1. من يملك المعطيات
التطبيق يشتغل في هاتف الجمعية. المنخرطون والقراءات والفواتير والأداءات تُحفظ في الجهاز، ويمكن للجمعية أن تستعمل التطبيق هكذا إلى الأبد دون أن يغادر الهاتف أي شيء.
المزامنة اختيارية. الجمعية التي تريدها تُنشئ قاعدة بيانات سحابية داخل حساب Google الخاص بها، تملكها وتطّلع عليها أو تحذفها متى شاءت.
نحن نوفّر الأداة، لا خدمة استضافة معطيات. والجمعية التي أنشأت قاعدتها الخاصة: لا نحتفظ بنسخة
من سجلّ منخرطيها، ولا يمكننا قراءته — لا لأننا وعدنا بذلك فقط، بل لأن الصلاحية التي نملكها في
مشروعها محصورة في قواعد الحماية (firebasedatabase.instances.get/update)،
وGoogle نفسها ترفض أي محاولة قراءة خارج هذا الحد.
القرارات المتعلقة بالمنخرطين — الفوترة والتحصيل وقطع الخدمة — تعود للجمعية وحدها.
2. ما تتعامل معه التطبيق من معطيات
المنخرطون: الاسم الكامل، رقم العداد، العنوان والهاتف (اختياريان)، دلائل العدادات والاستهلاك، الفواتير، الأداءات، الديون والتسبيقات.
المستعملون: البريد الإلكتروني والاسم من حساب Google المستعمل للدخول، أو اسم مستخدم تُصدره الجمعية.
الجهاز: رمز الإشعارات (FCM) للجهاز الذي فعّل الإشعارات، ورمز الانتساب الذي يربط المنخرط بملفه — وهو رمز مُولَّد لا يحمل أي معنى شخصي.
3. لماذا تُستعمل
تدبير الاشتراكات، تسجيل القراءات، إصدار الفواتير والوصولات كملفات PDF، تتبع الأداءات، تمكين المنخرط من الاطلاع على ملفه، وإرسال إعلانات الجمعية.
4. أين تُحفظ
افتراضياً: في الهاتف فقط. أما الجمعية التي فعّلت المزامنة:
| الخدمة | الدور |
|---|---|
| Google Firebase | تخزين ومزامنة، داخل حساب Google الخاص بالجمعية، على خواديم في الاتحاد الأوروبي |
| Google Drive | النسخة الاحتياطية، داخل حساب الجمعية، عند تفعيلها فقط |
| Cloudflare | جدول التوجيه وبيانات الدخول: رمز الجمعية وعنوان قاعدتها، ولا شيء من سجل المنخرطين (انظر القسم 6) |
مشروع Firebase الخاص بناpurewaterbilling-ff6f2 (الاتحاد الأوروبي) | ما يُشغّل التطبيق وحده: رخص الاستعمال، وإعدادات المنصة، والإشعارات وإحصاءات الاستعمال. ولا سجلّ منخرطين فيه. |
ورمز الإشعارات (FCM) يُحفظ لجهاز المنخرط الذي فعّل الإشعارات وحده، ويُحذف تلقائياً حين يتوقف الجهاز عن قبولها.
5. أذونات Google التي يطلبها التطبيق
هذه هي كل الأذونات التي قد يُطلب منك منحها، ولماذا:
| الإذن | السبب |
|---|---|
drive.file |
حفظ نسخة احتياطية في حسابك على Google Drive. هذا أضيق إذن ممكن: لا يصل التطبيق إلا إلى الملفات التي أنشأها هو، ولا يرى باقي ملفاتك. |
cloud-platformfirebasefirebase.database |
تهيئة مشروع Firebase داخل حسابكم الخاص عند تفعيل المزامنة، وتشغيل الخدمات الضرورية، وإعداد قواعد أمان صارمة لضمان العزل التام لبيانات جمعيتكم. (ملاحظة: هذا هو مستوى الصلاحيات الأدنى الذي تطلبه المنصة لإنشاء المشاريع). |
userinfo.email |
معرفة الحساب الذي أُنشئت القاعدة داخله، حتى تُربط الجمعية بحسابها الصحيح. |
6. مع من نتشارك المعطيات
لا نبيع المعطيات ولا نؤجّرها ولا نتبادلها، ولا نمرّرها إلى وسيط معطيات ولا إلى معلن. والجدول التالي هو كل من قد يصله شيء، وما يصله بالضبط، ولماذا:
| الجهة | ما يصلها | لماذا |
|---|---|---|
| Google (Cloud، Firebase، Identity Platform) |
معطيات الجمعية كما هي، داخل مشروع Google التابع لحساب الجمعية نفسها؛ وعنوان بريد حساب Google الذي أنشأ المشروع. | هي الاستضافة نفسها. تُعالجها Google وفق سياسة الخصوصية الخاصة بها، ونحن لا نقدر على قراءة ما بداخلها. |
| Cloudflare (مناول لدينا) |
رمز الجمعية وإعدادات مشروعها العمومية (projectId، apiKey، appId، databaseUrl)، وعنوان بريد حساب Google لرئيس الجمعية، وأسماء المستعملين وكلمات سرّهم. ولا يصلها اسم منخرط ولا قراءة ولا فاتورة ولا أداء. |
التحقق من بيانات الدخول، وتوجيه كل جمعية إلى قاعدة بياناتها هي. |
| نحن أنفسنا (مشروع Firebase الخاص بنا، ومشرفو المنصة) |
ما يُشغّل التطبيق وحده: رخص الاستعمال، وإعدادات المنصة، وما يقتضيه إرسال الإشعارات وقياس الاستعمال. ولا سجلّ منخرطين فيه. | الرخص، والإشعارات، والدعم التقني. الوصول محصور في مشرفي المنصة، ولا يقع إلا للدعم أو الصيانة أو تنفيذاً لموجب قانوني. |
| Google AdMob | معطيات تقنية عن الجهاز مثل معرّف الإعلانات، من كل واجهات التطبيق — انظر القسم 8. | الإعلانات التي تجعل التطبيق مجانياً. |
| Google Firebase Analytics | أرقام استعمال مجمّعة وتقارير أعطاب — انظر القسم 9. | كشف الأعطاب وتحسين التطبيق. |
ولا أحد غير هؤلاء. وخارج ما سبق، لا تُنقل المعطيات ولا تُفصح لأي طرف إلا في ثلاث حالات:
- بطلبكم أو بموافقتكم الصريحة — كأن تطلبوا مساعدة تقنية تقتضي الاطّلاع.
- موجب قانوني — أمر قضائي أو طلب رسمي صحيح بمقتضى القانون المغربي (القانون 09-08)، وبالقدر الذي يفرضه ذلك الطلب وحده.
- حماية من الاعتداء — كشف اختراق أو غش أو إضرار بالخدمة أو بمستعمليها.
7. معطيات مستعمل Google: من يصله ماذا
«معطيات مستعمل Google» هي ما يحصل عليه التطبيق من حسابكم عبر الأذونات المذكورة في القسم 5.
وطريقة العمل بإيجاز: حين يضغط الرئيس على «أنشئ قاعدة بياناتي»، يُحوَّل إلى صفحة الموافقة عند Google؛ وبعد موافقته يتلقّى خادومنا (Cloudflare Worker) رمز وصول مؤقتاً ويستعمله نيابةً عنه لإنشاء مشروع Firebase داخل حسابه، وتشغيل الخدمات الضرورية، وكتابة قواعد الحماية. فمعطيات Google تمرّ عبر خادومنا لهذا الغرض وحده. وهذا مصير كل واحد منها:
| المعطى | إلى أين يذهب، ومن يراه |
|---|---|
userinfo.emailعنوان بريد حساب Google |
يُحفظ في جدول التوجيه عند Cloudflare (مناول لدينا) لربط الجمعية بحسابها ومنع إنشاء قاعدتين للحساب نفسه. لا يُرسل إلى أي جهة أخرى، ولا يُستعمل في إعلان ولا في تسويق. |
| رمز الوصول (access token) | يُحفظ في سجل الإعداد المؤقت عند Cloudflare ما دام الإعداد جارياً، ويُحذف تلقائياً بعد ساعة على الأكثر. ولا نطلب رمز تجديد (refresh token) أصلاً (access_type=online)، فلا يمكننا العودة إلى حسابكم بعد انتهاء تلك الجلسة. ولا يُشارَك مع أي جهة. |
| حساب خدمة داخل مشروعكم ( PureWater Sync Auth) |
يُنشأ أثناء الإعداد لإصدار رموز الدخول، ويبقى مِلكاً لمشروعكم تحذفونه متى شئتم. والمفتاح المُولَّد له لا يُحفظ عندنا بشكل دائم: يبقى في سجل الإعداد المؤقت الذي يُحذف بعد ساعة على الأكثر. |
drive.fileملفات النسخ الاحتياطي |
تبقى في Google Drive الخاص بكم. لا تُنسخ إلينا ولا إلى غيرنا، ولا يرى التطبيق من محتوى حسابكم إلا الملفات التي أنشأها هو. |
cloud-platformfirebasefirebase.database |
المشروع يُنشأ داخل حسابكم بموافقتكم أنتم وباسمكم، وتملكونه أنتم. وتبقى لنا فيه بعد الإعداد صلاحية واحدة دائمة — دور مخصوص اسمه purewaterLicence لا يحمل غير firebasedatabase.instances.get/update — تكفي لتحديث قواعد الحماية عند تجديد الرخصة ولا تُخوّل قراءة سجل المنخرطين. ولا نأخذ نسخة منه، ولا يُشارَك مع أي جهة. ويمكنكم سحب هذا الدور من وحدة IAM في مشروعكم في أي وقت. |
استعمالُ «ماء جمعيتي» للمعلومات المتحصَّلة من واجهات Google، ونقلُها إلى أي تطبيق آخر، يخضع لسياسة Google الخاصة بمعطيات مستعملي خدمات الواجهات، بما فيها شروط الاستعمال المحدود (Limited Use). ونصّ التصريح بالإنجليزية:
8. الإعلانات
التطبيق مجاني، والإعلانات هي ما يجعله كذلك. ولذلك تظهر في كل واجهات التطبيق ولكل المستعملين — الرئيس والمحصّل والمنخرط على السواء: عند فتح التطبيق، وفي الشاشة الرئيسية، والفواتير، والاستهلاك، والإحصاءات، وبوابة المنخرط. وهناك نوع واحد يختاره المستعمل بنفسه: إعلان يشاهده مقابل تحميل وثيقة.
والجمعية التي تشترك في مدة مدفوعة تتوقف عندها الإعلانات عن الرئيس والمحصّلين، ويبقى المنخرط يراها. وهذا هو الفرق الوحيد الذي يصنعه الأداء: لا شيء في التطبيق يتوقف عن العمل ولا يُحجب، وليس للأمر أثر على المعطيات ولا على من يصله شيء منها.
وتُعرض كلها عبر Google AdMob. وقد تصل AdMob معطيات تقنية عن الجهاز مثل معرّف الإعلانات، تعالجها بصفتها هي وفق سياسة Google. لا يصلها اسم منخرط ولا فاتورة ولا أداء، ولا يصلها أي شيء من معطيات مستعمل Google المذكورة في القسم 7. يمكن التحكم في تتبع الإعلانات من: إعدادات الهاتف ← Google ← الإعلانات.
9. إحصاءات الاستعمال
يستعمل التطبيق Google Firebase Analytics لقياس كيفية استعماله — الشاشات التي تُفتح، نوع الجهاز، والأعطاب — قصد تحسينه. هذه أرقام مجمّعة لا تحمل اسم منخرط ولا فاتورة ولا قراءة ولا أداء، ولا تحمل شيئاً من معطيات مستعمل Google.
10. الأمان
تُنقل المعطيات عبر اتصال مشفَّر وتُخزَّن مشفَّرة. وقواعد الحماية تعزل كل جمعية عن غيرها، ولا يرى المنخرط غير ملفه هو.
11. الأذونات داخل الهاتف
إذن واحد: الإشعارات، حتى تصل إعلانات الجمعية وتذكيرات الفواتير إلى المنخرط. اختيار الشعار وحفظ الفواتير يمرّان عبر منتقي الملفات في أندرويد ولا يحتاجان أي إذن تخزين.
12. حذف المعطيات
القرار كله بيد الجمعية، ومن داخل التطبيق نفسه. أمام القاعدة السحابية خياران:
- فصل فقط — يتوقف التطبيق عن المزامنة ويرجع إلى العمل المحلي، وتبقى القاعدة في حسابكم كما هي.
- حذف قاعدة البيانات نهائياً — يُحذف المشروع بكامله من حساب Google الخاص بكم، بما فيه القاعدة وكل ما بداخلها. يُنفَّذ بموافقتكم على صفحة Google، ولا رجعة فيه.
ولحذف المعطيات المحلية من الهاتف: الإعدادات ← خيارات متقدمة ← إعادة ضبط المصنع. ولحذف حساب الجمعية لدينا — بما فيه عنوان البريد المحفوظ في جدول التوجيه وما يخصّها في مشروعنا — راسلنا على البريد أسفله ويُحذف داخل ثلاثين يوماً.
ويمكن في أي وقت سحب الأذونات الممنوحة للتطبيق من myaccount.google.com/permissions.
13. الاتصال
الأسئلة المتعلقة بالمعطيات التي تحتفظ بها جمعية معيّنة تُوجَّه إلى تلك الجمعية. أما المسائل التقنية والمتعلقة بالتطبيق نفسه: support@maajamiati.com
Privacy Policy — Maa jaamiati (ماء جمعيتي)
Last updated: 17 August 2026. Android app eduapptool.purewaterbilling. This is a full translation of the Arabic policy above; the two say the same thing.
1. Who holds the data
The app runs on the association's phone. Subscribers, meter readings, bills and payments are stored on the device, and an association can use the app this way indefinitely with nothing leaving the phone.
Synchronisation is optional. An association that wants it creates a cloud database inside its own Google account, which it owns and can inspect or delete at any time.
We provide a tool, not a data-hosting service. For an association that has created its own
database, we hold no copy of its subscriber register and cannot read it — not merely because
we promise not to, but because the only access we retain in its project is the database
security rules (firebasedatabase.instances.get/update), and Google itself
refuses any attempt to read beyond that limit.
Decisions about subscribers — billing, collection, disconnection — belong to the association alone.
2. What data the app handles
Subscribers: full name, meter number, address and phone (both optional), meter readings and consumption, bills, payments, debts and advances.
Users: the email address and name from the Google account used to sign in, or a username issued by the association.
Device: the notification (FCM) token of a device that has enabled notifications, and the link code that binds a subscriber to his own file — a generated code carrying no personal meaning.
3. Why it is used
Managing subscriptions, recording readings, producing bills and receipts as PDF files, tracking payments, letting a subscriber see his own file, and sending the association's announcements.
4. Where the data is kept
By default: on the phone only. For an association that has enabled synchronisation:
| Service | Role |
|---|---|
| Google Firebase | Storage and sync, inside the association's own Google account, on servers in the European Union. |
| Google Drive | Backup, inside the association's own account, only when enabled. |
| Cloudflare | The routing table and sign-in check: the association's code and the address of its database — nothing from the subscriber register. See section 6. |
Our own Firebase projectpurewaterbilling-ff6f2 (European Union) | Only what runs the app: the usage licences, platform settings, and notifications and usage statistics. No subscriber register. |
The notification (FCM) token is stored only for a subscriber's device that has enabled notifications, and is deleted automatically once that device stops accepting them.
5. Google permissions the app requests
| Scope | Why |
|---|---|
drive.file |
Saving a backup to your own Google Drive. This is the narrowest possible scope: the app can reach only the files it created itself and cannot see the rest of your Drive. |
cloud-platformfirebasefirebase.database |
Creating a Firebase project inside your own account when you enable sync, switching on the services it needs, and writing strict security rules so your association's data is fully isolated. (There is no narrower scope that can create a project.) |
userinfo.email |
Knowing which account the database was created in, so the association is bound to the correct account and cannot end up with two databases. |
6. Who we share, transfer or disclose data to
We do not sell, rent or trade data, and we pass it to no data broker and no advertiser. The table below is everyone who receives anything, exactly what they receive, and why:
| Recipient | What it receives | Why |
|---|---|---|
| Google (Cloud, Firebase, Identity Platform) |
The association's data as it is, inside the Google project belonging to the association's own account; and the email address of the Google account that created the project. | It is the hosting itself. Google processes it under its own privacy policy, and we cannot read what is inside. |
| Cloudflare (our service provider / processor) |
The association's code and its project's public configuration (projectId, apiKey, appId, databaseUrl), the Google account email address of the association's president, and usernames with their passwords. No subscriber name, reading, bill or payment. |
Verifying sign-in credentials and directing each association to its own database. |
| Ourselves (our own Firebase project, and platform administrators) |
Only what runs the app: the usage licences, platform settings, and what sending notifications and measuring usage requires. No subscriber register. | Licences, notifications and technical support. Access is limited to platform administrators and happens only for support, maintenance, or to comply with a legal obligation. |
| Google AdMob | Technical device information such as the advertising identifier, from across the app — see section 8. | The advertising that keeps the app free. |
| Google Firebase Analytics | Aggregate usage figures and crash reports — see section 9. | Detecting failures and improving the app. |
No one else. Beyond the above, data is transferred or disclosed to no party except in three cases:
- At your request or with your explicit consent — for example when you ask for technical help that requires looking.
- A legal obligation — a court order or a valid official request under Moroccan law (Law 09-08), and only to the extent that request compels.
- Protection against abuse — investigating a breach, fraud, or harm to the service or its users.
7. Google user data: who receives what
"Google user data" is what the app obtains from your account through the scopes in section 5.
How it works, in brief: when the president taps "create my database", he is taken to Google's consent screen; once he consents, our server (a Cloudflare Worker) receives a temporary access token and uses it on his behalf to create a Firebase project inside his own account, switch on the services it needs, and write the security rules. Google user data passes through our server for that purpose alone. This is where each item goes:
| Data | Where it goes, and who sees it |
|---|---|
userinfo.emailGoogle account email address |
Stored in our routing table at Cloudflare (our processor) to bind the association to its account and prevent a second database being created for the same account. It is sent to no other party and is never used for advertising or marketing. |
| OAuth access token | Stored in the temporary setup record at Cloudflare while provisioning runs, and deleted automatically within one hour at most. No refresh token is requested at all (access_type=online), so we cannot return to your account once that session ends. It is shared with no one. |
| A service account inside your project ( PureWater Sync Auth) |
Created during setup for issuing sign-in tokens. It belongs to your project and you can delete it whenever you wish. The key generated for it is not retained by us permanently: it stays in the temporary setup record, which is deleted within one hour at most. |
drive.fileBackup files |
They stay in your own Google Drive. They are never copied to us or to anyone else, and the app sees nothing in your account beyond the files it created itself. |
cloud-platformfirebasefirebase.database |
The project is created inside your account with your consent and on your behalf, and is owned by you. After setup we retain exactly one standing permission in it — a custom role named purewaterLicence carrying nothing but firebasedatabase.instances.get/update — enough to update the security rules when a licence is renewed, and not enough to read the subscriber register. We take no copy and share it with no one. You can revoke that role from your project's IAM page at any time. |
8. Advertising
The app is free, and advertising is what makes it free. Ads therefore appear throughout the app and for every user — president, collector and subscriber alike: on app open, and on the dashboard, bills, consumption, statistics and subscriber-portal screens. One kind is chosen by the user himself: an ad watched in exchange for downloading a document.
For an association on a paid term, ads stop for the president and the collectors; subscribers continue to see them. That is the only difference paying makes: nothing in the app stops working or is withheld, and it has no bearing on the data or on who receives any of it.
All of them are served through Google AdMob, which may receive technical device information such as the advertising identifier and processes it as its own controller under Google's policy. It receives no subscriber name, bill or payment, and nothing from the Google user data described in section 7. Ad tracking can be controlled under Settings → Google → Ads.
9. Usage statistics
The app uses Google Firebase Analytics to measure how it is used — which screens are opened, device type, and crashes — in order to improve it. These are aggregate figures carrying no subscriber name, bill, reading or payment, and nothing from Google user data.
10. Security
Data travels over an encrypted connection and is stored encrypted. Access rules keep each association separate from every other, and a subscriber sees only his own file.
11. Permissions on the phone
One permission: notifications, so the association's announcements and bill reminders reach the subscriber. Choosing a logo and saving bills go through the Android file picker and need no storage permission.
12. Deleting data
The decision rests entirely with the association, from inside the app itself. There are two options for the cloud database:
- Unlink only — the app stops synchronising and returns to working locally; the database stays in your account untouched.
- Delete the database permanently — the entire project is deleted from your own Google account, the database and everything in it included. It runs on your consent at Google's own page, and it cannot be undone.
To erase the local data on the phone: Settings → Advanced → Factory reset. To delete the association's account with us — including the email address held in the routing table and whatever concerns it in our own project — write to the address below and it is removed within thirty days.
Permissions granted to the app can be withdrawn at any time at myaccount.google.com/permissions.
13. Contact
Questions about the data a particular association holds go to that association. Technical matters and questions about the app itself: support@maajamiati.com