Privacy policy

Privacy Policy

This policy explains how the Almumayaz Accounting team handles information about visitors to almumayaz.app and Almumayaz Accounting users, including optional Google Drive backups, licensing and support.

Last updated:

Privacy at a glance

Accounting records stay on your main computer, or on the computer running the demo. Licensing services use customer and device information to manage activation and access; they do not receive accounting records.

Google Drive backup is optional in the paid application. Backup contents are encrypted before upload to your account, but some information describing the file remains readable. Disconnecting does not delete earlier backups; you manage their deletion in Drive. The publisher holds separate recovery material that can decrypt a matching backup if its file is available; restoration requires publisher approval.

This website has no advertising, analytics tools or tracking cookies. The sections below explain the data handled by the services and their providers, and how to request access, correction or deletion. Contact: support@almumayaz.app.

Scope and contact

Almumayaz Accounting (المميز للمحاسبة) is the name under which we publish the application and provide this website and support. The information website, application and Google services are distinct products and services; the sections below identify the information involved in each. Contact us about privacy at support@almumayaz.app.

Available features depend on your release, license and configuration. Mobile monitoring and remote access are described separately below because they are being prepared for public availability.

Website and browser preferences

This website version has no visitor accounts, online checkout, subscriptions, advertising or analytics tools. Language is selected by the page URL. Appearance follows your device setting on your first visit, and your choice of light or dark mode is saved only in your browser for future visits; it is not used for tracking or analytics. We do not add tracking cookies or visitor data-collection scripts.

The public website is hosted on Cloudflare Pages. Cloudflare may process your internet connection address (IP address), browser information, pages requested and visit times to deliver and protect the site. Fonts load from the site itself, without connecting to Google Fonts. External links lead to services with their own practices.

Business records and local storage

Almumayaz Accounting processes information your business enters: details about your company and the parties it deals with, materials, invoices, cash transactions, inventory, installments and production where available. It also processes user accounts and permissions, an audit log recording actions in the application, and archived documents.

The standalone demo stores its data on the Windows computer where it runs. The paid application stores its database and archive on the customer’s main computer; approved devices exchange data with that computer according to account permissions. Exports and printed reports go to destinations you select. Accounting records are not uploaded to the activation or license-management service; optional cloud backups and mobile monitoring are described below.

Google Drive: choice, permission and data

Google Drive linking is optional and available in the paid application. The main-computer administrator starts the connection; sign-in and consent take place on Google’s page. Almumayaz Accounting does not receive your Google password. Local accounting and local backups do not require a Google account.

The only requested permission is https://www.googleapis.com/auth/drive.file. It concerns specific files the app creates or that you share with it, rather than unrestricted browsing of your Drive. The current integration creates its backup folder, uploads encrypted backup files and verifies them. It does not request Gmail, contacts or calendar access.

The application reads the account’s email address or display name through Drive to show which account is connected. Google supplies authorization tokens: codes that keep your approved connection working without sharing your password. No separate profile or email permission is requested for the account label.

To upload and verify backups and avoid duplicate uploads, the application processes identifying codes for the backup folder and files, filenames, sizes and technical information about the files. It also uses checksums, calculated values that help confirm a file arrived unchanged.

Backup encryption and authorization storage

Accounting records and attachments inside a backup are encrypted on the main computer before upload to your selected Google Drive account. Some information describing the backup remains readable in the file details or at the start of the file: customer, installation and backup identifiers, creation time, file format, size and checksums. Private recovery keys are not included in the backup file.

The main computer stores a refresh token, which keeps your Google connection active, together with the account name or email address and folder/file identifiers in storage protected by Windows. Temporary access tokens stay only in service memory; Google tokens are not sent to other client computers or phones. Cloud backups are stored in your Google account, not an account belonging to the Almumayaz Accounting team.

Licensing, device administration and account recovery

The Almumayaz Accounting activation service processes the customer name and contact details provided, identifying codes for the product, installation and license, a technical fingerprint used to distinguish the device, computer name, app version, approval requests and license status. Activation and administration services are hosted on Cloudflare. Activation requests do not contain financial records, archived documents or Google authorization tokens.

In releases that support main-computer administration, when the service is configured, the computer sends limited information about approved devices: their names, types and status. It also sends identifying codes for login sessions, their times and whether they are locked. This supports access management and approved actions. Administration requests, decisions and the results of those actions are also recorded.

Username recovery or password reset requires a request from the main computer, independent verification of the requester’s authority and publisher approval. The service exchanges the request type, identifiers, status and necessary verification information. A new password is entered locally and is not sent to the publisher dashboard. User-account recovery is separate from backup restoration.

Update checks and downloads

In releases that support online updates, the application sends information to find an update for your device: the product’s identifying code, operating system and processor type, application type (main, client, demo or mobile), update track (test or stable), and installed version’s build number. The check request contains no customer name, installation identifier, account credentials, license token, accounting records or Google tokens.

The update service and installer files are hosted on Cloudflare, which may process the IP address, request information and request times to deliver and protect the service. Downloads require temporary authorization. The service stores a fingerprint to verify that authorization, the release identifier and expiry time; expired authorization records are removed during cleanup. Expired authorization cannot start a new download.

Mobile monitoring and remote access when available

Mobile monitoring is read-only within the user’s account permissions and package. An approved phone is first paired on the local network using a file exported by the main-computer administrator after approval. Viewing data requires the main computer to remain on and connected; remote access requires internet at both ends. Public availability of mobile monitoring and remote access is still being prepared.

When remote access is used, the database stays on the main computer. The encrypted connection between phone and main computer passes through Cloudflare, which does not decrypt accounting content or store it permanently. The network provider can see connection addresses, times and the amount of data transferred. The connection-routing service keeps identifying codes that do not describe accounting content, and verification fingerprints of routing credentials separate from your account; it does not receive the account password or Google tokens.

The phone keeps pairing and remote-access credentials in storage protected by its operating system. The application does not permanently save passwords, login sessions or financial reports. Switching to another app or the home screen hides the content and ends the login session on the phone. Protect and lock your phone and revoke approval for lost devices.

Use, sharing and support

We use Google data to provide and secure the account-linking and backup features you use, and the specific help you request. Our use and transfer of information received through Google API services follows the Google API Services User Data Policy, including its Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy.

We do not sell or rent Google data, use it for targeted advertising or advertising profiles, or use it for purposes unrelated to the feature you authorized. General human browsing of your content is not allowed. Support involving access to specific data requires your affirmative agreement, except where needed for security or legal compliance as permitted by Google policy. Service providers acting for us are limited to the authorized purpose and must protect the information.

If you send a file, backup or diagnostic record for support, we process it for the help you requested. The publisher holds backup recovery material separately; it can enable decryption of a matching backup if that file is also available, but gives no automatic access to your computer or Drive. Backup restoration requires publisher approval. Please avoid sending unrelated information.

Google processes its account and Drive services under https://policies.google.com/privacy, and Cloudflare processes hosting and network services under https://www.cloudflare.com/privacypolicy/. Email providers process messages you send to support. Each provider has its own independent practices.

Retention, disconnecting and deletion

Business records remain in your installation until removed through appropriate record-management or maintenance procedures. Local backups are separate; configured local retention may remove eligible older copies. Local cleanup does not delete Google Drive backups.

When you disconnect Drive, the application deletes the saved authorization, account name or email address and folder/file links, and attempts to revoke authorization with Google. Uploaded-file identifiers may remain in local backup history, and an offline computer may not deliver the revocation request. You can revoke access directly from your Google account at https://myaccount.google.com/connections.

Disconnecting or revoking app access does not delete files previously uploaded to Google Drive. Manage and delete those files and their Trash through your Drive account. Relinking or changing Google configuration does not automatically transfer or delete old files and may require fresh consent.

We retain licensing, support, administration and recovery information as needed for the service, customer relationship, security and applicable recordkeeping obligations, without one fixed period for every category. Email us to request access, correction or deletion of information we hold. We verify the request and explain any information that needs to be retained. Information held only on your devices or Google account must be managed there; deleting recovery material can make some backups unrecoverable.

Protection and policy changes

Application safeguards include backup encryption and integrity checks, protected authorization, paired devices and permissions, and encrypted connections. No system prevents every loss or unauthorized access. Protect your accounts and devices and keep usable backups.

We update the page date when this policy changes. Before using Google data for a new purpose different from the one disclosed, we explain the change and obtain the necessary consent. For privacy or deletion requests, contact support@almumayaz.app.

Contact us with questions about privacy or these terms.

support@almumayaz.app