We do not gather data about you in the background. Everything described below is information you enter yourself, or content you choose to save, so that the App can function. None of it is used for internal analytics, tracking, or profiling of any kind.
You may create your account, or sign in to it, using Sign in with Google or Sign in with Apple instead of receiving a one-time code by email. If you choose to:
This content is stored so it can be synchronized securely across your devices. It belongs to you, and it is end-to-end encrypted: it is encrypted on your device with a key only you hold, and it reaches our servers only as unreadable ciphertext. We cannot read, search, analyze, or disclose it — not for support, not for product improvement, and not in response to a request from anyone else. Specifically, the following are encrypted before leaving your device:
That list is deliberate. Which laws and which rulings a named lawyer is researching, and under which case, is exactly the association end-to-end encryption exists to hide — so the reference itself is encrypted, not merely the file it sits beside.
Technical details are in Section 3.2, including the limited information that necessarily remains unencrypted so that synchronization can work at all.
A folder in ADL is meant to work as a case file, so you can attach documents to it: a PDF, a Word document, or an image — chosen from your files, picked from your photo library, or photographed with your camera. On paid plans, these are stored so that they reach your other devices and survive losing your phone.
The file is encrypted on your device before it is uploaded. Your device encrypts the file's contents, its original filename, and its file type, and then uploads that ciphertext directly to our storage provider. What exists on our systems is an opaque block of bytes. We cannot open it, preview it, index it, scan it, or convert it, and neither can our storage provider.
Because a stored file still has to be accounted for, a small amount of non-content information about it is visible to us and is described in Section 3.2: its size, a checksum of the encrypted bytes, which of your folders it sits in, and when it was added. Not its name, not its type, and not a single byte of what is inside it.
Your camera and photo library are read only at the moment you choose to add something, and never in the background; see Sections 4.4 and 4.5.
Photographs are stripped of their hidden metadata first. A photo normally carries an invisible record written by the camera: the date and time, the device, and — where the camera records it — the GPS coordinates of where the picture was taken. Photographing a document at a client's home would otherwise embed that address in the file.
ADL removes that record on your device, before the image is encrypted and before anything is uploaded. It is deleted outright rather than hidden: the bytes are not present in the stored file at all. The picture itself is untouched by this step: the image data is copied through byte for byte, and only the descriptive records around it are discarded. This applies to every image, however you added it: photographed in the App, chosen from your photo library, or picked from your files.
It also protects you after the fact. Because the metadata is gone from the stored file, a file you later share out of the App to a colleague or a court carries no location or device history with it.
If an image cannot be cleaned, it is not uploaded and the App tells you so. We would rather refuse a file than store one carrying data we said we had removed. For that reason ADL accepts PDF, Word, JPEG, PNG and WebP files: TIFF images are not accepted, because that format's location data cannot be removed without rebuilding the image itself.
Your files are never sent to the AI Agent or to any AI provider. That is not a policy we could relax quietly: the files are ciphertext, so there is nothing an AI service could read even if it received them.
The following exists only on your device. It is not collected, transmitted to, or stored on our servers:
Jurisprudence works differently, and we want to be exact about it. The collection of court rulings is served from our servers, so that every user reads the same, up-to-date text and corrections reach everyone at once. Browsing or searching rulings therefore sends your request — including the words you search for — to our servers. We use those requests for one thing: returning the results to you. We do not attach them to a profile, and we do not use them for analytics, advertising, or any assessment of you.
Access tokens and refresh tokens used to keep you securely signed in. These are stored exclusively in your device's secure storage — iOS Keychain on Apple devices, Android Keystore on Android devices — and are never accessible to other apps.
Unlike your notes, folders, files, and contracts, AI conversations are not end-to-end encrypted. They cannot be: the AI Agent has to read your question on our servers in order to answer it and to look up the relevant Lebanese laws and rulings. They are protected instead by encryption in transit and at rest (Section 3.4).
Your stored conversation history is used for one purpose only: operating and enhancing the AI Agent for you. Concretely, that means letting you reopen past conversations across your devices, giving the Agent the context of the conversation you are currently having so its answers follow on properly, and improving the quality, accuracy, and referencing of the answers the App gives. It is not used for advertising, profiling, marketing, or analytics, is never sold or shared for anyone else's purposes, and is not used by our AI provider to train its models (see Section 5).
Messages you send to the AI Agent are processed by an AI service acting on our behalf, and by that service's own model provider, solely to generate your answer — both are named in Section 5. Your conversations are private to your account, are visible to no other user, and are permanently deleted when your account is deleted.
The App lets you report an AI answer you find offensive, inaccurate, or harmful — a channel the app stores require us to provide. Reporting is entirely voluntary and nothing is sent unless you tap Report. When you send one, we store the reason you selected, any details you choose to write, a snapshot excerpt of the reported answer (kept so the report survives even if you later delete that conversation), your account reference, and — where the answer came from a saved conversation — a reference to it. A copy is emailed to our support address. We use reports for one purpose: reviewing and correcting the AI Agent's behaviour.
Subscriptions and packs of extra AI credits are purchased through, and paid to, the Apple App Store or Google Play. We never see or store your payment card information. Through our subscription-management provider (see Section 5) we receive and store your current plan and its expiry date, and, for a credit pack, the store's transaction identifier, which pack you bought, and how many credits were granted — the record that lets us apply each purchase to your account exactly once and never twice.
Our servers and our hosting provider keep short-lived technical logs of requests made to the service — the IP address a request came from, the time, and which part of the service was called. These exist to keep the service running, to apply rate limits, and to investigate abuse or attacks. They are not joined to your content and are not used to build any profile of you. We also record which device currently holds the active session for your account, so that signing in on a new device signs the previous one out.
We use your information to:
We do not use your data for advertising, profiling, or marketing. We do not sell or rent your data to any third party. Your information is never used for anyone's personal purposes — it is used exclusively to operate the App and enhance your user experience.
The information you entrust to the App is kept safe and encrypted — on your device, in transit, and on our servers. Your notes, folders, files, saved references, and contracts go further: they are end-to-end encrypted, meaning we hold only ciphertext we have no ability to decrypt.
Your data is stored locally in a database protected by your operating system's application sandboxing, which prevents other apps from accessing it. Authentication tokens and your encryption key are stored in your device's secure hardware-backed storage (iOS Keychain / Android Keystore). Your content is readable on your own device — that is what makes offline access and instant search possible — and is encrypted at the moment it is sent to us.
Files are handled more carefully than the rest. A file you have opened is kept on your device in its encrypted form, so that it stays available with no network at all. A readable copy is written only when something has to display it — a PDF viewer, or the share sheet — and that readable copy is deleted when you sign out and again every time the App starts cold. Decrypted case documents therefore do not accumulate on your device.
Signing out erases your local content, your encryption key, and every readable file copy from the device.
Your notes, folders, files, saved references, and contracts are encrypted on your device before being uploaded, and are only ever decrypted on your own devices. In plain terms:
Because synchronization has to know which record to route where, a small amount of non-content information necessarily remains unencrypted on our servers: record identifiers, creation and update timestamps, which folder a note or a file belongs to, whether a note is pinned, and which template a contract was created from. For a stored file we additionally hold its size in bytes and a checksum — computed over the encrypted bytes, deliberately, so that it cannot be used to test whether you hold a particular known document. The words you actually write, the files you store, and the laws and rulings you save are never among it.
In practice, what our servers can see about a case folder is that an account owns some folders, that those folders contain some notes, some references, and some files of a certain size, and when each last changed. What the case is, what is in it, and what you concluded about it, they cannot see at all.
Your account information, your User Content (notes, folders, saved references, contracts — stored as encrypted ciphertext, as described above), and your AI conversation history are stored on our backend servers, hosted on Railway. The files you add to your folders are stored as encrypted objects on Cloudflare R2. All communication between the App and our servers travels exclusively over encrypted HTTPS (TLS) connections, and data on our servers is encrypted at rest by our hosting infrastructure — a second layer beneath the end-to-end encryption you already hold the key to.
Files move between your device and storage over short-lived, single-purpose signed links that we issue to your device and that expire within minutes. They cannot be guessed, listed, or shared, and the storage bucket is not publicly readable by any route.
We implement these safeguards so that your information stays secure at every step. As with any online service, no method of transmission or storage can be guaranteed absolutely, which is why we layer these protections and keep them up to date.
The App requests permission to access your device calendar solely to write note reminders that you explicitly create within the App. We do not read, copy, collect, or store any of your existing calendar events. You can disable this permission in your device settings at any time; doing so will prevent the App from adding reminders to your calendar.
The App requests permission to send you notifications for the reminders you set. You can manage this in your device settings. Disabling notifications will prevent reminder alerts from reaching you.
The legal locations map shows public places: courts, ministries, and legal offices. On iPhone and iPad, it can also show your own position on that map, so you can see where you are in relation to them. Your device asks your permission the first time you open the map, and you may decline or revoke it at any time in your device settings — the map works fully without it.
Your location is used for that one purpose and nothing else. It never reaches us. It is not transmitted to our servers, not stored by us, not attached to your account, not used to decide which content or prices you see, and not used for analytics, advertising, profiling, or any location history. On Android this display is not enabled and the App requests no location permission at all.
To be exact about one thing: the map itself is drawn by Google's Maps service (Section 5). Displaying a map means Google receives what it needs to draw it — the area you are looking at and your device's network address — and, while the blue dot is shown, that is handled by Google's mapping component on your device. That is Google acting under its own privacy policy, not us collecting your position. If you would rather not involve it, decline the location permission: the map still works and simply does not show where you are.
The App can use your camera for one purpose: photographing a document so you can add it to a case folder. Your device asks your permission the first time you use it, and you may decline or revoke it at any time in your device settings — every other part of the App works without it. The camera is opened only when you tap to take a photo, never in the background, and nothing is captured or transmitted unless you keep the photo. The photograph has its hidden metadata — including the location it was taken — removed on your device, and is then encrypted before it is uploaded, so we never see the image or anything it came with (Section 1.4).
The App can read an image from your photo library so you can add it to a case folder. We receive only the image you select. The App does not browse, index, scan, or upload your photo library, cannot see any other image in it, and never reads it in the background. On iPhone and iPad you may grant access to selected photos only, and the App works normally that way. As with the camera, the image has its hidden metadata stripped on your device and is encrypted before upload, so we never see it.
The App does not request access to your microphone or your contacts.
We do not sell, rent, or trade your personal information, and we never share it for anyone else's purposes. The service providers listed below process it only on our behalf, only to make the App work, and only under instructions from us.
To operate the App, we rely on a small number of service providers that process data strictly on our behalf and under our instructions, over encrypted connections:
When you ask the AI Agent about a contract. Your contracts are end-to-end encrypted, so we cannot read them. If you open one and ask the AI Agent about it, your device decrypts that contract and sends its text to the AI service for that request alone, so the Agent can answer you. That conversation is a scratchpad: it is not saved on our servers and it disappears when you close it. The contract text is used only to produce your answer and is not retained by us or by the AI service afterwards. This happens only for a contract you deliberately ask about, and only while you are asking — never in the background, and never for your notes or folders. The one exception is if you choose to report an answer from that conversation, in which case the excerpt you report is stored as described in Section 1.8.
We may disclose your information only if required by applicable Lebanese law, a court order, or a lawful governmental authority request. Even then, we can only ever disclose what we actually hold in readable form — your notes, folders, saved references, contracts, and stored files are end-to-end encrypted, so for those we could produce nothing but ciphertext we are unable to decrypt.
We keep your account information, your encrypted User Content, and your AI conversation history for as long as your account remains active. More specifically:
Deleting your account. You can delete your account from inside the App, by contacting us, or by following the steps at adlapp.org/delete-account. Doing so deletes your account and everything attached to it from our live systems — your encrypted content, the stored files in your folders and the objects holding them, your AI conversations, your reports, your purchase records, and any linked Google or Apple sign-in. Where you used Sign in with Apple, we also tell Apple to sever the link between your Apple ID and ADL. Residual copies may remain in our providers' encrypted infrastructure backups for a short period before they are overwritten, and we may keep a minimal record where the law requires us to. Deletion is permanent and cannot be undone.
Under applicable Lebanese law, including provisions of Law No. 81 of October 10, 2018 on Electronic Transactions and Personal Data, you have the right to:
To exercise any of these rights, contact us using the information in Section 10. We do not charge for this and we do not treat you differently for asking.
If you are outside Lebanon. Where the law of your own country gives you further rights — for example under the GDPR in the European Economic Area or the United Kingdom, or under California privacy law — we honour those requests through the same contact point, including data portability and objection to processing. We do not sell or share personal information as those terms are defined under California law, and we have no advertising or profiling activity to opt out of.
Where your data is processed. ADL is operated from Lebanon, but our hosting, storage, email, subscription, and AI providers are international, so your information may be processed on servers outside Lebanon, including in the United States and the European Union. We use providers that are contractually bound to protect it on terms at least equivalent to those described in this Policy. Your notes, folders, files, saved references, and contracts travel and rest as ciphertext wherever they go.
One practical note on the right of access: because your notes, folders, files, saved references, and contracts are end-to-end encrypted, we hold no readable copy of them. Your own devices are the only place that content can be read, and the App itself is how you access and export it. A request to us can therefore cover your account information and AI conversation history, but for encrypted content we can only confirm what we store and supply it in its encrypted form. Your right to delete is unaffected — deletion removes the stored ciphertext entirely.
The App is intended for users 18 years of age or older and is not directed at minors. We do not knowingly collect personal information from anyone under 18. If we learn that we have inadvertently received such information, we will promptly delete it. If you believe a minor has provided us with personal data, please contact us immediately.
We may update this Privacy Policy periodically. Changes take effect upon posting to adlapp.org/privacy-policy with an updated "Last Updated" date. Continued use of the App after changes are posted constitutes your acceptance of the updated Policy.
For questions, concerns, or requests regarding this Privacy Policy:
Elie Abou Zeidan
Email: contact@adlapp.org
Website: adlapp.org
Privacy Policy: adlapp.org/privacy-policy
نحن لا نجمع بيانات عنك في الخلفية. وكل ما هو موصوف أدناه معلومات تُدخلها أنت بنفسك، أو محتوى تختار حفظه، ليتمكّن التطبيق من العمل. ولا يُستخدم أيّ منها لأغراض تحليلات داخلية أو تتبّع أو تنميط من أي نوع.
يمكنك إنشاء حسابك، أو تسجيل الدخول إليه، باستخدام تسجيل الدخول عبر Google أو تسجيل الدخول عبر Apple بدلاً من تلقّي رمز لمرة واحدة بالبريد الإلكتروني. وإذا اخترت ذلك:
يُخزَّن هذا المحتوى ليُزامَن بأمان بين أجهزتك. وهو ملك لك، وهو مشفَّر من طرف إلى طرف: يُشفَّر على جهازك بمفتاح تملكه وحدك، ولا يصل إلى خوادمنا إلا كنصّ مشفَّر غير قابل للقراءة. ولا يمكننا قراءته أو البحث فيه أو تحليله أو إفشاؤه — لا لأغراض الدعم، ولا لتحسين المنتج، ولا استجابةً لطلب من أي جهة. وتحديداً، تُشفَّر العناصر التالية قبل مغادرة جهازك:
وهذه القائمة مقصودة. فالقوانين والأحكام التي يبحث فيها محامٍ معروف بالاسم، وتحت أي قضية، هي بالضبط الصلة التي وُجد التشفير من طرف إلى طرف لإخفائها — لذلك يُشفَّر المرجع نفسه، لا الملف الموجود بجانبه فحسب.
وتجد التفاصيل التقنية في القسم 3.2، بما في ذلك المعلومات المحدودة التي تبقى بالضرورة غير مشفَّرة كي تعمل المزامنة أصلاً.
المجلد في «عدل» مصمَّم ليعمل كملف قضية، فيمكنك إرفاق مستندات به: ملف PDF أو مستند Word أو صورة — تختارها من ملفاتك أو من مكتبة صورك أو تلتقطها بكاميرتك. وفي الاشتراكات المدفوعة تُخزَّن هذه الملفات لتصل إلى أجهزتك الأخرى وتبقى محفوظة إذا فقدت هاتفك.
يُشفَّر الملف على جهازك قبل رفعه. يشفّر جهازك محتوى الملف واسمه الأصلي ونوعه، ثم يرفع ذلك النصّ المشفَّر مباشرةً إلى مزوّد التخزين لدينا. وما يوجد على أنظمتنا كتلة بايتات مبهمة. لا يمكننا فتحها أو معاينتها أو فهرستها أو فحصها أو تحويلها، ولا يستطيع ذلك مزوّد التخزين أيضاً.
ولأن الملف المخزَّن يجب أن يُحسب على أي حال، يبقى ظاهراً لنا قدر ضئيل من المعلومات غير المتعلّقة بالمحتوى، موصوف في القسم 3.2: حجمه، وبصمة تحقّق محسوبة على البايتات المشفَّرة، وفي أي من مجلداتك يقع، ومتى أُضيف. لا اسمه، ولا نوعه، ولا بايت واحد ممّا في داخله.
ولا تُقرأ كاميرتك ومكتبة صورك إلا في اللحظة التي تختار فيها إضافة شيء، ولا تُقرأ أبداً في الخلفية؛ راجع القسمين 4.4 و4.5.
وتُجرَّد الصور من بياناتها الوصفية المخفية أولاً. فالصورة تحمل عادةً سجلاً غير مرئي تكتبه الكاميرا: التاريخ والوقت، والجهاز، و— حيث تسجّلها الكاميرا — الإحداثيات الجغرافية للمكان الذي التُقطت فيه. ولولا ذلك، لكان تصوير مستند في منزل موكّل يضمّن ذلك العنوان في الملف.
ويزيل «عدل» ذلك السجلّ على جهازك، قبل تشفير الصورة وقبل رفع أي شيء. ويُحذف حذفاً تاماً لا إخفاءً: فالبايتات ليست موجودة في الملف المخزَّن إطلاقاً. أما الصورة نفسها فلا يمسّها هذا الإجراء: تُنسخ بيانات الصورة بايتاً بايتاً، ولا يُستبعد سوى السجلات الوصفية المحيطة بها. وينطبق ذلك على كل صورة، مهما كانت طريقة إضافتها: مصوَّرة داخل التطبيق، أو مختارة من مكتبة صورك، أو منتقاة من ملفاتك.
وهو يحميك لاحقاً أيضاً. فلأن البيانات الوصفية اختفت من الملف المخزَّن، فإن ملفاً تشاركه لاحقاً من التطبيق مع زميل أو مع محكمة لا يحمل معه أي موقع أو تاريخ جهاز.
وإذا تعذّر تنظيف صورة، فلا تُرفع ويُعلمك التطبيق بذلك. فنحن نفضّل رفض ملف على تخزين ملف يحمل بيانات قلنا إننا أزلناها. ولهذا السبب يقبل «عدل» ملفات PDF وWord وJPEG وPNG وWebP: أما صور TIFF فغير مقبولة، لأن بيانات الموقع في تلك الصيغة لا يمكن إزالتها من دون إعادة بناء الصورة نفسها.
ولا تُرسَل ملفاتك أبداً إلى المساعد الذكي ولا إلى أي مزوّد ذكاء اصطناعي. وهذه ليست سياسة يمكننا التراخي فيها بهدوء: فالملفات نصّ مشفَّر، ولا يوجد ما يمكن لخدمة ذكاء اصطناعي قراءته حتى لو تلقّته.
ما يلي موجود على جهازك فقط. ولا يُجمع ولا يُرسَل إلينا ولا يُخزَّن على خوادمنا:
أما الاجتهاد القضائي فيعمل بطريقة مختلفة، ونريد أن نكون دقيقين بشأنه. مجموعة الأحكام القضائية تُقدَّم من خوادمنا، ليقرأ كل المستخدمين النصّ نفسه محدَّثاً وتصل التصحيحات إلى الجميع دفعة واحدة. ولذلك فإن تصفّح الأحكام أو البحث فيها يرسل طلبك — بما في ذلك الكلمات التي تبحث عنها — إلى خوادمنا. ونستخدم تلك الطلبات لأمر واحد: إعادة النتائج إليك. ولا نربطها بأي ملفّ تعريفي، ولا نستخدمها لأي تحليلات أو إعلانات أو تقييم لك.
رموز الوصول ورموز التجديد المستخدَمة لإبقائك مسجّل الدخول بأمان. وتُخزَّن حصراً في التخزين الآمن لجهازك — iOS Keychain على أجهزة Apple، وAndroid Keystore على أجهزة Android — ولا يمكن لأي تطبيق آخر الوصول إليها.
وخلافاً لملاحظاتك ومجلداتك وملفاتك وعقودك، فإن محادثات الذكاء الاصطناعي ليست مشفَّرة من طرف إلى طرف. ولا يمكن أن تكون كذلك: إذ يجب أن يقرأ المساعد سؤالك على خوادمنا كي يجيب عنه ويبحث في القوانين والأحكام اللبنانية ذات الصلة. وهي محميّة بدلاً من ذلك بالتشفير أثناء النقل وفي حالة السكون (القسم 3.4).
ويُستخدم سجل محادثاتك المخزَّن لغرض واحد فقط: تشغيل المساعد الذكي وتحسينه من أجلك. وعملياً، يعني ذلك تمكينك من إعادة فتح محادثاتك السابقة عبر أجهزتك، ومنح المساعد سياق المحادثة الجارية لتأتي إجاباته متّسقة، وتحسين جودة إجابات التطبيق ودقّتها وإحالاتها. ولا يُستخدم للإعلان أو التنميط أو التسويق أو التحليلات، ولا يُباع أو يُشارَك أبداً لأغراض أي جهة أخرى، ولا يستخدمه مزوّد الذكاء الاصطناعي لتدريب نماذجه (راجع القسم 5).
وتُعالَج الرسائل التي ترسلها إلى المساعد الذكي من قِبل خدمة ذكاء اصطناعي تعمل لحسابنا، ومن قِبل مزوّد النماذج التابع لتلك الخدمة، حصراً لتوليد إجابتك — وكلاهما مذكور بالاسم في القسم 5. ومحادثاتك خاصة بحسابك، ولا يراها أي مستخدم آخر، وتُحذف نهائياً عند حذف حسابك.
يتيح لك التطبيق الإبلاغ عن إجابة تجدها مسيئة أو غير دقيقة أو ضارّة — وهي قناة تشترط متاجر التطبيقات علينا توفيرها. والإبلاغ اختياري تماماً ولا يُرسَل شيء ما لم تضغط «إبلاغ». وعند إرسالك بلاغاً، نخزّن السبب الذي اخترته، وأي تفاصيل تختار كتابتها، ومقتطفاً من الإجابة المبلَّغ عنها (يُحفظ ليبقى البلاغ قائماً حتى لو حذفت تلك المحادثة لاحقاً)، ومرجع حسابك، و— حيث تكون الإجابة من محادثة محفوظة — إشارة إليها. وتُرسَل نسخة إلى بريد الدعم لدينا. ونستخدم البلاغات لغرض واحد: مراجعة سلوك المساعد الذكي وتصحيحه.
تُشترى الاشتراكات وحزم النقاط الإضافية عبر Apple App Store أو Google Play وتُدفع لهما. ونحن لا نرى بيانات بطاقتك المصرفية ولا نخزّنها إطلاقاً. ومن خلال مزوّد إدارة الاشتراكات لدينا (راجع القسم 5) نتلقّى ونخزّن اشتراكك الحالي وتاريخ انتهائه، وفي حال حزمة نقاط: معرّف العملية لدى المتجر، وأي حزمة اشتريت، وكم نقطة مُنحت — وهو السجلّ الذي يتيح لنا تطبيق كل عملية شراء على حسابك مرة واحدة تماماً لا مرتين.
تحتفظ خوادمنا ومزوّد الاستضافة لدينا بسجلات تقنية قصيرة العمر للطلبات الواردة إلى الخدمة — عنوان IP الذي جاء منه الطلب، والوقت، وأي جزء من الخدمة استُدعي. وتوجد هذه السجلات لإبقاء الخدمة تعمل، ولتطبيق حدود المعدّل، وللتحقيق في إساءة الاستخدام أو الهجمات. وهي غير مرتبطة بمحتواك ولا تُستخدم لبناء أي ملفّ تعريفي عنك. كما نسجّل أي جهاز يحمل حالياً الجلسة النشطة لحسابك، بحيث يؤدي تسجيل الدخول على جهاز جديد إلى إخراج الجهاز السابق.
نستخدم معلوماتك من أجل:
ونحن لا نستخدم بياناتك للإعلان أو التنميط أو التسويق. ولا نبيع بياناتك أو نؤجّرها لأي طرف ثالث. ولا تُستخدم معلوماتك أبداً لأغراض شخصية لأي أحد — بل تُستخدم حصراً لتشغيل التطبيق وتحسين تجربتك.
المعلومات التي تأتمن التطبيق عليها تُحفظ بأمان ومشفَّرة — على جهازك، وأثناء النقل، وعلى خوادمنا. أما ملاحظاتك ومجلداتك وملفاتك ومراجعك المحفوظة وعقودك فتذهب أبعد من ذلك: فهي مشفَّرة من طرف إلى طرف، أي أننا لا نحوز سوى نصّ مشفَّر لا نملك أي قدرة على فكّه.
تُخزَّن بياناتك محلياً في قاعدة بيانات محميّة بعزل التطبيقات في نظام تشغيلك، وهو ما يمنع التطبيقات الأخرى من الوصول إليها. وتُخزَّن رموز المصادقة ومفتاح تشفيرك في التخزين الآمن المدعوم بالعتاد في جهازك (iOS Keychain / Android Keystore). ومحتواك قابل للقراءة على جهازك أنت — وهذا ما يتيح العمل دون اتصال والبحث الفوري — ويُشفَّر لحظة إرساله إلينا.
وتُعامَل الملفات بعناية أكبر من غيرها. فالملف الذي فتحته يُحفظ على جهازك بصيغته المشفَّرة، ليبقى متاحاً من دون أي شبكة. ولا تُكتب نسخة قابلة للقراءة إلا عندما يحتاج شيء ما إلى عرضه — عارض PDF أو قائمة المشاركة — وتُحذف تلك النسخة عند تسجيل الخروج ومرة أخرى في كل مرة يبدأ فيها التطبيق من جديد. وبذلك لا تتراكم مستندات القضايا المفكوك تشفيرها على جهازك.
وتسجيل الخروج يمحو محتواك المحلي ومفتاح تشفيرك وكل نسخة ملف قابلة للقراءة من الجهاز.
تُشفَّر ملاحظاتك ومجلداتك وملفاتك ومراجعك المحفوظة وعقودك على جهازك قبل رفعها، ولا يُفكّ تشفيرها إلا على أجهزتك أنت. وبعبارة بسيطة:
ولأن المزامنة يجب أن تعرف أي سجلّ يذهب إلى أين، يبقى بالضرورة قدر ضئيل من المعلومات غير المتعلّقة بالمحتوى غير مشفَّر على خوادمنا: معرّفات السجلات، وطوابع الإنشاء والتحديث الزمنية، وإلى أي مجلد تنتمي ملاحظة أو ملف، وما إذا كانت الملاحظة مثبَّتة، وأي نموذج أُنشئ منه العقد. وللملف المخزَّن نحوز إضافةً إلى ذلك حجمه بالبايت وبصمة تحقّق — محسوبة عمداً على البايتات المشفَّرة، حتى لا يمكن استخدامها لاختبار ما إذا كنت تحوز مستنداً معروفاً بعينه. أما الكلمات التي تكتبها فعلاً، والملفات التي تخزّنها، والقوانين والأحكام التي تحفظها، فليست ضمن ذلك أبداً.
وعملياً، فإن ما تستطيع خوادمنا رؤيته بشأن ملف قضية هو أن حساباً يملك بعض المجلدات، وأن تلك المجلدات تحتوي بعض الملاحظات وبعض المراجع وبعض الملفات بحجم معيّن، ومتى تغيّر كل منها آخر مرة. أما ما هي القضية، وما بداخلها، وما الذي خلصت إليه بشأنها، فلا تستطيع رؤيته إطلاقاً.
تُخزَّن معلومات حسابك، ومحتواك (الملاحظات والمجلدات والمراجع المحفوظة والعقود — مخزَّنة كنصّ مشفَّر كما وُصف أعلاه)، وسجل محادثاتك مع الذكاء الاصطناعي، على خوادمنا الخلفية المستضافة على Railway. أما الملفات التي تضيفها إلى مجلداتك فتُخزَّن ككائنات مشفَّرة على Cloudflare R2. وتنتقل كل الاتصالات بين التطبيق وخوادمنا حصراً عبر وصلات HTTPS (TLS) مشفَّرة، والبيانات على خوادمنا مشفَّرة في حالة السكون بواسطة بنيتنا التحتية للاستضافة — وهي طبقة ثانية تحت التشفير من طرف إلى طرف الذي تملك مفتاحه أنت.
وتنتقل الملفات بين جهازك والتخزين عبر روابط موقَّعة قصيرة العمر وأحادية الغرض نُصدرها لجهازك وتنتهي صلاحيتها خلال دقائق. ولا يمكن تخمينها أو سردها أو مشاركتها، وحاوية التخزين ليست قابلة للقراءة العلنية بأي طريق.
ونطبّق هذه الضمانات لتبقى معلوماتك آمنة في كل خطوة. وكما هي الحال في أي خدمة عبر الإنترنت، لا يمكن ضمان أي وسيلة نقل أو تخزين ضماناً مطلقاً، ولهذا نضاعف طبقات الحماية ونبقيها محدَّثة.
يطلب التطبيق إذن الوصول إلى تقويم جهازك حصراً لكتابة تذكيرات الملاحظات التي تنشئها أنت صراحةً داخل التطبيق. ولا نقرأ أو ننسخ أو نجمع أو نخزّن أياً من مواعيد تقويمك القائمة. ويمكنك تعطيل هذا الإذن من إعدادات جهازك في أي وقت؛ وسيمنع ذلك التطبيق من إضافة التذكيرات إلى تقويمك.
يطلب التطبيق إذناً بإرسال إشعارات إليك بشأن التذكيرات التي تضبطها. ويمكنك إدارة ذلك من إعدادات جهازك. وتعطيل الإشعارات سيمنع تنبيهات التذكيرات من الوصول إليك.
تُظهر خريطة المواقع القانونية أماكن عامة: المحاكم والوزارات والمكاتب القانونية. وعلى iPhone وiPad، يمكنها أيضاً إظهار موقعك أنت على تلك الخريطة، لترى أين تقع بالنسبة إليها. ويطلب جهازك إذنك في أول مرة تفتح فيها الخريطة، ويمكنك الرفض أو السحب في أي وقت من إعدادات جهازك — والخريطة تعمل بالكامل من دون ذلك.
ويُستخدم موقعك لهذا الغرض وحده لا غير. وهو لا يصل إلينا أبداً. فلا يُرسَل إلى خوادمنا، ولا نخزّنه، ولا يُربط بحسابك، ولا يُستخدم لتحديد المحتوى أو الأسعار التي تراها، ولا يُستخدم لأي تحليلات أو إعلانات أو تنميط أو سجلّ مواقع. وعلى Android هذا العرض غير مفعَّل ولا يطلب التطبيق أي إذن موقع إطلاقاً.
ولنكن دقيقين في أمر واحد: الخريطة نفسها ترسمها خدمة خرائط Google (القسم 5). وعرض خريطة يعني أن Google تتلقّى ما تحتاجه لرسمها — المنطقة التي تنظر إليها وعنوان جهازك على الشبكة — وأثناء إظهار النقطة الزرقاء، يتولّى ذلك مكوّن الخرائط من Google على جهازك. وهذا تصرّف من Google بموجب سياسة خصوصيتها هي، لا جمعاً منّا لموقعك. وإذا فضّلت عدم إشراكها، فارفض إذن الموقع: تبقى الخريطة تعمل ولا تُظهر ببساطة أين أنت.
يمكن للتطبيق استخدام كاميرتك لغرض واحد: تصوير مستند لتضيفه إلى ملف قضية. ويطلب جهازك إذنك في أول مرة تستخدمها، ويمكنك الرفض أو السحب في أي وقت من إعدادات جهازك — وكل جزء آخر من التطبيق يعمل من دونها. ولا تُفتح الكاميرا إلا عند ضغطك لالتقاط صورة، ولا تُفتح أبداً في الخلفية، ولا يُلتقط أو يُرسَل أي شيء ما لم تحتفظ بالصورة. وتُزال البيانات الوصفية المخفية من الصورة — بما فيها موقع التقاطها — على جهازك، ثم تُشفَّر قبل رفعها، فلا نرى الصورة ولا أي شيء جاء معها (القسم 1.4).
يمكن للتطبيق قراءة صورة من مكتبة صورك لتضيفها إلى ملف قضية. ولا نتلقّى سوى الصورة التي تختارها. ولا يتصفّح التطبيق مكتبة صورك ولا يفهرسها ولا يفحصها ولا يرفعها، ولا يمكنه رؤية أي صورة أخرى فيها، ولا يقرأها أبداً في الخلفية. وعلى iPhone وiPad يمكنك منح الوصول إلى صور مختارة فقط، ويعمل التطبيق بشكل طبيعي بهذه الطريقة. وكما هي الحال مع الكاميرا، تُجرَّد الصورة من بياناتها الوصفية المخفية على جهازك وتُشفَّر قبل الرفع، فلا نراها أبداً.
ولا يطلب التطبيق الوصول إلى الميكروفون ولا إلى جهات اتصالك.
نحن لا نبيع معلوماتك الشخصية ولا نؤجّرها ولا نتاجر بها، ولا نشاركها أبداً لأغراض أي جهة أخرى. ومزوّدو الخدمات المذكورون أدناه يعالجونها لحسابنا فقط، ولتشغيل التطبيق فقط، وبموجب تعليماتنا فقط.
ولتشغيل التطبيق، نعتمد على عدد محدود من مزوّدي الخدمات الذين يعالجون البيانات حصراً لحسابنا وبموجب تعليماتنا، عبر اتصالات مشفَّرة:
عندما تسأل المساعد الذكي عن عقد. عقودك مشفَّرة من طرف إلى طرف، فلا يمكننا قراءتها. وإذا فتحت عقداً وسألت المساعد الذكي عنه، يفكّ جهازك تشفير ذلك العقد ويرسل نصّه إلى خدمة الذكاء الاصطناعي لذلك الطلب وحده، ليتمكّن المساعد من الإجابة. وتلك المحادثة مسوّدة عابرة: لا تُحفظ على خوادمنا وتختفي عند إغلاقها. ويُستخدم نصّ العقد فقط لإنتاج إجابتك ولا نحتفظ به نحن ولا خدمة الذكاء الاصطناعي بعد ذلك. ولا يحدث هذا إلا لعقد تسأل عنه أنت عمداً، وفقط أثناء سؤالك — لا في الخلفية أبداً، ولا لملاحظاتك أو مجلداتك. والاستثناء الوحيد هو اختيارك الإبلاغ عن إجابة من تلك المحادثة، وعندها يُخزَّن المقتطف الذي تبلّغ عنه كما هو موصوف في القسم 1.8.
ولا يجوز لنا إفشاء معلوماتك إلا إذا اقتضى ذلك القانون اللبناني الساري أو قرار قضائي أو طلب مشروع من سلطة حكومية. وحتى عندها، لا يمكننا أن نفشي إلا ما نحوزه فعلاً بصيغة مقروءة — أما ملاحظاتك ومجلداتك ومراجعك المحفوظة وعقودك وملفاتك المخزَّنة فمشفَّرة من طرف إلى طرف، ولا يمكننا بشأنها أن نقدّم سوى نصّ مشفَّر نعجز عن فكّه.
نحتفظ بمعلومات حسابك ومحتواك المشفَّر وسجل محادثاتك مع الذكاء الاصطناعي ما دام حسابك نشطاً. وبمزيد من التحديد:
حذف حسابك. يمكنك حذف حسابك من داخل التطبيق، أو بمراسلتنا، أو باتّباع الخطوات على adlapp.org/delete-account. ويؤدي ذلك إلى حذف حسابك وكل ما يتصل به من أنظمتنا الحيّة — محتواك المشفَّر، والملفات المخزَّنة في مجلداتك والكائنات التي تحويها، ومحادثاتك مع الذكاء الاصطناعي، وبلاغاتك، وسجلات مشترياتك، وأي ارتباط بتسجيل دخول Google أو Apple. وحيث استخدمت تسجيل الدخول عبر Apple، نطلب من Apple أيضاً فصل الارتباط بين Apple ID الخاص بك وبين «عدل». وقد تبقى نسخ متبقّية في النسخ الاحتياطية المشفَّرة لدى مزوّدي بنيتنا التحتية لفترة قصيرة قبل أن يُعاد استبدالها، وقد نحتفظ بحدّ أدنى من السجلات حيث يفرض القانون ذلك علينا. والحذف نهائي ولا يمكن التراجع عنه.
بموجب القانون اللبناني الساري، بما في ذلك أحكام القانون رقم 81 تاريخ 10 تشرين الأول/أكتوبر 2018 المتعلق بالمعاملات الإلكترونية والبيانات ذات الطابع الشخصي، يحقّ لك:
ولممارسة أي من هذه الحقوق، تواصل معنا عبر المعلومات الواردة في القسم 10. ولا نتقاضى مقابلاً لذلك ولا نعاملك بشكل مختلف لأنك طلبته.
إذا كنت خارج لبنان. حيث يمنحك قانون بلدك حقوقاً إضافية — كما في النظام الأوروبي العام لحماية البيانات (GDPR) في المنطقة الاقتصادية الأوروبية والمملكة المتحدة، أو بموجب قانون الخصوصية في كاليفورنيا — فإننا نستجيب لتلك الطلبات عبر جهة التواصل نفسها، بما في ذلك قابلية نقل البيانات والاعتراض على المعالجة. ونحن لا نبيع المعلومات الشخصية ولا نشاركها بالمعنى المحدَّد لهذين المصطلحين في قانون كاليفورنيا، وليس لدينا أي نشاط إعلاني أو تنميطي يمكن الانسحاب منه.
أين تُعالَج بياناتك. يُدار «عدل» من لبنان، لكن مزوّدي الاستضافة والتخزين والبريد والاشتراكات والذكاء الاصطناعي لدينا دوليون، لذلك قد تُعالَج معلوماتك على خوادم خارج لبنان، بما في ذلك في الولايات المتحدة والاتحاد الأوروبي. ونستخدم مزوّدين ملزَمين تعاقدياً بحمايتها بشروط لا تقلّ عن تلك الموصوفة في هذه السياسة. وتنتقل ملاحظاتك ومجلداتك وملفاتك ومراجعك المحفوظة وعقودك وتستقرّ كنصّ مشفَّر أينما ذهبت.
وملاحظة عملية بشأن حق الاطّلاع: لأن ملاحظاتك ومجلداتك وملفاتك ومراجعك المحفوظة وعقودك مشفَّرة من طرف إلى طرف، فنحن لا نحوز أي نسخة مقروءة منها. وأجهزتك أنت هي المكان الوحيد الذي يمكن قراءة ذلك المحتوى فيه، والتطبيق نفسه هو وسيلتك للوصول إليه وتصديره. ولذلك يمكن أن يشمل الطلب المقدَّم إلينا معلومات حسابك وسجل محادثاتك مع الذكاء الاصطناعي، أما المحتوى المشفَّر فلا يمكننا سوى تأكيد ما نخزّنه وتقديمه بصيغته المشفَّرة. ولا يتأثّر حقّك في الحذف — فالحذف يزيل النصّ المشفَّر المخزَّن بالكامل.
التطبيق مخصّص للمستخدمين الذين تبلغ أعمارهم 18 عاماً فأكثر وهو غير موجَّه إلى القاصرين. ولا نجمع عن علم معلومات شخصية من أي شخص دون الثامنة عشرة. وإذا علمنا أننا تلقّينا مثل هذه المعلومات سهواً، فسنحذفها فوراً. وإذا كنت تعتقد أن قاصراً قدّم لنا بيانات شخصية، فيُرجى التواصل معنا فوراً.
قد نحدّث سياسة الخصوصية هذه دورياً. وتسري التعديلات فور نشرها على adlapp.org/privacy-policy مع تحديث تاريخ «آخر تحديث». ويشكّل استمرارك في استخدام التطبيق بعد نشر التعديلات قبولاً منك للسياسة المحدَّثة.
للأسئلة أو الملاحظات أو الطلبات المتعلقة بسياسة الخصوصية هذه:
إيلي أبو زيدان
البريد الإلكتروني: contact@adlapp.org
الموقع: adlapp.org
سياسة الخصوصية: adlapp.org/privacy-policy