Privacy Policy
27 August 2026 update: We added clear information about PostHog product analytics, masked session replay, and iOS network-performance measurements.
1. Who we are
Muamer (مُعَمِّر) is a business service for managing finishing-project accounts and records through a mobile app (iOS and Android). Every workspace belongs to an engineering company. We operate the service under the Muamer trade name. The official contact channel for this policy and for exercising your rights is support@muamer.net.
2. What data we collect
a. Account and sign-in data
- Your name and email address when you create an account. The app does not ask for the account holder's phone number during registration.
- A cryptographic password hash, or the account-link identifier, identity data, and access or refresh tokens made available by Google or Apple if you choose either sign-in method. Sensitive OAuth token fields are encrypted at rest.
- Your user ID, the IDs and names of organizations you belong to, and the roles, permissions, and invitations connected to those memberships.
- Your answer to the optional “How did you hear about Muamer?” question, asked once when you create your first company. If you pick “Something else”, the text you type is stored as written, so please do not include other people’s names or any third-party information. The answer is used only to understand where our users come from; it is never shown to any other user, never shared with anyone, and it is deleted when the account is deleted.
b. Organization and project data
- Project data, including project name, address, status, dates, notes, and client-portal settings.
- Business records the organization enters about clients, contractors, vendors, and team members, such as names, phone numbers, email addresses, and notes.
- Project-accounting records: material purchases, client payments, contractor payments, amounts, dates, categories, descriptions, notes, profit configuration, and supervision fees. These are bookkeeping entries inside a project; we do not collect payment-card or bank-account details to process payments.
- Photos, videos, documents, receipts, attachments, and the metadata needed to display and associate files with a project.
c. Data from your device that you choose to share
- If you use the contact picker, the app reads the name and phone numbers of only the contact you select, then adds those details to a client, contractor, or vendor record after you confirm.
- If you select a photo, video, or document, or take a photo with the camera, we upload the chosen file as an attachment to the record you specify. A staged storage copy may be created before the file is attached to that record.
- Muamer does not request precise-location permission or collect precise location for finishing-project account and record features. Google Sign-In may process coarse location, device identifiers, and technical usage data under Google's practices for its embedded sign-in component.
d. Usage and diagnostic data
- Account- and organization-linked product events, such as the action type, result, time, app version, and, where relevant, project ID, IP address, and device or browser user agent. We use these events to operate and secure the service and understand feature use. We record the request IP and retain it in our application events. We send the part used to understand feature use and diagnose failures to PostHog: the event name, result, and time, the user ID and organization ID, the screen name as a route pattern (for example
/projects/[projectId]) rather than a resolved path, and the IP address, which PostHog may use to derive an approximate location. Handled GraphQL server-error events sent to PostHog may include the error type (error_class), error code (error_code), and response status (status_code), together with internal user, organization, and event-record identifiers, and a request identifier inside the anonymous identifier when available. These events do not include the error message, client names, notes, amounts, any text you type, a GraphQL query or its variables, a request path, an operation name, request or response bodies, or a stack trace. - Crash, performance, and other diagnostic data processed by Sentry and linked, when signed in, to the user ID, email address, organization ID, and organization name. Error logs and failed-operation values may include business data from the request, such as names, notes, or amounts. Screen replay and screenshot attachment are disabled in Sentry.
- Masked visual recordings of app sessions, processed by PostHog. Recordings are captured as a sequence of screenshots, and masking is applied on your device before anything is uploaded: all rendered text (client names, project names, amounts, and any text you type), all images and attachments, and the contact and photo picker screens appear blocked out. We use them to see which step users stop at inside the app. These recordings do not include console diagnostic output. On iOS, these recordings may also include technical network-request measurements such as duration, size, and response status, but not request or response bodies.
e. Beta program data
If you ask to join the beta through our channels, we collect the email address you provide (your Apple ID email on iPhone or your Google Play account email on Android) and use it only to send your invite through Apple's TestFlight or Google Play testing. We remove it from our records when the beta ends or upon your request, whichever comes first.
3. Why we use this data
- To create accounts, verify identity, and operate organization workspaces, permissions, and project features.
- To store and display records and attachments to authorized organization members and clients.
- To send verification, password-reset, and membership-invitation emails, and to answer support and rights requests.
- To protect accounts, prevent abuse, investigate failures, improve stability and performance, and understand feature use.
- To perform our contract with the organization and meet legal obligations where they exist.
We do not display advertising, sell your data, use it to track you across other companies' apps or websites, or share it with anyone for marketing.
4. Who processes data with us
We share only what is necessary with service providers acting on our instructions to operate Muamer:
- Apple and Google: for the sign-in method you choose and for TestFlight or Google Play beta invitations.
- Sentry: to process crash, performance, and diagnostic data.
- PostHog: to process the usage events described in section d above, so we can see which product steps are completed and where people stop. Data is processed on PostHog servers in the European Union. We do not send your email address. Session replay is enabled with them in the masked form described in section d above.
- Expo: to check for and download application updates through EAS Update.
- Hosting, storage, and backup providers: to run the API and databases and retain attachments; production uses DigitalOcean Spaces for file storage and backups.
- Email provider: to deliver verification, reset, and invitation emails; production is configured to use SMTP delivery.
These providers process data under their terms, agreements, and applicable legal requirements, and we limit what we send to what is needed for the stated purpose. We may also disclose data where required by law or necessary to protect users' or the service's rights.
If you choose to share a client invitation through WhatsApp from inside the app, the app opens a message that you prepared and that may include the client's name and phone number, the project name, and an app link. This data is sent to WhatsApp only when you choose to share it and is then subject to Meta's and WhatsApp's practices.
5. What happens when you delete your account, and retention
Account deletion is available inside the app. When the operation completes, it immediately removes the account, sign-in methods, sessions, and membership links from the live operational database. There is no in-app recovery window. Copies of deleted data may remain in rolling backups for up to 30 days before they expire. Full steps are on the account deletion page.
The following categories remain after account deletion or may remain for a limited period. The in-app deletion screen summarizes the main account-related effects before confirmation, while this policy provides the complete list:
- A pseudonymous verification identifier: a deterministic keyed HMAC digest of the normalized email address, together with its reason and timestamps, used to prevent re-use of the evaluation period after an account or organization is deleted. The record does not store the readable email address, but the digest is pseudonymous rather than fully anonymous. The system currently applies no automatic expiry to this record; it is retained while the evaluation anti-abuse control remains in use.
- Organization content you helped create: what you recorded while working inside an organization is that organization's business record and stays with it, displaying the member name in the organization's own records without a link to your deleted account.
- Records organizations entered about you: member names, contact details, and invitations an organization keeps in its own business records. A pending invitation addressed to the account email is revoked on deletion, but the invitation record and its data remain with the organization.
- Operational, security, and diagnostic records: application events, server logs, and crash records may remain, including an event recording that account deletion completed, internal identifiers, IP address, device or browser user agent, and request data, for as long as needed for security, failure diagnosis, and legal obligations.
- Backups and staged files: rolling database backups expire within up to 30 days. Files uploaded to storage but not successfully attached to a record may remain until removed through storage cleanup.
Organization content and records persist as long as the organization itself does: we impose no separate horizon on them, and they are removed from the live operational database if the organization is deleted, subject to the backup period above.
6. Your rights and choices
You may at any time request access to your data, its rectification, its erasure, or the withdrawal of consent where processing depends on consent.
The primary erasure path is in-app account deletion. If you cannot access the app, use the fallback path on the account deletion page. You may also choose not to use social sign-in, the contact picker, or file uploads.
Requests concerning records an organization entered about you are answered within the same window; the substantive answer follows record ownership because those are the organization's business records, and we direct you to the organization.
7. Where data is stored and how we protect it
App data is transmitted over HTTPS/TLS and hosted on servers and storage services that may be located outside the Arab Republic of Egypt. Cross-border processing is subject to applicable legal requirements, including Egypt's Personal Data Protection Law (Law 151/2020) and its Executive Regulations. App-user access to organization-linked records is restricted by organization roles and permissions.
8. This website does not track you
muamer.net is a static site: no cookies, trackers, or measurement tools run in your browser. The single exception: the demo video plays from YouTube in privacy-enhanced mode (youtube-nocookie.com); no request is sent to YouTube before you press play yourself, and while playing, YouTube's privacy policy applies to the player. You can also message us straight from the contact form: your name, mobile number, message text, and email address if you chose to give one, are sent over HTTPS to Muamer's own server (api.muamer.net), stored so we can reply, and a notification reaches our support inbox. They are never shared with a third party and never used for marketing. WhatsApp and email remain available if you prefer them.
9. Changes to this policy
On any material change we update the effective date at the top and announce the change on this page.
10. Contact
For any question about this policy or to exercise your rights: support@muamer.net — or Muamer on WhatsApp, listed on the support page.