المسار الدراسي Privacy Policy
Effective date: 12 September 2026 • Publisher: Mohas Team • App identifier: com.almutawkel.studycards
This policy describes how المسار الدراسي (Masar) handles information on iOS, Android, and supported web builds. Masar is an offline-first educational study app intended primarily for students. It does not include advertising SDKs and does not use behavioral advertising or cross-app tracking.
1. Information we process
Most study content and progress are stored locally on the user's device. Cloud features are used only where needed for account identity, protected-content access, device security, notifications, reporting, synchronization, and online-content delivery.
When a user signs in or uses cloud features, Masar may process:
- Firebase user ID, email address, email-verification state, authentication provider, and account timestamps.
- Google Sign-In display name and profile-photo URL when the user chooses Google Sign-In.
- Apple Sign-In identity information made available by Apple when the user chooses Sign in with Apple, which may include an Apple relay email address and a name when Apple provides it.
- Protected-content eligibility, package, or access/entitlement status used to determine which study content the account may access.
- Account-security device records such as a random installation/device identifier, device/model label, platform/OS, app version, first-seen/last-active time, sign-out state, and revocation state.
- Push-notification registration tokens when the user allows notifications, so Masar can deliver app or study notifications.
- Signed-in study activity metadata such as content downloads, study type, grade, subject/chapter, item count, duration, app/content version, and timestamps. Anonymous sessions and administrator test sessions are not uploaded as normal user history.
- If the user explicitly opts in to the public study leaderboard: the chosen display name, school grade, aggregate Cards/MCQ/Wizari points, aggregate study duration, rank-related totals, and update timestamps. Email address, Firebase UID, and detailed question history are not displayed to other students.
- Optional encrypted structured sync data and the metadata required to maintain that sync.
- Study-content reports deliberately submitted by the user, including a limited snapshot of the reported item, reason, optional note, app version, context, grade/profile, and account ID.
Masar does not intentionally collect contacts, precise location, IMEI, hardware serial numbers, or advertising identifiers for these features, and it does not sell personal data.
2. Protected content access
During Masar's initial launch period, certain protected educational content is not offered for individual purchase. Access is enabled manually by the Masar team for selected authorized accounts as part of controlled launch and access management.
The current student-facing app does not offer a payment, purchase, subscription, or external checkout flow for protected study content. Users do not enter payment-card information into Masar to receive protected-content access in the current version.
Masar retains only the protected-content eligibility and access/entitlement information reasonably needed to determine which protected content an authenticated account may use.
3. Service providers
- Google Firebase Authentication for account authentication.
- Cloud Firestore for account/profile records, protected-content access entitlements, device security, protected-content metadata/chunks, notification registration, activity history, optional encrypted sync, and user-submitted study-content reports.
- Firebase Storage for publisher-managed Visual Learning packages and related educational assets delivered by the app.
- Firebase Cloud Messaging for optional remote notifications when notification permission is granted.
- Google Sign-In when the user chooses Google authentication.
- Sign in with Apple when the user chooses Apple authentication on supported Apple platforms.
- Apple App Store / Google Play for distribution of the app on supported platforms.
These providers may process ordinary service-delivery information such as IP address, device/network information, authentication metadata, and request timing according to their own terms and privacy policies.
4. Local storage and encryption
Downloaded protected study packages such as Cards, MCQ, and Wizari content are stored locally in encrypted form rather than as plain downloadable archives.
- iOS: protected downloadable content is encrypted with AES-256-GCM, with the local encryption key stored through iOS Keychain-backed secure storage.
- Android: protected downloadable content uses the app's Android Keystore-backed protection path.
- Web: supported web builds use an encrypted local cache with a browser-local secure-storage key.
Protected content is decrypted only when required for local study use. No security system can guarantee absolute protection.
5. Notifications and reports
Masar can provide optional local study reminders and remote app notifications. Notification permission is requested from the operating system before remote notification registration is used. Users can disable notifications through device settings and applicable in-app settings.
Cards, MCQ, and Wizari study items may include an in-app Report action. A report is sent only when the user intentionally submits it and may contain a limited snapshot of the reported item, a reason, an optional note, app version, grade/profile, and account identifier so authorized administrators can investigate quality or safety issues.
6. Account and data deletion
Users can permanently delete their cloud account inside the app through Settings → Account & Firebase → Cloud account → Delete cloud account. The app may require reauthentication before deletion.
Full cloud-account deletion removes the Firebase Authentication account and account-owned cloud data that the app is designed to remove, including profile data, protected-content access entitlements, device records, encrypted sync records/metadata, user activity history, and Cards/MCQ/Wizari correction reports associated with that account.
Local offline study data remains on the device until the user removes downloaded content, clears app data, or uninstalls the app. More information is available on the account deletion page.
Minimal records may be retained only where reasonably necessary to comply with law, address fraud/security issues, or establish or defend legal claims.
7. Students and minors
Masar is intended for educational study and may be used by students. Where applicable law requires a parent or guardian to authorize a minor's account creation or use of online features, that authorization should be obtained before those features are used.
8. Educational material and third-party references
Masar does not provide users with third-party source PDF files through the student app. Third-party reference material may be consulted during educational content preparation, while original source PDF files, pages, and branding are not distributed to students through Masar.
Third-party software packages and frameworks used by the app remain subject to their respective licenses.
9. Contact
For privacy, support, or deletion questions, contact Masar through Telegram @almasarapp. Publisher: Mohas Team.
ملخص سياسة الخصوصية بالعربية
المسار الدراسي تطبيق تعليمي يعمل بصورة أساسية محليًا على جهاز المستخدم، ولا يحتوي على إعلانات أو تتبع إعلاني سلوكي. عند استخدام الحساب أو الميزات السحابية قد يعالج التطبيق البريد الإلكتروني، معرّف Firebase، مزود تسجيل الدخول بما في ذلك Google أو تسجيل الدخول باستخدام Apple عند اختياره، حالة أهلية أو صلاحية الوصول إلى المحتوى المحمي، سجلات أمان الجهاز، رمز الإشعارات عند السماح بها، وسجل نشاط دراسي محدود للحساب المسجل.
تُستخدم Firebase Storage لتخزين وتقديم حزم الرسومات والمخططات التفاعلية وملفات Visual Learning والأصول التعليمية المرتبطة بها التي ينشرها فريق المسار.
لوحة المتصدرين اختيارية. عند تفعيلها يظهر للطلاب المسجلين فقط اسم العرض الذي يختاره المستخدم والمرحلة الدراسية والترتيب ومجاميع نقاط البطاقات وMCQ والوزاريات ومدة الدراسة الإجمالية. لا يظهر البريد الإلكتروني أو معرّف Firebase أو سجل الأسئلة التفصيلي للطلاب الآخرين، ويمكن إيقاف الظهور من صفحة «مساري».
خلال مرحلة الإطلاق الأولى للمسار، لا يُعرض بعض المحتوى الدراسي المحمي للبيع الفردي. يمنح فريق المسار الوصول يدويًا لحسابات مخولة محددة ضمن إدارة الإطلاق والوصول. ولا يوفر التطبيق الموجّه للطلاب حاليًا مسار دفع أو شراء أو اشتراك أو تحويل إلى صفحة دفع خارجية للوصول إلى هذا المحتوى.
الحزم الدراسية المحمية مثل البطاقات وMCQ والوزاريات تُحفظ محليًا بصورة مشفرة. على iOS يستخدم التطبيق AES-256-GCM مع مفتاح محفوظ في تخزين آمن مدعوم بـ Keychain، وعلى Android يستخدم مسار الحماية المدعوم بـ Android Keystore، وعلى الويب يستخدم مخزنًا محليًا مشفرًا.
يمكن للمستخدم حذف حسابه السحابي نهائيًا من داخل التطبيق، ويشمل الحذف بيانات الحساب السحابية المرتبطة به مثل الملف الشخصي وحالة الوصول إلى المحتوى المحمي وسجلات الأجهزة والمزامنة المشفرة وسجل النشاط وتقارير تصحيح البطاقات وMCQ والوزاريات. تبقى البيانات المحلية على الجهاز إلى أن يحذفها المستخدم أو يمسح بيانات التطبيق أو يزيل التطبيق.
لا يبيع المسار بيانات المستخدمين الشخصية. للاستفسارات المتعلقة بالخصوصية أو الدعم: @almasarapp.