Arraf

شروط إنشاء الحساب والخصوصية

الإصدار 2026-10-10-registration-v1، بتاريخ 10 أكتوبر 2026. تخص هذه الشروط إنشاء الحساب وتشغيله وطلبات الخصوصية، ولا تستبدل سجل موافقتك السابق على التجربة الخاصة.

نطاق التسجيل

التسجيل لإنشاء حساب فقط. لا يتيح إدخال توقعات الربع الرابع 2026 مبكرًا، ولا ينشر ملفك أو اسم العرض أو النبذة أو توقعاتك للعامة. المشاركة في الجولات ونشر الملفات أو التوقعات تتطلب إتاحة منفصلة وشروط المشاركة المعروضة حينها؛ إنشاء الحساب ليس موافقة على نشرها.

يتطلب الحساب بريدًا إلكترونيًا واسم عرض وكلمة مرور. نستخدم البريد للتحقق والدخول والاستعادة، واسم العرض لتعريف الحساب، ويمكن اختيار اسم مستعار. البريد غير منشور. النبذة والحساب العام الاختياريان ليسا شرطًا لإنشاء الحساب. اقرأ شروط الحساب وإشعار الخصوصية قبل قبولها وإرسال نموذج التسجيل.

احتفظ بكلمة المرور ورموز التحقق والمتابعة لنفسك. لا تنتحل هوية الآخرين ولا تستخدم الخدمة للإساءة أو للوصول إلى بياناتهم. التحقق من البريد لا يثبت الهوية أو المؤهلات المهنية، وإنشاء الحساب لا يمنح اعتمادًا مهنيًا أو خدمة استثمارية.

البيانات وأغراض استخدامها

نستقبل البيانات التي تدخلها عند التسجيل وتعديل الحساب وإرسال الطلبات: البريد واسم العرض والنبذة والحساب العام الاختياريان ومحتوى طلباتك. نسجل أيضًا بيانات الجلسات ومحاولات الدخول ومؤشرات الأمان مثل عنوان الشبكة والتوقيت، وسجل قبول نسخة الشروط وإجراءات الحساب، لتشغيل الحساب وحمايته ومنع إساءة الاستخدام ومعالجة طلباتك.

نعالج بيانات الحساب اللازمة لتقديم الخدمة التي تطلبها بموجب شروط الحساب، وبيانات الأمان لحماية الخدمة، والبيانات الاختيارية للأغراض التي تختار تقديمها لها. يمكنك ترك الحقول الاختيارية فارغة أو طلب تصحيحها أو إزالتها. عدم تقديم البريد واسم العرض وكلمة المرور يمنع إنشاء الحساب؛ عدم تقديم النبذة أو الحساب العام لا يمنعه.

تُرسل كلمة المرور إلى خدمة المصادقة للتحقق منها، ولا تدرج في نسخة بيانات الحساب. جلسات التطبيق تُدار لدى الخادم، ولا تُسلّم رموز المصادقة الخاصة بمقدم الخدمة إلى شيفرة واجهة التطبيق. لا تطلب المبادرة رقم هوية أو عنوان منزل أو بيانات دفع؛ لا ترسل كلمات مرور أو رموز تحقق أو وثائق هوية أو بيانات حساسة ضمن النبذة أو الطلبات.

المسؤول عن البيانات ومقدمو الخدمة

المسؤول عن بيانات المبادرة هو عبدالله البديري (Abdullah Albudairy)، وتُشغّل الخدمة باسم «إدارة عراف». التواصل وطلبات الخصوصية عبر «ملفي» ثم «طلبات الحساب والخصوصية»، أو صفحة الدعم عند تعذر الدخول. لا ننشر بريدًا شخصيًا أو رقم هاتف للتواصل.

تستخدم الخدمة Vercel للاستضافة، وSupabase لقاعدة البيانات والمصادقة، وResend لرسائل التحقق والاستعادة. قاعدة البيانات والمصادقة ووظائف التطبيق الحالية في سيول، كوريا الجنوبية. معالجة البريد أساسًا في الولايات المتحدة؛ وقد تجري معالجة تشغيلية أو إتاحة للدعم خارج سيول، بما فيها الولايات المتحدة وسنغافورة والاتحاد الأوروبي. تستضيف Vercel تقديم الخدمة عبر شبكة عالمية. توجد أيضًا نسخة احتياطية خاصة مشفرة لدى Google Drive؛ لا نَعِد بحصر موقعها في المملكة. اختيار سيول لا يعني أن جميع المعالجة أو النسخ محصورة هناك.

يستخدم مقدمو الخدمة البيانات اللازمة للمصادقة والاستضافة وتسليم البريد والحماية والتشغيل والنسخ الاحتياطي. بيانات الحساب وطلبات الخصوصية ليست صفحات عامة، ويصل إليها صاحب الحساب والإدارة ومقدمو الخدمة بحسب الحاجة التشغيلية. لا ينشئ التسجيل ملفًا عامًا، ولا ينشر البريد أو محتوى الطلبات.

الاحتفاظ والتنظيف

تنظيف قاعدة البيانات النشطة مفعّل، مع جدولة دفعات كل ساعة: يصبح الحساب غير المؤكد مؤهلًا للتنظيف بعد 7 أيام من إنشائه إذا لم يُستخدم للدخول ولم توجد بيانات أو اعتماديات تمنع حذفه؛ وسجلات الأمان بعد 30 يومًا من تسجيلها؛ والدعم العادي المغلق بعد 30 يومًا من إغلاقه الموثق؛ وسجلات طلبات الحقوق المغلقة وإيصالات التنفيذ بالحد الأدنى بعد 90 يومًا، عندما يكون الطلب مغلقًا والتنفيذ المرتبط به منتهيًا وقد انقضت المدة على آخر إجراء ذي صلة.

تعمل الدفعات ضمن حدود محددة، ولذلك لا تعني هذه المدد الحذف الفوري عند لحظة انتهائها. تُترك السجلات المحمية والطلبات أو الخطط غير المنتهية والاعتماديات غير المدعومة أو الكبيرة للمراجعة. لا يحذف هذا التنظيف الحساب الموثق النشط أو التوقعات المجمدة أو السجل المالي. قد تبقى سجلات تدقيق التسجيل والأمان غير المرتبطة مباشرة بطلب الإغلاق؛ توضح نتيجة الإجراء نطاق ما أزيل وما بقي.

هذه المدد تخص البيانات المؤهلة في قاعدة البيانات النشطة. لا يحذف هذا المسار سجلات مقدمي الخدمة أو النسخ الاحتياطية أو نسخ Google Drive السابقة أو ملفات التصدير التي نُزّلت بالفعل. حذف الحساب النشط ليس تأكيدًا لإتلاف كل النسخ؛ متابعة النسخ والسجلات الخارجية إجراء منفصل تديره إدارة عراف.

طلبات البيانات والتصحيح والإغلاق

يمكنك طلب العلم ببياناتك والوصول إليها والحصول على نسخة منها وتصحيحها وطلب إتلافها، وسحب الموافقة حيث تكون هي أساس المعالجة. سجّل طلبك من «طلبات الحساب والخصوصية» في حسابك. يظهر رقم مرجعي وحالة للطلب؛ إغلاق الطلب إداريًا لا يثبت تسليم البيانات أو حذف الحساب. تراجع الإدارة الطلب وتوضح نتيجة الإجراء أو ما يحتاج إلى متابعة؛ رسالة الدعم وحدها لا تسمح بتغيير حساب أو تسليم بياناته.

لطلب نسخة البيانات، اختر طلب الوصول أو النسخة ثم «تنزيل بيانات حسابي». يلزم دخول حديث لصاحب الحساب، وقد تحتاج إلى تسجيل الدخول مجددًا إذا مضت خمس دقائق. التنزيل خاص ببيانات التسجيل والحساب والطلبات المرتبطة بك ضمن النطاق المدعوم؛ لا يشمل كلمات المرور أو رموز الجلسات أو بيانات الآخرين أو سجلًا ماليًا محميًا أو محادثات دعم غير مربوطة بهوية متحققة أو سجلات مقدمي الخدمة والنسخ الاحتياطية. تجهيز النسخة لا يثبت أن جهازك استلمها.

لطلب إغلاق الحساب، اختر طلب الإغلاق ثم أكده بعد دخول حديث. التأكيد لا يحذف الحساب مباشرة؛ تراجع الإدارة الخطة وتنفذها بتفويض مناسب قبل انتهاء صلاحية التأكيد القصيرة، وقد يلزم تأكيد جديد. المسار الآلي مخصص للحسابات التي تقتصر على التسجيل: يسحب جلسات التطبيق والمصادقة ويحذف بيانات الحساب النشطة المشمولة، مع إيصال مختصر لا يحتوي محتوى البيانات المحذوفة.

إذا وجد سجل مالي ثابت أو بيانات محمية أو اعتماديات لا يدعم المسار إزالتها، لا ينفذ الحذف الآلي وتُحال الحالة إلى الإدارة لتوضيح السبب والمعالجة الممكنة. هذه نتيجة تقنية وليست حكمًا نهائيًا على حقك في الطلب. الإيصال يميز إزالة البيانات النشطة عن متابعة سجلات مقدمي الخدمة والنسخ الاحتياطية؛ لا يعد بإتلافها جميعًا.

عند تعذر الدخول، تتيح صفحة الدعم إيصالًا ورمز متابعة خاصين بالمحادثة فقط. لا يثبتان ملكية الحساب ولا يتيحان بياناته. تنتهي المتابعة بعد 30 يومًا من إنشاء المحادثة، وليس من آخر رد؛ انتهاء المتابعة لا يعني حذف الرسائل. احتفظ بالإيصال والرمز، ولا تعتمد على المحادثة وحدها لتنفيذ حقوق حساب تحتاج إلى التحقق من صاحبه. يمكنك تقديم شكوى إلى الجهة المختصة بحماية البيانات الشخصية.

تحديث الشروط

تُعرض نسخة الشروط المطلوبة عند التسجيل، ويُحفظ قبولك مرتبطًا بتلك النسخة. تبقى الموافقات السابقة مرتبطة بنسخها الأصلية، ولا تُحوّل موافقة التجربة الخاصة إلى قبول تلقائي لهذه النسخة. أي إتاحة لاحقة للمشاركة أو النشر ستعرض شروطها ذات الصلة بصورة منفصلة.


Account Terms and Privacy

Version 2026-10-10-registration-v1, dated 10 October 2026. These terms cover account creation, operation and privacy requests. They do not replace the record of your earlier private-preview consent.

Registration Scope

Registration creates an account only. It does not enable early Q4 2026 forecast entry or publicly publish your profile, display name, biography or forecasts. Round participation and profile or forecast publication require separate availability and the participation terms shown then; account creation is not consent to publish them.

An account requires an email address, display name and password. Email supports verification, sign-in and recovery; the display name identifies your account and may be a pseudonym. Your email is not public. An optional biography and public social account are not required for registration. Read the account terms and privacy notice before accepting them and submitting the signup form.

Keep your password, verification codes and follow-up codes private. Do not impersonate others, misuse the service or access their data. Email verification does not verify identity or professional qualifications. An account provides neither professional accreditation nor an investment service.

Data and Its Uses

We receive data you provide when registering, updating your account and sending requests: email, display name, optional biography and public social account, and request content. We also record session data, login attempts and security indicators such as network address and time, acceptance of a terms version and account actions, to operate and protect accounts, prevent abuse and handle your requests.

We process necessary account data to provide the service you request under the account terms, security data to protect the service, and optional data for the purposes for which you choose to provide it. You may leave optional fields blank or request their correction or removal. Without email, display name and password we cannot create an account; omitting a biography or public social account does not prevent registration.

Your password is sent to the authentication service for verification and is not included in account exports. Application sessions are managed server-side; provider authentication tokens are not delivered to application-interface JavaScript. The initiative does not request identity-document numbers, home addresses or payment details. Do not include passwords, verification codes, identity documents or sensitive data in biographies or requests.

Controller and Service Providers

The initiative's data controller is Abdullah Albudairy (عبدالله البديري), and the service operates as Arraf Management. Contact us through Profile, then Account and privacy requests, or the support page if you cannot sign in. We do not publish a personal email address or telephone number for contact.

The service uses Vercel for hosting, Supabase for its database and authentication, and Resend for verification and recovery emails. The current database, authentication and application functions are in Seoul, South Korea. Email processing is primarily in the United States; operational processing or support access may occur outside Seoul, including the United States, Singapore and the EU. Vercel delivers the service through a global network. An existing private encrypted backup is held with Google Drive; we do not promise Saudi-only storage for it. Seoul selection does not mean all processing or copies are confined there.

Service providers use data needed for authentication, hosting, email delivery, protection, operation and backup. Account data and privacy requests are not public pages; the account owner, management and providers access them according to operational need. Registration does not create a public profile or publish your email or request content.

Retention and Cleanup

Active-database cleanup is enabled, with hourly batch scheduling. An unconfirmed account becomes eligible after seven days from creation if it has never been used to sign in and has no data or dependencies blocking deletion; security records after 30 days from recording; closed ordinary support after 30 days from documented closure; and closed rights requests and minimal execution receipts after 90 days, once the request is closed, related execution is terminal and the interval has passed since the last relevant action.

Batches are bounded, so these intervals do not mean immediate deletion when the period ends. Protected records, unfinished requests or plans, and unsupported or oversized dependencies remain for review. This cleanup does not delete an active verified account, frozen forecasts or financial history. Registration audit records and security records not directly linked to a closure request may remain; the action result identifies what was removed and what remains.

These intervals apply to eligible active-database data. This workflow does not purge provider logs, backups, older Google Drive versions or exports already downloaded. Deleting an active account does not confirm destruction of every copy; external records and copies require separate follow-up by Arraf Management.

Access, Correction and Closure Requests

You may request information about your data, access, a copy, correction and destruction, and withdraw consent where it is the processing basis. Submit your request under Account and privacy requests. A reference and status are shown; administrative request closure does not prove data delivery or account deletion. Management reviews the request and explains the action result or remaining follow-up. A support message alone does not authorize account changes or release of account data.

For a copy, choose an access or copy request, then Download my account data. Fresh owner sign-in is required; you may need to sign in again after five minutes. The private download contains your registration, account and linked request data within the supported scope. It excludes passwords, session tokens, other people's data, protected financial history, support conversations not linked to verified ownership, provider logs and backups. Preparing an export does not prove that your device received it.

To close an account, choose a closure request and confirm it after fresh sign-in. Confirmation does not immediately delete the account. Management reviews and executes the plan with appropriate authorization before the short-lived confirmation expires; renewed confirmation may be needed. The automated path is for registration-only accounts: it revokes application and authentication sessions and removes covered active account data, retaining a minimal receipt without the erased content.

If immutable financial history, protected data or unsupported dependencies exist, automatic deletion does not proceed and management reviews the reason and available handling. This is a technical result, not a final determination of your rights. The receipt distinguishes active-data removal from outstanding provider-log and backup follow-up; it does not promise their complete destruction.

If you cannot sign in, the support page provides a receipt and private follow-up code for that conversation only. They neither verify account ownership nor grant access to account data. Follow-up expires 30 days after conversation creation, not after the last reply; expiry does not delete messages. Keep the receipt and code, and do not rely on the conversation alone to exercise account rights requiring owner verification. Complaints may be submitted to the competent personal-data protection authority.

Terms Updates

The required terms version is shown at registration, and your acceptance is recorded against that version. Earlier acceptances retain their original versions; private-preview consent is not automatically converted into acceptance of this version. Later participation or publication will present its relevant terms separately.