العربية

Open the app

Privacy Policy

What we collect, why, who sees it, and how long it is kept — written to be read, not to hide behind.

Last updated: October 2, 2026

This is a translation of the Arabic original. If there is any difference or inconsistency between this translation and the Arabic text, the Arabic text prevails.

Who we are

Sihreej is a service run by Ramez Studio (Ramez Medhat Al-Maqtari, Yemen), which is responsible for processing your account data. The projects, tasks, chats and files that companies put in their workspaces are the responsibility of each company; we process them on its behalf and according to its instructions.

We process your data because this is necessary to provide the service you asked for and to protect the service and its users from misuse, and we send the weekly summary unless you turn it off.

1 — What we collect

What you give us

ItemRequired?Why
NameYesYour teammates see it
EmailYesYour identity in the system; invitations and password recovery are sent to it
PasswordYes*Stored hashed (bcrypt) in a way that cannot be reversed — we cannot see it either
Job title · Phone · PhotoNoOptional, shown to your teammates
Language and time zoneNoTo show dates and the interface the way you expect

* Unless you sign in with a Google account — then you don't choose a password; we store a random value in its place that no one knows, and you can set your password later from “Forgot your password?”.

What your use creates

What is collected technically

What we don't collect: we don't track you across other websites, we don't set advertising or analytics cookies, and we don't buy or sell data about you. We don't read the content of your work or your chats — unless you ask for support and explicitly allow it.

We use your browser's local storage only to keep your session and your preferences; it is necessary for the app to work, and it is not used for tracking. If you turn on notifications, your browser is registered with Google's notification service so that they can reach you.

2 — Who sees what

Isolation between companies is the foundation Sihreej is built on, not a feature of it. Every row in our database is stamped with its company, and every query is limited to it.

3 — Signing in with Google

If you choose it, Google gives us your name, email and photo only — we don't ask for or access your email, your files or your contacts. We don't keep any key that would let us access your Google account, and you can withdraw the permission at any time from your account settings there.

4 — Where it is stored, and who processes it with us

ProviderWhat it processes
HostingerHosting, the database and files — in Europe
Mail serverSending confirmation, recovery and invitation emails
GoogleVerifying your identity when you choose to sign in with Google
Cloudflare R2Database backups (when enabled) — encrypted before they leave the server, and in Europe
Google Firebase Cloud MessagingDelivering mobile notifications — a notification may carry an excerpt of a message or a comment

Connections to the platform are always encrypted (HTTPS), and we aim to take a backup every day.

5 — How long it is kept

ItemPeriod
Backups on the server14 days
Encrypted backups in Cloudflare R2 (when enabled)30 days
Sign-in log90 days
Error reports90 days
Company audit logOne year
Read notifications30 days
Invitations not accepted30 days after they expire
Unfinished sign-up attemptsOne day
Payment recordsAs long as accounting regulations require
Session token30 days, or 14 days without use — whichever comes first
Email confirmation code15 minutes
Password recovery linkOne hour
Waiting period after a request to delete an account or a company14 days before it takes effect
Deleted data in backupsDisappears when the backup period ends
Code to confirm a deletion or an ownership transfer15 minutes
Record of a completed deletionA numeric ID for the account and the dates of the request and of the deletion, with no name and no email

6 — Your rights

7 — Children

Sihreej is not intended for anyone under sixteen, except through an educational institution that takes responsibility for obtaining the consent of a parent or guardian. If we learn that an account belonging to someone under sixteen was created outside an educational institution, we delete it.

8 — If this policy changes

We update the date above, and we notify users inside the app if the change is significant — we don't change it silently.

9 — Contact

For any question about your privacy, or to ask us to delete your data: privacy@sihreej.com.