Faab Support · Delete account · العربية

Faab Privacy Policy

Effective date: 17 September 2026

In short

1. Who we are

Faab is operated by FAAB Group Inc., 1287 Devon Rd, Oakville, Ontario L6J 2L7, Canada (“FAAB Group”, “we”). We are responsible for the personal information described here. Contact: info@faabgroupinc.com.

This policy covers the Faab apps for iPhone and Android and the servers that run Faab. FAAB Group's corporate website, faabgroupinc.com, has its own policy.

2. What is end-to-end encrypted

End-to-end encrypted content is locked on your phone with keys that only the people in the conversation hold. Our servers pass it along but cannot open it.

3. What is not end-to-end encrypted

4. What our servers store, and for how long

DataWhyHow long
Your account: a user ID derived from your keys, the @handle you chose, and your public keys (a key card in the directory and a key bundle on the key server).So people can find you and start an encrypted conversation with you.Until you delete your account. Section 9 lists what remains afterwards.
Signed, append-only transparency logs: the directory's log of @handle claims and releases (handle, user ID, time), and the key server's log of published keys.So the apps can detect a server that rewrites who owns a handle or which keys belong to an account.For as long as the service runs. Entries are not removed when an account is deleted.
Your device: the platform (iOS or Android) and, when the app has one, the push token Apple or Google issues to it.To deliver messages and wake the app.Until you delete your account.
Direct-message envelopes waiting for delivery: sealed content plus routing data (sender and recipient user IDs, conversation ID, message ID, server time, size).To deliver to a phone that is offline.Until the recipient's phone confirms receipt, then deleted. An envelope that is never collected has no time limit today.
Delivery records: the sender's user ID and the message ID of each message and call signal, with a per-conversation sequence number.Ordering, and refusing duplicates.No time limit today. Not removed when an account is deleted.
Group chats: names, members and roles, and the full message history (text, reactions, edits, file keys). We can read these.To run groups.No time limit today, including after members leave or delete their accounts.
Files you send (photos, videos, voice notes, documents), stored encrypted. We cannot decrypt files from direct messages; files sent to groups can be decrypted with the key in the group message, which our servers can read.Delivery and later download.No expiry today, and not yet removed when you delete your account (section 9).
Your block list.To stop delivery from people you blocked.Until you unblock them or delete your account.
Phone verification at sign-up. Not the number itself: to limit how often codes can be sent to one number, the messaging server keeps a keyed hash of it (HMAC-SHA-256), computed with a secret key that only we hold. The pending code is held by Twilio (section 8), not by us.To limit abuse: how many codes one number can be sent, and how many guesses can be made.At most about an hour after a code was last requested or checked, then it expires on its own. It is not linked to your account, and neither the number nor the hash is written to a log.
Connection state: whether your phone is connected now, and the time it last disconnected.Routing messages and calls.“Connected” expires within minutes. The last-disconnect time is kept and is not yet removed when you delete your account.
Calls: call signals (who called whom, when, voice or video, answered or declined) pass through the messaging server; the call relay sees participants' IP addresses and timing during a call.To connect calls.Not kept as history, apart from the delivery records and server logs in this table.
Server logs: time, request path (which can include a group ID), result and duration of requests; @handle claims and releases and account deletions with user IDs. Our reverse proxy and the call relay may also record IP addresses.Security, abuse prevention and keeping the service running.Rotated by size: each service keeps roughly its last 50 MB of log lines and overwrites the oldest. We do not copy logs to a separate archive.
E-mails you send us (support, abuse reports, deletion requests).To answer you.As long as your request is open, and no more than 12 months after we close it.

5. What we do not collect

6. On your phone

Messages, contacts and keys are kept in the app's private storage. Your identity key is sealed with a key protected by your phone's secure hardware (the Secure Enclave on iPhone, the Android Keystore on Android). On Android, if the Keystore cannot protect that key, the app falls back to keeping it unprotected in its private storage.

Message text is also kept in the app's database for search and chat-list previews. It is protected by your phone's own storage encryption, not by an additional app key. The app's stored messages, contacts and keys are excluded from your phone's system backups (such as iCloud or Google backups), so those backups do not contain them. On iPhone, the app's settings are not excluded, and they include your @handle and which chats you pinned, muted or hid. The app-lock PIN controls access to the app's screens; it does not encrypt data.

7. Link previews

When you type a link and link previews are on (the default), your phone fetches the page to build a preview card, even if you then don't send the message. The website sees a normal request from your phone, including your IP address. The card travels inside your message. You can turn previews off in the app's Settings.

8. Push notifications and other companies

9. Deleting your account

In the app: Settings › Delete all data. The app asks our servers to delete your account, then erases Faab's data from your phone:

What remains today:

In this pre-release version the key-server step can fail. The app then says that some account data may remain on the server. If that happens, or if you no longer have the app, request deletion on our account deletion page. Where the request is confirmed, we delete what remains, including the files you uploaded, within 30 days.

Deletion cannot be undone and there is no account recovery. A @handle released by deleting in the app can be claimed by someone else. After a deletion request by e-mail, we keep the @handle reserved for 12 months first.

10. Pre-release limitations

We will update this policy as these change.

11. Your rights

Depending on where you live (for example under Canada's PIPEDA, or the GDPR in the EU and UK), you can ask to access, correct, delete or receive a copy of the personal information we hold about you, and to object to or restrict its use. E-mail info@faabgroupinc.com; we answer within 30 days. Faab accounts have no e-mail address or phone number attached (we do not keep the number you sign up with), so we may ask you to confirm a request from the app.

We process this information to provide the service you asked for, to keep it secure and prevent abuse, and to meet legal obligations. You can complain to the Office of the Privacy Commissioner of Canada or to your local data protection authority.

12. Children

Faab is not directed at children under 13, and we do not knowingly provide it to them. If you believe a child under 13 is using Faab, contact us.

13. Where data is processed

FAAB Group is in Canada; Faab's servers are in the European Union. Apple and Google may process push-notification data, and Twilio your phone number and sign-up code, in the United States and other countries.

14. Requests from authorities

We respond only to legally valid requests, and we can disclose only what we hold, as listed in section 4. We cannot disclose the content of direct messages or calls, because we do not have the keys. Group messages that our servers store could be disclosed.

15. Changes

We publish changes to this policy on this page and update the effective date.


سياسة خصوصية Faab

تاريخ السريان: 17 سبتمبر 2026

باختصار

  • الرسائل الخاصة، بما فيها صورها ومقاطع الفيديو والرسائل الصوتية والملفات، مشفّرة طرفًا إلى طرف، وكذلك صوت المكالمات الثنائية وفيديوها. لا نستطيع قراءتها ولا سماعها.
  • المحادثات الجماعية ليست مشفّرة طرفًا إلى طرف. خوادمنا تخزّن رسائل المجموعات وتستطيع قراءتها.
  • خوادمنا ترى بيانات الحساب والتوجيه: مُعرِّف المستخدم الخاص بك والمعرّف الذي اخترته ويبدأ بـ @، ومفاتيحك العامة، ومن يتبادل الرسائل مع من ومتى، ومن اتصل بمن ومتى، ورمز الإشعارات الخاص بهاتفك.
  • يتطلّب إنشاء الحساب رقم هاتف. نستخدمه فقط لإرسال رمز لمرة واحدة إليك في رسالة نصية، ولا نحتفظ به: فلا يُحفظ، ولا يُربط بحسابك، ولا يستطيع أحد أن يجدك به.
  • لا إعلانات ولا متتبّعات ولا تحليلات ولا بيع للبيانات. ولا يقرأ التطبيق دفتر عناوينك.
  • خدمة Faab في إصدار مبكّر لها حدود معروفة، مذكورة في القسم 10.

1. من نحن

تشغّل FAAB Group Inc. تطبيق Faab، وعنوانها 1287 Devon Rd، أوكفيل، أونتاريو L6J 2L7، كندا (“FAAB Group”، “نحن”). ونحن المسؤولون عن المعلومات الشخصية الموصوفة هنا. للتواصل: info@faabgroupinc.com.

تغطي هذه السياسة تطبيقَي Faab لـ iPhone وAndroid والخوادم التي تشغّل Faab. وللموقع المؤسسي للشركة، faabgroupinc.com، سياسته الخاصة.

2. ما هو مشفّر طرفًا إلى طرف

المحتوى المشفّر طرفًا إلى طرف مقفل على هاتفك بمفاتيح لا يملكها إلا المشاركون في المحادثة. تمرّره خوادمنا لكنها لا تستطيع فتحه.

3. ما هو غير مشفّر طرفًا إلى طرف

4. ما تخزّنه خوادمنا، ولأي مدة

البياناتلماذاالمدة
حسابك: مُعرِّف مستخدم مشتقّ من مفاتيحك، والمعرّف الذي اخترته ويبدأ بـ @، ومفاتيحك العامة (بطاقة مفاتيح في الدليل، وحزمة مفاتيح على خادم المفاتيح).ليتمكّن الناس من العثور عليك وبدء محادثة مشفّرة معك.إلى أن تحذف حسابك. والقسم 9 يذكر ما يبقى بعد ذلك.
سجلّات شفافية موقّعة لا تقبل إلا الإضافة: سجل الدليل لحجز المعرّفات وإطلاقها (المعرّف الذي يبدأ بـ @، ومُعرِّف المستخدم المشتقّ من المفاتيح، والوقت)، وسجل خادم المفاتيح للمفاتيح المنشورة.لتتمكّن التطبيقات من كشف خادم يعيد كتابة مَن يملك معرّفًا، أو أيّ المفاتيح تخصّ حسابًا.ما دامت الخدمة تعمل. ولا تُزال المدخلات عند حذف حساب.
هاتفك: المنصّة (iOS أو Android)، ورمز الإشعارات الذي تصدره Apple أو Google للتطبيق حين يكون لديه واحد.لتسليم الرسائل وإيقاظ التطبيق.إلى أن تحذف حسابك.
مظاريف الرسائل الخاصة التي تنتظر التسليم: محتوى مختوم مع بيانات التوجيه (مُعرِّفا المرسِل والمستلِم، ومُعرِّف المحادثة، ومُعرِّف الرسالة، ووقت الخادم، والحجم).للتسليم إلى هاتف غير متصل.إلى أن يؤكّد هاتف المستلِم الاستلام، ثم تُحذف. أما المظروف الذي لا يُستلم أبدًا فلا حدّ زمني له اليوم.
سجلات التسليم: مُعرِّف مستخدم المرسِل ومُعرِّفات الرسائل وإشارات المكالمات، مع رقم تسلسلي في كل محادثة.الترتيب، ورفض المكرّر.لا حدّ زمني اليوم. ولا تُزال عند حذف حساب.
المحادثات الجماعية: الأسماء والأعضاء وأدوارهم، وسجل الرسائل كاملًا (النص والتفاعلات والتعديلات ومفاتيح الملفات). نستطيع قراءتها.لتشغيل المجموعات.لا حدّ زمني اليوم، حتى بعد مغادرة الأعضاء أو حذفهم لحساباتهم.
الملفات التي ترسلها (صور، فيديو، رسائل صوتية، مستندات)، مخزّنة مشفّرة. لا نستطيع فكّ تشفير ملفات الرسائل الخاصة؛ أما الملفات المرسلة إلى المجموعات فيمكن فكّها بالمفتاح الموجود في رسالة المجموعة، وهي رسالة تستطيع خوادمنا قراءتها.التسليم والتنزيل لاحقًا.لا انتهاء صلاحية اليوم، ولا تُزال بعدُ عند حذف حسابك (القسم 9).
قائمة المحظورين لديك.لوقف التسليم ممّن حظرتهم.إلى أن تلغي الحظر أو تحذف حسابك.
التحقّق من رقم الهاتف عند التسجيل. لا نحفظ الرقم نفسه: وللحدّ من عدد مرات إرسال الرموز إلى رقم واحد، يحتفظ خادم المراسلة بقيمة تجزئة للرقم (HMAC-SHA-256) محسوبة بمفتاح سرّي لا يملكه أحد غيرنا. أما الرمز المنتظر فتحتفظ به Twilio (القسم 8)، لا نحن.للحدّ من إساءة الاستخدام: عدد الرموز التي تُرسَل إلى رقم واحد، وعدد محاولات إدخالها.ساعة تقريبًا على الأكثر بعد آخر طلب للرمز أو تحقّق منه، ثم تنتهي صلاحيتها من تلقاء نفسها. ولا ترتبط بحسابك، ولا يُكتب الرقم ولا قيمة التجزئة في أي سجل.
حالة الاتصال: ما إذا كان هاتفك متصلًا الآن، ووقت آخر انقطاع له.توجيه الرسائل والمكالمات.تنتهي صلاحية “متصل” خلال دقائق. أما وقت آخر انقطاع فيُحفظ ولا يُزال بعدُ عند حذف حسابك.
المكالمات: تمرّ إشارات المكالمة (من اتصل بمن، ومتى، صوتية أم فيديو، أُجيبت أم رُفضت) عبر خادم المراسلة؛ ويرى مُرحِّل المكالمات عناوين IP الخاصة بالمشاركين وتوقيتهم أثناء المكالمة.لتوصيل المكالمات.لا تُحفظ كسجل، عدا سجلات التسليم وسجلات الخادم المذكورة في هذا الجدول.
سجلات الخادم: وقت الطلب ومساره (وقد يتضمّن مُعرِّف مجموعة) ونتيجته ومدّته؛ وحجز المعرّفات وإطلاقها وعمليات حذف الحسابات مع مُعرِّفات المستخدمين. وقد يسجّل الوكيل العكسي ومُرحِّل المكالمات عناوين IP أيضًا.الأمن، ومنع إساءة الاستخدام، وإبقاء الخدمة تعمل.تدور بحسب الحجم: تحتفظ كل خدمة بآخر 50 ميغابايت تقريبًا من أسطر سجلّها وتكتب فوق الأقدم. ولا ننسخ السجلات إلى أرشيف منفصل.
رسائل البريد الإلكتروني التي ترسلها إلينا (الدعم، بلاغات إساءة الاستخدام، طلبات الحذف).للردّ عليك.ما دام طلبك مفتوحًا، وبما لا يزيد على 12 شهرًا بعد إغلاقه.

5. ما لا نجمعه

6. على هاتفك

تُحفظ الرسائل وجهات الاتصال والمفاتيح في مساحة التخزين الخاصة بالتطبيق. ومفتاح هويتك مختوم بمفتاح يحميه العتاد الآمن في هاتفك (Secure Enclave على iPhone، وAndroid Keystore على Android). وعلى Android، إذا لم يستطع Keystore حماية ذلك المفتاح، يحتفظ به التطبيق غير محمي في مساحته الخاصة.

ويُحفظ نص الرسائل أيضًا في قاعدة بيانات التطبيق، للبحث ولمعاينات قائمة المحادثات. يحميه تشفير التخزين في هاتفك نفسه، لا مفتاح تطبيق إضافي. والرسائل وجهات الاتصال والمفاتيح التي يحفظها التطبيق مستثناة من النسخ الاحتياطية لنظام هاتفك (مثل نسخ iCloud أو Google)، فلا تحتوي تلك النسخ عليها. أما على iPhone فإعدادات التطبيق ليست مستثناة، وهي تتضمّن معرّفك الذي يبدأ بـ @ والمحادثات التي ثبّتّها أو كتمتها أو أخفيتها. ورمز PIN لقفل التطبيق يتحكّم في الوصول إلى شاشات التطبيق؛ وهو لا يشفّر البيانات.

7. معاينات الروابط

حين تكتب رابطًا وتكون معاينات الروابط مفعّلة (وهي الوضع الافتراضي)، يجلب هاتفك الصفحة ليبني بطاقة معاينة، حتى لو لم ترسل الرسالة بعدها. يرى الموقع طلبًا عاديًا من هاتفك، يتضمّن عنوان IP الخاص بك. وتنتقل البطاقة داخل رسالتك. ويمكنك إيقاف المعاينات من إعدادات التطبيق.

8. الإشعارات والشركات الأخرى

9. حذف حسابك

في التطبيق: الإعدادات › حذف كل البيانات. يطلب التطبيق من خوادمنا حذف حسابك، ثم يمحو بيانات Faab من هاتفك:

ما يبقى اليوم:

في هذا الإصدار المبكّر قد تفشل خطوة خادم المفاتيح. عندها يقول التطبيق إن بعض بيانات الحساب قد تبقى على الخادم. إذا حدث ذلك، أو لم يعد التطبيق لديك، فاطلب الحذف من صفحة حذف الحساب. وحين يتأكّد الطلب، نحذف ما تبقّى، بما في ذلك الملفات التي رفعتها، خلال 30 يومًا.

الحذف لا يمكن التراجع عنه، ولا توجد استعادة للحساب. والمعرّف الذي يُطلَق بالحذف من التطبيق يستطيع شخص آخر حجزه. أما بعد طلب حذف بالبريد الإلكتروني، فنُبقي المعرّف محجوزًا 12 شهرًا أولًا.

10. حدود الإصدار المبكّر

وسنحدّث هذه السياسة كلما تغيّرت هذه الأمور.

11. حقوقك

بحسب مكان إقامتك (مثلًا بموجب قانون PIPEDA في كندا، أو اللائحة العامة لحماية البيانات GDPR في الاتحاد الأوروبي والمملكة المتحدة)، يمكنك أن تطلب الاطّلاع على المعلومات الشخصية التي نحتفظ بها عنك، أو تصحيحها أو حذفها أو الحصول على نسخة منها، وأن تعترض على استخدامها أو تطلب تقييده. راسلنا على info@faabgroupinc.com؛ ونردّ خلال 30 يومًا. ولأن حسابات Faab ليس لها بريد إلكتروني ولا رقم هاتف مرتبط (فنحن لا نحتفظ بالرقم الذي تسجّل به)، قد نطلب منك تأكيد الطلب من التطبيق.

ونعالج هذه المعلومات لتقديم الخدمة التي طلبتها، ولإبقائها آمنة ومنع إساءة استخدامها، وللوفاء بالتزاماتنا القانونية. ويمكنك تقديم شكوى إلى مفوّضية حماية الخصوصية في كندا (Office of the Privacy Commissioner of Canada) أو إلى سلطة حماية البيانات في بلدك.

12. الأطفال

تطبيق Faab غير موجّه للأطفال دون 13 عامًا، ولا نقدّمه لهم عن علم. وإذا كنت تعتقد أن طفلًا دون 13 عامًا يستخدم Faab، فتواصل معنا.

13. أين تُعالَج البيانات

مقرّ FAAB Group في كندا، وخوادم Faab في الاتحاد الأوروبي. وقد تعالج Apple وGoogle بيانات الإشعارات، وتعالج Twilio رقم هاتفك ورمز التسجيل، في الولايات المتحدة وبلدان أخرى.

14. طلبات السلطات

لا نستجيب إلا للطلبات الصحيحة قانونًا، ولا نستطيع الإفصاح إلا عمّا نحتفظ به، كما هو مذكور في القسم 4. ولا نستطيع الإفصاح عن محتوى الرسائل الخاصة ولا المكالمات، لأننا لا نملك المفاتيح. أما رسائل المجموعات التي تخزّنها خوادمنا فيمكن الإفصاح عنها.

15. التغييرات

ننشر تغييرات هذه السياسة على هذه الصفحة، ونحدّث تاريخ السريان.