Privacy Policy — Sadis Plus
Last updated: 2 August 2026
Sadis Plus is the official learning application for students enrolled in our online educational program. Each enrolled student receives unique account credentials from the institution to access the educational materials included in their enrollment.
Sadis Plus is an offline study app for Iraqi 6th-preparatory students (السادس الإعدادي). This policy explains exactly what the app touches, what leaves your phone, and what does not.
Short version: no analytics, no ads, no tracking, and no social or third-party logins. The only account is the student account issued to enrolled students by our educational institution — a Student ID and a Student Access Credential. The app makes only one network request required for authentication: the one-time sign-in of the student account. After successful sign-in, all study features work completely offline.
1. What we collect
1.1 One-time student sign-in (the only data sent to our server)
Your account is a pair: the institution issues each Student Access Credential to one specific Student ID, and sign-in only succeeds when both halves match. A credential on its own signs nobody in.
When you sign in with your Student ID and Student Access Credential, the app sends one request to the account server and never contacts it again:
| Data | Why |
|---|---|
| Student Access Credential (16 characters, issued by the institution) | To check the credential is valid, unused and not disabled |
| Student ID (as you type it, normalized to letters/digits) | To check the credential was issued to this student — sign-in fails unless both match |
Device identifier (Android ANDROID_ID) |
To bind the student account to one phone, so one account can't be shared across many devices |
The Student ID the credential was issued to is already on that record before you ever sign in — the institution creates the pair. The server stores these three values against your student account record, plus the sign-in timestamp. It also writes a sign-in log entry containing the Student Access Credential, the device identifier, the action (sign-in / failed attempt) and a timestamp.
We do not store your IP address. The server sees it, as every web server must, and holds it in memory for up to 60 seconds to rate-limit repeated attempts. It is never written to the database or to a log file.
We do not collect your name, phone number, email, school, location, contacts, photos, or any behavioural data. Your Student ID is whatever identifier the account was issued under; if your account carries no real student ID, no personal identifier reaches us at all.
After sign-in succeeds the app receives a signed license token and works fully offline. There is no expiry check, no periodic phone-home, no background sync.
1.2 Data kept only on your device (never uploaded)
All of your study data stays in the app's private storage:
- Quiz scores, XP, level, streaks and progress
- Favourites and completed problems — stored as SHA-256 fingerprints of the text, not the text itself
- Text highlights — stored encrypted
- App settings (language, theme, fonts)
- Study-tab data: tasks, timer sessions, exam dates, mock-exam results
- The license token, stored in the Android Keystore, not in plain preferences
Android backup is disabled for the app (allowBackup="false"), so this data
is not copied to Google Drive or to another phone.
1.3 Content
All exam content ships inside the app as encrypted assets and is decrypted locally. Nothing you read, answer or search is transmitted anywhere.
2. Permissions and why the app asks for them
| Permission | Used for |
|---|---|
INTERNET |
The single sign-in request; opening support links you tap |
POST_NOTIFICATIONS |
Local study reminders and timer alerts (generated on-device) |
SCHEDULE_EXACT_ALARM / USE_EXACT_ALARM,
RECEIVE_BOOT_COMPLETED, WAKE_LOCK, VIBRATE |
Firing your study timer and reminders at the right moment, and restoring them after a reboot |
SYSTEM_ALERT_WINDOW, FOREGROUND_SERVICE*,
USE_FULL_SCREEN_INTENT |
The floating timer bubble, the countdown notification and the full-screen alarm |
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS |
Optional — keeps a scheduled timer alive on phones with aggressive battery management |
None of these permissions are used to collect or transmit data.
3. Reporting a problem (optional, you start it)
If you tap "report a problem", the app takes a screenshot of the current screen, lets you add a description, and hands both to Telegram or WhatsApp — whichever you pick. Nothing is sent until you send it inside that messenger, and you can see exactly what is attached first. Once the message leaves, it is governed by that messenger's own privacy policy, not this one. The screenshot is a temporary file shared only with the one app you selected.
4. Third parties
- Hosting — the account server runs on Render; the account database is hosted on Turso. Both see only the sign-in data in section 1.1.
- Messengers — Telegram / WhatsApp, only if you choose to contact support or send an issue report.
- No advertising networks, no analytics SDKs, no crash-reporting service, no social logins.
We do not sell, rent or share your data with anyone else, and we do not use it for advertising or profiling.
5. Retention
Student account records (Student Access Credential, Student ID, device identifier, sign-in time) are kept for as long as the account is valid — the account is lifetime, so the record persists while the app is supported. Sign-in log entries (Student Access Credential, device identifier, timestamp — no IP address) are kept for 90 days and are then deleted automatically.
Uninstalling the app erases all on-device data. It does not erase the server-side account record — that record is what lets you sign in again.
6. Your choices
- Change phone: contact support to have your student account reset to a new device.
- Deletion: you may ask us to delete your student account record. Doing so releases the device binding and the account can no longer be signed in without a new Student Access Credential.
- Access: you may ask what is stored against your student account.
Requests go to the support contact shown inside the app (Settings → support, or the sign-in sheet).
7. Children
The app is aimed at final-year secondary-school students, some of whom are under 18. It collects no personal profile, has no social features, no user content sharing, no ads and no location access. The only identifiers involved are a Student Access Credential, a Student ID and a device ID, all used solely to run the student account.
8. Security
- Exam content is encrypted (AES-256-CTR, encrypt-then-HMAC); the full content key is never in the APK and arrives only in the signed license token.
- The license token is signed with Ed25519 and verified locally on every launch; it is stored in the Android Keystore.
- Saved highlights are encrypted at rest; favourites and progress are stored as one-way fingerprints.
- Android backup and data extraction are disabled.
No system is perfect, but the app is built so that even full access to the installed APK yields no readable exam content and no personal data.
9. Changes
If this policy changes, the "Last updated" date above changes with it, and the new version ships with the app update.
10. Contact
Support contacts (Telegram / WhatsApp) are shown inside the app under Settings and on the sign-in sheet. Use them for privacy questions, account resets, or deletion requests.
سياسة الخصوصية — سادس بلص
آخر تحديث: ٢ آب ٢٠٢٦
«سادس بلص» هو التطبيق التعليمي الرسمي للطلبة المسجّلين في برنامجنا التعليمي الإلكتروني. يحصل كل طالب مسجّل على بيانات دخول خاصة به من المؤسسة التعليمية للوصول إلى المواد التعليمية المشمولة بتسجيله.
تطبيق «سادس بلص» تطبيق دراسي يعمل بدون إنترنت لطلبة السادس الإعدادي في العراق. باختصار: لا إعلانات، لا تحليلات، لا تتبّع، ولا تسجيل دخول عبر حسابات خارجية. الحساب الوحيد هو حساب الطالب الذي تمنحه المؤسسة التعليمية للطلبة المسجّلين: رقم الطالب ورمز دخول الطالب. لا يجري التطبيق سوى اتصال واحد بالشبكة لازم للمصادقة: تسجيل الدخول لمرة واحدة لحساب الطالب. وبعد نجاح تسجيل الدخول تعمل جميع ميزات الدراسة بلا إنترنت تماماً.
١. ما الذي نجمعه
١.١ تسجيل دخول الطالب لمرة واحدة (البيانات الوحيدة التي تصل خادمنا)
حسابك زوج مترابط: تمنح المؤسسة التعليمية كل رمز دخول لرقم طالب واحد بعينه، ولا ينجح تسجيل الدخول إلا إذا تطابق الاثنان. الرمز وحده لا يُدخل أحداً.
عند تسجيل الدخول برقم الطالب ورمز دخول الطالب، يُرسل التطبيق طلباً واحداً إلى خادم الحسابات ولا يتصل به بعدها أبداً:
| البيانات | السبب |
|---|---|
| رمز دخول الطالب (١٦ حرفاً تمنحه المؤسسة التعليمية) | للتحقق من أن الرمز صالح وغير مستخدَم وغير معطّل |
| رقم الطالب (كما تُدخله، بعد توحيده إلى حروف وأرقام) | للتحقق من أن الرمز مُنح لهذا الطالب — ولا ينجح الدخول إلا بتطابق الاثنين |
معرّف الجهاز (ANDROID_ID في أندرويد) |
لربط حساب الطالب بهاتف واحد، فلا يُتشارك حساب واحد بين أجهزة كثيرة |
رقم الطالب الذي مُنح له الرمز مسجَّل أصلاً في سجل الحساب قبل أن تسجّل الدخول أول مرة — فالمؤسسة التعليمية هي من تُنشئ الزوج. ويحفظ الخادم هذه القيم الثلاث في سجل حساب الطالب مع وقت تسجيل الدخول، ويكتب أيضاً سطر سجل دخول يتضمن رمز دخول الطالب ومعرّف الجهاز ونوع العملية (دخول ناجح / محاولة فاشلة) والوقت.
لا نحفظ عنوان IP الخاص بك. يراه الخادم كما يرى أي خادم ويب، ويبقى في الذاكرة مدة لا تتجاوز ٦٠ ثانية للحدّ من المحاولات المتكررة، ولا يُكتب في قاعدة البيانات ولا في أي ملف سجل.
لا نجمع اسمك ولا رقم هاتفك ولا بريدك ولا مدرستك ولا موقعك ولا جهات اتصالك ولا صورك ولا أي بيانات سلوكية. ورقم الطالب هو أي معرّف صدر الحساب باسمه؛ فإذا كان حسابك لا يحمل رقم طالب حقيقي، فلا يصلنا أي معرّف شخصي إطلاقاً.
بعد نجاح تسجيل الدخول يستلم التطبيق رمز ترخيص موقّعاً ويعمل بلا إنترنت نهائياً — لا انتهاء صلاحية، ولا اتصال دوري، ولا مزامنة في الخلفية.
١.٢ بيانات تبقى على جهازك وحده (لا تُرفع أبداً)
كل بيانات دراستك تبقى في التخزين الخاص بالتطبيق:
- درجات الاختبارات ونقاط الخبرة والمستوى والأيام المتتالية والتقدّم
- المفضّلة والمسائل المُنجزة — تُحفظ كـبصمات SHA-256 للنص، لا كنصّ
- التظليلات النصية — تُحفظ مشفّرة
- إعدادات التطبيق (اللغة، المظهر، الخطوط)
- بيانات تبويب الدراسة: المهام وجلسات المؤقّت ومواعيد الامتحانات ونتائج الامتحانات التجريبية
- رمز الترخيص، يُحفظ في مخزن مفاتيح أندرويد (Keystore) لا في التفضيلات العادية
النسخ الاحتياطي في أندرويد معطّل للتطبيق (allowBackup="false")، فلا تُنسخ
هذه البيانات إلى Google Drive ولا إلى هاتف آخر.
١.٣ المحتوى
كل محتوى الوزاريات يأتي داخل التطبيق كملفات مشفّرة ويُفكّ تشفيرها محلياً. لا يُرسَل إلى أي جهة شيء مما تقرأه أو تجيب عنه أو تبحث فيه.
٢. الأذونات ولماذا يطلبها التطبيق
| الإذن | الاستخدام |
|---|---|
INTERNET |
طلب تسجيل الدخول الوحيد، وفتح روابط الدعم التي تضغطها |
POST_NOTIFICATIONS |
تذكيرات الدراسة وتنبيهات المؤقّت (تُنشأ على الجهاز) |
SCHEDULE_EXACT_ALARM / USE_EXACT_ALARM،
RECEIVE_BOOT_COMPLETED، WAKE_LOCK، VIBRATE |
إطلاق مؤقّت الدراسة والتذكيرات في وقتها بالضبط، وإعادتها بعد إقلاع الهاتف |
SYSTEM_ALERT_WINDOW، FOREGROUND_SERVICE*،
USE_FULL_SCREEN_INTENT |
فقاعة المؤقّت العائمة، وإشعار العدّ التنازلي، والمنبّه بملء الشاشة |
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS |
اختياري — يُبقي المؤقّت المجدول حياً على الهواتف ذات إدارة البطارية الصارمة |
لا يُستخدم أي من هذه الأذونات لجمع بيانات أو إرسالها.
٣. الإبلاغ عن مشكلة (اختياري، وأنت من يبدؤه)
عند الضغط على «الإبلاغ عن مشكلة» يلتقط التطبيق صورة للشاشة الحالية، ويتيح لك إضافة وصف، ثم يسلّمهما إلى تيليغرام أو واتساب حسب اختيارك. لا يُرسل شيء إلا بضغطك أنت داخل تطبيق المراسلة، وترى بالضبط ما هو مرفق قبل ذلك. وبعد خروج الرسالة تحكمها سياسة خصوصية تطبيق المراسلة لا هذه السياسة. ولقطة الشاشة ملف مؤقّت لا يُشارَك إلا مع التطبيق الذي اخترته وحده.
٤. أطراف ثالثة
- الاستضافة — خادم الحسابات يعمل على Render، وقاعدة بيانات الحسابات مستضافة على Turso. ولا يريان سوى بيانات تسجيل الدخول في القسم ١.١.
- تطبيقات المراسلة — تيليغرام / واتساب، فقط إذا اخترت التواصل مع الدعم أو إرسال بلاغ.
- لا شبكات إعلانات، ولا أدوات تحليل، ولا خدمة تقارير أعطال، ولا تسجيل دخول عبر حسابات التواصل.
لا نبيع بياناتك ولا نؤجّرها ولا نشاركها مع أي جهة أخرى، ولا نستخدمها للإعلان أو التصنيف الشخصي.
٥. مدة الاحتفاظ
سجلات حساب الطالب (رمز دخول الطالب، رقم الطالب، معرّف الجهاز، وقت تسجيل الدخول) تُحفظ ما دام الحساب سارياً — والحساب مدى الحياة، فيبقى السجل ما دام التطبيق مدعوماً. أما أسطر سجل الدخول (رمز دخول الطالب، معرّف الجهاز، الوقت — بلا عنوان IP) فتُحفظ ٩٠ يوماً ثم تُحذف تلقائياً.
حذف التطبيق يمحو كل البيانات الموجودة على الجهاز، لكنه لا يمحو سجل الحساب على الخادم — فهذا السجل هو ما يتيح لك تسجيل الدخول مجدداً.
٦. خياراتك
- تغيير الهاتف: تواصل مع الدعم لإعادة ضبط حساب الطالب على جهاز جديد.
- الحذف: يمكنك أن تطلب منا حذف سجل حساب الطالب. وهذا يفكّ الارتباط بالجهاز، ولا يعود بالإمكان تسجيل الدخول بالحساب دون رمز دخول جديد.
- الاطّلاع: يمكنك أن تسأل عمّا هو محفوظ في سجل حساب الطالب الخاص بك.
تُرسَل الطلبات إلى جهة الدعم المعروضة داخل التطبيق (الإعدادات ← الدعم، أو نافذة تسجيل الدخول).
٧. الأطفال
التطبيق موجّه لطلبة الصف المنتهي، وبعضهم دون الثامنة عشرة. لا يجمع أي ملف شخصي، ولا يحتوي ميزات اجتماعية، ولا مشاركة محتوى بين المستخدمين، ولا إعلانات، ولا وصولاً إلى الموقع. والمعرّفات الوحيدة المستخدمة هي رمز دخول الطالب ورقم الطالب ومعرّف الجهاز، وكلها لتشغيل حساب الطالب فقط.
٨. الأمان
- محتوى الوزاريات مشفّر (AES-256-CTR مع HMAC بعد التشفير)، ومفتاح المحتوى الكامل غير موجود في ملف التطبيق ولا يصل إلا داخل رمز الترخيص الموقّع.
- رمز الترخيص موقّع بخوارزمية Ed25519 ويُتحقق منه محلياً عند كل تشغيل، ويُحفظ في مخزن مفاتيح أندرويد.
- التظليلات المحفوظة مشفّرة عند التخزين، والمفضّلة والتقدّم يُحفظان كبصمات أحادية الاتجاه.
- النسخ الاحتياطي واستخراج البيانات في أندرويد معطّلان.
لا يوجد نظام كامل، لكن التطبيق مبني بحيث لا يُخرج الوصولُ الكامل إلى ملف التطبيق المثبَّت أي محتوى امتحاني مقروء ولا أي بيانات شخصية.
٩. التغييرات
إذا تغيّرت هذه السياسة، تغيّر معها تاريخ «آخر تحديث» أعلاه، وتصل النسخة الجديدة مع تحديث التطبيق.
١٠. التواصل
جهات الدعم (تيليغرام / واتساب) معروضة داخل التطبيق في الإعدادات وفي نافذة تسجيل الدخول. استخدمها لأسئلة الخصوصية، أو إعادة ضبط الحساب، أو طلبات الحذف.