Data Protection & Privacy

Data policy

What we collect, who sees it, and where it goes

1. Who is responsible for your data

Project ZMAM, represented by its founder Ali Muwaffaq. He decides why your data is collected and how it is used.

2. What we collect

  • Your account: name, email and password (stored hashed by the sign-in service), and account type.
  • Your profile: phone, country, city, bio, photo, portfolio link, specialty, level, achievements, why you joined, and your GitHub account if you link it.
  • What you sign: the membership agreement, signatures, and documents you create (contracts, invoices, certificates) with their numbers.
  • What you post and write: projects, ratings, forum posts, groups, private messages, reports and blocks.
  • Your team work: tasks, notes, decisions and the event log in team workspaces.
  • Technical: an iOS device token if you enable notifications, your preferences (language, theme, sound), and how many times you use the assistant, to apply the daily limit.
  • Account security: when a wrong password is typed on a sign-in page we record a one-way hash of the account e-mail, a masked copy (like a***@gmail.com) and the number of attempts; when a usage limit is exceeded we record which limit and your account id, never your IP address. Only the founder sees them, to detect break-in attempts, and they are deleted after 30 days.
  • Technical faults: when something breaks in your browser we record the kind of error, its short message, the page, and the browser and system name, without your name, account, IP address or what you typed, and we mask any email or number in the message. Only the founder sees them, to fix the fault, and they are deleted after 30 days.
  • Audit record: we record platform events (sign-ins, permission changes, administrative decisions, data requests and the like) in a hash-chained record that cannot be edited. The network address (IP) is kept in full for 90 days, then only a one-way trace remains. We do not record passwords or the content of private messages.
  • Assessment and credentials: your answers, your practical task and the links you upload, your scores, result and credentials. Examiners grade the task under an alias and declare any relation to you. Someone verifying your credential by its code sees only your first name and an initial, your level and your field.
  • Conflicts and anonymous feedback: what you write in your case and the decisions taken in it, confidential to those handling it. Leader feedback is anonymous: your name is not stored with your answers and results are not shown before three people have answered.

3. Who sees your data inside ZMAM

  • Your public page (zmam.dev/u/yourname) is hidden by default and shows only if you turn it on in Settings. If you do, anyone on the internet can see it without an account: name, bio, badges, your card number (masked), published projects, skills and your verified GitHub account, and you are also listed in the talent search and on the leaderboard. It never shows your email or phone. You hide it any time with the "Hide page" button.
  • Approved members see each other in the member directory by name, bio and specialty, and never see your email or phone.
  • Your private messages are visible to the two participants only. They are read only as part of a report, and that is recorded in the admin log.
  • Admins see only what their permission allows; the founder sees everything. Every admin action is recorded under its author.
  • Your work in a team workspace is visible to its members, to leaders of workspaces above it, and to the founder. Sibling teams do not see each other.
  • To follow the work, only the founder sees for each member: last sign-in, last activity in teams, the number of open, late and finished tasks, reviews and accepted hours, and whether the ownership terms are signed. This never includes your private messages.

4. Artificial intelligence

  • The ZMAM assistant, the level check, the skill exam and the Telegram bot process your text with an external model provider (see the table below). Do not send passwords, keys or banking details; the assistant is built to refuse them.
  • We do not use your data to train models of our own. The provider's handling of what reaches it is governed by its terms.
  • The assistant sees your own account data only, and nothing private about other members.
  • Voice notes to the Telegram bot (up to two minutes) are turned into text by the same provider and then handled like a typed message. We do not keep the audio.
  • One exception: when the founder asks «عين زمام» about the state of the platform, the watch summary goes to the same model provider: team and member names and work indicators (last sign-in, tasks, reviews, hours, signature status) and open problems. It never includes your messages, email or phone.
  • The founder's assistant may keep short working notes the founder asks it to remember (for example a preference, a decision, or a note about following up with a team). They are visible only to the founder, who can delete them at any time.

Who receives your data outside ZMAM's own database, and what

ProviderWhyWhat it receivesWhere
SupabaseDatabase, sign-in, image storage and live updatesAll account data and contentGermany (Frankfurt, EU)
CloudflareHosting and delivery of the site, and AI models for skill exams, the level check, the Telegram bot and the ZMAM assistantThe text you send to the tool you useGlobal network, outside Iraq
Anthropic (Claude)The model behind the ZMAM assistant when you use itYour messages, the open page, and a summary of your account (specialty, level, skills, project counts, open task titles, competition entries)Outside Iraq
ResendEmail delivery: the admin digest and the newsletterThe recipient's email address and the messageOutside Iraq
Apple (APNs)iOS app notificationsThe device token and the notification textOutside Iraq
TelegramThe ZMAM bot when you use itYour messages to the bot and its repliesOutside Iraq
GitHubGitHub account verification and the level checkThe username you enter; we read only its public dataOutside Iraq

5. Where your data is stored

  • Your data is currently hosted outside Iraq: in Frankfurt, Germany, within the European Union.
  • We are working on a hosting option inside Iraq with local partners; it is not complete yet. We will say so here when it is, and will not describe it as done before then.

6. How we protect it

  • Every database table is covered by row-level access policies, so a member reads only what is theirs or was made available to them.
  • Admin sign-in requires two-factor verification. The full service key is never in the browser.
  • The site runs over HTTPS only, with security headers (CSP, HSTS) that block scripts from unapproved sources and stop other sites from embedding it.
  • The admin log and the team event log cannot be edited from the interface.
  • The admins may correct your profile details or email when needed (for example a wrong address that stops our emails), and you are told what changed. They never see or set your password; they send you a link to choose it yourself.
  • A protection system watches failed sign-ins, repeated breaches of usage limits and waves of new accounts. If someone tries to guess your password we tell you. On abuse, an account may be frozen temporarily (up to 3 days) or sign-up closed for a while, by the founder's decision; you can object through Contact the admins.
  • Administration reports are built from fixed database queries, not from a language model, and sealed with a hash recorded in the audit record, which anyone holding the file can check. Confidential reports are not sent over Telegram.
  • The founder's assistant "Jarvis" reads aggregated operational data (states, counters, dates), not member names or the text of cases, and cannot execute: it proposes and waits for the founder's approval. Every read it makes is recorded.
  • No system is perfectly secure. If you find a weakness, write to us at the address below.

7. Tracking and browser storage

  • We use no advertising trackers and do not sell your data. Cloudflare may give us aggregate visit statistics, depending on the hosting settings.
  • We store in your browser your sign-in session, your preferences, and the data of the local tools (encrypted vault, task board, snippets). These stay on your device until you clear them.

8. Retention, deletion and your rights

  • We keep your account data while the account exists. You edit your profile and preferences yourself in Settings.
  • Nightly backup: every night we copy account, signature, team, project and admin records into private storage inside the same database (Germany), reachable only by the server, and keep it 14 days to recover from mistakes. It does not include your private messages. What you erase by leaving stays in these copies for up to 14 days, then disappears.
  • In Settings you download a copy of your data, and leave ZMAM and close your account yourself. Leaving erases your personal data (name, phone, email, bio, photo, skills, preferences, notification tokens), blanks the text of your messages and posts, withdraws your personal projects from the gallery, and disables sign-in; it cannot be undone.
  • Some legal and administrative records remain after you leave and we cannot erase them: your signatures on documents, the membership agreement and card, the official documents you issued (verified by number), the admin log and the team event log (with names removed), the work done for ZMAM projects, and the financial record of any payment order. They are attributed to "a former member".
  • You cannot leave before handing over your leadership and open tasks, and declaring that you handed over the code of ZMAM projects and deleted any copy of it; this is part of the "Work ownership and exit terms" document.

9. Contact

For any question or request about your data, or to report a weakness, write to the founder:

[email protected]
Who we areLast updated: 2026-10-05

Open this page in the interactive site