Privacy Policy
What we collect, why, who sees it, and how long it is kept — written to be read, not to hide behind.
This is a translation of the Arabic original. If there is any difference or inconsistency between this translation and the Arabic text, the Arabic text prevails.
Who we are
Sihreej is a service run by Ramez Studio (Ramez Medhat Al-Maqtari, Yemen), which is responsible for processing your account data. The projects, tasks, chats and files that companies put in their workspaces are the responsibility of each company; we process them on its behalf and according to its instructions.
We process your data because this is necessary to provide the service you asked for and to protect the service and its users from misuse, and we send the weekly summary unless you turn it off.
1 — What we collect
What you give us
| Item | Required? | Why |
|---|---|---|
| Name | Yes | Your teammates see it |
| Yes | Your identity in the system; invitations and password recovery are sent to it | |
| Password | Yes* | Stored hashed (bcrypt) in a way that cannot be reversed — we cannot see it either |
| Job title · Phone · Photo | No | Optional, shown to your teammates |
| Language and time zone | No | To show dates and the interface the way you expect |
* Unless you sign in with a Google account — then you don't choose a password; we store a random value in its place that no one knows, and you can set your password later from “Forgot your password?”.
What your use creates
- Your work: companies, teams, projects, tasks, comments, milestones and deliverables.
- Your chats in team and engagement channels.
- The files you upload, with their original name, type and size.
- Work hours if you use the timer, and pay rates if whoever runs your company sets them.
- The audit log: who changed a role, who deleted a project, who paid out what was due — with the time and who did it.
What is collected technically
- Your sessions: a token for each device, the type of platform, and when it was last used — so that you can see them and end any of them from Settings.
- Your devices: the device name, platform and app version, and the notification token if you turn notifications on.
- Your connection address (IP) is used to limit requests and prevent guessing, and is kept with audit log events (such as role changes, deletions and payouts) for security purposes. We also record the IP address and time of every sign-in and sign-out, as well as failed sign-in attempts, to protect your account from unauthorized use. We delete these records automatically after 90 days.
- Error reports: when something breaks in the app or on the server, we record the type of error, a short version of its message and where in the code it happened, along with the app version, the platform and the name of the screen — without your name, your email or the content of your work, and we do not link them to your account. They stay on our own servers only, and are deleted after 90 days.
What we don't collect: we don't track you across other websites, we don't set advertising or analytics cookies, and we don't buy or sell data about you. We don't read the content of your work or your chats — unless you ask for support and explicitly allow it.
We use your browser's local storage only to keep your session and your preferences; it is necessary for the app to work, and it is not used for tracking. If you turn on notifications, your browser is registered with Google's notification service so that they can reach you.
2 — Who sees what
Isolation between companies is the foundation Sihreej is built on, not a feature of it. Every row in our database is stamped with its company, and every query is limited to it.
- Your teammates see your name, photo and job title — not your email.
- Your company's admin sees its members and their roles, and your email masked (like r****z@example.com) to tell apart members with similar names.
- Your client sees only what the engagement's visibility policy allows.
- We — the operators of the platform — see only company names, their plans and their counters. No tasks, no chats, no files and no member names.
3 — Signing in with Google
If you choose it, Google gives us your name, email and photo only — we don't ask for or access your email, your files or your contacts. We don't keep any key that would let us access your Google account, and you can withdraw the permission at any time from your account settings there.
4 — Where it is stored, and who processes it with us
| Provider | What it processes |
|---|---|
| Hostinger | Hosting, the database and files — in Europe |
| Mail server | Sending confirmation, recovery and invitation emails |
| Verifying your identity when you choose to sign in with Google | |
| Cloudflare R2 | Database backups (when enabled) — encrypted before they leave the server, and in Europe |
| Google Firebase Cloud Messaging | Delivering mobile notifications — a notification may carry an excerpt of a message or a comment |
Connections to the platform are always encrypted (HTTPS), and we aim to take a backup every day.
5 — How long it is kept
- As long as your account exists, your work data is kept — it is your work.
- Deleted projects, engagements and teams move to the company's Trash, can be restored within thirty days, and are then deleted permanently. Deleted tasks, comments and files, however, disappear immediately, cannot be restored, and are deleted permanently after thirty days.
- When you ask to delete your account, the deletion takes place after 14 days, and you can cancel it by signing in before then. Your personal data is then erased: your name, email, phone, sessions, devices and sign-in log. What you wrote in companies stays with them under the name “Deleted user”, because it is part of their work record. A company of yours with no one in it but you is deleted together with your account.
- When the owner asks to delete the company, the deletion takes place after 14 days, and the owner can cancel it before then; members see the date and clients are notified of it. Its workspace and files are then deleted; its name stays as “Deleted company” in its engagements with other companies, and payment records are kept for as long as accounting regulations require.
| Item | Period |
|---|---|
| Backups on the server | 14 days |
| Encrypted backups in Cloudflare R2 (when enabled) | 30 days |
| Sign-in log | 90 days |
| Error reports | 90 days |
| Company audit log | One year |
| Read notifications | 30 days |
| Invitations not accepted | 30 days after they expire |
| Unfinished sign-up attempts | One day |
| Payment records | As long as accounting regulations require |
| Session token | 30 days, or 14 days without use — whichever comes first |
| Email confirmation code | 15 minutes |
| Password recovery link | One hour |
| Waiting period after a request to delete an account or a company | 14 days before it takes effect |
| Deleted data in backups | Disappears when the backup period ends |
| Code to confirm a deletion or an ownership transfer | 15 minutes |
| Record of a completed deletion | A numeric ID for the account and the dates of the request and of the deletion, with no name and no email |
6 — Your rights
- To read and correct your data from Settings at any time.
- For the company owner to take a copy of its data (JSON), covering projects, tasks, chats and the list of attachments; the files themselves are downloaded one by one. As an individual, you can ask for a copy of your personal data by writing to us.
- To end your sessions on any device remotely.
- To delete your account yourself from Settings (“Delete account”), and for the company owner to delete the company (“Delete company”). This is done with a code sent to your email, with 14 days to change your mind. Anyone who cannot sign in can write to privacy@sihreej.com.
7 — Children
Sihreej is not intended for anyone under sixteen, except through an educational institution that takes responsibility for obtaining the consent of a parent or guardian. If we learn that an account belonging to someone under sixteen was created outside an educational institution, we delete it.
8 — If this policy changes
We update the date above, and we notify users inside the app if the change is significant — we don't change it silently.
9 — Contact
For any question about your privacy, or to ask us to delete your data: privacy@sihreej.com.