سياسة الخصوصية
آخر تحديث: 5 سبتمبر 2026
RaaKey يحوّل هاتفك إلى مفتاح دخول: يصلك طلب التحقّق على الهاتف، توافق عليه، فيدخل المتصفح. هذه الصفحة تشرح ما نجمعه بالضبط، وما لا نستطيع رؤيته حتى لو أردنا.
ما لا نراه أبدًا
- مفاتيح حساباتك (TOTP secrets). تُولَّد وتُخزَّن في المخزن الآمن على هاتفك (Android Keystore). لا تغادره إلا مشفَّرة.
- رموز التحقّق (OTP). تُولَّد على الهاتف وتُختَم لمفتاح متصفحك قبل أن تلمس شبكتنا. نحن ننقل ظرفًا معتمًا لا نملك ما يفكّه.
- رمز القفل (PIN) وعبارة الاستعادة. لا يُرسَلان إلينا في أي حالة.
- محتوى الصفحات التي تزورها. الإضافة لا تطلب صلاحية
<all_urls>ولا تقرأ صفحاتك.
ما نجمعه فعلًا
حسابك
الاسم، البريد الإلكتروني، اللغة، المنطقة الزمنية، وبصمة كلمة المرور (Argon2id — الكلمة نفسها لا تُخزَّن).
أجهزتك
اسم الجهاز الذي تختاره، نوعه (هاتف/متصفح)، حالته، وآخر ظهور. ومعها المفاتيح العامة فقط — المفاتيح الخاصة لا تغادر الجهاز أبدًا.
طلبات الدخول
| نجمع | لا نجمع |
|---|---|
أصل الصفحة (مثل github.com)، اسم المنصّة، وقت الطلب، النتيجة (موافقة/رفض/انتهاء) |
الرمز نفسه، اسم حسابك على المنصّة بشكل مقروء، أو أي شيء من محتوى الصفحة |
عند ربط حساب جديد نحفظ تلميحًا فقط: اسم المنصّة (GitHub) واسم حساب مُقنَّع
من جهازك قبل الإرسال (a***z@g***). السرّ نفسه يمرّ مشفَّرًا من المتصفح إلى الهاتف مباشرة.
الأحداث الأمنية
نوع الحدث ودرجة خطورته، الدولة، نوع الجهاز، عائلة المتصفح، وبادئة عنوان IP لا العنوان الكامل. الغرض الوحيد: اكتشاف محاولات الاختراق على حسابك وتنبيهك.
النسخ الاحتياطية (اختيارية)
إن أنشأت نسخة، فهي تُشفَّر على هاتفك بمفتاح مشتق من عبارة استعادة تعرفها وحدك (PBKDF2-SHA256 بـ300,000 دورة، ثم AES-256-GCM). ما يصلنا: نصّ معتم، وعدد الحسابات، ووسم تكتبه أنت. أسماء الحسابات نفسها داخل النصّ المشفَّر ولا نراها.
إن ضاعت العبارة، لا يمكن استرجاع النسخة — لا منّا ولا من غيرنا. هذا ليس نقصًا؛ هو نفس السبب الذي يجعلنا عاجزين عن قراءتها.
الإشعارات
نستخدم Firebase Cloud Messaging من Google لإيقاظ هاتفك. الرسالة data-only دائمًا: تحمل معرّف الطلب واسم المنصّة فقط. لا تحمل الرمز إطلاقًا — الرمز يُولَّد على جهازك بعد أن يستيقظ. وبذلك لا ترى Google رمزًا ولا سرًّا.
مع من نتشارك
- Google (Firebase Cloud Messaging) — لتسليم الإشعارات، بالمحتوى الموصوف أعلاه.
- مزوّد الاستضافة — يشغّل خوادمنا وقاعدة بياناتنا.
- Google Fonts — لخط هذا الموقع فقط. الإضافة والتطبيق لا يحمّلان أي شيء خارجي.
لا نبيع بياناتك ولا نستخدمها للإعلانات ولا نشاركها مع وسطاء بيانات. لا يوجد تتبّع من طرف ثالث في الإضافة ولا في التطبيق.
مدة الحفظ
- طلبات الدخول والرموز المرحّلة: تُمسح فور استهلاكها أو انتهاء صلاحيتها (دقائق).
- الأحداث الأمنية: تبقى للمراجعة، ثم تُحذف وفق سياسة الاحتفاظ.
- النسخ الاحتياطية: نحتفظ بآخر عشر نسخ، والأقدم يُحذف تلقائيًا. تستطيع حذف أي نسخة فورًا.
- حذف حسابك يحذف أجهزته ونسخه وبياناته المرتبطة.
حقوقك
تستطيع من لوحتك رؤية أجهزتك وإلغاء أيٍّ منها فورًا، ورؤية نسخك وحذفها. لطلب تصدير بياناتك أو حذف حسابك بالكامل راسلنا على mohamedhesham695@gmail.com.
صلاحيات إضافة المتصفح
| الصلاحية | لماذا |
|---|---|
storage | حفظ مفاتيح الجهاز وإعداداته محليًا في المتصفح. |
alarms | إيقاظ الإضافة دوريًا لسؤال الخادم إن كان هناك طلب مُوافَق عليه. |
| أصول محدّدة بالاسم | عرض نافذة الموافقة داخل صفحة تسجيل الدخول للمنصّات المدعومة فقط. القائمة مولّدة من المنصّات المدعومة، ولا تتضمّن <all_urls>. |
| أصل خادمنا | التحدّث مع واجهتنا البرمجية. بدونه لا تعمل الإضافة إطلاقًا. |
الأطفال
الخدمة ليست موجَّهة لمن هم دون 13 عامًا، ولا نجمع بياناتهم عن قصد.
تغييرات هذه السياسة
أي تغيير جوهري سيظهر هنا مع تاريخ تحديث جديد، ونخطرك بالبريد إن كان يمسّ ما نجمعه.
Privacy Policy
Last updated: 5 September 2026
RaaKey turns your phone into your login key: a verification request reaches your phone, you approve it, and the browser signs in. This section is the English equivalent of the policy above.
What we can never see
- Your account secrets (TOTP seeds). Generated and stored in your phone's secure storage (Android Keystore). They never leave it unencrypted.
- Verification codes (OTPs). Generated on the phone and sealed to your browser's key before they touch our network. We relay an opaque envelope we hold no key for.
- Your PIN and recovery passphrase. Never transmitted to us under any circumstance.
- The content of pages you visit. The extension does not request
<all_urls>and does not read your browsing.
What we actually collect
- Account: name, email, locale, timezone, and an Argon2id password hash (never the password).
- Devices: the name you choose, type (phone/browser), status, last-seen time, and public keys only. Private keys never leave the device.
- Login requests: page origin (e.g.
github.com), platform name, timestamps, and the outcome. Never the code itself. - Account enrolment: a platform name (
GitHub) and an account hint masked on your device before sending (a***z@g***). The secret itself travels encrypted from browser to phone. - Security events: event type and severity, country, device type, browser family, and an IP prefix — never the full address. Used solely to detect attacks on your account.
- Backups (optional): encrypted on your phone with a key derived from a passphrase only you know (PBKDF2-SHA256, 300,000 iterations, then AES-256-GCM). We receive opaque bytes, an account count, and a label you write. Account names live inside the ciphertext and are invisible to us. If the passphrase is lost, the backup cannot be recovered — by us or anyone.
Notifications
We use Google Firebase Cloud Messaging to wake your phone. The message is always data-only and carries a request identifier and a platform name. It never carries the code — the code is generated on your device after it wakes. Google therefore sees no code and no secret.
Sharing
Google (Firebase Cloud Messaging) for notification delivery; our hosting provider for servers and database; Google Fonts for this website's typeface only. We do not sell your data, do not use it for advertising, and do not share it with data brokers. There is no third-party tracking in the extension or the app.
Retention
- Login requests and relayed codes: deleted the moment they are consumed or expire (minutes).
- Security events: kept for review, then deleted under our retention policy.
- Backups: the ten most recent are kept; older ones are deleted automatically. You can delete any backup instantly.
- Deleting your account deletes its devices, backups, and associated data.
Your rights
From your dashboard you can see and instantly revoke any device, and view or delete any backup. For a data export or full account deletion, email mohamedhesham695@gmail.com.
Extension permissions
storage— keep device keys and settings locally in the browser.alarms— periodically wake the extension to ask our server whether a request was approved.- Named host permissions — show the approval dialog inside the sign-in page of supported platforms only. The list is generated from the supported-platform registry and never includes
<all_urls>. - Our API origin — talk to our backend. Without it the extension cannot function.
Children
The service is not directed to children under 13, and we do not knowingly collect their data.