1 مقدمة وفلسفة الخصوصية
نرحب بكم في خدمات وتطبيقات NoctraLab. نحن نؤمن بأن الخصوصية حق أصيل لكل مستخدم، ولذلك صممنا أنظمتنا لتعمل وفق مبدأ انعدام المعرفة الكامل (Zero-Knowledge Architecture). يعني هذا المبدأ أن محتوى رسائلك المشفرة يظل سرياً بينك وبين المستلم المحدد، ولا يمتلك فريق عملنا ولا خوادمنا أي وسيلة تقنية للاطلاع على ما تكتبه أو تشاركه.
تعهد الخصوصية الصارم: لا تقوم NoctraLab ببيع بيانات المستخدمين، ولا نشاركها مع جهات إعلانية، ولا نستخدم أي برمجيات تتبع مخفية داخل التطبيق.
2 البيانات التي لا نصل إليها إطلاقاً
من خلال تصميمنا المعماري المشفر، نضمن عدم وصولنا نهائياً إلى الفئات التالية من البيانات:
محتوى الرسائل غير المشفر
تتم معالجة التشفير وفك التشفير على هاتفك المحمول حصرياً، ولا يغادر هاتفك أي نص صريح.
الرمز السري الخاص بالرسالة (PIN)
يتحقق النظام من صحة الرمز باستخدام بصمات تجزئة مشفرة دون معرفة أو حفظ الرقم السري الفعلي.
قائمة الأسماء وجهات الاتصال
لا يطلب تطبيقنا صلاحية الوصول إلى دليل الهاتف أو جهات الاتصال الخاصة بك.
الموقع الجغرافي الدقيق
لا نطلب ولا نسجل إحداثيات موقعك الجغرافي (GPS) تحت أي ظرف.
3 البيانات التقنية المحدودة التي نتعامل معها
لغرض تمكينك من استخدام الخدمة وضمان أمن الحساب ومنع الهجمات الإلكترونية، يتعامل النظام فقط مع البيانات التقنية الدنيا التالية:
اسم المستخدم (Username): معرف تختاره لتمكين الوصول إلى حسابك، ويتم ربطه برموز مصادقة مشفرة.
معرف الجهاز التقني (Device ID): معرف عشوائي يتم توليده برمجياً لتنظيم الجلسات النشطة ومنع سرقة الجلسات.
كلمات المرور المشفرة: لا نخزن كلمة المرور بشكل صريح، بل تتم حمايتها باستخدام خوارزمية التجزئة المعقدة PBKDF2 المدعومة بقيم عشوائية فريدة (Salt & Pepper).
عنوان الإنترنت المجهول (IP Address): يُستخدم مؤقتاً عبر خدمات الحماية السحابية لمنع هجمات الحرمان من الخدمة وهجمات التخمين، ولا يُربط بهويتك الشخصية.
4 دورة حياة الرسائل والإتلاف الفوري
تم تصميم النظام لحماية الرسائل الحساسة لفترات محددة:
• تحديد مدة الصلاحية (TTL): تحدد مدة بقاء الرسالة المشفرة في النظام، وبمجرد انتهاء الوقت يتم إتلافها تلقائياً وبشكل نهائي.
• القراءة لمرة واحدة (View Once): عند تفعيل هذا الخيار، يتم إتلاف مفتاح التشفير ومسح الرسالة فور قيام المستلم بفتحها بنجاح، مما يجعل استرجاعها مستحيلاً برمجياً.
5 تدابير الأمان الفنية المطبقة
نطبق أعلى المعايير الهندسية المعترف بها دولياً:
• تشفير محلي عالي القوة باستخدام AES-256-GCM مع مفاتيح مصادقة فريدة لكل رسالة.
• اتصالات شبكية مشفرة بالكامل عبر بروتوكول TLS الحديث (HTTPS) مع حظر الاتصالات غير الآمنة.
• حماية واجهات الخدمة ضد الروبوتات وهجمات التخمين المؤتمتة باستخدام خدمة Cloudflare Turnstile دون الاعتماد على ملفات تعريف الارتباط الإعلانية.
6 حقوق المستخدم وآلية حذف الحساب والبيانات
التزاماً بمتطلبات متجر Google Play وقوانين حماية البيانات العالمية، نمنح كل مستخدم السيطرة الكاملة على بياناته:
• يحق لك طلب حذف حسابك نهائياً في أي وقت. عند طلب الحذف، يتم مسح اسم المستخدم وسجلات الجلسات ومفاتيح المصادقة المرتبطة به من قاعدة البيانات فوراً.
• لتقديم طلب حذف الحساب أو الاستفسار عن بياناتك، يمكنك التواصل مباشرة مع فريق الدعم عبر البريد الإلكتروني المعتمد: support@noctralab.tech، وسيتم تنفيذ طلبك فوراً ودون تأخير.
7 خصوصية الأطفال والقصّر
خدمات NoctraLab غير موجهة للأطفال دون سن الثالثة عشرة عاماً (أو السن القانونية المحددة في بلدك). نحن لا نجمع عن قصد أي بيانات تخص الأطفال، وفي حال اكتشاف أي تسجيل مخالف نقوم بمسحه على الفور.
8 قنوات التواصل الرسمية
لأي استفسارات قانونية أو تقنية تتعلق بسياسة الخصوصية، يرجى التواصل معنا عبر:
البريد الإلكتروني المعتمد: support@noctralab.tech
الموقع الإلكتروني الرسمي: https://info.noctralab.tech
1 Overview & Zero-Knowledge Architecture
This Privacy Policy explains how NoctraLab operates and protects user privacy across its applications and backend infrastructure. NoctraLab is engineered on a rigorous Zero-Knowledge Architecture. Your sensitive messages are encrypted locally on your personal device prior to transmission; neither our servers nor our personnel possess the cryptographic capability to decrypt, inspect, or reconstruct your cleartext content.
Core Privacy Guarantee: NoctraLab does not sell personal data, we do not monetize user telemetry, and our software contains zero third-party advertising or analytics trackers.
2 Data We Never Collect or Process
By cryptographic design and operational policy, the following data categories are completely excluded from our access:
Unencrypted Message Plaintext
All encryption and decryption operations occur exclusively within your client environment via AES-256-GCM.
User PINs & Secret Codes
Access verification relies on HMAC-derived commitment tokens without ever transmitting or storing raw PIN values.
Contacts & Address Books
NoctraLab does not request or require permissions to access your personal contact lists or address book.
Precise Geolocation Data
We do not collect, request, or monitor GPS or real-time location metrics under any circumstances.
3 Limited Technical Data Collected
To maintain service integrity, provide account functionality, and defend against malicious attacks, we process strictly minimal technical artifacts:
Account Identifier (Username): A user-defined credential used to authenticate your session state.
Pseudorandom Device Identifier: An ephemeral 16-byte cryptographically random token used to isolate authenticated sessions and prevent credential replay.
Hashed Credentials: Passwords are never stored in plaintext. Passwords are fortified using 100,000 PBKDF2 iterations with unique salts and server-side secret peppers.
Network Telemetry: Transient IP addresses are inspected exclusively at the Cloudflare security edge to enforce sliding-window rate limits and deflect distributed brute-force abuse.
4 Ephemeral Lifespan & Irreversible Destruction
NoctraLab enforces deliberate lifecycle controls on all shared encrypted payloads:
• Configurable Time-To-Live (TTL): Payloads expire automatically based on the sender's policy. Upon expiration, associated key material is purged permanently.
• View Once Enforcement: When enabled, cryptographic release tokens are atomically revoked upon the first successful recipient decryption, rendering any future access attempt mathematically impossible.
5 Security Architecture
We implement comprehensive industry-standard technical safeguards:
• Local symmetric encryption utilizing AES-256-GCM with 96-bit unique nonces and 128-bit authentication tags.
• Modern TLS 1.3 / HTTPS transport encryption exclusively; unencrypted traffic is rejected unconditionally.
• Abuse prevention powered by privacy-preserving Cloudflare Turnstile challenges without tracking cookies.
6 User Rights & Account Deletion
In compliance with the Google Play User Data Policy and applicable privacy frameworks (including GDPR):
• Users possess the unrestricted right to terminate their accounts and request complete deletion of all associated authentication records.
• To initiate an immediate account deletion or inquire regarding stored technical data, please transmit your request directly to our designated support mailbox: support@noctralab.tech. Requests are executed expeditiously upon identity verification.
7 Child Privacy (COPPA Compliance)
Our services are not targeted at or intended for individuals under 13 years of age. We do not knowingly collect personal information from children. If we identify that account information belongs to an ineligible minor, it will be promptly removed.
8 Official Contact Information
For legal inquiries, privacy concerns, or data requests, contact NoctraLab through:
Support Mailbox: support@noctralab.tech
Official Website: https://info.noctralab.tech