Nafis

سياسة الخصوصية لتطبيق نفيس

نفيس تطبيق لمتابعة أسعار الذهب والفضة والعملات والعملات الرقمية، مع خزنة شخصية لممتلكاتك وتنبيهات أسعار وحاسبة زكاة وأخبار. التطبيق بلا حسابات وبلا خادم خاص بنا، وبياناتك المالية لا تغادر جهازك.

آخر تحديث: · تغطي الإصدار 1.18.0 وما بعده · معرّف الحزمة com.mohamedgado.nafis

باختصار

  • لا توجد حسابات، ولا إعلانات، ولا بيع بيانات، ولا خادم يملكه نفيس.
  • خزنتك وأسعارك المسجّلة وأهدافك وصورك وإعداداتك محفوظة على جهازك فقط.
  • يستخدم التطبيق قياسات استخدام مجهولة الهوية (PostHog و EAS) لتحسين التطبيق، وهي لا تتضمن أي مبالغ أو ممتلكات.
  • الموقع والكاميرا والصور اختيارية تمامًا، والتطبيق يعمل كاملًا بدونها.
  • حذف التطبيق يمحو كل بياناتك المخزّنة على الجهاز.

١. من نحن ونطاق السياسة

نفيس (com.mohamedgado.nafis) تطبيق يطوّره ويشغّله فرد واحد: محمد جادو. تغطي هذه السياسة تطبيق نفيس على أندرويد وأي إصدار مستقبلي على iOS، وتغطي كذلك هذه الصفحة نفسها. الصفحة لا تضع كوكيز ولا تحمّل أي ملف من خادم آخر.

يمكنك فتح هذه الصفحة في أي وقت من داخل التطبيق: الإعدادات ← سياسة الخصوصية.

مبدأ التصميم الأساسي: بلا مفاتيح وبلا خادم. كل مصادر البيانات عامة ومجانية، ولا يوجد خادم وسيط يملكه نفيس تمرّ منه طلباتك. يعني ذلك أننا لا نستطيع تقنيًا رؤية محفظتك أو أرصدتك، لأنها لا تُرسل إلى أي مكان.

٢. ما يبقى على جهازك

البيانات التالية تُخزَّن محليًا على جهازك فقط (قاعدة بيانات SQLite، وذاكرة تفضيلات مشفّرة الوصول داخل التطبيق، ومجلد ملفات التطبيق)، ولا تُرفع ولا تُزامَن مع أي خادم:

لا يوجد تسجيل دخول، ولا مزامنة سحابية، ولا نسخة احتياطية تلقائية لدينا. أنت المالك الوحيد لهذه البيانات.

٣. ما يغادر جهازك

لعرض الأسعار والأخبار يتصل التطبيق مباشرة بخدمات عامة. هذه الطلبات لا تحمل هويتك ولا محتوى خزنتك، بل تحمل فقط ما يلزم لجلب المعلومة (رمز الأصل أو كلمة البحث الإخبارية مثلًا). ككل اتصال إنترنت، يرى الخادم المستقبِل عنوان IP الخاص بجهازك ونوع العميل، وهو أمر لا يمكن لأي تطبيق تجنّبه عند جلب بيانات من الشبكة.

الخدمات التي يتصل بها التطبيق وما يُرسل إليها
الخدمة الغرض ما يُرسل
api.gold-api.com أسعار المعادن الفورية رمز المعدن فقط
open.er-api.com أسعار صرف العملات رمز العملة الأساسية
api.coingecko.com أسعار العملات الرقمية معرّفات العملات المطلوبة
query1.finance.yahoo.com السلاسل التاريخية للمخططات رمز الأصل والمدة الزمنية
egrates.com و banklive.net أسعار البنوك المحلية للعملات رمز العملة
api.bigdatacloud.net تحويل الإحداثيات إلى اسم دولة ومدينة إحداثيات تقريبية (فقط عند منحك إذن الموقع)
geocoding-api.open-meteo.com البحث اليدوي عن مدينة نص المدينة الذي تكتبه
bing.com (خلاصات RSS) عناوين الأخبار كلمات الموضوع ورمز الدولة واللغة
skynewsarabia.com، arabic.rt.com، youm7.com، dailynewsegypt.com خلاصات أخبار مختارة طلب الخلاصة فقط
r.jina.ai استخراج نص المقال عند فشل الاستخراج المباشر رابط المقال الذي فتحته
eu.i.posthog.com قياسات الاستخدام وتقارير الأخطاء (خوادم الاتحاد الأوروبي) معرّف مجهول وأسماء أحداث وخصائص عامة (القسم ٧)
u.expo.dev وخدمات EAS تحديثات التطبيق وقياسات الأداء والأعطال إصدار التطبيق ونوع الجهاز ونظام التشغيل وأزمنة التشغيل
play.google.com فتح صفحة المتجر أو نافذة التقييم لا شيء سوى فتح الرابط بطلب منك

لا يستخدم قارئ الأخبار في نفيس متصفحًا مدمجًا (WebView)، لذلك لا تعمل سكربتات الناشرين ولا تُحفظ كوكيز تتبّع عند قراءة مقال داخل التطبيق.

٤. بيانات الموقع

إذن الموقع اختياري ويُطلب فقط أثناء استخدام التطبيق. عند منحه، يستخدم نفيس إحداثياتك مرة واحدة لتحديد دولتك، ثم يرسلها إلى BigDataCloud لتحويلها إلى اسم دولة ومدينة، ليختار العملة وعيارات الذهب وأسعار الصاغة المناسبة لك.

٥. الكاميرا والصور

يمكنك إضافة صورة لأي قطعة في الخزنة، من الكاميرا أو من معرض الصور. تُنسخ الصورة إلى مجلد التطبيق على جهازك ويُحفظ مسارها في قاعدة البيانات المحلية. الصور لا تُرفع ولا تُحلَّل ولا تُشارك، ولا يُطلب إذن الكاميرا أو الصور إلا في اللحظة التي تختار فيها إضافة صورة.

٦. الإشعارات والتنبيهات

كل التنبيهات (حدود الأسعار، تنبيهات الحركة، الملخّص اليومي، الملخّص الأسبوعي، تنبيهات الخزنة) تُحسب وتُطلق على جهازك عبر إشعارات محلية. لا يوجد إشعار دفع من خادم، ولا يُرسل رمز جهاز (push token) إلى أي طرف. تتم مقارنة الأسعار محليًا بعد كل تحديث ناجح، وكذلك عبر مهمة خلفية دورية.

٧. قياسات الاستخدام وتقارير الأعطال

لتحسين التطبيق ومعرفة الشاشات التي تُستخدم فعلًا وأين يحدث خلل، يرسل نفيس أحداث استخدام مجهولة الهوية إلى PostHog (خوادم الاتحاد الأوروبي) وإلى EAS Observe / Expo Insights من Expo.

ما يُرسل

ما لا يُرسل أبدًا

لا يتضمن الإصدار الحالي مفتاحًا لإيقاف القياسات داخل التطبيق. إن رغبت في إيقافها أو في حذف بياناتك المجهولة، راسلنا على البريد في القسم ١٧ وسننفّذ الطلب. نخطط لإضافة مفتاح إيقاف داخل الإعدادات في إصدار قادم.

٨. النسخ الاحتياطي والمشاركة

يتيح نفيس تصدير نسخة احتياطية كاملة (JSON) أو تصدير الخزنة كملف CSV، ومشاركة صور للأسعار أو الحاسبة. كل ذلك يبدأ بطلب منك، ويُكتب الملف في مجلد مؤقت على جهازك ثم يُفتح لك اختيار المشاركة الخاص بالنظام. الملف يذهب حيث ترسله أنت فقط (درايف، واتساب، الملفات)، ولا نستلم نسخة منه. بعد ذلك تحكمه سياسة الخصوصية للتطبيق الذي اخترته.

٩. التحديثات

يستخدم نفيس تحديثات Expo (EAS Update) لتوصيل إصلاحات سريعة دون انتظار المتجر. يتصل التطبيق بخوادم Expo ليسأل: هل يوجد تحديث لهذا الإصدار؟ ويُرسل في الطلب إصدار التطبيق وقناة التحديث ونظام التشغيل ونوع الجهاز. لا تُرسل أي بيانات شخصية أو مالية في هذه العملية.

١٠. أذونات أندرويد

لماذا يطلب التطبيق كل إذن
الإذن إلزامي؟ السبب
الموقع (تقريبي ودقيق) يطلب منك تحديد الدولة لاختيار العملة والأسعار المحلية
الكاميرا يطلب منك تصوير قطعة لإضافتها للخزنة، وتبقى الصورة على الجهاز
الإشعارات يطلب منك تنبيهات الأسعار والملخّص اليومي والأسبوعي
الإنترنت وحالة الشبكة والواي فاي تلقائي جلب الأسعار والأخبار، ومعرفة أنك دون اتصال لعرض شارة عدم الاتصال
الاهتزاز تلقائي تنبيه لمسي مع الإشعار
تنبيه التطبيقات (شارة العداد) تلقائي عرض عدد الإشعارات على أيقونة التطبيق في المشغّلات التي تدعمها
خدمة تعمل في المقدمة وإبقاء المعالج مستيقظًا تلقائي إتمام فحص الأسعار في الخلفية قبل أن ينام الجهاز
التشغيل بعد إعادة التشغيل تلقائي إعادة جدولة تنبيهاتك بعد إعادة تشغيل الجهاز
منبّه مجدول (أندرويد ١٢ فأقل) تلقائي ضبط موعد الملخّص اليومي
قراءة وكتابة التخزين (أندرويد ١٢ فأقل) يطلب منك اختيار صورة من المعرض على الإصدارات القديمة

هذه هي القائمة الكاملة. لا يطلب نفيس الميكروفون، ولا الرسم فوق التطبيقات الأخرى، ولا البصمة، ولا جهات الاتصال، ولا قائمة تطبيقاتك، ولا الموقع في الخلفية. الإصدارات حتى 1.18.0 كانت تُعلن أذونات الميكروفون والرسم فوق التطبيقات والبصمة لأنها دخلت مع مكتبات، ولم يستخدمها التطبيق أبدًا؛ وقد أُزيلت اعتبارًا من الإصدار التالي.

١١. تأمين البيانات

ما لا يُجمع لا يمكن أن يُسرَّب. هذا هو الإجراء الأمني الأول في نفيس: لا خادم، ولا حساب، ولا كلمة مرور، ولا قاعدة بيانات مركزية فيها بيانات مستخدمين يمكن اختراقها. إضافة إلى ذلك:

لا يمكن لأي شخص، بمن فيهم المطوّر، الاطلاع على محتوى خزنتك عن بُعد. إن وجدت ثغرة أمنية، راسلنا على البريد في القسم ١٧ قبل نشرها.

١٢. الاحتفاظ بالبيانات وحذفها

١٣. حقوقك

إن كنت داخل الاتحاد الأوروبي أو المملكة المتحدة أو كاليفورنيا، فلك حقوق الوصول والتصحيح والحذف والاعتراض على المعالجة. عمليًا:

١٤. خصوصية الأطفال

نفيس تطبيق مالي موجّه للبالغين، وهو غير مخصص للأطفال دون ١٣ عامًا، ولا نجمع عن قصد أي بيانات شخصية منهم. إن اعتقدت أن طفلًا أرسل بيانات إلينا، راسلنا وسنتصرف.

١٥. روابط خارجية وخدمات الغير

عند فتح مقال في المتصفح أو زيارة موقع ناشر، تنطبق سياسة ذلك الموقع. سياسات الخدمات المذكورة أعلاه:

١٦. تعديلات السياسة

قد نحدّث هذه السياسة عند إضافة ميزة أو تغيير مصدر بيانات. يظهر تاريخ آخر تحديث أعلى الصفحة، وسجل التغييرات كاملًا متاح في مستودع الصفحة على GitHub. التغييرات الجوهرية سنشير إليها في ملاحظات إصدار التطبيق.

١٧. التواصل

لأي سؤال عن الخصوصية، أو طلب حذف بيانات، أو ممارسة أي من حقوقك: boogado@yahoo.com

المطوّر: محمد جادو · التطبيق: نفيس (com.mohamedgado.nafis)

هذه الصفحة ثابتة ومستضافة على GitHub Pages. لا تضع كوكيز، ولا تشغّل أي قياس، ولا تحمّل خطوطًا أو سكربتات من خوادم أخرى.

التطبيق الذي تغطيه هذه السياسة: نفيس على Google Play.

Privacy Policy for Nafis

Nafis tracks prices for gold, silver, currencies and crypto, and adds a personal holdings vault, price alerts, a zakat calculator and news. It has no accounts and no server of ours. Your financial data never leaves your device.

Last updated: · Covers app version 1.18.0 and later · Package com.mohamedgado.nafis

At a glance

  • No accounts, no ads, no data selling, no server owned by Nafis.
  • Your vault, price history, goals, photos and settings stay on your device only.
  • Anonymous usage analytics (PostHog and EAS) help improve the app and never include amounts or holdings.
  • Location, camera and photos are optional. The app works fully without them.
  • Uninstalling the app deletes everything it stored on your device.

1. Who we are and what this covers

Nafis (com.mohamedgado.nafis) is built and operated by one person, Mohamed Gado. This policy covers the Nafis Android app, any future iOS release, and this page itself. The page sets no cookies and loads nothing from another host.

You can open this page from inside the app at any time: Settings, then Privacy Policy.

The core design principle is keyless and serverless. Every data source is a free public API, and there is no Nafis backend that your requests pass through. As a direct consequence, we cannot see your portfolio or balances, because they are never transmitted anywhere.

2. What stays on your device

The following is stored locally only (a SQLite database, an app-private preferences store, and the app's own file directory). None of it is uploaded or synced:

There is no sign-in, no cloud sync and no automatic backup on our side. You are the only holder of this data.

3. What leaves your device

To show live prices and headlines, the app talks directly to public services. Those requests carry no identity and no vault contents, only what is needed to fetch the information (an asset symbol, a news topic). As with any internet request, the receiving server sees your device IP address and client type. No app can avoid that when fetching data from a network.

Services the app contacts, and what is sent
Service Purpose What is sent
api.gold-api.com Precious metal spot prices Metal symbol only
open.er-api.com Currency exchange rates Base currency code
api.coingecko.com Cryptocurrency prices Requested coin ids
query1.finance.yahoo.com Historical series for charts Symbol and time range
egrates.com and banklive.net Local bank buy and sell rates Currency code
api.bigdatacloud.net Turn coordinates into a country and city name Approximate coordinates (only if you grant location)
geocoding-api.open-meteo.com Manual city search The city text you type
bing.com (RSS feeds) News headlines Topic keywords, country and language code
skynewsarabia.com, arabic.rt.com, youm7.com, dailynewsegypt.com Curated publisher feeds The feed request only
r.jina.ai Article text fallback when direct extraction fails The URL of the article you opened
eu.i.posthog.com Product analytics and error reports (EU servers) Anonymous id, event names, coarse properties (section 7)
u.expo.dev and EAS services App updates, performance and crash metrics App version, device model, OS, launch and navigation timings
play.google.com Opening the store listing or the review prompt Nothing beyond the link you chose to open

The Nafis reader never uses a WebView, so publisher scripts do not run and no tracking cookies are stored when you read an article inside the app.

4. Location data

Location is optional and requested only while you use the app. When granted, Nafis reads your coordinates once to work out your country, then sends them to BigDataCloud to resolve a country and city name, so it can pick the right currency, karat set and local retail prices.

5. Camera and photos

You can attach a photo to a vault piece, from the camera or your gallery. The image is copied into the app's own folder and its path is saved in the local database. Photos are never uploaded, analysed or shared, and the camera or photo permission is requested only at the moment you choose to add one.

6. Notifications and alerts

Every alert (price targets, move alerts, the daily digest, the weekly recap, vault alerts) is evaluated and delivered on your device as a local notification. There are no remote push notifications and no device push token is sent to anyone. Prices are compared locally after each successful refresh and in a periodic background task.

7. Analytics and crash reporting

To improve the app, see which screens are actually used and find what breaks, Nafis sends anonymous usage events to PostHog (EU servers) and to EAS Observe / Expo Insights from Expo.

What is sent

What is never sent

The current release has no in-app switch to turn analytics off. If you want it disabled, or want your anonymous data deleted, email us (section 17) and we will do it. An in-app opt-out is planned for a future release.

8. Backups and sharing

Nafis can export a full backup (JSON), export the vault as CSV, and share price or calculator images. Each one starts with your action. The file is written to a temporary folder on your device and handed to the system share sheet. It goes only where you send it (Drive, WhatsApp, Files), and we never receive a copy. From that point the receiving app's own privacy policy applies.

9. App updates

Nafis uses Expo updates (EAS Update) to ship fixes without waiting for a store review. The app asks Expo's servers whether an update exists for its version, sending the app version, update channel, OS and device type. No personal or financial data is involved.

10. Android permissions

Why each permission is requested
Permission Required? Reason
Location (coarse and fine) You are asked Detect your country to pick currency and local prices
Camera You are asked Photograph a vault piece. The photo stays on the device
Notifications You are asked Price alerts, daily digest and weekly recap
Internet, network and wifi state Granted at install Fetch prices and news, and detect that you are offline
Vibrate Granted at install Haptic feedback with a notification
App badge Granted at install Show a notification count on the icon, on launchers that support it
Foreground service and wake lock Granted at install Finish a background price check before the device sleeps
Run after boot Granted at install Reschedule your alerts after a restart
Scheduled alarm (Android 12 and below) Granted at install Schedule the daily digest at your chosen hour
Read and write storage (Android 12 and below) You are asked Pick a gallery image on older Android versions

That is the complete list. Nafis does not request the microphone, drawing over other apps, biometrics, contacts, your installed app list, or background location. Builds up to 1.18.0 did declare microphone, overlay and biometric permissions that arrived with libraries. The app never used them, and they are removed from the next release onward.

11. How we secure data

Data that is never collected cannot leak. That is the first security measure in Nafis: no server, no account, no password, and no central user database to breach. Beyond that:

Nobody, including the developer, can inspect your vault remotely. If you find a security issue, please email us (section 17) before disclosing it.

12. Retention and deletion

13. Your rights

If you are in the EU, the UK or California, you have rights of access, correction, deletion and objection to processing. In practice:

14. Children's privacy

Nafis is a finance app intended for adults. It is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child sent us data, contact us and we will act on it.

15. External links and third parties

When you open an article in your browser or visit a publisher site, that site's own policy applies. Policies of the services named above:

16. Changes to this policy

We update this policy when a feature or a data source changes. The date at the top of the page reflects the latest version, and the full change history is public in this page's GitHub repository. Material changes will also be called out in the app's release notes.

17. Contact

For any privacy question, deletion request, or to exercise your rights: boogado@yahoo.com

Developer: Mohamed Gado · App: Nafis (com.mohamedgado.nafis)