Skip to content
Tabaa
Legal

Privacy Policy

We collect what the service needs to work, nothing more - and every item is spelled out here. Last updated: 2026-08-13.

This English translation is provided for convenience only. The Arabic version is the authoritative text and governs in the event of any discrepancy.

Tabaa is a subscription software service that blocks sites, apps, and unwanted content and manages screen time on Android phones and Windows PCs. It works through an openly declared relationship between two parties: the supervisor, who holds the account and sets the rules, and the user, who holds the managed device - and they may well be the same person in a self-control setup. This policy explains what we collect, why, how long we keep it, and who can see it.

Scope of this policy

This policy covers the Tabaa website, the supervisor app, and the software installed on the managed device, whether an Android phone or a Windows PC. Tabaa is not spyware: it is installed with the device holder's knowledge, it is visible on the device, and the supervisor's role is known to both sides before activation.

Data we collect

  • Account data: name, email, phone number, username, and password - the password is stored as a one-way hash, so nobody can recover it, ourselves included.
  • Device data: a technical device identifier, the manufacturer, model, and OS version, and the last time it checked in - used to link the device to the supervisor account and apply its policy.
  • Installed app list: each app's name and icon, so the supervisor picks what to allow from the device's real apps instead of a generic list.
  • Usage data: minutes and open counts per app per day, screen unlocks, and PC on-time plus its busiest programs - used to show the supervisor's reports and enforce time limits.
  • Protection settings: the lists, limits, schedules, and modes the supervisor configures for the device.
  • Location data: the device's coordinates, their accuracy, and when they were captured. Collected from Android phones only, and only after location permission is explicitly granted on the device, so the supervisor can see where the device is.
  • Audit log: a record of the changes a supervisor or our support team makes to a device's settings, for traceability, troubleshooting, and protecting the account from tampering.
  • Subscription data: the plan, its status, and its expiry date. Your card details never reach us and are never stored by us: they are entered directly with the approved payment gateway and stay there.

What we do not collect

  • We do not read your messages, calls, photos, or files.
  • We do not log your keystrokes and we do not capture your screen.
  • We do not keep a history of the sites you visit; the address is checked against the block lists on the device itself, before the page opens.
  • We do not sell or rent your data to anyone, and we do not use it for advertising or to train any other system.

Why we use this data

We use data to run the service and nothing else: enforcing the rules on the device, showing reports to its linked supervisor, syncing settings, managing the subscription, providing support when you ask for it, and protecting the service from tampering and abuse.

Who can see the data

A managed device's data is visible to that device's linked supervisor only. Within Tabaa, access is limited to what running the system and answering support requests actually requires, under the principle of least privilege, and every action is written to the audit log. We share none of it with anyone else except under a binding legal request.

Location data in particular

Location reporting is optional and only runs once location permission has been granted on the device; withdraw that permission at any time in the device settings and reporting stops immediately. The supervisor sees the latest fix plus a short recent trail. We keep location history for seven days only - anything older is deleted automatically. We never use location data for any other purpose and never share it.

How long we keep data

We keep account and device data for as long as the subscription runs. Location records are deleted automatically after seven days. Usage is stored as a daily rollup (minutes per app per day) to power the reports. When a device is unlinked or removed from a supervisor account, its associated data is deleted with it. You can ask us to delete your account entirely and we will, within a reasonable time, unless the law requires us to retain certain accounting records.

Third-party services we rely on

To run the service we rely on external providers, and each one receives only the minimum its job requires:

  • Google's push messaging service, to deliver a sync signal to the device the moment a supervisor changes a setting.
  • an external domain-filtering provider that the managed device's internet lookups pass through, so harmful sites are blocked before they open.
  • a web analytics service that measures visits to this website only and has no access to any managed-device data.
  • an approved payment gateway that processes payments and holds the payment-method details instead of us.

How we protect data

Data travels over an encrypted connection, passwords are stored as one-way hashes using a modern algorithm, and each device holds its own token that unlocks only that device's data. Internal access is bound by least privilege and fully logged. Even so, no system is one hundred percent secure, and we keep reviewing and improving our defences.

Children

The service is used by adults as much as by children. Where the managed device belongs to a child, their guardian is the account-holding supervisor, accepts this policy on their behalf, and is responsible for the rules they set.

Your rights and how you stay in control

  • Access the data linked to your account or your device.
  • Correct your account details from inside the app at any time.
  • Unlink the device from the supervisor account - done from the supervisor account itself - which stops that device from reporting anything.
  • Withdraw the location permission in the device settings at any time.
  • Ask us to delete your account and its data.
  • Unlinking a device is the supervisor's decision - speak to them directly, or to us via support.

Changes to this policy

We may update this policy, and the last-updated date at the top of the page changes with every revision. Continuing to use the service after a change means you accept the updated policy.

Contact

For any privacy question, or to request a copy of your data or its deletion, contact us at +201507966165.

All our contact channels are listed on the contact page.