توضّح هذه السياسة ما تجمعه منصة Mathar من بيانات، ولماذا تجمعها، ومع من تُشارَك، وكم تبقى محفوظة. كُتبت لتُقرأ من إدارة المدرسة ومن وليّ الأمر معاً، لا للمحامين وحدهم.
من نحن، ومن يملك البيانات
Mathar منصة تعلّم تُقدَّم للمدارس باشتراك. المدرسة هي الطرف الذي يقرّر ما يُجمع عن طلابه ولماذا، ونحن نعالج تلك البيانات نيابةً عنها وبتعليماتها. بعبارة قانونية: المدرسة هي المتحكّم بالبيانات، وMathar هي المعالِج.
عملياً هذا يعني أن طلبات الاطّلاع أو التصحيح أو الحذف تُقدَّم إلى إدارة المدرسة أولاً، وننفّذها بناءً على طلبها. ولا نبيع بيانات أي طالب، ولا نستخدمها في الإعلانات، ولا نشاركها مع أي جهة خارج المذكورة صراحةً في هذه الوثيقة.
تُشغَّل Mathar ويطوّرها محمد الحاج علي بصفته مطوّراً مستقلاً، وهو الشخص المسؤول عن المعالجة الموصوفة في هذه الوثيقة وعن الردّ على أي طلب يتعلّق بها.
البيانات التي نجمعها
لا يوجد تسجيل ذاتي في المنصة. كل الحسابات تُنشئها المدرسة، والبيانات التالية هي ما قد تُدخله المدرسة أو ما يُنتَج أثناء الاستخدام:
عن الطالب
- بيانات التعريف: الاسم، الرقم الدراسي، الصف، الجنس، تاريخ الميلاد، صورة الملف الشخصي إن رُفعت.
- بيانات وليّ الأمر: اسم الأب، اسم الأم، رقم هاتف وليّ الأمر، العنوان — تُدخلها المدرسة عند الحاجة.
- بيانات الدخول: رمز الدخول محفوظ مُجزّأً (hashed) لا كنصّ صريح، ومفتاح المصادقة الثنائية إن فُعّلت.
- العمل الدراسي: الإجابات المكتوبة، الاختيارات، صور أوراق الحل بخطّ اليد عند رفعها، ومستوى الثقة الذي يحدّده الطالب قبل الإرسال.
- مؤشرات الأداء: مؤشر الأداء، الرتبة، نقاط الخبرة، السلسلة اليومية، خريطة الإتقان لكل موضوع، الدقّة الأسبوعية، ومؤشرات معايرة الثقة.
- إشارات سلوك آلية: مؤشرات تُرفع تلقائياً عند أنماط إجابة غير معتادة، تُعرض للمعلّم كإشارة لا كحكم، ولا تُتّخذ بناءً عليها إجراءات آلية.
عن الكادر
- الاسم، البريد الإلكتروني، رقم الهاتف، الدور الوظيفي، الجنس، تاريخ الميلاد، وصورة الملف الشخصي إن رُفعت.
- كلمة المرور محفوظة مُجزّأة، ومفتاح المصادقة الثنائية إن فُعّلت.
بيانات تُجمَع تلقائياً
- عنوان IP عند تسجيل الدخول، ويُستخدم لتحديد محاولات الدخول الفاشلة ومنع تخمين كلمات المرور. لا نبني منه ملفاً تعريفياً ولا نتتبّع به التصفّح.
- سجلّات تشغيلية للأخطاء والأداء، وسجلّات استهلاك الذكاء الاصطناعي لأغراض الفوترة والمراقبة.
- رمز إشعارات الجهاز عند السماح بالإشعارات على الهاتف — وهو معرّف يُصدره نظام تشغيل الجهاز ليصل الإشعار إلى ذلك الجهاز وحده. لا يكشف رقم الهاتف ولا موقعه ولا أي تطبيق آخر عليه، ويُحذف عند تسجيل الخروج أو إلغاء تثبيت التطبيق.
- تقارير الأعطال إذا توقّف التطبيق عن العمل فجأة — نوع العطل ومسار الشيفرة الذي وقع فيه، وطراز الجهاز وإصدار نظامه وإصدار التطبيق. لا تتضمّن لقطةً للشاشة ولا نصّ ما كان معروضاً عليها، لأنّ خاصّيتي التقاط الشاشة وتسلسل عناصرها مُعطَّلتان في إعدادات التطبيق تحديداً لهذا السبب: قد تحمل الشاشة سؤالاً وإجابة طالب.
- ملفات المنهج التي ترفعها المدرسة، والصور المستخرجة من صفحاتها.
ما لا نجمعه: لا نستخدم إعلانات، ولا أدوات تتبّع من طرف ثالث، ولا تحليلات سلوكية، ولا نطلب موقع الجهاز، ولا نصل إلى الكاميرا أو الملفات إلا في اللحظة التي يختار فيها المستخدم رفع صورة أو ملف.
لماذا نعالج هذه البيانات
- تقديم الخدمة: توليد سؤال مناسب لكل طالب، تصحيحه، وعرض النتيجة له ولمعلّمه.
- قياس التقدّم: حساب مؤشر الأداء وخريطة الإتقان لتحديد المواضيع التي تحتاج مراجعة.
- إدارة المدرسة: تمكين الإدارة والمعلّمين من متابعة الصفوف والجداول والحضور الدراسي للمهام.
- الأمان: منع الدخول غير المصرّح به، وكشف محاولات تخمين كلمات المرور.
- التشغيل والفوترة: قياس استهلاك الذكاء الاصطناعي لكل مدرسة ضمن الحدّ المتفق عليه.
الأطراف التي تُعالَج لديها البيانات
نستعين بمزوّدي خدمة محدودين، ولكلٍّ منهم دور واحد واضح:
| المزوّد | الدور | ما يصله |
|---|---|---|
| OpenAI (الولايات المتحدة) | توليد الأسئلة، التصحيح، وقراءة صفحات المنهج وأوراق الحل المصوّرة | نصّ السؤال والإجابة، ومحتوى صفحات المنهج، وصور أوراق الحل. لا تُرسَل أسماء الطلاب ولا بيانات أوليائهم مع هذه الطلبات. ووفقاً لسياسة المزوّد المعلنة، لا تُستخدم البيانات المُرسَلة عبر واجهة البرمجة في تدريب نماذجه |
| Cloudflare | تخزين الملفات، شبكة التوصيل، وحماية الوصول | ملفات المنهج وصورها، وأرشيف السجلّات، ومرور الموقع |
| Hostinger (فرانكفورت، ألمانيا) | استضافة الخوادم وقاعدة البيانات | كامل بيانات المنصة، مخزّنة في مركز بيانات داخل الاتحاد الأوروبي |
| Expo / Google Firebase (الولايات المتحدة) | إيصال إشعارات الهاتف | رمز إشعارات الجهاز، وعنوان الإشعار ونصّه كما يظهران على الشاشة. لا تُرسَل معه إجابات الطلاب ولا درجاتهم ولا محتوى الدروس. والإشعار يمرّ بهذين المزوّدين لأن إيصاله إلى هاتف أندرويد لا يتم إلا عبر خدمة الرسائل السحابية من Google |
| Brevo (فرنسا) | إرسال البريد الصادر من عناوين المنصّة | نصّ الرسائل التي نرسلها إلى المدرسة وعنوان المُرسَل إليه، ونسخ منها تبقى محفوظة لدى المزوّد لمدّة محدودة. البريد الوارد إلينا لا يمرّ به |
| Sentry (منطقة الاتحاد الأوروبي) | تقارير أعطال تطبيق الهاتف | نوع العطل ومسار الشيفرة الذي وقع فيه، وطراز الجهاز وإصدار نظامه وإصدار التطبيق. لا تُرسَل معه لقطات شاشة، ولا إجابات الطلاب، ولا أسماؤهم. اختير المزوّد في منطقة الاتحاد الأوروبي فتبقى هذه التقارير مخزَّنة داخل الاتحاد، كما هي حال الخادم نفسه |
نُفصح كذلك عن البيانات إذا ألزمنا بذلك قانون واجب التطبيق، وفي هذه الحالة نُبلغ المدرسة ما لم يمنعنا القانون من ذلك.
حماية بيانات الطلاب
- بيئة مستقلة لكل مدرسة. بيانات كل مدرسة معزولة عن غيرها على مستوى قاعدة البيانات، ولا تستطيع مدرسة الوصول إلى بيانات مدرسة أخرى.
- لا لوحة شرف بين الطلاب. كل طالب يرى رتبته وتقدّمه هو فقط. لا تُعرض درجات طالب لطالب آخر.
- ما يصل الذكاء الاصطناعي محدود. يُرسَل نصّ السؤال والإجابة ومحتوى صفحة المنهج، دون اسم الطالب ودون بيانات وليّ أمره.
- صور أوراق الحل. عندما يرفع الطالب صورة لورقة حلّه، تُعالَج لقراءة ما كُتب فيها ثم تُحفظ ضمن ملفات مدرسته. هذه أوضح نقطة يجب أن تعرفها المدرسة قبل تفعيل هذه الميزة لصفوفها.
- لا إعلانات ولا بيع. بيانات الطلاب لا تُباع ولا تُستخدم في أي استهداف إعلاني، لا من قِبلنا ولا من قِبل أي مزوّد نستعين به.
- الوصول داخل المدرسة محدود بالدور. المعلّم يرى طلابه، والمنسّق يرى الصفوف المسندة إليه، والمدير يرى مدرسته.
- عند انتهاء الاشتراك، تُسلَّم بيانات المدرسة إليها بناءً على طلبها، ثم تُحذف وفق ما هو موضّح في قسم مدة الاحتفاظ.
مدة الاحتفاظ بالبيانات
لا نحتفظ بشيء «إلى الأبد لأنه قد ينفع لاحقاً». هذه هي المدد الفعلية المطبَّقة في النظام:
| النوع | المدة |
|---|---|
| حساب الطالب وسجلّه الدراسي | طوال اشتراك المدرسة، ثم بحسب تعليمات المدرسة عند انتهائه |
| سجلّات النظام التشغيلية | 90 يوماً |
| سجلّات استهلاك الذكاء الاصطناعي | سنة واحدة في قاعدة البيانات، مع أرشفة مبكّرة إلى التخزين |
| الإشعارات | 60 يوماً |
| الإعلانات المدرسية | 90 يوماً |
| تذاكر الدعم | 7 أيام بعد الإغلاق، و90 يوماً كحدّ أقصى |
| لقطات الرتب التاريخية | سنة واحدة |
| النسخ الاحتياطية المشفَّرة | 30 يوماً |
النسخ الاحتياطية مشفَّرة بمفتاح عام، ولا يوجد على الخادم مفتاح يفكّ تشفيرها — أي أن من يخترق الخادم لا يستطيع قراءة النسخ الاحتياطية.
كيف نحمي البيانات
- كل الاتصالات مشفَّرة عبر HTTPS مع إلزام المتصفّح باستخدامه.
- كلمات المرور ورموز الدخول محفوظة مُجزّأة، ولا يمكن استرجاعها كنصّ — حتى نحن لا نستطيع قراءتها.
- مصادقة ثنائية متاحة لجميع الأدوار، وسياسة كلمات مرور تمنع إعادة استخدام آخر كلمات مرور.
- قفل تصاعدي عند تكرار محاولات الدخول الفاشلة.
- لوحة إدارة المنصة غير منشورة على الإنترنت العام، ويُشترط اجتياز تحقّق هوية على حافة الشبكة قبل الوصول إليها.
- قاعدة البيانات وذاكرة التخزين المؤقّت غير منشورتين على الإنترنت، ولا يمكن الوصول إليهما إلا من داخل الشبكة الداخلية.
- النسخ الاحتياطية تُجرى يومياً وتُشفَّر قبل رفعها، وقد جُرِّبت عملية الاستعادة فعلياً لا نظرياً.
لا يوجد نظام محصَّن تماماً. إذا وقع خرق يمسّ بيانات شخصية، نُبلغ المدرسة المتأثّرة دون تأخير غير مبرَّر، مع وصف ما حدث وما نعرفه عن نطاقه وما اتُّخذ من إجراءات.
حقوق الطلاب وأولياء الأمور
لأن المدرسة هي المتحكّم بالبيانات، تُوجَّه الطلبات إليها وهي تتواصل معنا لتنفيذها. الحقوق المتاحة:
- الاطّلاع على البيانات المحفوظة عن الطالب.
- التصحيح إذا كانت بيانات غير دقيقة.
- الحذف ضمن ما لا يتعارض مع التزام قانوني أو سجلّ أكاديمي تحتفظ به المدرسة.
- الحصول على نسخة من بيانات الطالب بصيغة قابلة للقراءة.
- الاعتراض على معالجة معيّنة، ويُبحث الطلب مع المدرسة.
إذا لم تتمكّن من الوصول إلى مدرستك، يمكن مراسلتنا مباشرة على العنوان في نهاية هذه الصفحة، وسنوجّه الطلب إلى المدرسة المعنيّة.
الأطفال
المنصة مخصّصة للاستخدام داخل المدارس، ومعظم مستخدميها قاصرون. لا يستطيع أي طالب إنشاء حساب بنفسه؛ الحسابات تُنشئها المدرسة ضمن علاقتها التعليمية مع الطالب ووليّ أمره، والموافقة على استخدام المنصة تمرّ عبر المدرسة.
لا نوجّه أي محتوى تسويقي للطلاب داخل المنصة، ولا نستخدم بياناتهم لأي غرض خارج تقديم الخدمة التعليمية نفسها.
المنصّة مخصّصة للطلاب من عمر 13 سنة فما فوق. تخدم المنصّة صفوف المرحلتين الإعدادية والثانوية، وتلتزم المدرسة في اتفاقية الاشتراك بألّا تُنشئ حسابات لطلاب دون هذا العمر. ولأن الحسابات تُنشئها المدرسة وحدها ولا يستطيع أحد التسجيل بنفسه، فإن التحقّق من العمر يقع عند إنشاء الحساب لا عند الدخول.
ملفات تعريف الارتباط والتخزين المحلّي
هذا الموقع التعريفي لا يستخدم ملفات تعريف ارتباط للتتبّع، ولا أدوات تحليلات. الشيء الوحيد المحفوظ في متصفّحك هنا هو لغة العرض التي اخترتها، ليبقى اختيارك عند العودة.
داخل التطبيق نفسه تُستخدم بيانات جلسة تقنية للإبقاء على تسجيل دخولك، وهي ضرورية لعمل الخدمة ولا تُستخدم للتتبّع.
التغييرات على هذه السياسة
عند تعديل هذه السياسة يتغيّر تاريخ آخر تحديث أعلى الصفحة. وإذا كان التغيير جوهرياً — كإضافة مزوّد جديد تصله بيانات، أو توسيع ما يُجمع — نُبلغ المدارس المشتركة قبل سريانه.
التواصل
لأي سؤال يتعلّق بالخصوصية أو بحماية بيانات الطلاب:
- المسؤول عن حماية البيانات: محمد الحاج علي
- البريد: support@mathar.app
- للمدارس الراغبة بالاشتراك: contact@mathar.app
This policy sets out what data the Mathar platform collects, why, who it is shared with, and how long it is kept. It is written to be read by a school administrator and by a parent, not only by lawyers.
Who we are, and who owns the data
Mathar is a learning platform provided to schools under subscription. The school decides what is collected about its students and why; we process that data on the school's behalf and on its instructions. In legal terms: the school is the data controller, Mathar is the processor.
Mathar is operated and developed by Mohammad Elhajj Ali, an independent developer, who is the person responsible for the processing described in this policy and for answering any request about it.
In practice this means requests to access, correct or delete data go to the school first, and we act on the school's instruction. We do not sell any student's data, we do not use it for advertising, and we do not share it with anyone beyond the parties named explicitly in this document.
What data we collect
There is no self sign-up. Every account is created by the school. The following is what the school may enter, or what is produced through use:
About the student
- Identity: name, student number, class, gender, date of birth, and a profile photo if one is uploaded.
- Guardian details: father's name, mother's name, guardian phone number, address — entered by the school where needed.
- Credentials: the access code is stored hashed, never in clear text, along with a two-factor key if enabled.
- School work: written answers, selected options, photographs of handwritten work when uploaded, and the confidence level the student sets before submitting.
- Performance signals: the performance index, rank, experience points, daily streak, per-topic mastery map, weekly accuracy, and confidence-calibration figures.
- Automated behaviour flags: raised automatically on unusual answering patterns, shown to the teacher as a signal rather than a verdict. No automated action is taken on them.
About staff
- Name, email address, phone number, role, gender, date of birth, and a profile photo if uploaded.
- The password is stored hashed, along with a two-factor key if enabled.
Collected automatically
- IP address at sign-in, used to count failed attempts and stop password guessing. We do not build a profile from it and do not use it to track browsing.
- Operational logs for errors and performance, plus AI usage logs for billing and monitoring.
- A device notification token once notifications are allowed on the phone — an identifier issued by the device's operating system so a notification reaches that device alone. It reveals no phone number, no location and nothing about other apps, and it is deleted on sign-out or when the app is uninstalled.
- Crash reports if the app stops working unexpectedly — the error type, the code path it occurred in, the device model, its operating system version and the app version. They contain no screenshot and no text of what was on screen, because screenshot and view-hierarchy capture are switched off in the app's configuration for exactly this reason: a screen may hold a question and a student's answer.
- Curriculum files uploaded by the school, and the page images extracted from them.
What we do not collect: no advertising, no third-party trackers, no behavioural analytics, no device location. We access the camera or files only at the moment a user chooses to upload an image or a document.
Why we process this data
- Delivering the service: generating a question suited to each student, grading it, and showing the result to them and their teacher.
- Measuring progress: computing the performance index and mastery map so weak topics can be identified.
- School administration: letting administrators and teachers follow classes, schedules and task completion.
- Security: preventing unauthorised access and detecting password-guessing attempts.
- Operations and billing: measuring each school's AI usage against the agreed cap.
Where the data is processed
We rely on a small number of service providers, each with one clearly defined role:
| Provider | Role | What it receives |
|---|---|---|
| OpenAI (United States) | Question generation, grading, and reading curriculum pages and photographed answer sheets | Question and answer text, curriculum page content, and photographs of handwritten work. Student names and guardian details are not sent with these requests. Per the provider's published policy, data submitted through its API is not used to train its models |
| Cloudflare | File storage, content delivery, and access protection | Curriculum files and their images, log archives, and site traffic |
| Hostinger (Frankfurt, Germany) | Server and database hosting | All platform data, stored in a data centre inside the European Union |
| Expo / Google Firebase (United States) | Delivering phone notifications | The device notification token, and the notification's title and text exactly as they appear on screen. No student answers, grades or lesson content are sent with it. Notifications pass through these two providers because reaching an Android phone is only possible via Google's cloud messaging service |
| Brevo (France) | Sending outbound email from the platform's addresses | The text of messages we send to the school and the recipient address, plus copies retained by the provider for a limited period. Mail coming in to us does not pass through it |
| Sentry (European Union region) | Crash reporting for the phone app | The error type and the code path it occurred in, plus the device model, its operating system version and the app version. No screenshots, student answers or student names are sent with it. The provider's European Union region was chosen, so these reports stay stored inside the Union, as the server itself is |
We will also disclose data where required by applicable law, and in that case we will notify the school unless the law forbids it.
Student data protection
- A separate environment per school. Each school's data is isolated from every other at the database level; no school can reach another school's data.
- No honour board between students. Each student sees only their own rank and progress. One student's grades are never shown to another.
- What reaches the AI is limited. Question and answer text and curriculum page content are sent, without the student's name and without guardian details.
- Photographs of handwritten work. When a student uploads a photo of their working, it is processed to read what was written and then stored among their school's files. This is the clearest point a school should understand before enabling that feature for its classes.
- No advertising, no sale. Student data is never sold and never used for ad targeting, by us or by any provider we use.
- Access inside the school is limited by role. A teacher sees their students, a coordinator sees the classes assigned to them, a director sees their school.
- When a subscription ends, the school's data is handed over on request and then deleted as described under retention.
How long data is kept
We do not keep anything "forever in case it is useful later". These are the windows actually enforced in the system:
| Type | Retention |
|---|---|
| Student account and academic record | For the life of the school's subscription, then per the school's instruction |
| Operational system logs | 90 days |
| AI usage logs | 1 year in the database, archived to storage earlier |
| Notifications | 60 days |
| School announcements | 90 days |
| Support tickets | 7 days after closing, 90 days maximum |
| Historical rank snapshots | 1 year |
| Encrypted backups | 30 days |
Backups are encrypted with a public key, and no key capable of decrypting them is held on the server — so an attacker who compromises the server still cannot read the backups.
How we protect the data
- All traffic is encrypted over HTTPS, with browsers instructed to require it.
- Passwords and access codes are stored hashed and cannot be recovered as text — not even by us.
- Two-factor authentication is available for every role, with a password policy that blocks reuse of recent passwords.
- Escalating lockout on repeated failed sign-in attempts.
- The platform administration console is not published on the public internet and requires an identity check at the network edge before it can be reached.
- The database and cache are not exposed to the internet and are reachable only from the internal network.
- Backups run daily and are encrypted before upload, and the restore procedure has been rehearsed in practice rather than assumed.
No system is perfectly secure. If a breach affecting personal data occurs, we will notify the affected school without undue delay, describing what happened, what we know of its scope, and what has been done about it.
Student and guardian rights
Because the school is the data controller, requests go to the school, which then contacts us to carry them out. The available rights are:
- Access to the data held about the student.
- Correction of inaccurate data.
- Deletion, to the extent it does not conflict with a legal obligation or an academic record the school must keep.
- A copy of the student's data in a readable format.
- Objection to a particular processing activity, which is considered together with the school.
If you cannot reach your school, you may write to us directly at the address at the end of this page and we will route the request to the school concerned.
Children
The platform is intended for use inside schools, and most of its users are minors. No student can create an account themselves; accounts are created by the school within its educational relationship with the student and guardian, and consent to use the platform is handled through the school.
We do not direct any marketing content at students inside the platform, and we do not use their data for any purpose beyond delivering the educational service itself.
The platform is intended for students aged 13 and over. It serves lower- and upper-secondary year groups, and the school undertakes in its subscription agreement not to create accounts for students below that age. Because accounts are created by the school alone and nobody can sign themselves up, the age check sits at account creation rather than at sign-in.
Cookies and local storage
This marketing site uses no tracking cookies and no analytics tools. The only thing stored in your browser here is the display language you chose, so your choice persists on your next visit.
Inside the application itself, technical session data is used to keep you signed in. It is necessary for the service to work and is not used for tracking.
Changes to this policy
When this policy changes, the last-updated date at the top of the page changes with it. If a change is material — such as adding a new provider that receives data, or widening what is collected — we notify subscribing schools before it takes effect.
Contact
For any question about privacy or student data protection:
- Responsible for data protection: Mohammad Elhajj Ali
- Email: support@mathar.app
- Schools interested in subscribing: contact@mathar.app