابير معقولة لحماية معلوماتك.
7. الاحتفاظ بالبيانات وحذفها
لحذف حسابك أو بيانات محددة، افتح الإعدادات ← حذف الحساب داخل التطبيق. سيؤدي ذلك إلى فتح صفحة طلب الحذف الآمنة الخاصة بنا في متصفحك، حيث يمكنك الاختيار بين إغلاق حسابك بالكامل أو حذف بيانات محددة فقط (مثل الصور أو التعليقات أو المواقع التي أرسلتها)، مع إبقاء حسابك نشطًا.
نتحقق من كل طلب عبر البريد الإلكتروني قبل حذف أي شيء، للتأكد من أنك صاحب الحساب فعلًا. تتم معالجة الطلبات التي تم التحقق منها خلال مدة تتراوح بين 7 و30 يومًا. تتم إزالة البيانات المحددة من أنظمتنا النشطة خلال 30 يومًا من التحقق، ولا نحتفظ بها بعد تلك المدة إلا إذا استلزم القانون أو متطلبات الأمان أو منع الاحتيال مدة احتفاظ أطول.
يؤدي إرسال نموذج الطلب إلى تخزين عنوان بريدك الإلكتروني والوصف الذي تقدمه في قاعدة بياناتنا، وذلك للتحقق من ملكيتك للحساب واتخاذ الإجراء المناسب بشأن الطلب. ويُحذف هذا السجل فور اكتمال تنفيذ الطلب.
يتم الاحتفاظ بالبلاغات. عند الإبلاغ عن محتوى ما، يتم الاحتفاظ بالبلاغ — بما في ذلك نسخة المحتوى المُبلَّغ عنه الموضّحة في القسم 1 — حتى بعد حذف المحتوى الأصلي. ونحتفظ به لمنع إساءة الاستخدام، ولدعم القرار الذي تم اتخاذه، وللتعرّف على المخالفين المتكررين. وينطبق ذلك سواء تمت إزالة المحتوى من قِبلنا أو تم حذفه من قِبل الشخص الذي نشره.
حذف الحساب والبيانات: طلب الحذف
8. خصوصية الأطفال
لا يستهدف التطبيق الأطفال دون سن 13 عامًا. إذا كنت تعتقد أننا جمعنا معلومات شخصية من طفل دون سن 13 عامًا، يُرجى التواصل معنا وسنقوم بحذفها.
9. المحتوى الذي ينشئه المستخدمون، والإبلاغ، والإشراف
يمكن للمستخدمين المسجَّلين إرسال التعليقات والوسائط ومعلومات المواقع السياحية. يُمنع نشر المحتوى غير اللائق، بما في ذلك العُري، أو المواد الجنسية الصريحة، أو العنف الصادم، أو خطاب الكراهية، أو المحتوى غير القانوني، أو التحرّش.
الإبلاغ. يتضمن التطبيق ميزة للإبلاغ تتيح لأي شخص يستخدم التطبيق — بما في ذلك المستخدمين الذين يتصفحونه دون حساب — الإبلاغ عن أي محتوى يعتقدون أنه غير لائق. يمكنك الإبلاغ عن:
- تعليق (على سبيل المثال: رسائل مزعجة، أو تحرّش، أو معلومات كاذبة).
- موقع سياحي مُدرَج (على سبيل المثال: معلومات مضلِّلة، أو صور غير لائقة، أو إدخال مكرر). يتم الإبلاغ عن الصور ومقاطع الفيديو كجزء من الموقع الذي تنتمي إليه.
لا يتم الإبلاغ عن الحسابات مباشرة. وعند الإبلاغ عن تعليق ما، يمكن لفريق الإشراف لدينا اتخاذ إجراء بحق الحساب الذي نشره.
للإبلاغ عن محتوى ما، افتح القائمة الموجودة بجانب التعليق، أو انقر على أيقونة العلَم في صفحة الموقع السياحي، ثم اختر السبب، ويمكنك اختياريًا إضافة تفاصيل قبل الإرسال. لا يلزم وجود حساب لتقديم بلاغ. يوضّح القسم 1 البيانات التي يسجّلها البلاغ.
الحظر. إذا كنت مسجّل الدخول، يمكنك حظر مستخدم آخر من القائمة الموجودة بجانب أحد تعليقاته. وبمجرد الحظر، لن تظهر تعليقاته لك بعد ذلك. يؤثر الحظر فقط على عرضك الخاص للتطبيق — فهو ليس بلاغًا، ولا يتم إشعار الشخص الذي تحظره. يمكنك الاطّلاع على قائمة جميع من حظرتهم، وإلغاء حظرهم في أي وقت، من خلال الإعدادات ← المستخدمون المحظورون.
المراجعة واتخاذ الإجراءات. يقوم فريقنا بمراجعة البلاغات المُقدَّمة، وقد يزيل المحتوى المخالف، أو يعلّق الحساب المسؤول، أو كليهما معًا. يتم تسجيل خروج الحساب المُعلَّق من التطبيق وتظهر له رسالة توضّح سبب التعليق، ولا يمكنه تسجيل الدخول مرة أخرى. إذا كنت تعتقد أن حسابك عُلِّق عن طريق الخطأ، يُرجى التواصل معنا على العنوان المذكور في القسم 11.
10. التغييرات على هذه السياسة
قد نقوم بتحديث سياسة الخصوصية هذه من وقت لآخر. سيتم نشر أي تغييرات هنا مع تحديث تاريخ السريان. ويُعدّ استمرارك في استخدام التطبيق بعد إجراء أي تغييرات بمثابة قبول للسياسة المحدَّثة.
11. تواصل معنا
إذا كانت لديك أي أسئلة أو طلبات متعلقة بالخصوصية، يُرجى التواصل معنا عبر Dahozoheir1@gmail.com.