Privacy PolicyOffline-first

Last updated: October 9, 2025 Version 2.0

Languages: English العربية

Privacy at a Glance

📱

Offline-First

Your data stays on your device by default

🔒

No Tracking

We don't collect analytics or behavioral data

☁️

Optional Cloud

Backups are opt-in only, your choice

🚫

No Data Sales

We never sell or share your financial data

Who We Are

TadbirLabs ("we", "us", "our") develops Tadbir, an Arabic-first, offline-first expense tracker designed to help you manage your finances with complete privacy. We are based in Egypt and committed to protecting your financial data.

Contact: tadbirlabs@gmail.com
Privacy inquiries: privacy@tadbirlabs.com

Scope

This privacy policy explains how your information is handled when you use Tadbir mobile applications (iOS and Android) and related pages at tadbirlabs.github.io. By using our app or services, you agree to the terms outlined in this policy.

Data Model (Offline-First)

Our Core Principle: Your data belongs to you and stays with you.

By default, your entries, categories, budgets, and settings are stored locally on your device only. We do not transmit your personal data to our servers because we operate no backend infrastructure. This "offline-first" approach means:

Any optional cloud features you enable (e.g., backups, cross-device sync) will clearly state the provider and terms before activation, and you must explicitly opt in to use them.

Information We Process

On-Device Data (Local Storage)

The following data is stored locally on your device and never transmitted to our servers unless you explicitly enable cloud features:

Optional Cloud Sync/Backup (If Enabled)

If you choose to enable cloud backup or synchronization features, your data may be transferred to the cloud storage provider you select:

When you enable these features, the provider's privacy policy applies in addition to ours:

Important: Cloud backups are encrypted before transmission. We do not have access to the encryption keys or your cloud storage credentials.

Diagnostics & Crash Reports (Minimal)

We may collect minimal, anonymized crash reports to improve app stability:

No behavioral analytics: We do not use analytics tools that track your behavior, screen views, or interactions. We do not collect data on which features you use or how often you use the app.

Third-Party Services & SDKs

Tadbir operates with minimal third-party dependencies to protect your privacy. The following services may process limited data:

Cloud Storage (Optional, User-Initiated)

Crash Reporting (If Implemented)

If we implement crash reporting in future versions, we will use privacy-respecting services and update this policy. Currently, crash data is collected only through app store mechanisms (Google Play Console, Apple App Store Connect).

What We DON'T Use

To be transparent, we explicitly do NOT integrate:

Commitment: If we add any new third-party service in the future, we will update this section and notify you through an in-app announcement with the option to opt out.

App Permissions

Tadbir requests the following device permissions. All permissions are requested with clear explanations, and you can revoke them at any time through your device settings:

Required Permissions

Optional Permissions

Note: We never request permissions for contacts, microphone, location, or phone calls. These are not needed for expense tracking.

Data Retention & Deletion

Local Data

All locally stored data remains on your device indefinitely until you manually delete it through the app's data management features:

Cloud Backups (If Enabled)

If you enable cloud backup features:

Cached Data (Minimal)

If we introduce any server-side features in the future, cached data would be purged within 7 days. Currently, no data is cached on our servers because we operate no backend.

Request Data Deletion

To request complete data deletion (if applicable for future cloud features):

  1. Email privacy@tadbirlabs.com with subject "Data Deletion Request"
  2. Include your registered email address (if you created an account in future versions)
  3. We will provide detailed instructions within 48 hours
  4. Deletion is completed within 30 days for GDPR compliance

Security Measures

We take the security of your financial data seriously, even though it primarily resides on your device:

Local Storage Security

Cloud Backup Security (If Enabled)

Infrastructure Security

Since we operate no backend servers for data storage:

Your Responsibility: The security of your data depends significantly on your device's security. Please enable device encryption, use strong passwords, keep your OS updated, and avoid installing untrusted apps.

Your Privacy Rights

We respect your privacy rights under various global privacy laws. Depending on your location, you may have the following rights:

For All Users

Additional Rights for EU/EEA/UK Users (GDPR)

If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):

Data Controller: TadbirLabs acts as the data controller for local data processing. For cloud backups, you and your cloud provider share data controller responsibilities.

Legal Basis: We process your data based on your consent (for optional features) and contractual necessity (to provide the app's core functionality).

Additional Rights for California Users (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Do Not Sell My Personal Information: We do not sell or share personal information. This statement serves as our official CCPA disclosure.

How to Exercise Your Rights

To exercise any of the rights above:

  1. Email us: privacy@tadbirlabs.com with subject line "Privacy Rights Request"
  2. Include: Your name, email (if applicable), specific right you wish to exercise, and jurisdiction
  3. Verification: We may request verification of your identity to protect against fraudulent requests
  4. Response time:
    • GDPR requests: Within 30 days (extendable to 60 days for complex requests)
    • CCPA requests: Within 45 days (extendable to 90 days for complex requests)
    • General requests: Within 10 business days

Children's Privacy

Tadbir is not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction, which may be 16 in some EU countries). We do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@tadbirlabs.com, and we will assist with deletion steps.

Since our app operates offline-first, any data entered by a child would be stored locally on the device. Parents can delete this data by:

Policy Changes

We may update this privacy policy from time to time to reflect changes in our practices, legal requirements, or app features. When we make changes:

We encourage you to review this policy periodically to stay informed about how we protect your privacy.

Privacy Policy Version History
  • v2.0 (October 9, 2025) - Added comprehensive GDPR/CCPA rights, third-party SDK disclosure, detailed data retention policy, improved accessibility
  • v1.0 (January 15, 2025) - Initial privacy policy published

Contact Us

If you have any questions, concerns, or requests regarding this privacy policy or our privacy practices, please contact us:

Response commitment: We aim to respond to all privacy inquiries within 48 hours for urgent matters and 5 business days for general inquiries.


This privacy policy is effective as of October 9, 2025, and applies to all users of Tadbir mobile applications.