Introduction and scope
This policy covers the ArabDev website and app, its API, and the documentation sites published with it. It applies to everyone who visits, whether or not they have an account.
ArabDev is a community for Arabic-speaking developers to share technical posts, follow each other, discuss ideas and discover new topics. To do that, the service has to handle some information about the people who use it: at the very least an email address and a password to sign in, and the posts, comments and profile details that people choose to publish.
We believe you should be able to understand exactly what happens to that information. This policy therefore describes our real practices in concrete terms. Where it names a specific cookie, a specific time limit or a specific protection, that is how the service actually works today.
What this policy covers
- The ArabDev web application at arabdev.site, including the sign-in and registration pages, the dashboard (your home feed at arabdev.site/dashboard), profiles, the editor, search, notifications and settings.
- The ArabDev API at
/api/v1, which the web application uses and which developers can call directly. - Uploaded files, such as profile pictures and images attached to posts.
- Emails we send about your account, such as password reset messages. They always come from an @arabdev.site address.
- The documentation sites: the Wiki at wiki.arabdev.site, this Privacy Policy at privacy.arabdev.site, and the Patch notes at patch.arabdev.site.
What this policy does not cover
- Websites that people link to from their posts, comments or profiles, and websites that advertisers link to. Those sites have their own policies (see Links to other websites).
- Copies of the ArabDev software that other people or organisations run on their own servers. ArabDev is open source, and whoever runs a copy is responsible for the data on it (see Self-hosted copies).
- Information you share with other developers outside ArabDev, for example if you give someone your email address in a post and they contact you directly.
How to read this policy
Every section starts with an In short box summarising it in a sentence or two. The summaries are there to help you find your way; the full text of each section is what applies. Terms such as personal information, processing and content are explained in the Definitions at the end.
This policy is available in Arabic and English. Both versions say the same thing. If a translation ever seems to differ, contact us and we will clarify and correct it; the more protective reading for you applies in the meantime.
Who we are
The ArabDev team operates the service and decides how your information is used, which makes us responsible for it under data protection law.
“ArabDev”, “we”, “us” and “our” in this policy mean the team that operates the official ArabDev service at arabdev.site. When you use ArabDev, we are the controller of your personal information: we decide why and how it is processed, and we are accountable to you and to regulators for doing so lawfully and carefully.
Some companies help us run the service, such as the hosting provider whose servers ArabDev runs on. They act as our processors: they handle information only on our instructions and only to provide their service to us. They are described in When information is shared.
You can reach us about anything in this policy using the details in Contact us.
We never sell your data
We do not sell, rent or trade your personal information, and we do not use it to target ads at you. Your information is safe and secure with us.
ArabDev does not sell user information. We have never done so, we do not do so now, and we will not do so in the future. There is no setting to opt out of because there is nothing to opt out of.
In particular, we do not:
- Sell, rent, lease or trade your personal information to anyone, for money or for anything else of value.
- Give or license your information to data brokers, marketing companies or list sellers.
- Share your information with advertisers. Advertisers never receive your name, username, email, interests, posts or activity.
- Build advertising profiles about you, or use your posts, likes, follows or searches to choose which ads you see.
- Put third-party tracking pixels, analytics scripts, fingerprinting code or social-media “like” buttons on ArabDev.
- Read your private information (such as your drafts or saved posts) for marketing purposes.
- Use your content to train commercial models for sale to third parties.
This commitment also covers the future. If ArabDev were ever reorganised, merged with another organisation or transferred to new operators, the promise not to sell your information would be a condition of that transfer. We would tell you before your information became subject to a different privacy policy, and you would be able to delete your account first.
Under some laws, such as the California Consumer Privacy Act, “selling” and “sharing” have wide legal meanings that include handing information to advertisers in exchange for services. We do not do that either, under any of those definitions.
Information you give us
To create an account you give us a username, an email address and a password. Everything else, such as your bio, picture and interests, is optional and yours to change.
Account details
When you register, we ask for:
| Information | Why we need it | Who can see it |
|---|---|---|
| Username | Your unique name on ArabDev. It forms your profile address (/u/username) and lets people mention you. It is 3 to 20 characters: lowercase letters, numbers and underscores, starting with a letter. |
Public |
| Email address | To sign you in, to let you reset a forgotten password, and to contact you about your account or about important changes to this policy. | Only you |
| Password | To protect your account. We never store your password itself: we store a one-way hash made with Argon2id, so even we cannot read it (see Security). | No one, not even us |
| Interface language | The language you were using when you registered (Arabic or English), so ArabDev keeps talking to you in it. | Only you |
We do not ask for your real name, date of birth, gender, phone number, national identity number, address or payment details. ArabDev does not need them.
Profile details (optional)
After registering, you can add details to your profile. All of them are optional, and all of them are shown publicly on your profile because their purpose is to introduce you to other developers. Only add what you are comfortable sharing.
- Display name: the name shown on your posts and profile (up to 50 characters). It does not need to be your legal name.
- Bio: a short description of yourself (up to 280 characters).
- Location: free text (up to 60 characters). You decide how precise to be; a country or city is plenty, and you can leave it empty.
- Website: a link to your site, portfolio or code repository (up to 200 characters).
- Profile picture: an image you upload. We process it before storing it, as described below.
- Interests: topics you choose during onboarding or in your settings, such as Python, React or DevOps. They personalise your feed and recommendations and are shown on your profile.
Content you publish
ArabDev exists so that you can share things. What you publish includes:
- Posts, including their text, formatting, code blocks, tables, links, tags and an attached image.
- Comments on posts.
- Mentions of other developers (
@username) inside posts and comments.
Posts and comments are public: anyone who visits ArabDev can read them, including people who are not signed in. Please do not put private information, yours or anyone else's, into posts or comments. In particular, never publish passwords, API keys, access tokens or private keys inside code samples.
Drafts
When you save a draft in the editor, it is stored on our servers so that you can continue on another device. Drafts are private: only you can see them, they never appear in feeds or search, and you can discard them at any time. Publishing a draft turns it into a normal public post.
Images you upload
When you upload a profile picture or an image for a post, we do not simply store the file you sent. We check that it really is an image, then re-encode it into the WebP format. Re-encoding removes hidden metadata that photos often carry, such as the camera model, the date and time the photo was taken and, most importantly, GPS location. We store the cleaned image together with basic technical details (its size, dimensions and format) and a note of which account uploaded it.
Many phones embed the exact place a photo was taken. Because ArabDev strips that data from every upload, sharing a screenshot or photo does not reveal where you live or work.
Settings and preferences
We store the choices you make in Settings so they follow you across devices:
- Appearance: light, dark or system theme, and Arabic or English.
- Privacy: whether you appear in suggestions and people search, whether your follower lists are visible, and who may mention you (everyone, people you follow, or no one).
- Notifications: whether you are notified about likes, comments, new followers, reposts and mentions.
When you contact us
If you write to us, we receive your message, your email address and anything you choose to include. We use it only to answer you and to keep a record of the request, for example of a privacy request we have fulfilled.
Information created as you use ArabDev
Using ArabDev naturally creates records such as who you follow, what you liked or saved, and your notifications. We keep them to run the features you use, not to profile you.
Some information is not typed in by you but is created by the things you do on ArabDev:
| Record | What it contains | Visibility |
|---|---|---|
| Follows | Which accounts you follow and which accounts follow you, and when. | Public unless you hide your lists |
| Likes | Which posts you liked. Other people see the total number of likes on a post. | Counts are public |
| Reposts | Which posts you reposted. Reposts appear on your profile and in your followers' feeds. | Public |
| Bookmarks (saved posts) | Which posts you saved for later. | Only you |
| Notifications | Who liked, commented on or reposted your posts, who followed you, who mentioned you, and whether you have read each notification. | Only you |
| Onboarding status | Whether you have finished the four-step welcome, so we do not show it again. | Only you |
| Account timestamps | When your account was created, when it was last updated, and when you last signed in. | Joining month is public; the rest are private |
| Post statistics | The number of likes, comments and reposts on each post, and when it was published or edited. | Public |
We use these records to make the features work: to build your feed from people you follow and topics you care about, to show accurate counts, to notify you, and to suggest developers with similar interests. We do not sell them, and we do not use them to target advertising (see Advertising).
How recommendations work
ArabDev suggests posts and developers using a small number of transparent signals: the interests you selected, the tags on posts, who you already follow, and how recent and how discussed a post is. These calculations happen on our servers when you open a page. We do not buy data about you from other sources, and we do not combine ArabDev activity with information from other websites.
You can influence recommendations directly by changing your interests in Settings, and you can remove yourself from other people's suggestions by turning off discoverability.
Information collected automatically
Like every website, our servers see your IP address and basic browser details when you connect. We use them for security and to keep the service running, and we keep them only briefly.
IP address
Your device's IP address is sent to our servers with every request; the internet cannot work without it. We use it in two ways:
- Rate limiting. To stop password-guessing, spam and abuse, ArabDev limits how many times certain actions can be performed in a short period (for example, ten sign-in attempts per minute). The limiter keeps a counter linked to the IP address, in memory, only for the length of the limit window, which is at most one hour. These counters are not written to the database and are not linked to your account.
- Server logs. Our web servers record basic request logs: the time, the IP address, the page or API address requested and whether it succeeded. We use these logs only to keep ArabDev running, to fix errors and to investigate attacks or abuse, and we delete them within 30 days.
We do not use IP addresses to work out your precise location, and we do not use them to build a profile of you.
Browser and device information
Your browser tells every website it visits what browser and operating system it is (the user agent) and which languages you prefer. We use your language preference to show messages in Arabic or English. When you sign in, we store the user agent with that sign-in session, so that sessions can be told apart and suspicious sign-ins can be investigated. It is deleted together with the session record (see Retention).
Sign-in sessions
When you sign in, we create a session record containing a hashed version of your session token (never the token itself), when it expires, whether you ticked Remember me, and the user agent described above. These records let you stay signed in and let us sign you out everywhere when you change your password.
Ad counts
Each ad keeps two totals: how many times it has been displayed and how many times it has been clicked. These are plain numbers, such as “shown 1,204 times, clicked 37 times”. They do not record who saw or clicked the ad.
Search terms
When you search ArabDev, your search terms are used to find matching posts, developers and tags and are then discarded. We do not keep a search history, and your searches are not added to your account or used for advertising.
Information we do not collect
We deliberately collect as little as possible. Here is a list of things ArabDev does not ask for or record.
Collecting less is the most reliable way to protect information. ArabDev does not collect:
- Your legal name, date of birth, gender, nationality or photo identification.
- Your phone number or postal address.
- Payment card or bank details. ArabDev is free and has nothing to pay for.
- Your contacts or address book.
- Precise location from your device's GPS. We also remove location data from uploaded photos.
- Special categories of data, such as health, religion, political opinions or biometric data. We never ask for them; please do not include them in your profile.
- Your browsing on other websites. There are no trackers, analytics tags or advertising pixels on ArabDev.
- Device fingerprints, meaning hidden identifiers calculated from your screen, fonts or hardware.
- Keystrokes, mouse movements or session recordings.
- Information about you from data brokers or other companies.
How we use information
We use your information to run ArabDev, to keep it and you secure, to communicate with you about your account, and to improve the service. Nothing else.
To provide the service
- Create and maintain your account and sign you in.
- Show your profile, posts, comments and reposts to other people.
- Build your feed, recommendations and search results.
- Save your drafts, bookmarks and settings.
- Send you notifications about activity involving you, according to your notification settings.
- Remember your language and appearance choices.
To keep ArabDev safe
- Protect accounts from password guessing and takeover, for example with rate limits and by detecting reuse of stolen session tokens.
- Prevent spam and abuse, and enforce our community guidelines.
- Investigate and fix security issues and errors.
- Clean uploaded content and remove unsafe code from posts before anyone sees them.
To communicate with you
- Send password reset links you ask for.
- Tell you about important changes to your account, to the service or to this policy.
- Reply when you contact us.
We do not send marketing emails or newsletters. If we ever offer one, it will be strictly opt-in, and every message will include a one-click way to unsubscribe.
To improve ArabDev
We look at information such as error reports, the overall number of posts and accounts, and aggregate ad totals to understand what is working and what to fix. We use aggregate figures for this wherever possible, not information about individual people.
To meet legal obligations
We may use information to comply with the law, to respond to valid legal requests, and to establish, exercise or defend legal claims.
What we will not use it for
- Selling or renting it, or letting advertisers target you with it.
- Making automated decisions about you that have legal or similarly significant effects.
- Any purpose incompatible with the ones above without first telling you and, where required, asking for your consent.
Legal bases for processing
Some laws require us to name the legal reason for each use of your information. For most of what we do, it is to provide the service you signed up for.
Data protection laws such as the EU and UK General Data Protection Regulation (GDPR), and several laws in the Arab world, allow personal information to be processed only when there is a valid legal basis. These are the bases we rely on:
| Legal basis | What we use it for |
|---|---|
| Performance of a contract | Creating your account, signing you in, publishing your posts and comments, showing your profile, building your feed, saving drafts, bookmarks and settings, and sending notifications and password reset emails. Without this processing we could not provide ArabDev to you. |
| Legitimate interests | Keeping ArabDev secure (rate limiting, server logs, session protection), preventing abuse, counting ad impressions and clicks in aggregate, understanding usage in aggregate, and recommending developers and posts. We have weighed these interests against your rights and kept the processing minimal and expected. |
| Consent | Optional profile details you choose to publish, and any future optional features such as newsletters. You can withdraw consent at any time by removing the details or switching the feature off. |
| Legal obligation | Keeping records we are legally required to keep and responding to lawful requests from authorities. |
Where we rely on legitimate interests, you have the right to object (see Your rights).
What is public and what is private
Your profile, posts, comments, reposts and follows are public. Your email, drafts, bookmarks, notifications and settings are private.
ArabDev is a public community, so a lot of what you do on it is meant to be seen. It is important to know exactly where the line is:
| Information | Visibility | Notes |
|---|---|---|
| Username, display name, bio, location, website, profile picture | Public | Visible to anyone, including people who are not signed in. |
| Interests | Public | Shown on your profile. |
| Posts and comments | Public | Readable by anyone and findable through ArabDev search. |
| Reposts | Public | Shown on your profile and in feeds. |
| Who you follow and who follows you | Public by default | You can hide these lists in Settings → Privacy. The totals remain visible. |
| Likes | Totals are public | People can see how many likes a post has. |
| Joining date | Public | Shown as a month and year on your profile. |
| Email address | Private | Never shown to other users or to advertisers. |
| Drafts | Private | Only you can open them. |
| Bookmarks | Private | The author is not told that you saved their post. |
| Notifications | Private | Only you can see them. |
| Settings | Private | Only you can see them. |
| Password | Unreadable | Stored only as a one-way hash. |
Controls you have
- Discoverability: turn it off and ArabDev stops suggesting your account to others and leaves you out of people search, unless someone types your exact username. Your profile and posts are still reachable by direct link.
- Follow lists: hide who you follow and who follows you.
- Mentions: choose whether everyone, only people you follow, or no one may mention you.
- Editing and deleting: edit or delete your posts at any time. Deleting a post also removes its comments, likes, reposts and bookmarks.
Once something is public, other people may have read, copied or screenshotted it, and search engines may have indexed it. Deleting it from ArabDev removes it from ArabDev, but we cannot remove copies that others made outside ArabDev.
When information is shared
We share information only with service providers who help us run ArabDev, when the law requires it, or to protect people. We never sell it.
Apart from the content you choose to make public, we share personal information only in these situations:
Service providers
We use a small number of trusted companies to run ArabDev, such as the provider that hosts our servers and database, the network that delivers the website's files, and, once configured, an email service to deliver password reset messages. These providers:
- Receive only the information they need to do their job.
- Are bound by contracts that require them to protect it and to use it only on our instructions.
- Are not allowed to use it for their own purposes, including advertising.
- Must delete or return it when their service to us ends.
Legal requirements
We may disclose information if we believe in good faith that the law requires it, for example in response to a court order. We review every request carefully, push back on requests that are too broad or lack a proper legal basis, and disclose only the minimum required. Unless the law forbids it, we will tell you about a request concerning your account before we disclose anything, so that you can object.
Protecting people and ArabDev
We may share information when it is necessary to prevent serious harm to someone's life or safety, or to investigate fraud or security attacks against ArabDev and its users.
Changes to the organisation
If ArabDev is reorganised or transferred to new operators, user information may pass to them as part of that change. As explained in We never sell your data, any successor must keep the commitments in this policy, and we will tell you in advance.
With your permission
In any other situation, we will ask for your explicit permission first.
Advertising
ArabDev shows a small number of clearly labelled ads. They are chosen by page position and language, never by who you are, and advertisers receive nothing about you.
Ads help keep ArabDev free. We designed them to respect your privacy completely.
How ads are chosen
An ad is picked using only:
- Where it will appear: in the feed (after every eight posts) or in the sidebar.
- The language of the interface, so Arabic readers see Arabic ads.
- The page number in the feed, so that different pages show different ads.
That is the whole list. Ads are not chosen using your identity, interests, posts, likes, follows, searches, location or browsing history. Two different people reading the same page in the same language see the same ads.
How ads are measured
We count how many times each ad is displayed and clicked, as totals only. When you click an ad, ArabDev adds one to that ad's click count and then opens the advertiser's site in a new tab. We do not record which account clicked, and we do not tell the advertiser who you are.
What advertisers receive
Advertisers may receive the total impressions and clicks of their own ads. They receive no personal information about ArabDev users. ArabDev does not load advertising code from advertisers or ad networks: every ad is displayed by ArabDev itself.
For sponsors
Businesses and communities that want to sponsor ArabDev or place an ad can write to hi@arabdev.site. Every sponsor is bound by the same rules: no tracking code, no personal data, and clear labelling.
After you click
Once you are on an advertiser's website, their privacy policy applies, not ours. They may see your IP address and use their own cookies, as any website can. ArabDev opens ad links in a way that prevents the advertiser's page from controlling the ArabDev tab.
Every ad is marked “Sponsored” and designed to look different from posts, so you always know what you are looking at.
Cookies and browser storage
ArabDev uses one essential cookie to keep you signed in and a few small browser-storage entries to remember your preferences. There are no advertising or tracking cookies.
Cookies and browser storage are small pieces of information that a website saves in your browser. ArabDev uses them only where they are strictly necessary or remember a choice you made. Because none of them track you, we do not show a cookie consent banner: there is nothing for you to accept or refuse.
Cookies
| Name | Purpose | Duration | Type |
|---|---|---|---|
arabdev_refresh |
Keeps you signed in. It holds a random session token that ArabDev exchanges for short-lived access. It is marked HttpOnly, so page scripts cannot read it, is sent only to ArabDev's sign-in endpoints, and is sent only over HTTPS in production. | 30 days with Remember me; otherwise until you close the browser (and at most 12 hours) | Strictly necessary |
That is the only cookie ArabDev sets. The short-lived access token that proves who you are to the API is held only in the page's memory and disappears when you close the tab.
Browser storage
| Key | Purpose | Contents |
|---|---|---|
arabdev.lang | Remembers your interface language, including before you sign in. | ar or en |
arabdev.mode | Remembers light, dark or system appearance, so the page does not flash the wrong colours while loading. | light, dark or system |
arabdev.session | A hint that this browser has signed in before, so ArabDev knows whether to try to restore your session. It contains no identifier or token. | 1, or absent |
mui-color-scheme-light, mui-color-scheme-dark | Set by the interface library ArabDev uses, to remember which colour palette belongs to light and dark mode. | light or dark |
react-router-scroll-positions | Remembers how far you had scrolled on pages you visited in this tab, so the Back button returns you to the same place. Kept in session storage, which the browser deletes when you close the tab. | ArabDev page addresses and scroll positions |
All of these entries except the last are kept in local storage. None of them is sent to our servers or shared with anyone. You can clear them at any time through your browser's settings; ArabDev will simply return to its default language and appearance.
Global Privacy Control and Do Not Track
Because ArabDev does not track you or sell or share your information, the result is already what these signals ask for. We honour them automatically, and there is nothing further to switch off.
How we keep your information secure
Your information is kept safe and secure with modern, layered protections, from how passwords are stored to how every upload and post is checked.
Security is built into ArabDev from the ground up, not added afterwards. The main protections are:
Passwords
- Passwords are hashed with Argon2id, a modern algorithm designed to make stolen hashes extremely costly to crack. We never store or log the password itself.
- Passwords must be at least 8 characters and contain both letters and numbers, and we reject very repetitive ones.
- When you change or reset your password, every other signed-in session is ended immediately.
- Sign-in takes the same time whether or not an email address is registered, and the password reset page gives the same answer either way, so neither can be used to find out who has an account.
Sessions
- Access tokens are short-lived (15 minutes) and kept only in the page's memory.
- The long-lived session token is stored in an HttpOnly cookie that scripts cannot read, and in our database only as a SHA-256 hash.
- Session tokens are rotated every time they are used. If an old token is ever used again, which suggests it was stolen, every session in that chain is ended.
- Session refreshes require a special request header that other websites cannot send, which protects against cross-site request forgery.
- Password reset links are single-use, expire after 30 minutes and are stored only as hashes.
Content and uploads
- Every post is cleaned on the server with a strict allow-list before it is saved, and cleaned again in your browser before it is shown, so scripts and dangerous code cannot run.
- Links in posts are marked so they do not pass your ArabDev page address to other sites and cannot control the ArabDev tab.
- Uploaded images are checked, size-limited (5 MB) and re-encoded, which also removes hidden metadata and location data.
Infrastructure
- In production, all traffic is encrypted with HTTPS.
- Sensitive actions are rate limited to stop automated attacks.
- The service sends security headers that stop other sites from framing ArabDev and stop browsers from misinterpreting files.
- Access to servers and the database is limited to the people who operate ArabDev, and only for maintenance, security and legal obligations.
- Secrets such as signing keys are kept out of the source code and must be set separately for every deployment.
What you can do
- Use a unique password for ArabDev, ideally from a password manager.
- Only tick Remember me on your own devices, and sign out on shared ones.
- Never share your password. ArabDev staff will never ask you for it.
- Never publish secrets such as API keys or tokens in your posts' code blocks.
No service on the internet can promise perfect security, but we take every reasonable measure to keep your information safe, and we keep improving them. If you find a security weakness, please tell us privately (see Contact us) so we can fix it before it can be misused.
How long we keep information
We keep your account information for as long as you have an account. Technical records such as sessions and logs are deleted automatically after short, fixed periods.
| Information | How long we keep it |
|---|---|
| Account, profile and settings | Until you delete your account. |
| Posts, comments, reposts, likes and bookmarks | Until you delete them or delete your account. |
| Drafts | Until you publish or discard them, or delete your account. |
| Uploaded images | Until the post or profile they belong to is deleted, or your account is deleted. Images uploaded but never used can be removed right away. |
| Notifications | Until the related post, comment or account is deleted, or your account is deleted. |
| Sign-in session records | Until the session expires or ends, plus 7 days (so that stolen tokens can still be recognised), then deleted automatically. |
| Password reset links | Valid for 30 minutes; deleted automatically one day after they are used or expire. |
| Rate-limit counters | For the length of the limit window, at most one hour, in memory only. |
| Server logs | Up to 30 days. |
| Aggregate ad totals | For as long as the ad exists. They contain no personal information. |
| Messages you send us | As long as needed to handle your request, and for privacy requests up to three years as a record that we fulfilled them. |
| Backups | Deleted information may remain in encrypted backups until they are overwritten, within 30 days. |
We may keep specific information longer only when the law requires it or when it is needed for an ongoing legal claim or security investigation, and only for as long as that lasts.
Deleting your account
You can permanently delete your account yourself from Settings. It takes effect immediately and removes everything linked to it.
Go to Settings → Account, choose Delete my account and confirm with your password. The password check makes sure nobody else can delete your account from a device you left signed in.
What is deleted
Deletion is immediate and permanent. It removes:
- Your account, email address, password hash, profile and settings.
- All your posts, together with the comments, likes, reposts and bookmarks on them.
- All your comments on other people's posts.
- Your likes, reposts and bookmarks.
- Who you follow and who follows you.
- Your drafts and notifications, and notifications about you in other people's accounts.
- Every image you uploaded; the files themselves are removed from storage.
- All your sign-in sessions, which signs you out everywhere.
The counts on other people's posts, such as the number of likes, are recalculated so they no longer include your activity.
Once deleted, an account cannot be restored, even by us. If you might want your posts later, copy them before deleting your account.
Your username afterwards
After deletion your username becomes available again, and someone else may register it later. Links to your old profile will stop working.
Your rights and choices
You can see, correct, download and delete your information, and object to how it is used. Most of this you can do yourself in Settings; for anything else, contact us.
Wherever you live, we give every ArabDev user the following rights. Some laws also give you additional rights, described in Regional privacy laws.
| Right | What it means | How to use it |
|---|---|---|
| Access | Know what information we hold about you and get a copy. | Your profile, posts, drafts, bookmarks and settings are visible to you in the app. For a complete copy, contact us. |
| Correction | Fix information that is wrong or incomplete. | Settings → Account and Settings → Profile let you change your username, email, password and every profile detail. |
| Deletion | Have your information erased. | Delete individual posts, comments and images at any time, or delete your whole account in Settings. |
| Portability | Receive your information in a structured, machine-readable format. | Contact us and we will send you a JSON export of your account, profile, posts, comments and other records. |
| Objection | Object to processing based on our legitimate interests. | Contact us and explain your situation; we will stop unless we have compelling grounds or need it for a legal claim. |
| Restriction | Ask us to pause the use of your information while a concern is resolved. | Contact us. |
| Withdraw consent | Take back consent you gave, without affecting earlier processing. | Remove the optional detail or switch the feature off. |
| Complain | Raise a concern with a data protection authority. | You can contact your local authority at any time. We would appreciate the chance to help first. |
How we handle requests
- We will confirm receipt within 7 days and respond fully within 30 days. If a request is complex, we may extend this by up to two more months, and we will tell you why.
- To protect your account, we will ask you to confirm your identity, normally by writing from the email address on your account.
- Using your rights is free. We will never treat you differently for using them.
- If we cannot do what you asked, we will explain why and tell you how to challenge our decision.
Regional privacy laws
Depending on where you live, specific privacy laws give you additional protections. We respect them all, and the rights above already meet or exceed most of them.
Arab countries
Many Arab countries have modern personal data protection laws. Depending on where you live, these may include, among others:
- Saudi Arabia: the Personal Data Protection Law (PDPL) and its implementing regulations.
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
- Egypt: Law No. 151 of 2020 on the Protection of Personal Data.
- Qatar: Law No. 13 of 2016 on the Protection of Personal Data Privacy.
- Bahrain: Law No. 30 of 2018 on the Protection of Personal Data.
- Oman: the Personal Data Protection Law issued by Royal Decree No. 6/2022.
- Jordan: the Personal Data Protection Law No. 24 of 2023.
- Morocco: Law No. 09-08 on the protection of individuals with regard to the processing of personal data.
- Tunisia: Organic Law No. 2004-63 on the protection of personal data.
These laws generally give you the right to be informed, to access and correct your data, to have it deleted, and to withdraw consent, and they require that data be kept secure and not used for unrelated purposes. This policy and the rights in Your rights and choices are designed to meet these requirements. Where a law in your country gives you a right not described here, contact us and we will honour it.
European Union, EEA and United Kingdom
If you are in the EU, EEA or UK, the GDPR (or UK GDPR) applies. You have all the rights listed in Your rights and choices, and our legal bases are set out in Legal bases for processing. You may lodge a complaint with the data protection authority in the country where you live or work, or where you believe a problem occurred.
United States
If you live in California or another US state with a consumer privacy law, you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to opt out of its sale or sharing for targeted advertising. As explained throughout this policy:
- The categories of personal information we collect are identifiers (username, email, IP address), account and profile information, content you create, and internet activity on ArabDev (such as follows and likes).
- We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the past 12 months.
- We do not use or disclose sensitive personal information for purposes that would give you a right to limit it.
- We will not discriminate against you for exercising any of your rights.
You may use an authorised agent to make a request; we will verify both the agent's authority and your identity.
Children
ArabDev is not intended for children under 13, or under the older minimum age that applies where they live.
ArabDev is a community for developers and is not directed at children. You must be at least 13 years old to create an account. If the law in your country sets a higher age for using online services without a parent's consent, such as 16 in some countries, you must meet that age or have your parent's or guardian's consent.
We do not knowingly collect information from children below these ages. If you believe a child has created an account, please contact us. We will investigate, and if the account belongs to a child below the minimum age, we will delete it and its information.
Young developers are an important part of every tech community. If you are a teenager using ArabDev, please be especially careful about sharing personal details such as your school, city or photos of yourself.
Where information is processed
ArabDev's servers and providers may be in a different country from you. Wherever your information goes, it gets the same protection.
ArabDev is used by developers in many countries, and the servers and service providers we rely on may be located outside your country. For example, the website's files may be delivered through a global content delivery network so that pages load quickly wherever you are.
When information is transferred between countries, we make sure it stays protected as this policy describes and as the law requires. For example, we use providers in countries recognised as offering adequate protection, or we sign contracts based on approved standard clauses, together with any additional safeguards that are needed.
Self-hosted copies of ArabDev
Because ArabDev is open source, anyone can run their own copy. This policy covers the official service; whoever runs another copy is responsible for its data.
The ArabDev software is published under the GNU General Public License version 3, which lets anyone run, study, modify and share it. Schools, companies and communities may therefore run their own copies of ArabDev.
- This policy applies only to the official ArabDev service operated by us at arabdev.site and its subdomains.
- The organisation or person that runs another copy decides how it is configured and is the controller of its users' information. We have no access to it.
- If you use a copy run by someone else, read their privacy policy and contact them about your data.
If you run your own copy, we encourage you to adopt the same commitments as this policy, starting with never selling user information. You are welcome to adapt this policy as a starting point, but you must make sure it accurately describes your own setup and complies with the laws that apply to you.
Links to other websites
Posts, profiles and ads can link to other websites. When you follow a link, you leave ArabDev and that site's privacy policy applies.
Developers often link to documentation, code repositories and articles. ArabDev is not responsible for the content or privacy practices of other websites.
To reduce what other sites learn when you follow a link, ArabDev marks links in posts, comments and profiles so that:
- The other site is not told which ArabDev page you came from.
- The other site cannot control or redirect the ArabDev tab you came from.
ArabDev does not embed content from other sites, such as videos, social media widgets or third-party comment systems, which could otherwise track you while you read.
ArabDev's fonts are hosted on ArabDev's own servers, so loading a page does not contact any third-party font service.
The wiki, this policy and patch notes
The documentation sites are simple static pages. They set no cookies and send nothing about you anywhere.
The ArabDev Wiki, this Privacy Policy and the Patch notes have their own addresses, wiki.arabdev.site, privacy.arabdev.site and patch.arabdev.site, and open in their own tab. They:
- Set no cookies.
- Save
arabdev.langin their own browser storage, so that next time their front page opens in the language you last read them in. - Save
arabdev.modeif you switch between light and dark mode on them. Until you do, they follow your device's setting. - Keep these entries separate from the app's: because each site has its own address, browsers do not share their storage with arabdev.site.
- Run their search entirely in your browser. What you type is never sent to our servers.
- Contain no analytics, trackers or ads.
As with any website, the server that delivers these pages receives your IP address and basic request details, handled as described in Information collected automatically.
Open source and transparency
ArabDev's code is open, so anyone can check that it does what this policy says.
Privacy promises are easier to trust when they can be checked. ArabDev is free software licensed under the GNU General Public License v3. Its source code shows exactly which information is stored, which cookies are set and how data is deleted.
Security researchers and developers are welcome to review the code and report problems. We will publish meaningful changes to how ArabDev handles data in the Patch notes, and we will update this policy before any such change takes effect.
If something goes wrong
If a security incident affects your information, we will act quickly to contain it and tell you what happened and what to do.
We prepare for security incidents in the hope of never needing to. If one happens, we will:
- Act immediately to contain it and stop any further harm.
- Investigate what happened and which information and accounts were affected.
- Notify the relevant data protection authorities within the time the law requires, which is often 72 hours.
- Tell affected users without undue delay, in plain language: what happened, what information was involved, what we are doing, and what you can do to protect yourself.
- Take protective steps on your behalf where it helps, such as ending sessions or requiring a password reset.
- Learn from it and strengthen our protections so it does not happen again.
Changes to this policy
If we change this policy, we will update the date at the top. For important changes, we will tell you in advance.
ArabDev will grow, and this policy will change with it. When it does, we will update the Last updated date and the version number at the top of this page, and record the change in the history below.
- For important changes, such as collecting a new kind of information or using it in a new way, we will notify you at least 30 days in advance, by email or with a clear notice in ArabDev.
- For minor changes, such as clearer wording or corrected links, we will update this page.
- We will never use a policy change to weaken the promise that we do not sell your information.
Version history
| Version | Date | Summary |
|---|---|---|
| 1.0 | 19 September 2026 | First version of the ArabDev Privacy Policy, published with ArabDev 1.0.0. |
Contact us
Questions, requests or concerns about privacy? Write to us, and a person will reply.
You can write to us in Arabic or English. To help us respond quickly, please:
- Write from the email address linked to your ArabDev account, if your message concerns your account.
- Include your ArabDev username.
- Tell us clearly what you would like us to do, for example “send me a copy of my data”.
- Never include your password. We will never ask for it.
- For security problems, use the subject “Security” and do not publish the details until we have fixed them.
We only ever write to you from an @arabdev.site address. Treat any other message that claims to come from ArabDev with suspicion.
If you are not satisfied with our answer, you have the right to complain to the data protection authority where you live.
Definitions
What the key terms in this policy mean.
- Personal information
- Any information that relates to an identified or identifiable person, such as an email address, a username, an IP address or a post written by you. Some laws call it “personal data”.
- Processing
- Anything done with personal information, including collecting, storing, using, sharing and deleting it.
- Controller
- The organisation that decides why and how personal information is processed. For the official ArabDev service, that is us.
- Processor
- A company that processes personal information on a controller's behalf and on its instructions, such as a hosting provider.
- Content
- Posts, comments, images and other material that users publish on ArabDev.
- Selling
- Giving personal information to someone else in exchange for money or anything else of value. ArabDev does not do this.
- Hash
- The result of a one-way mathematical function. A hash can be used to check whether a password or token is correct, but the original cannot be recovered from it.
- Session
- The period during which you stay signed in on a device, from signing in until you sign out or the session expires.
- Cookie
- A small piece of information that a website asks your browser to store and send back with later requests.
- Local storage
- Storage inside your browser where a website can keep small preferences. Unlike cookies, it is not sent to the server automatically.
- Metadata
- Information about a file rather than its visible content, such as the camera model or GPS location inside a photo.
- Rate limiting
- Restricting how often an action can be repeated in a period of time, to prevent abuse.
- Aggregate
- Combined into totals so that no single person can be identified, for example “this ad was clicked 37 times”.