سياسة الخصوصية

تطبيق رحلة (Rihla) — com.rihla.app

آخر تحديث: ١٧ أغسطس ٢٠٢٦

الخلاصة

ما الذي نخزّنه

ما تكتبه في التطبيق. المهام والمشاريع والأهداف والنتائج الرئيسية والمعالم ومجالات الحياة والهويات والعادات وسجلّاتها وجلسات التركيز وملخّصاتها والبلوكات المجدولة والمراجعات الأسبوعية والملاحظات والبطاقات والمواد ومحتوى المعرفة وصندوق الوارد وإعدادات حسابك. هذا هو التطبيق نفسه.

حسابك. بريدك الإلكتروني، وكلمة المرور (مُعمّاة، تديرها Supabase ولا نراها أبداً)، أو اسمك المعروض إن سجّلت عبر Google.

ملفّك الشخصي، إن أدخلته. الدولة ورقم الهاتف وتاريخ الميلاد. هذه اختيارية بالكامل — والتطبيق يعمل دونها — لكن إن أدخلتها فهي تُزامَن مع خادمنا مثل بقيّة بياناتك.

أين تذهب

نسخة تبقى على جهازك (قاعدة بيانات محلية)، ونسخة تُزامَن مع خادم رحلة (Render) وقاعدة بيانات Postgres لدى Supabase. لا يحصل أحد غيرك على صلاحية قراءتها — الخادم يفصل صفوف كل مستخدم بمعرّف حسابه، ولا يُسلّم صفّاً لطلب لا يحمل رمز صاحبه.

المدرّب ومزوّد الذكاء الاصطناعي — اقرأ هذا

المدرّب متوقّف تماماً حتى تختار مزوّداً وتضيف مفتاحه بنفسك في الإعدادات. المزوّدون المتاحون اليوم: openrouter.ai، وapi.openai.com، وapi.anthropic.com، وgenerativelanguage.googleapis.com (Gemini)، أو أي خادم متوافق مع OpenAI تكتب عنوانه بنفسك. إن فعّلته، فإن ما يُرسَل إلى المزوّد الذي اخترته عند كل رسالة هو:

  • إحصاءات تركيزك (الدقائق، الساعة الذهبية، التوزيع بالساعات).
  • عناوين بلوكاتك الأخيرة ونصّ نيّتك المكتوبة فيها.
  • عناوين مهامّك وأهدافك ومشاريعك المفتوحة.
  • أسماء موادك ونصّ ملخّصاتك (الديبريف) — أي ما كتبته بنفسك عن جلساتك.
  • رسائلك في المحادثة وما سبقها من ردود.

هذا محتوى حقيقي كتبته أنت، ويغادر جهازك إلى شركة أخرى تخضع لسياستها هي لا سياستنا. إن لم يعجبك ذلك فلا تضف مفتاحاً — ويبقى بقيّة التطبيق كاملاً كما هو. مفتاحك يُخزَّن في المخزن المُعمّى للجهاز ولا يُرسَل إلى خادمنا أبداً.

حالة واحدة لا يغادر فيها شيء: إن وجّهت رحلة إلى خادم متوافق مع OpenAI يعمل على جهازك نفسه (Ollama أو LM Studio أو llama.cpp)، فالطلب لا يترك جهازك أصلاً.

يطلب التطبيق كذلك قائمة النماذج المتاحة من خادمنا (GET /ai/registry). هذا الطلب عامّ ولا يحمل حسابك ولا أيّ شيء كتبته — يسأل «ما النماذج المتاحة اليوم» ولا شيء غير ذلك.

الإحصاءات المجهّلة

متوقّفة افتراضياً («ساعد في تحسين رحلة» في الإعدادات). إن فعّلتها نسجّل أحداثاً من قائمة مغلقة ومحدّدة سلفاً — «فُتح التطبيق»، «اكتمل التهيئة»، «أول جلسة تركيز» — مع وقتها ومعرّف عشوائي لا يرتبط بحسابك. لا حقول نصّية إطلاقاً، فلا يمكن بنيوياً أن يتسرّب منها شيء مما تكتبه. إيقافها يمسح ما جُمِع.

التنبيهات

كل التنبيهات تُجدوَل على جهازك محلياً. لا نستخدم خدمة إشعارات سحابية ولا نملك رمز إشعارات لجهازك.

ما لا نفعله

الحذف والاحتفاظ

نحتفظ ببياناتك ما دام حسابك قائماً. عند طلب الحذف تبدأ مهلة ١٤ يوماً يُلغى الطلب خلالها بمجرّد تسجيل دخولك مرة أخرى، ثم تُحذف بياناتك وحسابك حذفاً نهائياً. التفاصيل كاملة في صفحة حذف الحساب.

الأطفال

رحلة ليست موجّهة لمن هم دون ١٣ عاماً، ولا نجمع بياناتهم عن قصد. إن علمت بحساب لطفل دون هذه السنّ راسلنا وسنحذفه.

هذا الموقع

هذا الموقع لا يطلب منك تسجيل دخول، ولا يحفظ ما تكتبه فيه، ولا يستخدم متتبّعات إعلانية. وإن أرسلت بريدك عبر نموذج «أبلغني» فهو يفتح تطبيق البريد لديك لترسل الرسالة بنفسك — لا يُخزَّن هنا شيء.

التواصل

لأي سؤال عن خصوصيتك أو بياناتك: [email protected]


Privacy Policy

Rihla (رحلة) — com.rihla.app

Last updated: 17 August 2026

The short version

What we store

What you write in the app. Tasks, projects, goals, key results, milestones, life areas, identities, habits and their logs, focus sessions, debriefs, scheduled blocks, weekly reviews, notes, cards, subjects, knowledge entries, your inbox, and your account settings. This is the app itself.

Your account. Your email address and password (hashed, managed by Supabase — we never see it), or your display name if you sign in with Google.

Your profile, if you fill it in. Country, phone number, and date of birth. These are entirely optional — the app works without them — but if you enter them they sync to our server along with everything else.

Where it goes

One copy stays on your device (a local database). One copy syncs to the Rihla server (Render) and a Postgres database at Supabase. Nobody else gets to read it: the server scopes every row to the account that owns it and will not hand a row to a request that does not carry that account's token.

The Coach and your AI provider — read this one

The Coach is completely off until you choose a provider and add your own API key for it in Settings. The providers available today are openrouter.ai, api.openai.com, api.anthropic.com, generativelanguage.googleapis.com (Gemini), or any OpenAI-compatible server whose address you type in yourself. If you turn it on, here is what is sent to the provider you chose on every message:

  • Your focus statistics (minutes, golden hour, hourly distribution).
  • The titles of your recent blocks and the intentions you wrote in them.
  • The titles of your open tasks, goals, and projects.
  • Your subject names and your debrief text — what you wrote about your own sessions.
  • Your chat messages and the replies before them.

That is real content you wrote, leaving your device for another company under their policy, not ours. If that is not a trade you want, do not add a key — the rest of the app is unaffected and complete without it. Your key is kept in your device's encrypted storage and is never sent to our server.

One case sends nothing anywhere: if you point Rihla at an OpenAI-compatible server running on your own machine (Ollama, LM Studio, llama.cpp), the request never leaves your device.

The app also asks our server which models are currently available (GET /ai/registry). That request is public and carries neither your account nor anything you wrote — it asks “what models exist today” and nothing else.

Anonymous usage events

Off by default(“Help improve Rihla” in Settings). If you turn it on we record events from a fixed, closed list — app opened, onboarding completed, first focus session — with a timestamp and a random identifier not tied to your account. There are no free-text fields at all, so it is structurally impossible for anything you wrote to leak through it. Turning it off erases what was collected.

Notifications

All notifications are scheduled locally on your device. We do not use a cloud push service and hold no push token for your device.

What we do not do

Deletion and retention

We keep your data for as long as your account exists. When you request deletion a 14-day window begins, during which signing back in cancels it; after that, your data and your account are permanently deleted. Full detail on the account deletion page.

Children

Rihla is not directed to anyone under 13 and we do not knowingly collect their data. If you believe a child under that age has an account, email us and we will delete it.

This website

This site has no login, stores nothing you type into it, and uses no advertising trackers. If you submit your address through the “Notify me” form, it opens your own mail app so you send the message yourself — nothing is stored here.

Contact

Any question about your privacy or your data: [email protected]