سياسة الخصوصية — «Glowbee»

آخر تحديث: 11 سبتمبر 2026 · النسخة 2.5

تصف هذه السياسة كيف يجمع تطبيق «Glowbee» البيانات الشخصية ويستخدمها ويحميها ويشاركها، وما هي حقوقك. «Glowbee» تطبيق تواصل خاص للأفراد والعائلات من مختلف الأعمار، ويشمل مستخدموه أطفالًا يستخدمونه تحت تحكّم وليّ الأمر وإشرافه. باستخدامك التطبيق فأنت تقرّ بهذه السياسة.

١) المتحكّم بالبيانات

المسؤول عن معالجة البيانات هو Yousef Alhelfy («نحن»)، من دولة الكويت. جهة التواصل لأي طلب متعلّق بالخصوصية أو البيانات: glowbeeco@gmail.com.

٢) نطاق الجمهور وحماية الأطفال

التطبيق موجَّه لجمهور مختلط يشمل البالغين والأطفال. لا ينشئ الطفل حسابًا بنفسه؛ بل ينشئه وليّ أمره ويديره. عندما يكون المستخدم طفلًا، نطبّق حمايات إضافية موضّحة في القسمين (٧) و(٨)، وبما يتوافق مع أنظمة حماية بيانات الأطفال المعمول بها (مثل COPPA و GDPR-K).

٣) البيانات

نحن لا نجمع محتواك ولا نحتفظ به. الصور والفيديو والرسائل الصوتية تمرّ بخوادمنا مُشفَّرةً لغرض واحد: أن تصل إلى من أرسلتَها إليه — ثم تُحذف من خوادمنا فور مشاهدتها. لا نطّلع عليها، ولا نحلّلها، ولا نستعملها لتدريب أي نظام، ولا نبيعها.

ولا استثناء — حتى تصحيح التسميع في قسم القرآن. حين يختار الطفل أن يُسمّع سورةً ليصحَّح له، يجري التقييم داخل الهاتف نفسه بنموذج تعرّفٍ صوتيٍّ محلّيّ، ولا يغادر التسجيلُ الجهازَ: لا يُرسَل إلينا ولا إلى أيّ طرفٍ ثالث، ولا يُحفظ، ولا يُستعمل لتدريب أي نظام. ولا يستعمل التطبيق أيّ خدمة ذكاءٍ اصطناعيّ خارجيّة. وفحص المحتوى قبل الإرسال يجري كذلك داخل الهاتف نفسه ولا يغادره شيء.

ما يمرّ ولا يُحفظ

الفئةماذا يحدث لهينطبق على
الصور والفيديو والرسائل الصوتية والقصصيمرّ ليصل، ثم يُحذف من خوادمنا فور مشاهدته — ولا نحتفظ بنسخةالجميع
صوت المكالماتلا يُسجَّل ولا يُخزَّن إطلاقًا — ولا يوجد في تطبيقنا أي مُسجِّل مكالماتالجميع
الموقعلا نطلب إذن الموقع ولا نخزّن موقعًا. عند استعمال «ملصق الطقس» فقط، تُقرأ المدينة تقريبيًّا من عنوان IP لحظةَ الاستعمال ثم تُنسى — وهذه الأداة متاحة لحسابات أولياء الأمور البالغين وحدها، ومحجوبة عن كل الأطفال والمراهقينأولياء الأمور فقط

ما نحفظه فعلًا — وهو الحدّ الأدنى لتشغيل الخدمة

الفئةماذا نحفظ ولماذاالمدّة
بيانات الحسابلحساب الوالد: الاسم والبريد ومُعرّف الحساب من تسجيل دخول Google. لحساب الطفل: اسم/لقب للعرض، تاريخ الميلاد، والجنس (يُدخلها الوالد)، ومُعرّف حساب مجهول لا يرتبط ببريد ولا برقم هاتف للطفلحتى حذف الحساب
شبكة التواصلقائمة الأصدقاء المعتمدين ورموز الصداقة — بلا هذه لا يعرف التطبيق بمن يُسمح لطفلك أن يتواصلحتى حذف الحساب
سجلّ المكالمات (بيانات وصفية فقط)مَن اتصل بمَن، والوقت، والمدّة — بلا أي صوت. سببه الوحيد أنه سجلّ الرقابة الأبوية: هو ما يُمكّن وليّ الأمر من رؤية مع مَن يتحدّث طفله، ولا يستطيع الطفل تعديله ولا حذفه٩٠ يومًا ثم يُحذف تلقائيًّا
بيانات تشغيليةرمز الإشعارات (FCM) ومُعرّف جلسة الجهاز الواحد ووقت آخر نشاطحتى حذف الحساب
بلاغات الأعطالعند تعطّل التطبيق يُرسَل تقريرٌ تقنيّ عبر Firebase Crashlytics لإصلاح العطل: نوع الجهاز، إصدار النظام والتطبيق، وموضع الخطأ في الكود، ومُعرّفُ تثبيتٍ خاصّ بـCrashlytics (ليس مُعرّفًا إعلانيًّا ولا يرتبط بالحساب). بلا اسم، ولا رسائل، ولا وسائط، ولا مُعرّفات إعلانية. أخطاءُ التطبيق نفسه تُنقّى من أي بريد أو رقم أو مُعرّف قبل إرسالها؛ أمّا أعطالُ نظام التشغيل الأصلية فتجمعها مكتبةُ Crashlytics مباشرةً٩٠ يومًا (الإعداد الافتراضي لـCrashlytics)

لا نجمع الموقع الجغرافي الدقيق، ولا جهات اتصال الجهاز، ولا رسائله، ولا مُعرّفات إعلانية من الأطفال.

٤) أغراض المعالجة وأسسها القانونية

٥) الفحص الأمني على الجهاز

حمايةً للأطفال، يجري فحص أمني للصور والفيديو داخل جهاز المُرسِل نفسه قبل الإرسال — ويعمل عندما يكون أحد طرفَي المحادثة طفلًا ويتواصل مع طرف من خارج عائلته. الفحص محليّ بالكامل: لا تُرفع الصورة إلى أي خادم لغرض الفحص، ولا نحتفظ بنتيجته، ولا يطّلع عليها بشر لدينا.

حدود هذا الفحص — نقولها بصراحة: الفحص آليّ بالكامل ويعتمد على الاحتمالات، وليس مضمونًا ولا معصومًا من الخطأ. قد يمنع محتوًى بريئًا بالخطأ، وقد يمرّ محتوًى غير لائق دون أن يكتشفه. وهو ليس بديلًا عن إشراف وليّ الأمر، ولا نُقدّمه ضمانًا بأن كل ما يصل طفلك آمن. واللغات التي يغطّيها فحص الكتابة محدودة، ونقولها بوضوح: فلتر الألفاظ يعمل بقائمتين نُعدّهما ونصونهما بأنفسنا: قائمة عربية (الفصحى واللهجة الخليجية أساسًا)، وقائمة بالحروف اللاتينية أساسها الإنجليزية. أمّا بقيّة لغات الواجهة — التركية والفرنسية والإسبانية والألمانية والإيطالية والهولندية والبرتغالية واليابانية — فلا قوائم مخصّصة لها، ولا يُلتقط منها إلا ما يشترك مع القائمة اللاتينية. وحتى داخل العربية، اللهجات تختلف اختلافًا كبيرًا (مغربية وشامية ومصرية وسودانية وغيرها)، وكلمةٌ عاديّة في بلد قد تكون شتيمة في بلد آخر والعكس — فالتغطية غير متساوية بين اللهجات بطبيعتها، ونحن نوسّعها باستمرار ولا نَعِد بأنها كاملة. كما أنّ بعض الأنواع لا تُفحص أصلًا بطبيعتها: الصوت (لا يوجد لدينا نموذج لفحصه)، والمكالمات المباشرة (تجري لحظيًّا بين الجهازين ولا نطّلع عليها). الحماية الأساسية في هذين تظلّ أن الطرف الآخر صديق اعتمدتَه أنت. ونحن نوصي وليّ الأمر باستعمال أدوات الرقابة في القسم (٧) ومتابعة دائرة طفله بنفسه.

٦) الاحتفاظ والحذف

٧) خصوصية الأطفال والموافقة الأبوية

لا يُجمع أي بيانات عن طفل قبل موافقة وليّ الأمر المُتحقَّقة. الوالد ينشئ حساب الطفل من جهازه، ويؤكّد موافقته عبر خطوة تحقّق برمز يُرسَل إلى بريده الإلكتروني. لا يعمل حساب الطفل الجديد حتى يُدخل وليّ الأمر هذا الرمز؛ ورمز واحد يوثّق موافقته على جميع أطفاله، الحاليّين ومن يُضاف بعده؛ والحسابات القائمة التي لم تُوثَّق تُمهَل سبعة أيام ثمّ تتوقّف حتى التوثيق. لا يستطيع الطفل التسجيل بنفسه. ويملك الوالد لوحة تحكّم كاملة: مراجعة بيانات الطفل، اعتماد الأصدقاء أو رفضهم، الحظر، الإيقاف المؤقت، تحديد الأوقات، وحذف الحساب وسحب الموافقة في أي وقت.

٨) المشاركة ومزوّدو الخدمة — ولا بيع للبيانات

لا نبيع بياناتك الشخصية ولا نؤجّرها. نستعين بمزوّدين موثوقين كمعالِجات بيانات نيابةً عنّا، وبالقدر اللازم لتشغيل الخدمة فقط، ويلتزمون بعدم استخدامها لأي غرض آخر:

المزوّدالغرض
Google Firebaseالمصادقة، قاعدة البيانات، الإشعارات، وبلاغات الأعطال التقنية (Crashlytics)
Cloudflare R2تخزين ملفات الوسائط المؤقت
خوادم ربط المكالمات (STUN/TURN): Google STUN وMetered.ca «Open Relay»ربط المكالمات الصوتية عندما تتعذّر الوصلة المباشرة (لا يُخزَّن الصوت؛ الحِزم تمرّ مشفَّرة ولا يملك الخادم مفاتيحها). يصل إلى هذه الخوادم عنوانُ IP للجهاز أثناء المكالمة فقط، وهو ما تحتاجه أي مكالمة عبر الإنترنت لتصل. Open Relay خادم ترحيل مجّاني مشترك نستخدمه في فترة التجربة المغلقة، وسيُستبدل بمزوّد ترحيل بعقد معالجة بيانات قبل الإطلاق العامّ، وتُحدَّث هذه الصفحة عندها
ipwho.isتحديد المدينة تقريبيًّا من عنوان IP — لملصق الطقس وحده، ولحسابات أولياء الأمور فقط
Open-Meteoدرجة الحرارة وحالة الطقس — لملصق الطقس وحده، ولحسابات أولياء الأمور فقط
خدمات الذكاء الاصطناعي الخارجيّةلا شيء. فحص المحتوى وتصحيح التسميع يجريان داخل الهاتف.

قد يخزّن هؤلاء البيانات على خوادم خارج الكويت؛ ونعتمد عليهم بموجب التزامات حماية بيانات تعاقدية.

٩) الإعلانات

قد يعرض التطبيق إعلانات لإبقائه مجانيًّا. لا نعرض للأطفال إعلانات موجَّهة (قائمة على الاهتمامات) ولا نطبّق إعادة استهداف، ولا نشارك بيانات الأطفال مع شبكات إعلانية. أي إعلان يُعرض للأطفال يكون غير موجَّه — يعتمد على محتوى الشاشة الحالي فقط لا على هوية المستخدم — ومناسبًا للأطفال، ومميَّزًا كإعلان، وأي رابط خارجي يكون خلف بوّابة أبوية.

١٠) أمن البيانات

نُشفّر البيانات أثناء النقل (TLS)، ويُشفَّر صوت المكالمات أثناء النقل عبر WebRTC (DTLS-SRTP). ينطبق هذا على المكالمة الثنائية والمكالمة الجماعية (حتى ٤ أشخاص) معًا: الجماعية شبكة من روابط ثنائية مباشرة، لكلّ رابط مفاتيح تشفير خاصة به تُتفَق عليها بين الجهازين، ولا يمرّ الصوت عبر أي خادم وسيط يفكّ تشفيره. وحين تتعذّر الوصلة المباشرة يُستخدم خادم ترحيل (TURN) يمرّر الحِزم مشفَّرة كما هي ولا يملك مفاتيحها. لا يُخزَّن صوت أي مكالمة، ويحفظ سجلّ الوالد بياناتها الوصفية فقط (الطرفان، الوقت، المدّة). نطبّق قواعد وصول صارمة على الخادم تمنع أي حساب من قراءة بيانات غيره — بما فيها بيانات ملف المستخدم التي لا يقرأها إلا صاحبها ووليّ أمره وأصدقاؤه المعتمدون — والدخول محصور بجهاز واحد لكل حساب. (ملاحظة: التشفير أثناء النقل ليس تشفيرًا طرفيًّا كاملًا لكل المحتويات؛ إذ نعالج الصور والرسائل للسلامة كما هو موضّح — أمّا صوت المكالمات فلا نعالجه ولا نستمع إليه.) لا يمكن ضمان أمان مطلق لأي نظام على الإنترنت.

١١) حقوق ولي الأمر والمستخدم وحذف الحساب

يحقّ لك الاطّلاع على بياناتك أو بيانات طفلك وتصحيحها أو حذفها، وسحب الموافقة. من داخل التطبيق:

أو راسلنا على glowbeeco@gmail.com. للتفاصيل: صفحة حذف الحساب.

١٢) تعديلات هذه السياسة

قد نحدّث هذه السياسة، وسننشر أي تعديل جوهري داخل التطبيق قبل نفاذه.

١٣) القانون الحاكم

تخضع هذه السياسة لقوانين دولة الكويت، مع التزامنا بمعايير حماية الأطفال العالمية المطبَّقة على متاجر التطبيقات (بما فيها متطلبات Google Play وحماية بيانات الأطفال).

للتواصل: glowbeeco@gmail.com

Glowbee — Privacy Policy

Last updated: September 11, 2026 · Version 2.5

This policy describes how the Glowbee app collects, uses, protects and shares personal data, and your rights. Glowbee is a private communication app for individuals and families of all ages; its users include children who use it under the control and supervision of a parent. By using the app you acknowledge this policy.

1) Data Controller

The controller responsible for processing is Yousef Alhelfy ("we"), based in the State of Kuwait. Contact for any privacy or data request: glowbeeco@gmail.com.

2) Audience & protection of children

The app is directed at a mixed audience of adults and children. A child does not create an account; their parent creates and manages it. When a user is a child, we apply the additional protections in sections (7) and (8), consistent with applicable children's-data laws (e.g. COPPA and GDPR-K).

3) Data

We do not collect or keep your content. Photos, videos and voice messages pass through our servers encrypted for one purpose — reaching the person you sent them to — and are then deleted from our servers as soon as they are viewed. We do not look at them, analyse them, use them to train any system, or sell them.

No exception — not even Quran recitation feedback. When a child chooses to recite a surah to be corrected, the grading runs on the phone itself with a local speech-recognition model, and the recording never leaves the device: it is not sent to us or to any third party, not stored, and not used to train any system. The app uses no external AI service. Content screening before sending likewise runs entirely on the phone and nothing leaves it.

What passes through and is not kept

CategoryWhat happens to itApplies to
Photos, videos, voice messages, storiesPass through to be delivered, then deleted from our servers as soon as viewed — we keep no copyEveryone
Call audioNever recorded and never stored — our app contains no call recorder at allEveryone
LocationWe request no location permission and store no location. Only when the weather sticker is used, an approximate city is read from the IP address at that moment and then forgotten — and that tool is available to adult parent accounts only, hidden from all children and teensParents only

What we do keep — the minimum needed to run the service

CategoryWhat we keep and whyFor how long
Account dataParent: name, email, account ID from Google Sign-In. Child: display name/nickname, date of birth, gender (entered by the parent), and an anonymous account ID with no child email and no phone numberUntil the account is deleted
Social graphApproved friends list and friend codes — without these the app cannot know who your child is allowed to talk toUntil the account is deleted
Call log (metadata only)Who called whom, when, and for how long — with no audio whatsoever. Its only purpose is that it is the parental-supervision record: it is what lets a parent see who their child talks to, and a child can neither edit nor delete it90 days, then deleted automatically
OperationalNotification token (FCM), single-session device ID, last-activity timeUntil the account is deleted
Crash reportsWhen the app crashes, a technical report is sent through Firebase Crashlytics so we can fix it: device model, OS and app version, where in the code it failed, and a Crashlytics installation identifier (not an advertising ID, not linked to the account). No name, no messages, no media, no advertising identifiers. Errors inside the app itself are stripped of any email, number or identifier before they are sent; native operating-system crashes are collected by the Crashlytics library directly90 days (Crashlytics default)

We do not collect precise geolocation, device contacts, device messages, or advertising identifiers from children.

4) Purposes & legal bases

5) On-device safety scanning

To protect children, photos and videos are scanned on the sender's own device before sending — and this runs when one party to a conversation is a child communicating with someone outside their family. The scan is fully local: the image is never uploaded for scanning, we do not retain its result, and no human at our company ever sees it.

The limits of this scanning — stated plainly: the scan is fully automated and probabilistic. It is not guaranteed and not free from error. It may block innocent content by mistake, and unsuitable content may pass without being detected. It is not a substitute for parental supervision, and we do not offer it as a guarantee that everything reaching your child is safe. The languages the text filter covers are limited, and we say so plainly: the profanity filter uses two lists we write and maintain ourselves: an Arabic list (Modern Standard and mainly Gulf dialect) and a Latin-script list built around English. The remaining interface languages — Turkish, French, Spanish, German, Italian, Dutch, Portuguese and Japanese — have no dedicated lists, and are covered only where they overlap with the Latin one. Even within Arabic, dialects differ greatly (Moroccan, Levantine, Egyptian, Sudanese and others): a word that is ordinary in one country can be an insult in another and the reverse, so coverage is inherently uneven across dialects. We keep widening it and we do not promise it is complete. Some types are also not scanned at all by their nature: audio (we have no model for it) and live calls (they happen in real time between the two devices and we do not have access to them). For those two, the core protection remains that the other party is a friend you approved yourself. We encourage parents to use the controls in section 7 and to stay involved in their child's circle.

6) Retention & deletion

7) Children's privacy & parental consent

No data about a child is collected before verifiable parental consent. The parent creates the child's account from their own device and confirms consent via a verification code sent to their e-mail address. A new child's account does not work until the parent enters that code; one code verifies the parent's consent for all their children, current and later; existing accounts that were never verified get seven days, then stop until they are. A child cannot self-register. The parent has a full dashboard: review the child's data, approve or reject friends, block, pause, set time limits, and delete the account or withdraw consent at any time.

8) Sharing & processors — no data sales

We do not sell or rent your personal data. We use trusted processors acting on our behalf, only as needed to run the service, contractually bound not to use the data for any other purpose:

ProviderPurpose
Google FirebaseAuthentication, database, notifications, and technical crash reports (Crashlytics)
Cloudflare R2Temporary media file storage
Call connection servers (STUN/TURN): Google STUN and Metered.ca "Open Relay"Connecting voice calls when a direct link is impossible (audio not stored; packets pass through still encrypted and the server holds none of the keys). The device's IP address reaches these servers during a call only, which any internet call needs in order to connect. Open Relay is a free, shared relay we use during the closed testing period; it will be replaced by a relay provider under a data-processing agreement before public launch, and this page will be updated then
ipwho.isApproximate city from the IP address — weather sticker only, adult parent accounts only
Open-MeteoTemperature and conditions — weather sticker only, adult parent accounts only
External AI servicesNone. Content screening and recitation grading both run on the phone.

These may store data on servers outside Kuwait; we rely on them under contractual data-protection commitments.

9) Advertising

The app may show ads to keep it free. We do not show children interest-based (targeted) ads, do not use remarketing, and do not share children's data with ad networks. Any ad shown to children is non-personalized — based only on the current screen content, not on a user's identity — appropriate for children, marked as an ad, with any external link behind a parental gate.

10) Data security

Data is encrypted in transit (TLS), and call audio is encrypted in transit over WebRTC (DTLS-SRTP). This covers both one-to-one and group calls (up to 4). A group call is a mesh of direct peer-to-peer links, each with its own encryption keys negotiated between the two devices; audio never passes through a server that could decrypt it. When a direct link is impossible, a relay (TURN) server forwards the packets still encrypted and holds none of the keys. No call audio is stored; the parent's log keeps only metadata (parties, time, duration). Strict server-side rules prevent any account from reading another's data — including profile documents, readable only by the user, their guardians and their approved friends — and login is limited to one device per account. (Note: in-transit encryption is not full end-to-end encryption for all content; we process images and messages for safety as described — call audio is never processed or listened to.) No internet system can be guaranteed perfectly secure.

11) Your rights & account deletion

You may access, correct or delete your data or your child's, and withdraw consent. In-app:

Or email glowbeeco@gmail.com. See the Account Deletion page.

12) Changes to this policy

We may update this policy and will announce any material change inside the app before it takes effect.

13) Governing law

This policy is governed by the laws of the State of Kuwait, alongside our commitment to global child-protection standards applicable to app stores (including Google Play requirements and children's data protection).

Contact: glowbeeco@gmail.com