انتقل إلى المحتوى
Yora
الرئيسية الخصوصية الشروط الدعم
حذف الحساب

الخصوصية

سياسة خصوصية يورا

شرح واقعي للبيانات التي يحتاجها التطبيق، ومتى تُرسل إلى خدمات أخرى، وما تستطيع التحكم به.

آخر تحديث: 4 أغسطس 2026الإصدار: 2026-08-04

المحتويات

1. من يدير يورا2. البيانات التي نجمعها3. كيف نستخدمها4. معالجة الذكاء الاصطناعي5. مزودو الخدمة6. البيع والإعلانات7. الاحتفاظ والحذف8. الحماية9. اختياراتك10. العمر11. التواصل والتغييرات

1. من يدير يورا

تشغّل يورا خدمة المساعد الشخصي المتاحة عبر تطبيق iPhone وموقع www.useyora.com. للتواصل بشأن الخصوصية استخدم privacy@useyora.com، وللدعم العام support@useyora.com.

TODO قانوني قبل الإطلاق: لا يحتوي المستودع على الاسم القانوني الكامل للجهة المشغلة أو عنوانها البريدي أو رقم تسجيلها. يجب إضافتها هنا وفي شروط الاستخدام بعد تأكيدها من المالك القانوني.

2. البيانات التي نجمعها

الحساب والدخول

اسم المستخدم، البريد الإلكتروني، حالة التحقق، كلمة مرور مجزأة، معرّف Apple عند استخدام Sign in with Apple، جلسات الدخول، ورموز تحقق/استعادة مجزأة. نسجل أيضًا الموافقات مع عنوان IP وبيانات وكيل المستخدم لأغراض الإثبات والأمان.

الملف والتفضيلات

الاسم، اللغة، الجنس، سنة الميلاد، المنطقة الزمنية، البلد والمدينة والعملة وأيام العمل ومجالات التركيز، وإعدادات العرض والإشعارات والذاكرة. تُحفظ صورة الملف كبيانات صورة إذا اخترتها.

المحتوى الذي تدخله

المحادثات، ملخصاتها وسياقها، المهام والقوائم والمواعيد والتذكيرات والأهداف والمراحل والعادات والروتين واليوميات والمزاج والسجلات الصحية والمصروفات والميزانيات والأشخاص والأحداث والملاحظات والتغذية الراجعة.

الذاكرة والاستنتاجات

حقائق واهتمامات وسمات وأنماط وذكريات قد تستخرجها يورا من المحادثات أو عناصر التطبيق، مع مصدرها ودرجة الثقة والحساسية وتاريخ الصلاحية إن وُجد.

الصوت والصور

يُرفع تسجيل الصوت عند استخدام الإدخال الصوتي لنسخه إلى نص. لا تُخزّن مسارات النسخ الحالية التسجيل الخام في قاعدة البيانات عمدًا؛ قد يُحفظ النص الناتج إذا أرسلته في المحادثة. تُخزن صورة الملف عند اختيارها.

الموقع والطقس

عند السماح، يطلب التطبيق موقعًا منخفض الدقة لعرض الطقس ويرسل الإحداثيات إلى خادم يورا ثم إلى مزود الطقس. قد يستخدم المنطقة الزمنية كتقدير بديل. يمكن حفظ مدينة أو إحداثيات صلاة تختارها ضمن ملفك.

الجهاز والاستخدام

رموز الإشعارات، لغة وتوقيت الجهاز، إصدار التطبيق والبناء، تفاعلات المنتج وسجلات الاستخدام والحدود، ومعرّفات الطلبات اللازمة لمنع التكرار وإساءة الاستخدام.

الأعطال والاشتراكات

رسائل الخطأ ومسار الخطأ والشاشة أو المكوّن والبيانات الفنية المرتبطة، وبيانات معاملة StoreKit وحالة الاشتراك والمنتج وتواريخ الاستحقاق والتجديد.

3. كيف نستخدم البيانات

  • تشغيل الحساب والتحقق من البريد واستعادة كلمة المرور وتسجيل الدخول عبر Apple.
  • تحويل طلباتك إلى مهام ومواعيد وتذكيرات وأهداف وعادات وروتين وخطط ومراجعات.
  • تخصيص الردود بحسب لغتك وتوقيتك وعناصر يومك وذاكرتك وإعداداتك.
  • إرسال الإشعارات التي فعّلتها والتحقق من وصولها.
  • تشغيل الميزات الاختيارية مثل الطقس والصوت والبحث والأماكن وأسعار الصرف عند طلبها.
  • التحقق من المشتريات وإدارة الاستحقاق عبر Apple.
  • حماية الخدمة، تطبيق حدود الاستخدام، اكتشاف محاولات الوصول غير المصرح والتكرار والأسرار داخل الذاكرة، وتشخيص الأعطال.
  • تحسين موثوقية المنتج عبر تحليلات استخدام داخلية لاستخدام التطبيق؛ لا نستخدمها لبناء إعلانات موجهة.

4. معالجة الذكاء الاصطناعي

عندما تراسل يورا، تُرسل رسالتك والسياق المرتبط اللازم إلى مزود ذكاء اصطناعي مهيأ لتوليد الرد أو تنفيذ خطوة تنظيمية.

قد يشمل السياق آخر المحادثة، واللغة والمنطقة الزمنية والاسم، والعناصر ذات الصلة مثل مهامك ومواعيدك وأهدافك وعاداتك وحقائق أو ذكريات مناسبة. لا يحتاج مزود الذكاء الاصطناعي إلى كلمة مرورك أو رمز الجلسة أو رمز الإشعارات.

يدعم الكود الحالي OpenAI وGoogle Gemini وGroq وDeepSeek وQwen عبر Alibaba Cloud DashScope، وقد يختار الخادم مزودًا مختلفًا حسب الإعداد والتوفر ونوع الطلب. بعض وظائف الصوت والصور تستخدم OpenAI عند تفعيلها. قد يوفر المستخدم مفتاح مزود خاصًا به؛ تُخزن هذه المفاتيح مشفرة على الخادم ولا تظهر في تصدير البيانات إلا باسم المزود وتاريخ الإضافة.

المحادثات ليست مشفرة من طرف إلى طرف. تعامل معها كبيانات ترسل إلى خدمة سحابية، وتجنب كلمات المرور وأرقام الهوية والحسابات والسجلات الطبية الكاملة. راجع صفحة شفافية الذكاء الاصطناعي للحدود والتوقعات.

5. مزودو الخدمة والجهات التي تستلم البيانات

  • Railway: استضافة خادم التطبيق وتشغيله.
  • Supabase / PostgreSQL المهيأ: استضافة قاعدة البيانات وفق وثائق النشر الحالية.
  • مزودو الذكاء الاصطناعي المهيؤون: OpenAI وGoogle Gemini وGroq وDeepSeek وAlibaba Cloud DashScope، لمعالجة الرسائل أو الصوت أو الصور بحسب الميزة والإعداد.
  • Apple: Sign in with Apple وStoreKit والتحقق من المعاملات وإدارة الاشتراكات.
  • Expo: تحديثات التطبيق وإرسال الإشعارات.
  • Sentry: تتبع الأعطال ومراقبة الأخطاء عند وجود DSN؛ الإعداد يوقف إرسال بيانات التعريف الافتراضية، لكن سجل الخطأ والبيانات الفنية المرفقة قد تصل إليه.
  • Resend: إرسال رسائل التحقق واستعادة كلمة المرور عند تهيئته.
  • خدمات خارجية حسب الطلب: OpenWeather وOpen-Meteo وTomTom وTavily وNager.Date وExchangeRate-API وAladhan وWikipedia، لإجابات الطقس والأماكن والبحث والعطل وأسعار الصرف وأوقات الصلاة والمعلومات العامة. نرسل المدخل اللازم للميزة فقط.
  • Google connectivity check: قد يجري التطبيق طلبًا فنيًا بسيطًا لاختبار الاتصال، دون إرسال محتوى الحساب عمدًا.
  • الجهات النظامية: إذا كان الإفصاح مطلوبًا قانونًا أو لحماية الحقوق والسلامة.

قد تعالج هذه الجهات البيانات في دول مختلفة وفق عقودها وشروطها وسياساتها. فترات احتفاظها لا يحددها هذا المستودع؛ راجع شروط المزود المطبق.

6. بيع البيانات والإعلانات

لا يحتوي الكود الحالي على شبكة إعلانات أو مسار لبيع البيانات الشخصية أو استخدامها لاستهداف إعلاني. لا نبيع بياناتك ولا نستخدم محتوى محادثاتك للإعلانات. إذا تغير نموذج المعالجة ماديًا، يجب تحديث هذه السياسة وطلب الموافقة المناسبة قبل تشغيل ذلك التغيير حيث يلزم.

7. الاحتفاظ والحذف

تُحفظ بيانات الحساب والمحتوى ما دام الحساب نشطًا أو إلى أن تحذف عنصرًا أو الحساب، ما لم يلزم سجل محدود للأمان أو الامتثال. لا يعرّف الكود مدة موحدة لكل محتوى، لذلك لا نعد بفترة ثابتة غير مطبقة.

  • جلسة الدخول مضبوطة لتنتهي بعد 7 أيام.
  • رموز التحقق من البريد تنتهي بعد 24 ساعة، ورموز استعادة كلمة المرور بعد 30 دقيقة.
  • ذاكرة يورا يمكن حذفها عنصرًا عنصرًا أو كاملة؛ حذف الذاكرة لا يحذف تلقائيًا المهام أو الأهداف أو المواعيد المرتبطة.
  • حذف الحساب يزيل بيانات المستخدم والجلسات في معاملة قاعدة بيانات واحدة.
  • بعد حذف الحساب قد تبقى بصمة معرّف مجزأة وغير مرتبطة بالحساب ضمن سجل أهلية التجربة لمنع تكرار التجربة، لمدة نافذة مكافحة الإساءة التي يطبقها الكود (حتى 12 شهرًا من استخدام التجربة). لا تحتوي هذه البصمة على المعرّف الخام.
  • فترات سجلات مقدمي الخدمات مثل Sentry أو مزودي الذكاء الاصطناعي تخضع لإعدادات وحسابات يورا وشروط المزود الحالية، ولا يثبت المستودع مدة واحدة يمكن التعهد بها.

حذف حساب يورا لا يلغي اشتراك App Store تلقائيًا؛ يجب إدارة الإلغاء من إعدادات اشتراكات Apple. راجع تعليمات حذف الحساب.

8. كيف نحمي البيانات

نستخدم إجراءات تقنية موجودة في الكود، منها نقل HTTPS/TLS، تجزئة كلمات المرور باستخدام bcrypt، جلسات HttpOnly وSameSite، رموز تحقق واستعادة مجزأة وقصيرة العمر، التحقق من رموز Apple، التحقق من المدخلات، حدود الطلبات والتكلفة، فحوص ملكية السجلات، حماية من إعادة إرسال طلبات الصوت، وتشفير مفاتيح مزودي الذكاء الاصطناعي التي يضيفها المستخدم.

لا توجد خدمة آمنة بنسبة 100٪. راجع صفحة الأمان لشرح الحدود الواقعية وكيف تبلغ عن مشكلة.

9. اختياراتك وحقوقك

  • عرض وتعديل ملفك وتفضيلاتك وعناصر يومك من داخل التطبيق.
  • تصدير بيانات الحساب بصيغة JSON من الإعدادات.
  • مراجعة ذاكرة يورا وتصحيحها وتأكيدها وحذفها وتصديرها، وإيقاف التعلم الخلفي أو استدعاء الذكريات الحساسة.
  • حذف المحادثات المرئية أو عناصر منفردة حيث تدعم الشاشة ذلك؛ «مسح المحادثة» الحالي يخفي السجل من نافذة المحادثة ولا يعني حذف الخادم أو الذاكرة.
  • حذف الحساب والبيانات التابعة من الإعدادات.
  • سحب أذونات الموقع والميكروفون والصور والإشعارات من إعدادات iPhone.

للطلبات التي لا تستطيع تنفيذها داخل التطبيق، راسل privacy@useyora.com. قد نطلب التحقق من الهوية قبل تنفيذ الطلب.

10. العمر والخصوصية

يورا غير موجهة لمن هم دون 13 سنة، وتتحقق عملية الإعداد من سنة ميلاد توافق عمر 13 سنة على الأقل. إذا علمنا أن طفلًا دون السن المناسب أنشأ حسابًا، تواصل معنا لحذفه.

11. التواصل والتغييرات

أسئلة الخصوصية والطلبات: privacy@useyora.com. الدعم: support@useyora.com.

قد نحدّث هذه السياسة عندما تتغير الميزات أو المعالجة أو المتطلبات النظامية. سنغيّر تاريخ التحديث ونقدم إشعارًا مناسبًا داخل التطبيق عند التغييرات الجوهرية.

Privacy

Yora Privacy Policy

A factual explanation of the data the app needs, when it goes to other services, and what you can control.

Last updated: August 4, 2026Version: 2026-08-04

Contents

1. Who operates Yora2. Data we collect3. How we use it4. AI processing5. Service providers6. Sale and advertising7. Retention and deletion8. Protection9. Your choices10. Age11. Contact and changes

1. Who operates Yora

Yora operates the personal assistant service available through the iPhone app and www.useyora.com. For privacy matters, email privacy@useyora.com. For general support, email support@useyora.com.

Legal TODO before launch: The repository does not identify the operator’s full legal name, postal address, or registration number. The legal owner must confirm and add them here and in the Terms.

2. Data we collect

Account and sign-in

Username, email, verification status, hashed password, Apple identifier when using Sign in with Apple, sessions, and hashed verification or recovery tokens. Consent records include IP address and user agent for evidence and security.

Profile and preferences

Name, language, gender, birth year, time zone, country, city, currency, workdays, focus areas, and display, notification, and memory settings. A profile photo is stored as image data if you choose one.

Content you enter

Chats, summaries and context, tasks, lists, appointments, reminders, goals and milestones, habits, routines, journals, moods, health logs, expenses, budgets, people, events, notes, and feedback.

Memory and inferences

Facts, interests, traits, patterns, and memories Yora may derive from chats or app items, together with source, confidence, sensitivity, and expiry where present.

Voice and images

A voice recording is uploaded when you use voice input so it can be transcribed. Current transcription routes do not intentionally store the raw recording in the database; the transcript may be stored when sent to chat. A selected profile photo is stored.

Location and weather

With permission, the app requests low-accuracy location for weather and sends coordinates to Yora’s server and a weather provider. It may estimate from time zone instead. A city or prayer coordinates you choose may be saved to your profile.

Device and use

Push tokens, device language and time zone, app and build version, product interactions, usage and quota records, and request identifiers used for replay and abuse prevention.

Crashes and subscriptions

Error messages, stack traces, screen or component, attached technical metadata, and StoreKit transaction, product, entitlement, expiry, and renewal data.

3. How we use data

  • Operate accounts, email verification, password recovery, and Apple sign-in.
  • Turn requests into tasks, appointments, reminders, goals, habits, routines, plans, and reviews.
  • Personalize replies using language, time zone, daily items, memory, and settings.
  • Deliver enabled notifications and test delivery.
  • Run optional features such as weather, voice, search, places, and currency information when requested.
  • Verify Apple purchases and manage entitlement.
  • Protect the service, enforce limits, detect unauthorized access, replay, abuse, and secrets in memory, and diagnose failures.
  • Improve reliability through internal product analytics; these are not used to build targeted advertising.

4. AI processing

When you message Yora, your message and relevant context are sent to a configured AI provider to generate a response or perform an organizational step.

Context may include recent chat, language, time zone, name, and relevant tasks, appointments, goals, habits, facts, or memories. The AI provider does not need your password, session token, or push token.

The current code supports OpenAI, Google Gemini, Groq, DeepSeek, and Qwen through Alibaba Cloud DashScope. The server may use a different provider based on configuration, availability, and request type. Some voice and image functions use OpenAI when enabled. Users may add their own provider key; these keys are encrypted on the server and an export shows only provider name and creation date.

Chats are not end-to-end encrypted. Treat them as cloud-processed data and avoid passwords, government IDs, account numbers, or complete medical records. See AI Transparency for limits and expectations.

5. Service providers and recipients

  • Railway: application server hosting and operation.
  • Configured Supabase / PostgreSQL: database hosting, as identified by the current deployment documentation.
  • Configured AI providers: OpenAI, Google Gemini, Groq, DeepSeek, and Alibaba Cloud DashScope for messages, voice, or images depending on configuration and feature.
  • Apple: Sign in with Apple, StoreKit, transaction verification, and subscription management.
  • Expo: app updates and push delivery.
  • Sentry: crashes and error monitoring when a DSN is configured. Default PII sending is disabled, but stack traces and attached technical metadata may be sent.
  • Resend: verification and password-reset emails when configured.
  • Feature-specific external services: OpenWeather, Open-Meteo, TomTom, Tavily, Nager.Date, ExchangeRate-API, Aladhan, and Wikipedia for requested weather, places, search, holidays, exchange rates, prayer times, and general information. Only feature-relevant input is sent.
  • Google connectivity check: the app may make a small technical request to test connectivity, without intentionally sending account content.
  • Authorities: where disclosure is legally required or needed to protect rights and safety.

These services may process data in different countries under their own agreements and policies. Their retention periods are not defined by this repository; the terms of the active provider apply.

6. Data sale and advertising

The current code contains no ad network or path for selling personal data or using it for ad targeting. We do not sell your data or use chat content for advertising. A material future change would require this policy to be updated and appropriate consent before activation where required.

7. Retention and deletion

Account data and content are kept while the account is active or until you delete an item or the account, unless a limited security or compliance record is needed. The code does not set one universal duration for all content, so this policy does not promise an unimplemented fixed period.

  • Sign-in sessions are configured to expire after 7 days.
  • Email-verification tokens expire after 24 hours; password-reset tokens after 30 minutes.
  • Yora memory can be deleted item by item or all at once. Deleting memory does not automatically delete related tasks, goals, or appointments.
  • Account deletion removes user data and sessions in one database transaction.
  • After account deletion, an unlinkable hashed identifier may remain in the trial-eligibility record to prevent repeated trials for the code’s abuse-prevention window: up to 12 months after trial use. It does not contain the raw identifier.
  • Retention by Sentry or AI providers follows Yora’s configured accounts and the provider’s current terms; the repository does not prove a single period we can promise.

Deleting a Yora account does not automatically cancel an App Store subscription. Manage cancellation in Apple subscription settings. See Delete Account.

8. How we protect data

Implemented controls include HTTPS/TLS transport, bcrypt password hashing, HttpOnly and SameSite sessions, short-lived hashed verification and recovery tokens, Apple token verification, input validation, request and cost limits, record ownership checks, voice-request replay protection, and encryption of user-added AI provider keys.

No service is 100% secure. See Security for realistic boundaries and reporting instructions.

9. Your choices and rights

  • View and edit profile, preferences, and daily items in the app.
  • Export account data as JSON from Settings.
  • Review, correct, confirm, delete, and export memory, and turn background learning or sensitive recall off.
  • Delete individual items where a screen supports it. The current Clear Chat action hides history from the chat window; it does not mean server or memory deletion.
  • Delete the account and associated data in Settings.
  • Withdraw location, microphone, photo, and notification permissions in iPhone Settings.

For requests you cannot complete in the app, email privacy@useyora.com. We may verify identity first.

10. Age and children’s privacy

Yora is not directed to children under 13. Onboarding validates a birth year consistent with an age of at least 13. If you learn that an underage child created an account, contact us to have it removed.

11. Contact and changes

Privacy questions and requests: privacy@useyora.com. General support: support@useyora.com.

We may update this policy when features, processing, or legal requirements change. We will change the update date and provide appropriate in-app notice for material changes.

Yora

مساعد حياة عربي يفهم مقصدك ويساعدك على رؤية يومك بوضوح.

المساعدة

الدعمحذف الحسابsupport@useyora.com

الثقة والقانون

الخصوصيةالشروطالأمانشفافية الذكاء الاصطناعي
© 2026 Yora. جميع الحقوق محفوظة.آخر تحديث للسياسة: 4 أغسطس 2026