Home

Privacy policy

Last published:

Who is responsible

ARRIB is owned by Amal El Ghamdi, an Arabic teacher, with a team based in Saudi Arabia. The ARRIB Team handles questions about personal data through the Contact page. This policy describes how the current ARRIB service uses information.

Account and technical information

We store your name, email address, verification state, account role, interface language, timezone and account state. Google sign-in may provide a profile image and authentication information. Authentication records include sessions, sign-in tokens and, for email and password accounts, a protected password representation. Session records may include an IP address and browser information for account security.

Learning information

We store your onboarding choice, placement attempt and result, lesson completions, exemptions, study dates and counts, and earned badges. We temporarily hold exercise session state to evaluate answers and resume eligible activities. Typed exercise answers are not kept as a permanent answer history. Detailed technical lesson-session information is cleared after completion or expiry, with a target retention of no more than 30 days for abandoned records.

Why we use information

We use information to create and protect accounts, verify email addresses, recover access, deliver lessons, calculate progress and study activity, and provide support. Administrators can see relevant learner information for these tasks. Minimal audit events record high-impact administrative actions without passwords, provider tokens or full learner answer histories.

Cookies and abuse prevention

Essential session cookies keep you signed in, and a language preference remembers your interface choice. We use limited anti-abuse counters to protect forms and authentication. Contact abuse counters use hashed identifiers instead of storing the submitted message. ARRIB has no advertising, public learner profiles or behavioural analytics service.

Service providers

ARRIB uses Neon PostgreSQL for database storage, Vercel for hosting and public learning media, Resend for transactional and contact email, and Google when you choose Google sign-in. These providers process information needed to deliver their services. Provider processing or storage may occur outside Saudi Arabia; the actual hosting regions, transfer arrangements and provider retention must be confirmed before the service is launched.

Contact messages

The contact form sends your name, email, subject and message to the ARRIB Team by email. Contact messages are not stored in the ARRIB application database. Messages may remain in the support inbox and email-provider systems under their retention practices. Do not send passwords or unnecessary sensitive information.

Retention and deletion

Account and learning records remain until your account is deleted or removed operationally. Authentication sessions and verification or reset links expire. Administrative audit events remain for operational history; account deletion unlinks learner-targeted audit events. You can permanently delete your learning account in Settings. ARRIB does not maintain a custom backup system for recovering deleted learner accounts.

Your choices and requests

You can update your name, interface language and timezone in Settings, request password recovery where applicable, and delete your account. Contact the ARRIB Team to ask about your information, request access or a copy, correct information, or raise a privacy concern. We may need to verify your identity before handling a request. Applicable law may provide additional rights.

Children

ARRIB is a general-audience service and is not designed specifically for children. Users under 13 require parent or guardian consent. We do not ask for a date of birth, use advertising or offer public social features. A parent or guardian can contact us about a child’s account.

Policy updates

The published policy shows its latest publication date. Contact the ARRIB Team if any explanation is unclear or if you have a privacy question.