Before I Leave · قبل ما أطلع

سياسة الخصوصية — قبل ما أطلع

تاريخ النفاذ: 2026-09-28

آخر تحديث: 2026-09-28

التطبيق: «قبل ما أطلع» (Before I Leave) — المعرّف التقني com.paymentery.beforeileave

المطوّر: paymentery.com

للتواصل: [email protected]

ملاحظة: هذه ترجمة كاملة للنسخة الإنجليزية المنشورة في هذه الصفحة. في حال وجود أي تعارض في التفسير، يُرجى مراجعة [email protected].

الصلاحيات باختصار

الصلاحيةلماذامتى تُطلبإذا رفضت
الإشعاراتالتذكير الاختياري الواحد لكل جلسة (البند ٩).فقط بعد أن تختار تفعيل تذكير (أو في صفحة التذكيرات الاختيارية ضمن التعريف الأول) — وليس أبدًا عند أول فتح للتطبيق.كل شيء آخر يعمل؛ فقط لن تصلك تذكيرات.
الكاميرا«صوّر» المكان الذي وضعت فيه الغرض (البند ٦).على iPhone: أول مرة تضغط «صوّر». على Android: يُسلّم التطبيق المهمة لتطبيق الكاميرا في هاتفك ولا يملك صلاحية الكاميرا.يُحفظ الغرض بدون صورة.
الصور«اختر صورة» عبر منتقي الصور الخاص بالنظام (البند ٦).لا تُطلب أبدًا — منتقي النظام يعطي التطبيق الصورة التي تختارها فقط، بدون وصول إلى معرض الصور.—
Face ID / البصمةقفل التطبيق الاختياري (البند ٨).فقط إذا فعّلت قفل التطبيق بالبصمة؛ النظام يتحقق منك ويخبر التطبيق بنعم أو لا فقط.رمز PIN الخاص بالتطبيق يبقى يعمل.

لا يطلب التطبيق أبدًا صلاحية الموقع أو جهات الاتصال أو التقويم أو الميكروفون أو التتبّع، ولا يملك على Android صلاحية الإنترنت.

١. باختصار

يساعدك «قبل ما أطلع» على تسجيل الأشياء التي وزّعتها في مكان مؤقت — غرفة فندق، عيادة، سيارة مستأجرة، مكتب مؤقت — ثم يتأكد من أنك أخذتها كلها معك قبل أن تغادر.

نحن لا نجمع بياناتك. ولا أي جزء منها.

لا يوجد حساب، ولا تسجيل دخول، ولا سيرفر، ولا أي أدوات تحليل. كل ما تكتبه في «قبل ما أطلع» يُحفظ في قاعدة بيانات مشفّرة على هاتفك أنت، ويبقى فيه. والتطبيق يعمل بالكامل والشبكة مغلقة — يمكنك استخدامه في وضع الطيران من البداية إلى النهاية.

نحن، المطوّر، لا نستلم معلوماتك أبدًا، لأنه لا يوجد أي مكان تُرسل إليه.

٢. نطاق هذه السياسة

تنطبق هذه السياسة على تطبيق «قبل ما أطلع» لأجهزة iPhone وAndroid. ولا تنطبق على الخدمات المنفصلة التي قد تختار استخدامها معه — فمثلًا، إذا حفظت ملف نسخة احتياطية في iCloud Drive أو Google Drive، فإن ذلك الملف يصبح خاضعًا لسياسة خصوصية Apple أو Google إلى جانب هذه السياسة. انظر البند ٧.

٣. ما المعلومات التي يتعامل معها التطبيق

أنت من يكتب هذه المعلومات بنفسك، وهي تبقى على جهازك:

ماذامثالأين تُحفظ
اسم الجلسة ونوعها«فندق هيلتون، غرفة ٤٠٢»، «سيارة مستأجرة»على جهازك
أسماء الأغراض«الجواز»، «شاحن الجوال»، «دواء الطفل»على جهازك
المكان الذي تسجّله لكل غرض«في الخزنة»، «جنب السرير»، «في الثلاجة»على جهازك
ملاحظات اختيارية على الغرض«اطلب النسخة الإضافية من الاستقبال»على جهازك
صورة اختيارية للغرضصورة للمكان الذي تركت فيه شيئًاعلى جهازك
وقت التذكير، إن ضبطته«ذكّرني الساعة ١١:٠٠»على جهازك
حالة كل غرضاستُرجع / ما زال في مكانه / تُرك عن قصدعلى جهازك
سجل جلساتك السابقةالجلسات المكتملة والجلسات التي أنهيتها مبكرًاعلى جهازك
القوالب التي تحفظها«سفر العائلة»على جهازك
إعدادات التطبيقاللغة، وهل قفل التطبيق مفعّل، وتاريخ آخر نسخة احتياطيةعلى جهازك

ولا نطلب منك، ولا يوجد في التطبيق حقل لإدخال: اسمك الحقيقي، أو بريدك الإلكتروني، أو رقم جوالك، أو تاريخ ميلادك، أو اسم مستخدم، أو كلمة مرور خاصة بنا، أو وسيلة دفع، أو أي رقم هوية رسمي أو بيانات صحية.

انتبه إلى أنك حرّ في كتابة ما تشاء في الحقول النصية المفتوحة. وإذا اخترت كتابة معلومات حسّاسة في اسم غرض أو في ملاحظة، فإن ذلك النص يُحفظ على جهازك بنفس الحماية المطبّقة على كل شيء آخر — لكن التطبيق لا يستطيع أن يمنعك من تدوين شيء قد تفضّل عدم تدوينه. استخدم تقديرك، تمامًا كما تفعل مع ورقة ملاحظات.

٤. ما لا يفعله التطبيق

لنكون محدّدين لا عامّين:

  • لا حساب ولا تسجيل دخول. لا يوجد ما تسجّل فيه، ولا كلمة مرور تنشئها عندنا.
  • لا سيرفر لنا. التطبيق بلا واجهة خلفية. ولا توجد قاعدة بيانات نديرها تحتوي أغراضك.
  • لا أدوات تحليل. لا Firebase Analytics، ولا Google Analytics، ولا Meta SDK، ولا Mixpanel، ولا Amplitude، ولا أي أداة تحليل استخدام من أي نوع.
  • لا إعلانات. لا حزمة إعلانات، ولا شبكة إعلانية، ولا معرّف إعلاني (لا IDFA على iOS، ولا Advertising ID على Android)، ولا إعلانات داخل التطبيق.
  • لا تتبّع. لا نتتبّعك بين التطبيقات والمواقع، ولا نبني ملفًا تعريفيًا عنك، ولا نربط نشاطك بأي شيء آخر. ولا نشارك أي شيء مع وسطاء البيانات، لأنه لا يوجد عندنا ما نشاركه.
  • لا خدمة لتقارير الأخطاء أو الانهيار. لا Crashlytics، ولا Sentry، ولا Bugsnag. وإذا تعطّل التطبيق فلن نعلم بذلك، ولن يخرج أي تقرير من هاتفك.
  • لا موقع جغرافي. التطبيق لا يطلب صلاحية الموقع أو GPS إطلاقًا، ولا يسجّل مكانك. وعندما تكتب «في الخزنة»، فهذه كلمة كتبتها أنت، وليست موقعًا قِسناه نحن.
  • لا جهات اتصال، ولا تقويم، ولا ميكروفون، ولا تصفّح لمعرض الصور، ولا بيانات صحية، ولا سجلات مكالمات أو رسائل. والكاميرا لا تُستخدم إلا عندما تضغط «التقاط صورة» (البند ٦).
  • لا تتبّع في الخلفية ولا أي نشاط شبكي في الخلفية.
  • لا بيع للبيانات. لا توجد عندنا بيانات لنبيعها. وبموجب قانون خصوصية المستهلك في كاليفورنيا (CCPA) والقوانين المشابهة، فإننا لا نبيع ولا نشارك أي معلومات شخصية.

٥. أين تُحفظ بياناتك، وكيف تُحمى

كل جلساتك وأغراضك وأماكنها وملاحظاتك وأوقات تذكيرك وإعداداتك تُحفظ في ملف قاعدة بيانات واحد داخل مساحة التخزين الخاصة بالتطبيق على جهازك — وهي المساحة التي يخصّصها نظام التشغيل لهذا التطبيق ويمنع التطبيقات الأخرى من الوصول إليها.

وهذه القاعدة مشفّرة أثناء التخزين بمعيار AES-256، باستخدام نظام التشفير SQLCipher 4 (عبر مكتبة SQLite3MultipleCiphers مفتوحة المصدر). والمفتاح الذي يفتحها مفتاح عشوائي بطول 256 بت يُنشأ على هاتفك عند أول تشغيل للتطبيق. وهو ليس مكتوبًا داخل كود التطبيق ولا محفوظًا في القاعدة نفسها، بل يحتفظ به مخزن المفاتيح الآمن الخاص بنظام التشغيل: iOS Keychain على iPhone (كعنصر «لهذا الجهاز فقط» لا يُزامَن ولا ينتقل إلى جهاز آخر)، ومخزن محمي بـAndroid Keystore على Android. وإذا فُقد هذا المفتاح أو تعذّرت قراءته، فالتطبيق لا ينشئ قاعدة بيانات جديدة غير مشفّرة فوق بياناتك، بل يعرض شاشة استرداد.

أما الصور التي ترفقها (البند ٦) فتُحفظ كملفات صور منفصلة في مساحة التطبيق الخاصة نفسها، بجانب قاعدة البيانات لا داخلها. وتحميها عزلة التطبيق في النظام وتشفير التخزين الخاص بهاتفك، لا تشفير قاعدة بيانات التطبيق.

وما تحميه هذه التقنية، بصراحة: التشفير أثناء التخزين يحمي بياناتك إذا وصل أحدهم إلى ملف قاعدة البيانات نفسه — من نسخة احتياطية للجهاز، أو من تحليل جنائي، أو من هاتف مفقود. لكنه ليس حماية ممّن يحمل هاتفك غير المقفل بيده ويفتح التطبيق. ولهذا الغرض، شغّل قفل التطبيق (البند ٨).

النسخة الاحتياطية الخاصة بهاتفك

التطبيق يستثني بياناته من النسخ الاحتياطي التلقائي لهاتفك. فعلى Android، النسخ الاحتياطي للتطبيق ونقل البيانات من جهاز إلى جهاز معطّلان لهذا التطبيق، فلا تُنسخ بياناته إلى النسخة الاحتياطية في حساب Google ولا إلى هاتف جديد. وعلى iPhone، المجلد الذي يحوي قاعدة البيانات والصور مُعلَّم بعبارة «لا تنسخ احتياطيًا»، فلا يُضمَّن في iCloud Backup ولا في النسخ الاحتياطية على الكمبيوتر، ومفتاح قاعدة البيانات عنصر Keychain «لهذا الجهاز فقط» لا ينتقل إلى جهاز آخر أبدًا.

والطريقة الوحيدة لخروج بياناتك من الهاتف هي ملف نسخة احتياطية تنشئه أنت (البند ٧).

٦. الصور الاختيارية

يمكنك إرفاق صورة بأي غرض — مثل صورة للدرج الذي وضعت فيه شيئًا. وهذا اختياري تمامًا، والتطبيق يعمل بكامل وظائفه بدونه.

وهناك طريقتان لإضافتها، ولا تبدأ أيٌّ منهما إلا عندما تضغط عليها:

  • اختيار صورة يفتح منتقي الصور الخاص بنظام التشغيل عندك. وهذا المنتقي يديره النظام، لا نحن. تختار صورة واحدة، وتلك الصورة وحدها هي ما يُسلَّم للتطبيق. والتطبيق لا يحصل، ولا يطلب، صلاحية قراءة معرض صورك، ولا يستطيع أن يستعرض أو يفهرس أو يرى أي صورة أخرى تملكها. (على iPhone يتضمّن التطبيق نصًّا يوضّح سبب الوصول إلى الصور لأن Apple تشترطه للمنتقي، لكن لا تظهر أي نافذة طلب صلاحية.)
  • التقاط صورة يفتح الكاميرا لتصوّر المكان الذي وضعت فيه الشيء. على iPhone يطلب النظام صلاحية الكاميرا أول مرة تضغط فيها على هذا الخيار. وعلى Android يُسلّم التطبيق المهمة لتطبيق الكاميرا في هاتفك، ولا يحمل هو نفسه صلاحية الكاميرا. وإذا رفضت، يُحفظ الغرض ببساطة بدون صورة.

وتُصغَّر الصورة وتُنسخ إلى مساحة التطبيق الخاصة باسم ملف عشوائي مُولَّد (ولا يُحتفظ باسم الملف الأصلي). ولا تُرفع أبدًا، ولا تُرسل، ولا تُشارك معنا ولا مع أي أحد، ولا تُكتب في معرض صورك. وعندما تحذف جلسة تُحذف صورها فورًا؛ وعندما تحذف غرضًا واحدًا يُزال ملف صورته في المرة التالية التي يُفتح فيها التطبيق (حتى يبقى «التراجع» قادرًا على إعادتها). ويُحذف كل شيء عند إزالتك للتطبيق.

٧. النسخ الاحتياطي والاستعادة — وما أنت مسؤول عنه

النسخ الاحتياطي في «قبل ما أطلع» يدوي وتحت سيطرتك بالكامل. لا شيء يُنسخ تلقائيًا، ولا شيء يُنسخ إلينا.

عندما تضغط لإنشاء نسخة احتياطية، يجمع التطبيق بياناتك (الجلسات والأغراض والقوالب وأسماء الأماكن المستخدمة مؤخرًا والصور المرفقة بالأغراض — لا إعداداتك ولا رمز PIN) في ملف مشفّر واحد، ثم يسلّم ذلك الملف إلى نافذة المشاركة/الحفظ القياسية في نظام تشغيلك. وأنت من يقرّر إلى أين يذهب. قد تحفظه في تطبيق «الملفات» على iPhone، أو في iCloud Drive، أو في Google Drive، أو على ذاكرة USB، أو في محادثة مع نفسك — هذا اختيارك، والتطبيق لا يتخذه عنك.

وملف النسخة الاحتياطية لا يمرّ بأي سيرفر لنا إطلاقًا. لا توجد عندنا نسخة منه. ولا نستطيع استرجاعه لك، ولا نستطيع مساعدتك في فتحه.

وهذا يعني أمرين يجب أن تفهمهما:

  1. بمجرد أن تحفظ النسخة في مكان ما، تنطبق قواعد ذلك المكان. إذا وضعتها في iCloud Drive، فهي خاضعة لسياسة خصوصية Apple ولكل من يستطيع الوصول إلى حساب Apple الخاص بك. وإذا وضعتها في Google Drive، فالأمر نفسه ينطبق على Google. وإذا أرسلتها إلى بريدك، فهي تبقى في صندوق بريدك. واختيار مكان الملف — والحفاظ على أمن ذلك المكان — مسؤوليتك أنت، لا مسؤوليتنا.
  2. إذا فقدت الملف، أو فقدت ما يلزم لفك تشفيره، فإن البيانات التي فيه تضيع. فلأننا لا نحتفظ بأي نسخة ولا بأي مفتاح، لا يوجد مسار «نسيت كلمة المرور»، ولا طريقة لنا لاسترجاع نسخة احتياطية. وهذا هو الثمن المباشر لتصميم لا نحتفظ فيه بأي شيء عنك.

كيف يُحمى الملف. كل نسخة احتياطية تتطلب كلمة مرور تختارها أنت (٨ أحرف على الأقل). ويحوّل التطبيق كلمة المرور إلى مفتاح تشفير باستخدام PBKDF2-HMAC-SHA256 (٣١٠٬٠٠٠ تكرار مع «ملح» عشوائي)، ويشفّر المحتوى بـAES-256-GCM، الذي يكشف أيضًا أي عبث بالملف. ولأن المفتاح مأخوذ من كلمة مرورك لا من هاتفك، يمكنك استعادة الملف على هاتف آخر. ونحن لا نرى كلمة المرور ولا نحفظها.

  • إذا نسيت كلمة مرور النسخة، فلا أحد يستطيع فتح ذلك الملف — ولا نحن. ويحذّرك التطبيق من ذلك ويطلب منك تأكيد أنك حفظت كلمة المرور قبل أن ينشئ الملف.
  • يمكنك إضافة تلميح لكلمة المرور اختياري (حتى ٦٠ حرفًا). ويُحفظ التلميح بدون تشفير داخل الملف حتى يُعرض قبل أن تكتب كلمة المرور، أي أن أي شخص يملك الملف يستطيع قراءته. ويرفض التطبيق أي تلميح يحتوي على كلمة المرور نفسها.
  • ويسجّل رأس صغير غير مشفّر أيضًا وقت إنشاء النسخة وإصدار التطبيق، لتعرضهما شاشة الاستعادة. وكل ما عدا ذلك — جلساتك وأغراضك وملاحظاتك وصورك — مشفّر.

والاستعادة تقرأ ملفًا تختاره أنت، وتطلب كلمة مروره، وتتحقق من أنه نسخة احتياطية صحيحة وبإصدار مدعوم، وتفحصه بالكامل في نسخة مؤقتة، ثم تطلب تأكيدك قبل أن تستبدل أي شيء. وبياناتك الحالية لا تتغيّر حتى ينجح كل ذلك، والاستبدال يتم في خطوة واحدة إمّا أن تكتمل أو تترك بياناتك كما كانت تمامًا.

٨. قفل التطبيق، وFace ID وTouch ID ورمز PIN

يمكنك اختياريًا أن تطلب Face ID أو Touch ID أو بصمة Android أو رمز PIN قبل فتح التطبيق. وهذا معطّل إلا إذا شغّلته أنت.

وبياناتك الحيوية لا تصل إلى التطبيق أبدًا. فوجهك وبصمتك مسجّلان ومحفوظان ويتم التحقق منهما عند نظام تشغيل جهازك داخل عتاد آمن مخصّص. والتطبيق يسأل النظام: «هل هذا مالك الجهاز؟» ويستلم «نعم» أو «لا» فقط. ونحن لا نرى ولا نستلم ولا نحفظ ولا نرسل أي معلومة حيوية، ولا يمكن تقنيًا للتطبيق أن يفعل ذلك.

وإذا ضبطت رمز PIN (من ٤ إلى ٦ أرقام)، فالرمز نفسه لا يُحفظ أبدًا. بل يحتفظ التطبيق فقط ببصمة أحادية الاتجاه له مع «ملح» عشوائي (PBKDF2-HMAC-SHA256) في iOS Keychain أو في مخزن محمي بـAndroid Keystore، ولا تُرسل أبدًا. وبعد ٥ محاولات خاطئة يجعلك التطبيق تنتظر قبل المحاولة من جديد، وتطول مدة الانتظار مع كل محاولة خاطئة بعدها. والمحاولات الخاطئة لا تمسح أي شيء أبدًا.

وإذا نسيت رمز PIN، فلا يوجد رابط لإعادة تعيينه، ولا أحد — ولا نحن — يستطيع استرجاعه، لأنه لا يوجد حساب. فإذا كنت قد فعّلت الفتح بـFace ID أو البصمة، يمكنك الفتح بها. وإلا فالطريق الوحيد هو مسح كل شيء والبدء من جديد، ويجب أن تؤكده بكتابة كلمة محددة؛ وهو يحذف كل الجلسات والقوالب والصور والتذكيرات على هذا الهاتف ويزيل الرمز. وإذا كنت قد أنشأت ملف نسخة احتياطية، يمكنك استعادته بعد ذلك (فكلمة مروره منفصلة عن رمز PIN).

وقفل التطبيق يتحكم في الوصول إلى شاشات التطبيق، وليس هو ما يشفّر بياناتك: فقاعدة البيانات مشفّرة سواء كان قفل التطبيق مفعّلًا أم لا (البند ٥).

٩. الإشعارات

إذا اخترت ضبط تذكير لجلسة، فإن التطبيق يجدول إشعارًا محليًا. ومحلي تعني ذلك بالحرف: التذكير يُحفظ ويُسلَّم عبر نظام تشغيل جهازك أنت، في الوقت الذي اخترته. ولا يُرسل أي تذكير إلى سيرفر، ولا تتدخّل أي خدمة Push — فالتطبيق لا يملك أي بنية للإشعارات الفورية أصلًا.

ولا تُطلب صلاحية الإشعارات عند أول فتح للتطبيق. بل يشرح التطبيق التذكير أولًا، ولا تظهر نافذة الصلاحية الخاصة بالنظام إلا بعد أن تضغط للسماح بالتذكيرات — عند ضبط تذكير، أو في صفحة التذكيرات الاختيارية ضمن التعريف الأول بالتطبيق. وإذا رفضت، فكل شيء آخر في التطبيق يستمر في العمل، وكل ما يحدث أنك لن تستلم تذكيرات، ولا يحفظ التطبيق تذكيرًا لا يمكن توصيله.

والتذكير يعرض دائمًا نصًّا عامًّا واحدًا — «قبل ما تطلع» / «تفقّد أغراضك قبل ما تمشي.» — ولا يذكر أبدًا اسم الجلسة ولا أغراضك ولا أماكنها، فلا يظهر أي شيء خاص على شاشة القفل. ويُلغى التذكير تلقائيًا عند إنهائك الجلسة أو إنهائها مبكرًا أو حذفها.

١٠. الوصول إلى الشبكة

لا يحتاج «قبل ما أطلع» إلى الإنترنت لأي شيء. فكل وظيفة — إنشاء جلسة، وإضافة أغراض، وقائمة المغادرة، والسجل، والقوالب، والتذكيرات، والنسخ الاحتياطي والاستعادة — تعمل والشبكة مغلقة تمامًا.

والتطبيق لا يحتوي على أي كود خاص به للاتصال بالشبكة، ولا يرسل أي طلب عبر الشبكة. وعلى Android لا يملك حتى صلاحية الإنترنت، فنظام التشغيل نفسه سيمنع أي محاولة اتصال. ولا يخرج ملف النسخة الاحتياطية من هاتفك إلا إذا أرسلته أنت بنفسك عبر نافذة المشاركة (البند ٧).

١١. خصوصية الأطفال

«قبل ما أطلع» أداة عامة الاستخدام. وهو غير مصمّم للأطفال وغير موجّه إليهم، ولا يجمع معلومات عن قصد من أي شخص في أي عمر — لأنه لا يجمع معلومات إطلاقًا.

ولا يوجد تسجيل، فنحن لا نعرف عمر أي مستخدم. ولا توجد إعلانات، ولا تتبّع، ولا مشتريات داخل التطبيق، ولا ميزات اجتماعية، ولا محادثات، ولا محتوى ينشئه المستخدم ويُشارك مع أحد، ولا روابط خارجية إلى محتوى لا نتحكّم به. ويمكن لأي والد أن يستخدم التطبيق بأمان لمتابعة أغراض طفله؛ وأي أسماء أو ملاحظات تُكتب تبقى على جهاز ذلك الوالد.

ولأننا لا نجمع شيئًا ولا نرسل شيئًا، فلا توجد معلومات شخصية عن أي طفل لنكشف عنها أو نحذفها أو نُسأل عنها بموجب COPPA، أو مدوّنة التصميم الملائم للعمر في المملكة المتحدة، أو المادة ٨ من اللائحة الأوروبية GDPR، أو القوانين المشابهة.

١٢. مكوّنات الطرف الثالث

بُني التطبيق بـFlutter ويستخدم مكوّنات مفتوحة المصدر لوظائف محلية: تخزين قاعدة البيانات وتشفيرها، والتخزين الآمن للمفاتيح، والإشعارات المحلية، ومنتقي الصور والكاميرا الخاصين بالنظام، والتحقق بالبصمة، واختيار الملفات وحفظها ومشاركتها، وتجميع ملفات النسخ الاحتياطي وتشفيرها، وتنسيق التواريخ.

وهذه المكوّنات تعمل بالكامل على جهازك. ولا أي منها خدمة تحليل أو إعلان أو إحالة أو تقارير انهيار، ولا أي منها يرسل بياناتك إلى أي مكان. وقد استثنينا عن قصد كل حزمة من ذلك النوع.

ولا توجد عندنا أي اتفاقيات معالجة بيانات نفصح عنها، ولا أي معالجين فرعيين نذكرهم، لأنه لا يوجد طرف ثالث يستلم بياناتك أبدًا.

١٣. حقوقك على بياناتك

بياناتك في حوزتك مباشرةً، ولذلك تمارس هذه الحقوق بنفسك، فورًا، دون أن تطلب منّا شيئًا:

  • الاطلاع عليها — افتح التطبيق؛ كل شيء موجود فيه.
  • تصحيحها — عدّل أي غرض أو مكان أو ملاحظة أو جلسة.
  • حذف جزء منها — احذف غرضًا أو جلسة أو قالبًا. وحذف الجلسة نهائي، ويطلب التطبيق تأكيدك أولًا.
  • تصديرها — أنشئ ملف نسخة احتياطية (البند ٧).
  • حذفها بالكامل — أزل التطبيق من جهازك. فهذا يحذف مساحة التطبيق الخاصة، ومنها قاعدة البيانات المشفّرة وأي صور أرفقتها. (وإذا كان قفل التطبيق مفعّلًا، فخيار «نسيت الرمز ← مسح كل شيء» يحذفها كلها أيضًا من داخل التطبيق.)

وهناك تحفّظ مهم: إزالة التطبيق لا تحذف أي ملف نسخة احتياطية حفظته سابقًا في مكان آخر. فإذا حفظت نسخة في iCloud Drive أو Google Drive أو تطبيق «الملفات»، فعليك حذف ذلك الملف بنفسك.

ملاحظة تقنية عن iPhone. قد يحتفظ iOS بعناصر Keychain الخاصة بتطبيق ما بعد إزالته. وبالنسبة إلى «قبل ما أطلع» فهذه العناصر مجرد مادة مفاتيح وإعدادات قفل: مفتاح قاعدة البيانات العشوائي، والبصمة أحادية الاتجاه لرمز PIN إن كنت ضبطته، وهل كان قفل التطبيق مفعّلًا. ولا تحتوي على أي من جلساتك أو أغراضك أو ملاحظاتك أو صورك، ولا فائدة منها بدون قاعدة البيانات المحذوفة. أما على Android، فمفاتيح Keystore الخاصة بالتطبيق تُحذف مع التطبيق.

وبموجب اللائحة الأوروبية GDPR، ولائحة المملكة المتحدة، وCCPA/CPRA والقوانين المشابهة، فإن أي طلب يُوجَّه إلينا للاطلاع أو النقل أو التصحيح أو التقييد أو الاعتراض أو المحو لن يجد بيانات يتعامل معها: فنحن لسنا «مراقبًا» ولا «معالجًا» لمحتوى تطبيقك، لأننا لا نستلمه أبدًا. وإذا رغبت في تأكيد ذلك كتابةً لسجلاتك الخاصة، فاكتب إلى [email protected] وسنفيدك بذلك.

ولا يوجد حساب لحذفه، ولذلك لا ينطبق شرط Apple الخاص بحذف الحساب على هذا التطبيق.

١٤. مدة الاحتفاظ بالبيانات

تبقى بياناتك على جهازك ما دمت تريد الاحتفاظ بها. لا شيء تنتهي صلاحيته من تلقاء نفسه، ولا شيء يُحذف من دون علمك، ولا شيء نحتفظ به نحن في أي مرحلة — فلا توجد مدة احتفاظ نذكرها من جهتنا، لأنه لا يوجد جمع للبيانات أصلًا.

١٥. الحوادث الأمنية

لأننا لا نحتفظ بأي نسخة من بياناتك، فإن أي اختراق لأنظمتنا لا يمكن أن يكشف جلساتك أو أغراضك أو صورك.

والمخاطر الواقعية على بياناتك محلية: فقدان جهاز غير مقفل، أو شخص لديه وصول إلى هاتفك غير المقفل، أو ملف نسخة احتياطية محفوظ في مكان غير آمن. ولتقليلها: استخدم رمز قفل للجهاز، وشغّل قفل التطبيق من إعداداته، وفكّر جيدًا في المكان الذي تحفظ فيه النسخ الاحتياطية.

وإذا علمنا يومًا بخلل أمني في التطبيق نفسه قد يعرّض بيانات على جهازك للخطر، فسننشر إصدارًا مصحّحًا ونوضّح المشكلة في ملاحظات الإصدار.

١٦. النقل الدولي للبيانات

لا يوجد. فبياناتك لا تخرج من جهازك، ولذلك لا يوجد نقل لها عبر الحدود، ولا حاجة إلى أي آلية نقل مثل الشروط التعاقدية القياسية.

١٧. التغييرات على هذه السياسة

إذا غيّرنا طريقة تعامل التطبيق مع البيانات، فسنحدّث هذه السياسة ونغيّر تاريخ «آخر تحديث» في أعلاها.

وإذا بدأ إصدار مستقبلي من التطبيق يومًا بجمع أو إرسال أي شيء — وهو ما يمثّل تغييرًا جوهريًا في تصميم المنتج — فلن نفعل ذلك بصمت. بل سنحدّث هذه السياسة قبل إطلاق ذلك الإصدار، وسنطلب موافقتك داخل التطبيق أولًا.

والنسخة الحالية من هذه السياسة متاحة دائمًا على https://beforeileave.paymentery.com/privacy/.

١٨. التواصل

للأسئلة المتعلقة بالخصوصية في «قبل ما أطلع»:

[email protected] paymentery.com

سنبذل جهدنا في الإجابة، لكن تذكّر الحد العملي الموضّح في هذه السياسة بأكملها: لا نستطيع رؤية بياناتك ولا استرجاعها ولا استعادتها ولا حذفها نيابةً عنك، لأنها لم تكن عندنا في أي وقت.


Privacy Policy — Before I Leave

Effective date: 2026-09-28

Last updated: 2026-09-28

Application: Before I Leave (قبل ما أطلع) — technical identifier com.paymentery.beforeileave

Developer: paymentery.com

Contact: [email protected]

Permissions at a glance

PermissionWhyWhen it is askedIf you say no
NotificationsThe one optional reminder per session (section 9).Only after you choose to turn on a reminder (or on the optional reminders page of the introduction) — never when the app first opens.Everything else works; you just don't get reminders.
Camera"Take photo" of where you put an item (section 6).iPhone: the first time you tap "Take photo". Android: the app hands off to your camera app and holds no camera permission.The item is saved without a photo.
Photos"Choose photo" through the system photo picker (section 6).Never — the system picker gives the app only the one photo you pick, without library access.—
Face ID / fingerprintOptional app lock (section 8).Only if you turn on app lock with biometrics; the system checks you and tells the app only yes or no.The app PIN still works.

The app never requests location, contacts, calendar, microphone or tracking permission, and on Android it has no internet permission.

1. The short version

Before I Leave helps you list the things you put around a temporary place — a hotel room, a clinic, a rental car, a borrowed office — and then confirms you took all of them with you before you leave.

We do not collect your data. Not any of it.

There is no account, no sign-in, no server, and no analytics. Everything you type into Before I Leave is written to an encrypted database on your own phone and stays there. The app works completely with the network turned off — you can use it in airplane mode from start to finish.

We, the developer, never receive your information, because there is nowhere for it to be sent.

2. Who this policy is for

This policy applies to the Before I Leave mobile application for iPhone and Android. It does not apply to the separate services you may choose to use alongside it — for example, if you save a backup file to iCloud Drive or Google Drive, that file is then governed by Apple's or Google's privacy policy as well as this one. See section 7.

3. What information the app handles

You type this information in yourself, and it stays on your device:

WhatExampleWhere it lives
Session name and type"Hilton, room 402", "Rental car"On your device
Item names"Passport", "Phone charger", "Child's medicine"On your device
Places you note for each item"In the safe", "Next to the bed", "In the fridge"On your device
Optional notes on an item"Ask reception for the spare"On your device
Optional photo of an itemA picture of where you left somethingOn your device
Reminder time, if you set one"Remind me at 11:00"On your device
Status of each itemRecovered / still out / left on purposeOn your device
Your history of past sessionsCompleted sessions and sessions you ended earlyOn your device
Templates you save"Family trip"On your device
App settingsLanguage, whether app lock is on, the date of your last backupOn your device

We never ask you for, and the app has no field for: your real name, your email address, your phone number, your date of birth, a username, a password for us, a payment method, or any government or health identifier.

Please note that you are free to type anything you like into a free-text field. If you choose to type sensitive information into an item name or note, that text is stored on your device under the same protection as everything else — but the app cannot stop you from writing something you would rather not record. Use your judgement, exactly as you would with a paper note.

4. What the app does not do

To be specific, rather than vague:

  • No account and no sign-in. There is nothing to register for and no password to create with us.
  • No server of ours. The app has no backend. There is no database we operate that holds your items.
  • No analytics. No Firebase Analytics, no Google Analytics, no Meta SDK, no Mixpanel, no Amplitude, no product-analytics tool of any kind.
  • No advertising. No ad SDK, no ad network, no ad identifier (no IDFA on iOS, no Advertising ID on Android), no in-app advertising.
  • No tracking. We do not track you across apps or websites, we do not build a profile of you, and we do not link your activity to anything else. We do not share anything with data brokers, because we have nothing to share.
  • No crash or error reporting service. No Crashlytics, no Sentry, no Bugsnag. If the app crashes, we do not find out, and no report leaves your phone.
  • No location. The app never requests GPS or location permission and never records where you are. When you type "in the safe", that is a word you typed, not a place we measured.
  • No contacts, no calendar, no microphone, no photo-library browsing, no health data, no call or SMS logs. The camera is used only when you tap "Take photo" (section 6).
  • No background tracking or background network activity.
  • No selling of data. We have no data to sell. Under the California Consumer Privacy Act and comparable laws, we do not sell or share personal information.

5. Where your data is stored, and how it is protected

All of your sessions, items, places, notes, reminder times and settings are stored in a single database file inside the app's own private storage area on your device — the area the operating system reserves for this app and keeps other apps out of.

That database is encrypted at rest with AES-256, using the SQLCipher 4 encryption scheme (implemented by the open-source SQLite3MultipleCiphers library). The key that unlocks it is a random 256-bit key created on your phone the first time the app starts. It is not written into the app's code and is not stored in the database. It is held by the operating system's own secure key storage: the iOS Keychain on iPhone (as a "this device only" item that is never synced or moved to another device), and storage protected by the Android Keystore on Android. If that key is ever missing or unreadable, the app does not create a new, unencrypted database over your data; it shows a recovery screen instead.

Photos you attach (section 6) are stored as separate image files in the same private app storage, next to the database but not inside it. They are protected by the app sandbox and by your phone's own storage encryption, not by the app's database encryption.

What this protects against, honestly stated: at-rest encryption protects your data if someone gets hold of the database file itself — for example from a device backup, a forensic dump, or a lost phone. It is not a defence against someone who has your unlocked phone in their hand and opens the app. For that, turn on app lock (section 8).

Your phone's own backup

The app excludes its data from your phone's automatic backups. On Android, app backup and device-to-device transfer are switched off for this app, so its data is not copied to your Google account backup or to a new phone. On iPhone, the folder that holds the database and photos is marked "do not back up", so it is not included in iCloud Backup or computer backups, and the database key is a "this device only" Keychain item that never moves to another device.

The only way your data leaves the phone is a backup file that you create (section 7).

6. Optional photos

You can attach a photo to an item — for example a picture of the drawer you put something in. This is entirely optional and the app works fully without it.

There are two ways to add one, and each starts only when you tap it:

  • Choose photo opens your operating system's own photo picker. That picker is run by the system, not by us. You pick one picture, and only that picture is handed to the app. The app does not get, and does not ask for, permission to read your photo library, and it cannot browse, index or see any other photo you own. (On iPhone the app includes a photo-library purpose string because Apple requires it for the picker, but no permission prompt is shown.)
  • Take photo opens the camera so you can photograph where you put something. On iPhone, the system asks for camera permission the first time you tap it. On Android, the app hands off to your phone's own camera app and does not hold a camera permission itself. If you decline, the item is simply saved without a photo.

The picture is resized and copied into the app's private storage under a randomly generated filename (the original filename is not kept). It is never uploaded, never transmitted, never shared with us or anyone else, and never written to your gallery. When you delete a session, its photos are deleted at once; when you delete a single item, its photo file is removed the next time the app starts (so that "Undo" can still bring it back). Everything is removed when you uninstall the app.

7. Backup and restore — and what you are responsible for

Backup in Before I Leave is manual and entirely under your control. Nothing is backed up automatically, and nothing is backed up to us.

When you tap to create a backup, the app packages your data (sessions, items, templates, recently used place names and the photos attached to items — not your settings or PIN) into a single encrypted file and then hands that file to your operating system's standard share/save sheet. You decide where it goes. You might save it to Files on your iPhone, to iCloud Drive, to Google Drive, to a USB drive, to a chat with yourself — that choice is yours and the app does not make it for you.

The backup file never passes through any server of ours. We do not have a copy. We cannot retrieve it for you, and we cannot help you open it.

This means two things you need to understand:

  1. Once you save the backup somewhere, that place's rules apply. If you put it in iCloud Drive, it is subject to Apple's privacy policy and to whoever can access your Apple Account. If you put it in Google Drive, the same is true of Google. If you email it to yourself, it sits in your mailbox. Choosing where the file lives — and keeping that place secure — is your responsibility, not ours.
  2. If you lose the file, or lose what is needed to decrypt it, the data in it is gone. Because we hold no copy and no key escrow, there is no "forgot password" path and no way for us to recover a backup. This is the direct cost of a design where we hold nothing about you.

How the file is protected. Every backup requires a password that you choose (at least 8 characters). The app turns that password into an encryption key with PBKDF2-HMAC-SHA256 (310,000 iterations and a random salt) and encrypts the contents with AES-256-GCM, which also detects any tampering with the file. Because the key comes from your password and not from your phone, you can restore the file on a different phone. We never see or store the password.

  • If you forget the backup password, nobody can open that file — including us. The app warns you about this and asks you to confirm that you have saved the password before it creates the file.
  • You can add an optional password hint (up to 60 characters). The hint is stored unencrypted inside the file so that it can be shown before you type the password, which means anyone who has the file can read it. The app refuses a hint that contains the password.
  • A small unencrypted header also records when the backup was made and the app version, so the restore screen can show them. Everything else — your sessions, items, notes and photos — is encrypted.

Restoring reads a file you select, asks for its password, checks that it is a valid backup of a supported version, verifies it completely in a temporary copy, and asks you to confirm before it replaces anything. Your current data is not changed until all of that has succeeded, and the replacement happens in a single step that either completes or leaves your data exactly as it was.

8. App lock, Face ID, Touch ID and PIN

You can optionally require Face ID, Touch ID, an Android biometric, or a PIN before the app opens. This is off unless you turn it on.

Your biometric data never reaches the app. Your face and fingerprint are enrolled with, stored by, and checked by your device's operating system inside dedicated secure hardware. The app asks the operating system "is this the device owner?" and receives only a yes or a no. We never see, receive, store or transmit any biometric information, and it is not technically possible for the app to do so.

If you set a PIN (4 to 6 digits), the PIN itself is never stored. The app keeps only a salted, one-way hash of it (PBKDF2-HMAC-SHA256) in the iOS Keychain or in Android Keystore-protected storage, and it is never transmitted. After 5 wrong attempts the app makes you wait before trying again, and the wait grows with further wrong attempts. Wrong attempts never erase anything.

If you forget your PIN, there is no reset link and nobody — including us — can recover it, because there is no account. If you turned on Face ID / fingerprint unlock, you can still unlock with that. Otherwise the only way back in is Erase everything and start fresh, which you must confirm by typing a word; it deletes every session, template, photo and reminder on this phone and removes the PIN. If you made a backup file, you can then restore it (its password is separate from the PIN).

App lock controls access to the app's screens. It is not what encrypts your data: the database is encrypted whether or not app lock is on (section 5).

9. Notifications

If you choose to set a reminder for a session, the app schedules a local notification. Local means exactly that: the reminder is stored and delivered by your own device's operating system, at the time you chose. No reminder is sent to a server, and no push service is involved — the app has no push notification infrastructure at all.

Notification permission is not requested when you first open the app. The app explains what the reminder is first, and the system permission dialog appears only after you tap to allow reminders — when you set a reminder, or on the optional reminders page of the first-time introduction. If you decline, everything else in the app continues to work; you simply will not get reminders, and the app does not save a reminder that could not be delivered.

A reminder always shows the same generic text — "Before you leave" / "Check your things before you go." It never names the session, your items or where you put them, so nothing private appears on your lock screen. The reminder is cancelled automatically when you finish, end or delete the session.

10. Network access

Before I Leave does not need the internet for anything. Every feature — creating a session, adding items, the leaving checklist, history, templates, reminders, backup and restore — works with the network fully off.

The app has no networking code of its own and makes no network requests. On Android it does not even hold the internet permission, so the operating system would block any connection attempt. A backup file leaves your phone only if you send it somewhere yourself through the share sheet (section 7).

11. Children's privacy

Before I Leave is a general-purpose utility. It is not designed for or directed at children, and it does not knowingly collect information from anyone of any age — because it does not collect information at all.

There is no sign-up, so we never learn any user's age. There are no ads, no tracking, no in-app purchases, no social features, no chat, no user-generated content shared with anyone, and no external links to content we do not control. A parent may safely use the app to keep track of a child's belongings; any names or notes typed in stay on that parent's device.

Because we collect nothing and transmit nothing, there is no personal information about a child for us to disclose, delete, or be asked about under COPPA, the UK Age Appropriate Design Code, GDPR Article 8, or similar laws.

12. Third-party components

The app is built with Flutter and uses open-source software components for local functions: database storage and encryption, secure key storage, local notifications, the system photo picker and camera, biometric authentication, choosing, saving and sharing files, packaging and encrypting backup files, and date formatting.

These components run entirely on your device. None of them is an analytics, advertising, attribution or crash-reporting service, and none of them sends your data anywhere. We have deliberately excluded every SDK of that kind.

We have no data-processing agreements to disclose and no sub-processors to list, because no third party ever receives your data.

13. Your rights over your data

You hold your data directly, so you exercise these rights yourself, immediately, without asking us:

  • See it — open the app; everything is there.
  • Correct it — edit any item, place, note or session.
  • Delete some of it — delete an item, a session or a template. Deleting a session is permanent; the app asks you to confirm first.
  • Export it — create a backup file (section 7).
  • Delete all of it — remove the app from your device. That deletes the app's private storage, including the encrypted database and any photos you attached. (If app lock is on, "Forgot PIN → Erase everything" also deletes all of it from inside the app.)

One important caveat: removing the app does not delete any backup file you previously saved elsewhere. If you saved a backup to iCloud Drive, Google Drive or your Files app, you must delete that file yourself.

A technical footnote about iPhone. iOS can keep an app's Keychain items after the app is removed. For Before I Leave those items are only key material and lock settings: the random database key, the one-way hash of your PIN if you set one, and whether app lock was on. They contain none of your sessions, items, notes or photos, and they are useless without the deleted database. On Android, the app's Keystore keys are deleted together with the app.

Under the GDPR, the UK GDPR, the CCPA/CPRA and comparable laws, a request to us for access, portability, correction, restriction, objection or erasure would have no data to act on: we are not a controller or processor of your app content, because we never receive it. If you would like this confirmed in writing for your own records, write to [email protected] and we will say so.

There is no account to delete, so Apple's account-deletion requirement does not apply to this app.

14. Data retention

Your data stays on your device for as long as you keep it. Nothing expires on its own, nothing is deleted behind your back, and nothing is retained by us at any point — there is no retention period to state on our side, because there is no collection.

15. Security incidents

Because we hold no copy of your data, a breach of our systems could not expose your sessions, items or photos.

The realistic risks to your data are local ones: losing an unlocked device, someone with access to your unlocked phone, or a backup file saved somewhere insecure. To reduce them: use a device passcode, turn on app lock in the app's settings, and think about where you save backups.

If we ever became aware of a security defect in the app itself that could expose data on your device, we would publish a fixed version and describe the issue in the release notes.

16. International transfers

None. Your data does not leave your device, so there is no cross-border transfer of it, and no transfer mechanism such as Standard Contractual Clauses is needed.

17. Changes to this policy

If we change how the app handles data, we will update this policy and change the "Last updated" date at the top.

If a future version of the app were ever to start collecting or transmitting anything — which would be a fundamental change to the product's design — we would not do so silently. We would update this policy before that version shipped, and ask for your consent inside the app first.

The current version of this policy is always available at https://beforeileave.paymentery.com/privacy/.

18. Contact

Questions about privacy in Before I Leave:

[email protected] paymentery.com

We will do our best to answer, but please keep in mind the practical limit described throughout this policy: we cannot see, retrieve, restore or delete your data for you, because we never had it.