سياسة الخصوصية

«ماء جمعيتي» — تطبيق لتدبير وفوترة الماء الصالح للشرب لدى الجمعيات.

آخر تحديث: 17 غشت 2026

English version below ↓

ملخص الخصوصية: تُحفظ بيانات جمعيتكم محلياً على جهازكم الخاص، ويعمل التطبيق بكامل خصائصه دون نقل أي معلومات للخارج. في حال تفعيل المزامنة السحابية، تُستضاف قاعدة البيانات حصرياً داخل حساب Google التابع لجمعيتكم وبذلك توافقون على شروط خدمة Google — نحن لا نحتفظ بأي نسخة من سجلّ المنخرطين. ونحتفظ في مشروعنا الخاص بما يُشغّل التطبيق نفسه: حساب الجمعية، ورمزها، وحالة رخصتها — تفصيلها في القسمين 4 و6.

1. من يملك المعطيات

التطبيق يشتغل في هاتف الجمعية. المنخرطون والقراءات والفواتير والأداءات تُحفظ في الجهاز، ويمكن للجمعية أن تستعمل التطبيق هكذا إلى الأبد دون أن يغادر الهاتف أي شيء.

المزامنة اختيارية. الجمعية التي تريدها تُنشئ قاعدة بيانات سحابية داخل حساب Google الخاص بها، تملكها وتطّلع عليها أو تحذفها متى شاءت.

نحن نوفّر الأداة، لا خدمة استضافة معطيات. والجمعية التي أنشأت قاعدتها الخاصة: لا نحتفظ بنسخة من سجلّ منخرطيها، ولا يمكننا قراءته — لا لأننا وعدنا بذلك فقط، بل لأن الصلاحية التي نملكها في مشروعها محصورة في قواعد الحماية (firebasedatabase.instances.get/update)، وGoogle نفسها ترفض أي محاولة قراءة خارج هذا الحد.

وما نحتفظ به نحن، بصراحة: يبقى في مشروع Firebase الخاص بنا ما يُشغّل التطبيق وحده — رخص الاستعمال، وإعدادات المنصة كرقم الدعم، وما يقتضيه إرسال الإشعارات وقياس الاستعمال. ولا يحتوي سجلّ أي جمعية: فالتطبيق يرفض المزامنة إلى أي مكان غير مشروع الجمعية نفسها، وإن لم يكن متصلاً به بقيت المعطيات في الهاتف إلى أن يتصل. ويمكن لمشرف من جهتنا الوصول إلى ما في مشروعنا تقنياً، ولا يقع ذلك إلا للدعم أو الصيانة أو تنفيذاً لموجب قانوني — وتفصيله في القسم 6.

القرارات المتعلقة بالمنخرطين — الفوترة والتحصيل وقطع الخدمة — تعود للجمعية وحدها.

2. ما تتعامل معه التطبيق من معطيات

المنخرطون: الاسم الكامل، رقم العداد، العنوان والهاتف (اختياريان)، دلائل العدادات والاستهلاك، الفواتير، الأداءات، الديون والتسبيقات.

المستعملون: البريد الإلكتروني والاسم من حساب Google المستعمل للدخول، أو اسم مستخدم تُصدره الجمعية.

الجهاز: رمز الإشعارات (FCM) للجهاز الذي فعّل الإشعارات، ورمز الانتساب الذي يربط المنخرط بملفه — وهو رمز مُولَّد لا يحمل أي معنى شخصي.

3. لماذا تُستعمل

تدبير الاشتراكات، تسجيل القراءات، إصدار الفواتير والوصولات كملفات PDF، تتبع الأداءات، تمكين المنخرط من الاطلاع على ملفه، وإرسال إعلانات الجمعية.

4. أين تُحفظ

افتراضياً: في الهاتف فقط. أما الجمعية التي فعّلت المزامنة:

الخدمةالدور
Google Firebaseتخزين ومزامنة، داخل حساب Google الخاص بالجمعية، على خواديم في الاتحاد الأوروبي
Google Driveالنسخة الاحتياطية، داخل حساب الجمعية، عند تفعيلها فقط
Cloudflareجدول التوجيه وبيانات الدخول: رمز الجمعية وعنوان قاعدتها، ولا شيء من سجل المنخرطين (انظر القسم 6)
مشروع Firebase الخاص بنا
purewaterbilling-ff6f2 (الاتحاد الأوروبي)
ما يُشغّل التطبيق وحده: رخص الاستعمال، وإعدادات المنصة، والإشعارات وإحصاءات الاستعمال. ولا سجلّ منخرطين فيه.

ورمز الإشعارات (FCM) يُحفظ لجهاز المنخرط الذي فعّل الإشعارات وحده، ويُحذف تلقائياً حين يتوقف الجهاز عن قبولها.

5. أذونات Google التي يطلبها التطبيق

هذه هي كل الأذونات التي قد يُطلب منك منحها، ولماذا:

الإذنالسبب
drive.file حفظ نسخة احتياطية في حسابك على Google Drive. هذا أضيق إذن ممكن: لا يصل التطبيق إلا إلى الملفات التي أنشأها هو، ولا يرى باقي ملفاتك.
cloud-platform
firebase
firebase.database
تهيئة مشروع Firebase داخل حسابكم الخاص عند تفعيل المزامنة، وتشغيل الخدمات الضرورية، وإعداد قواعد أمان صارمة لضمان العزل التام لبيانات جمعيتكم. (ملاحظة: هذا هو مستوى الصلاحيات الأدنى الذي تطلبه المنصة لإنشاء المشاريع).
userinfo.email معرفة الحساب الذي أُنشئت القاعدة داخله، حتى تُربط الجمعية بحسابها الصحيح.

6. مع من نتشارك المعطيات

لا نبيع المعطيات ولا نؤجّرها ولا نتبادلها، ولا نمرّرها إلى وسيط معطيات ولا إلى معلن. والجدول التالي هو كل من قد يصله شيء، وما يصله بالضبط، ولماذا:

الجهةما يصلهالماذا
Google
(Cloud، Firebase، Identity Platform)
معطيات الجمعية كما هي، داخل مشروع Google التابع لحساب الجمعية نفسها؛ وعنوان بريد حساب Google الذي أنشأ المشروع. هي الاستضافة نفسها. تُعالجها Google وفق سياسة الخصوصية الخاصة بها، ونحن لا نقدر على قراءة ما بداخلها.
Cloudflare
(مناول لدينا)
رمز الجمعية وإعدادات مشروعها العمومية (projectId، apiKey، appId، databaseUrl)، وعنوان بريد حساب Google لرئيس الجمعية، وأسماء المستعملين وكلمات سرّهم. ولا يصلها اسم منخرط ولا قراءة ولا فاتورة ولا أداء. التحقق من بيانات الدخول، وتوجيه كل جمعية إلى قاعدة بياناتها هي.
نحن أنفسنا
(مشروع Firebase الخاص بنا، ومشرفو المنصة)
ما يُشغّل التطبيق وحده: رخص الاستعمال، وإعدادات المنصة، وما يقتضيه إرسال الإشعارات وقياس الاستعمال. ولا سجلّ منخرطين فيه. الرخص، والإشعارات، والدعم التقني. الوصول محصور في مشرفي المنصة، ولا يقع إلا للدعم أو الصيانة أو تنفيذاً لموجب قانوني.
Google AdMob معطيات تقنية عن الجهاز مثل معرّف الإعلانات، من كل واجهات التطبيق — انظر القسم 8. الإعلانات التي تجعل التطبيق مجانياً.
Google Firebase Analytics أرقام استعمال مجمّعة وتقارير أعطاب — انظر القسم 9. كشف الأعطاب وتحسين التطبيق.

ولا أحد غير هؤلاء. وخارج ما سبق، لا تُنقل المعطيات ولا تُفصح لأي طرف إلا في ثلاث حالات:

وإن انتقلت ملكية التطبيق يوماً إلى جهة أخرى، انتقلت هذه السياسة معه؛ تُبلَّغ الجمعيات قبل أي تغيير، ويبقى لكل جمعية أن تحذف معطياتها.

7. معطيات مستعمل Google: من يصله ماذا

«معطيات مستعمل Google» هي ما يحصل عليه التطبيق من حسابكم عبر الأذونات المذكورة في القسم 5.

وطريقة العمل بإيجاز: حين يضغط الرئيس على «أنشئ قاعدة بياناتي»، يُحوَّل إلى صفحة الموافقة عند Google؛ وبعد موافقته يتلقّى خادومنا (Cloudflare Worker) رمز وصول مؤقتاً ويستعمله نيابةً عنه لإنشاء مشروع Firebase داخل حسابه، وتشغيل الخدمات الضرورية، وكتابة قواعد الحماية. فمعطيات Google تمرّ عبر خادومنا لهذا الغرض وحده. وهذا مصير كل واحد منها:

المعطىإلى أين يذهب، ومن يراه
userinfo.email
عنوان بريد حساب Google
يُحفظ في جدول التوجيه عند Cloudflare (مناول لدينا) لربط الجمعية بحسابها ومنع إنشاء قاعدتين للحساب نفسه. لا يُرسل إلى أي جهة أخرى، ولا يُستعمل في إعلان ولا في تسويق.
رمز الوصول (access token) يُحفظ في سجل الإعداد المؤقت عند Cloudflare ما دام الإعداد جارياً، ويُحذف تلقائياً بعد ساعة على الأكثر. ولا نطلب رمز تجديد (refresh token) أصلاً (access_type=online)، فلا يمكننا العودة إلى حسابكم بعد انتهاء تلك الجلسة. ولا يُشارَك مع أي جهة.
حساب خدمة داخل مشروعكم
(PureWater Sync Auth)
يُنشأ أثناء الإعداد لإصدار رموز الدخول، ويبقى مِلكاً لمشروعكم تحذفونه متى شئتم. والمفتاح المُولَّد له لا يُحفظ عندنا بشكل دائم: يبقى في سجل الإعداد المؤقت الذي يُحذف بعد ساعة على الأكثر.
drive.file
ملفات النسخ الاحتياطي
تبقى في Google Drive الخاص بكم. لا تُنسخ إلينا ولا إلى غيرنا، ولا يرى التطبيق من محتوى حسابكم إلا الملفات التي أنشأها هو.
cloud-platform
firebase
firebase.database
المشروع يُنشأ داخل حسابكم بموافقتكم أنتم وباسمكم، وتملكونه أنتم. وتبقى لنا فيه بعد الإعداد صلاحية واحدة دائمة — دور مخصوص اسمه purewaterLicence لا يحمل غير firebasedatabase.instances.get/update — تكفي لتحديث قواعد الحماية عند تجديد الرخصة ولا تُخوّل قراءة سجل المنخرطين. ولا نأخذ نسخة منه، ولا يُشارَك مع أي جهة. ويمكنكم سحب هذا الدور من وحدة IAM في مشروعكم في أي وقت.
ولا يحدث هذا أبداً: معطيات مستعمل Google لا تُباع ولا تُؤجَّر ولا تُنقل إلى معلن أو وسيط معطيات أو أي طرف ثالث لأغراضه الخاصة؛ ولا تُستعمل في تخصيص الإعلانات؛ ولا تُستعمل في تطوير أو تدريب أو تحسين أي نموذج ذكاء اصطناعي أو تعلُّم آلي — لا نموذجاً خاصاً بنا ولا نموذجاً عامّاً لجهة أخرى؛ ولا يقرأها بشر إلا بموافقتكم الصريحة، أو لضرورة أمنية، أو تنفيذاً لموجب قانوني.

استعمالُ «ماء جمعيتي» للمعلومات المتحصَّلة من واجهات Google، ونقلُها إلى أي تطبيق آخر، يخضع لسياسة Google الخاصة بمعطيات مستعملي خدمات الواجهات، بما فيها شروط الاستعمال المحدود (Limited Use). ونصّ التصريح بالإنجليزية:

Maa jaamiati's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. الإعلانات

التطبيق مجاني، والإعلانات هي ما يجعله كذلك. ولذلك تظهر في كل واجهات التطبيق ولكل المستعملين — الرئيس والمحصّل والمنخرط على السواء: عند فتح التطبيق، وفي الشاشة الرئيسية، والفواتير، والاستهلاك، والإحصاءات، وبوابة المنخرط. وهناك نوع واحد يختاره المستعمل بنفسه: إعلان يشاهده مقابل تحميل وثيقة.

والجمعية التي تشترك في مدة مدفوعة تتوقف عندها الإعلانات عن الرئيس والمحصّلين، ويبقى المنخرط يراها. وهذا هو الفرق الوحيد الذي يصنعه الأداء: لا شيء في التطبيق يتوقف عن العمل ولا يُحجب، وليس للأمر أثر على المعطيات ولا على من يصله شيء منها.

وتُعرض كلها عبر Google AdMob. وقد تصل AdMob معطيات تقنية عن الجهاز مثل معرّف الإعلانات، تعالجها بصفتها هي وفق سياسة Google. لا يصلها اسم منخرط ولا فاتورة ولا أداء، ولا يصلها أي شيء من معطيات مستعمل Google المذكورة في القسم 7. يمكن التحكم في تتبع الإعلانات من: إعدادات الهاتف ← Google ← الإعلانات.

9. إحصاءات الاستعمال

يستعمل التطبيق Google Firebase Analytics لقياس كيفية استعماله — الشاشات التي تُفتح، نوع الجهاز، والأعطاب — قصد تحسينه. هذه أرقام مجمّعة لا تحمل اسم منخرط ولا فاتورة ولا قراءة ولا أداء، ولا تحمل شيئاً من معطيات مستعمل Google.

10. الأمان

تُنقل المعطيات عبر اتصال مشفَّر وتُخزَّن مشفَّرة. وقواعد الحماية تعزل كل جمعية عن غيرها، ولا يرى المنخرط غير ملفه هو.

لا يوجد نظام آمن بشكل مطلق، ولا يُقدَّم أي ضمان ضد الاختراق أو ضياع المعطيات. يُقدَّم التطبيق كما هو، والجمعية مسؤولة عن بيانات الدخول التي في عهدتها وعن المعطيات التي تجمعها. احتفظ بكلمات السر وبريد الحساب في مكان آمن، وأبقِ هاتفك مقفلاً.

11. الأذونات داخل الهاتف

إذن واحد: الإشعارات، حتى تصل إعلانات الجمعية وتذكيرات الفواتير إلى المنخرط. اختيار الشعار وحفظ الفواتير يمرّان عبر منتقي الملفات في أندرويد ولا يحتاجان أي إذن تخزين.

12. حذف المعطيات

القرار كله بيد الجمعية، ومن داخل التطبيق نفسه. أمام القاعدة السحابية خياران:

ولحذف المعطيات المحلية من الهاتف: الإعدادات ← خيارات متقدمة ← إعادة ضبط المصنع. ولحذف حساب الجمعية لدينا — بما فيه عنوان البريد المحفوظ في جدول التوجيه وما يخصّها في مشروعنا — راسلنا على البريد أسفله ويُحذف داخل ثلاثين يوماً.

ويمكن في أي وقت سحب الأذونات الممنوحة للتطبيق من myaccount.google.com/permissions.

13. الاتصال

الأسئلة المتعلقة بالمعطيات التي تحتفظ بها جمعية معيّنة تُوجَّه إلى تلك الجمعية. أما المسائل التقنية والمتعلقة بالتطبيق نفسه: support@maajamiati.com


Privacy Policy — Maa jaamiati (ماء جمعيتي)

Last updated: 17 August 2026. Android app eduapptool.purewaterbilling. This is a full translation of the Arabic policy above; the two say the same thing.

An association's data is stored locally on its own phone, and the app works fully without sending anything out. If cloud sync is enabled, the database is hosted exclusively inside the association's own Google account — we keep no copy of the subscriber register. What we do keep in our own project is what runs the app itself: the association's account, its code, and its licence status — set out in sections 4 and 6.

1. Who holds the data

The app runs on the association's phone. Subscribers, meter readings, bills and payments are stored on the device, and an association can use the app this way indefinitely with nothing leaving the phone.

Synchronisation is optional. An association that wants it creates a cloud database inside its own Google account, which it owns and can inspect or delete at any time.

We provide a tool, not a data-hosting service. For an association that has created its own database, we hold no copy of its subscriber register and cannot read it — not merely because we promise not to, but because the only access we retain in its project is the database security rules (firebasedatabase.instances.get/update), and Google itself refuses any attempt to read beyond that limit.

What we do hold, stated plainly: our own Firebase project keeps only what runs the app — the usage licences, platform settings such as the support number, and what sending notifications and measuring usage requires. It holds no association's register: the app refuses to synchronise anywhere but the association's own project, and while it is not attached to one the data stays on the phone until it is. An administrator on our side can technically reach what is in our project, and that happens only for support, maintenance, or to comply with a legal obligation — detailed in section 6.

Decisions about subscribers — billing, collection, disconnection — belong to the association alone.

2. What data the app handles

Subscribers: full name, meter number, address and phone (both optional), meter readings and consumption, bills, payments, debts and advances.

Users: the email address and name from the Google account used to sign in, or a username issued by the association.

Device: the notification (FCM) token of a device that has enabled notifications, and the link code that binds a subscriber to his own file — a generated code carrying no personal meaning.

3. Why it is used

Managing subscriptions, recording readings, producing bills and receipts as PDF files, tracking payments, letting a subscriber see his own file, and sending the association's announcements.

4. Where the data is kept

By default: on the phone only. For an association that has enabled synchronisation:

ServiceRole
Google FirebaseStorage and sync, inside the association's own Google account, on servers in the European Union.
Google DriveBackup, inside the association's own account, only when enabled.
CloudflareThe routing table and sign-in check: the association's code and the address of its database — nothing from the subscriber register. See section 6.
Our own Firebase project
purewaterbilling-ff6f2 (European Union)
Only what runs the app: the usage licences, platform settings, and notifications and usage statistics. No subscriber register.

The notification (FCM) token is stored only for a subscriber's device that has enabled notifications, and is deleted automatically once that device stops accepting them.

5. Google permissions the app requests

ScopeWhy
drive.file Saving a backup to your own Google Drive. This is the narrowest possible scope: the app can reach only the files it created itself and cannot see the rest of your Drive.
cloud-platform
firebase
firebase.database
Creating a Firebase project inside your own account when you enable sync, switching on the services it needs, and writing strict security rules so your association's data is fully isolated. (There is no narrower scope that can create a project.)
userinfo.email Knowing which account the database was created in, so the association is bound to the correct account and cannot end up with two databases.

6. Who we share, transfer or disclose data to

We do not sell, rent or trade data, and we pass it to no data broker and no advertiser. The table below is everyone who receives anything, exactly what they receive, and why:

RecipientWhat it receivesWhy
Google
(Cloud, Firebase, Identity Platform)
The association's data as it is, inside the Google project belonging to the association's own account; and the email address of the Google account that created the project. It is the hosting itself. Google processes it under its own privacy policy, and we cannot read what is inside.
Cloudflare
(our service provider / processor)
The association's code and its project's public configuration (projectId, apiKey, appId, databaseUrl), the Google account email address of the association's president, and usernames with their passwords. No subscriber name, reading, bill or payment. Verifying sign-in credentials and directing each association to its own database.
Ourselves
(our own Firebase project, and platform administrators)
Only what runs the app: the usage licences, platform settings, and what sending notifications and measuring usage requires. No subscriber register. Licences, notifications and technical support. Access is limited to platform administrators and happens only for support, maintenance, or to comply with a legal obligation.
Google AdMob Technical device information such as the advertising identifier, from across the app — see section 8. The advertising that keeps the app free.
Google Firebase Analytics Aggregate usage figures and crash reports — see section 9. Detecting failures and improving the app.

No one else. Beyond the above, data is transferred or disclosed to no party except in three cases:

If ownership of the app ever passes to another party, this policy passes with it; associations are told before any change, and each remains free to delete its data.

7. Google user data: who receives what

"Google user data" is what the app obtains from your account through the scopes in section 5.

How it works, in brief: when the president taps "create my database", he is taken to Google's consent screen; once he consents, our server (a Cloudflare Worker) receives a temporary access token and uses it on his behalf to create a Firebase project inside his own account, switch on the services it needs, and write the security rules. Google user data passes through our server for that purpose alone. This is where each item goes:

DataWhere it goes, and who sees it
userinfo.email
Google account email address
Stored in our routing table at Cloudflare (our processor) to bind the association to its account and prevent a second database being created for the same account. It is sent to no other party and is never used for advertising or marketing.
OAuth access token Stored in the temporary setup record at Cloudflare while provisioning runs, and deleted automatically within one hour at most. No refresh token is requested at all (access_type=online), so we cannot return to your account once that session ends. It is shared with no one.
A service account inside your project
(PureWater Sync Auth)
Created during setup for issuing sign-in tokens. It belongs to your project and you can delete it whenever you wish. The key generated for it is not retained by us permanently: it stays in the temporary setup record, which is deleted within one hour at most.
drive.file
Backup files
They stay in your own Google Drive. They are never copied to us or to anyone else, and the app sees nothing in your account beyond the files it created itself.
cloud-platform
firebase
firebase.database
The project is created inside your account with your consent and on your behalf, and is owned by you. After setup we retain exactly one standing permission in it — a custom role named purewaterLicence carrying nothing but firebasedatabase.instances.get/update — enough to update the security rules when a licence is renewed, and not enough to read the subscriber register. We take no copy and share it with no one. You can revoke that role from your project's IAM page at any time.
What never happens: Google user data is not sold, rented or transferred to any advertiser, data broker or third party for their own purposes; it is not used for ad personalisation; it is not used to develop, train or improve any artificial intelligence or machine-learning model — neither our own nor any generalised model belonging to another party; and no human reads it except with your explicit consent, for a security necessity, or to comply with a legal obligation.
Maa jaamiati's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Advertising

The app is free, and advertising is what makes it free. Ads therefore appear throughout the app and for every user — president, collector and subscriber alike: on app open, and on the dashboard, bills, consumption, statistics and subscriber-portal screens. One kind is chosen by the user himself: an ad watched in exchange for downloading a document.

For an association on a paid term, ads stop for the president and the collectors; subscribers continue to see them. That is the only difference paying makes: nothing in the app stops working or is withheld, and it has no bearing on the data or on who receives any of it.

All of them are served through Google AdMob, which may receive technical device information such as the advertising identifier and processes it as its own controller under Google's policy. It receives no subscriber name, bill or payment, and nothing from the Google user data described in section 7. Ad tracking can be controlled under Settings → Google → Ads.

9. Usage statistics

The app uses Google Firebase Analytics to measure how it is used — which screens are opened, device type, and crashes — in order to improve it. These are aggregate figures carrying no subscriber name, bill, reading or payment, and nothing from Google user data.

10. Security

Data travels over an encrypted connection and is stored encrypted. Access rules keep each association separate from every other, and a subscriber sees only his own file.

No system is completely secure, and no guarantee is given against breach or loss of data. The app is provided as is, and the association is responsible for the credentials in its keeping and for the data it collects. Keep passwords and the account email somewhere safe, and keep the phone locked.

11. Permissions on the phone

One permission: notifications, so the association's announcements and bill reminders reach the subscriber. Choosing a logo and saving bills go through the Android file picker and need no storage permission.

12. Deleting data

The decision rests entirely with the association, from inside the app itself. There are two options for the cloud database:

To erase the local data on the phone: Settings → Advanced → Factory reset. To delete the association's account with us — including the email address held in the routing table and whatever concerns it in our own project — write to the address below and it is removed within thirty days.

Permissions granted to the app can be withdrawn at any time at myaccount.google.com/permissions.

13. Contact

Questions about the data a particular association holds go to that association. Technical matters and questions about the app itself: support@maajamiati.com