Hamed Saghafi app for Android and iOS
Privacy Policy
Summary
- Signing in is optional. Prices, the calculators, the archive and sharp-move alerts all work without an account, and that data stays only on your own phone.
- If you sign in with your mobile number or email, it is the same account as on hamedsaghafi.com: your name, mobile number and email, plus your settings, favorites, price alerts and calculation archive, are kept on our server so they come back on any phone you sign in on, and so alerts reach you even when the app is closed.
- You can delete your account at any time from inside the app; only course and certificate records are kept (section 11).
- From version 3.9, anonymous usage statistics are sent. Even when you're signed in they aren't linked to your account, name or phone number, and you can turn them off in Settings.
- No data is sold, used for other companies' advertising, or shared with advertising companies. The app has no ads and no third-party tracking tools.
1. Without an account (guest): what stays on your phone
If you don't sign in, the following are stored only on your phone's own storage and are never sent to any server: calculator inputs and results, the archive and invoices, favorites, price alerts and their thresholds, settings (language, currency, theme), and home-screen and smartwatch widget data. Deleting the app removes them all.
Guests can turn on sharp-move alerts too, and they are checked on the phone itself. Creating a new custom price alert requires an account with a verified mobile number, and new IPO notifications require signing in (section 4). Backup to a file has been removed in this version; account sync replaces it.
2. Your account (optional)
Signing in and signing up use a one-time code, with no password. The app account is the same account as on the hamedsaghafi.com website; if you already have an account there, the same mobile number or email signs you in to it. With an account we keep:
- Your mobile number and/or email, and whether each is verified. One is enough to sign in; adding the other is optional. You change them from the account screen by confirming a code on both the current and the new value.
- Your first and last name — required for new accounts, because it appears on course certificates and in our messages to you. If you entered other details on the website (such as date of birth or city), they stay there; the app doesn't ask for them.
- A sign-in session for each phone or browser: when you signed in, the IP address and software identifier (user agent) at sign-in, whether it's the app or the website, the operating system and app version, and when it was last used (updated at most once every ten minutes). Each session is valid for at most 90 days, and ends immediately when you sign out, change your mobile number or email, or delete your account. The session key is kept on the phone in the Keychain (iOS) or Keystore (Android).
- One-time codes are stored only in hashed form, are valid for 3 minutes and stop working after 5 wrong attempts. To prevent abuse, which mobile number or email a code was requested for, when, and from which IP address is recorded, and the number of requests is limited.
- An account security log: verifying or adding a mobile number or email, changing them or your name, and deleting the account — with the previous and new value, time and IP address — so we can investigate if someone accesses an account without permission or if there is a dispute about a course or certificate.
Purposes: signing in and maintaining your account, sending codes, security and abuse prevention, sync and alerts (sections 3 and 4), showing certificates (section 5), and our messages to you (section 4). Sign-in codes are delivered through SMS and email delivery providers; they receive only the mobile number or email and the code message in order to deliver it, and may not use it for anything else.
3. Cloud sync (signed in only)
While you're signed in, the following are kept on our servers so they come back on another phone or after reinstalling:
- Settings (language, theme, currency unit and display options).
- Favorites and their order.
- Custom price alerts: the asset, condition and threshold, whether each is on, repeat, and when and how many times it has triggered.
- Notification choices: sharp-move alerts (on/off and sensitivity) and new IPO notifications.
- The calculation archive: each calculation's title, type, inputs and result.
When you delete something, the server keeps only a “deleted” marker with no content so your other phones delete it too; that marker is removed after 90 days. Signing out stops syncing; the data on that phone and the copy in your account are left as they are. Deleting your account removes the copy on the server.
4. Alerts, notifications and our messages
Price alerts and new IPOs
Creating a new custom price alert requires an account with a verified mobile number, and new IPO notifications require signing in. Your account's alerts are checked both on your phone and on our server, so we can still notify you if the app is closed or your phone was offline for a while. Each time an alert triggers, which alert, at what price, when, and whether the phone or the server detected it are recorded, so the same notification never reaches you twice. Sharp-move alerts are checked only on the phone; with an account, only their settings are synced.
Your phone's notification identifier
To deliver notifications to a phone, the operating system (Google's notification service on Android and Apple's on iOS) creates a notification identifier. If you've allowed notifications:
- While you're signed in: this identifier, together with the operating system, app version, app language, whether notifications are on, and when it was last used, is linked to your account and to that phone's session, so alerts and account messages reach all your phones. It is removed when you sign out, delete your account, or when Google or Apple reports it is no longer valid.
- For “News from the developer” (turned on and off in Settings): the same identifier is registered, without a name or account, in the list for general news, and turning that switch off removes it from that list immediately. If you're signed in, the identifier stays linked to your account until you sign out, but our news isn't sent to that phone.
Notifications travel from our own notification sending service — which runs on cloud infrastructure — to Google's or Apple's notification service, and from there to your phone. The text of each send and its recipient identifiers are kept for at most 7 days to track delivery, then deleted.
Our messages to you
We may send you, or a group of users, a notification (sometimes with an image) about the app, courses or important news. Groups are chosen using information in this account — for example courses you've completed, your operating system, or how much you use the app — and no data is given to another company for this. Turning off “News from the developer”, or the app's notifications in your phone's settings, stops these messages.
Each kind of notification can be turned off separately: alerts and IPO notifications in the app itself, “News from the developer” in Settings, and all of them at once in your phone's notification settings. If anonymous statistics are on, the type of notification that was shown or tapped is counted in those statistics.
5. My Certificates
If you've completed a course, the “Certificates” tab shows your certificates from your website account: name, course name, date and verification code. Each certificate has a public verification page that anyone with its link can open — that's what makes it trustworthy.
- Show in Google search is off by default, and you turn it on or off yourself. Off means the page opens only from its link.
- Sharing and LinkedIn: the LinkedIn button fills in LinkedIn's “add certification” form with the course name, date, link and verification code; nothing is recorded until you save it on LinkedIn yourself, and we send no data to LinkedIn.
- View statistics: each time a certificate's public page is opened, we record the day, an estimated country and city, the kind of source (search, social network, link or direct), the domain of the referring site, and a daily hashed key used to count distinct visitors; that key changes every day. The visitor's IP address is not stored; country and city are estimated from it on our own server, with no outside service, using the DB-IP database (licensed under CC BY 4.0), and may be inaccurate. Your own visits, bots and messaging-app link previews aren't counted. These statistics are shown only to the certificate's owner (and the system administrator).
6. Fetching prices
To show live rates, the app gets data from our server (hamedsaghafi.com) and from public price services — such as currency and gold rate websites, cryptocurrency exchanges and global price services. As with any internet request, these services see your IP address and standard technical request information. No personal information, calculations, identifiers or account keys are sent in these requests; requests that reach our own server also include the app version and the operating system type.
Like every web server, ours temporarily keeps technical logs (IP address, time and requested address) for security and troubleshooting. In internal reports these logs are used only as aggregate counts, and they are never given to anyone.
7. Anonymous usage statistics (from version 3.9)
To learn which parts of the app are actually useful, which go unseen and where errors happen, the app sends the following statistics to our own server:
- A random installation ID that the app creates when it is installed. It isn't derived from your phone, SIM card, advertising ID or identity, and it changes if you delete and reinstall the app.
- The app version and build number, the operating system type and version, and the app language.
- App opens and how long each use lasts.
- The sections and tabs that are opened (for example “Prices → Gold” or “Gold Touchstone → Coin”).
- Feature use without values: “a calculation was made”, “an alert was created”, “sync completed”, “a certificate was shared” — no numbers and no asset names.
- Notifications shown and tapped, with only the notification type (for example “price alert” or “new IPO”).
- Counts of app errors and whether price sources were reachable, without personal details.
Never included in these statistics: account ID, name, phone number, email, location, contacts, calculation values, archive contents, favorite assets or alert thresholds. IP addresses are not stored with these statistics either. The installation ID is never linked to your account — not in the app and not on the server — even while you're signed in.
These statistics are kept on our own servers and never go to any other analytics or advertising service. Raw events are deleted after 180 days; all that remains is aggregate counts (for example “how many times the Coin section was opened today”) that can't be traced back to any installation.
Turning it off
You can turn it off at any time in Settings → Share anonymous usage stats. Sending stops immediately, and statistics that haven't been sent yet are deleted from the phone. Because these statistics aren't linked to your identity or account, we can't look them up by your name or phone number either.
8. Feedback
Only when you fill in the “Send feedback” form yourself are your message, an optional email address for a reply, and basic technical device information (app version, device model and operating system version, language, and the section you were in) sent for review. No account or installation ID is attached, and this information is used only to reply and to fix problems.
9. Who can access the data
- The system administrator (Hamed Saghafi) can see, in the admin panel, the list of accounts, which accounts use the app, operating system and version, last use, sessions and connected phones — for support, security and sending the messages in section 4.
- Service providers working on our behalf, who receive only the data their job needs: server hosting, SMS and email delivery providers (for sign-in codes), the cloud infrastructure of our notification sending service, and Google's and Apple's notification services.
- If the law requires us to, and only as far as required.
All communication between the app and our servers is encrypted (HTTPS).
10. How long data is kept
- Account and synced data: until you delete your account.
- Sign-in session: valid for at most 90 days; ends sooner when you sign out or delete your account.
- One-time code: valid for 3 minutes, stored only in hashed form.
- “Deleted” markers in sync: 90 days.
- Notification identifier: until you sign out, delete your account or it becomes invalid; for general news, until you turn the switch off.
- Text and recipients of each notification send: at most 7 days.
- Raw anonymous statistics events: 180 days.
11. Deleting your account
In the app: Settings → Account → Delete account. To be sure it's you, a code is sent to your verified mobile number or email, and entering it deletes the account immediately. If you can't use the app, write to hello@hamedsaghafi.com from the account's email address or mention its mobile number.
Removed:
- Mobile number, email and their verification; date of birth and city if you entered them on the website.
- First and last name — unless you hold a certificate that hasn't been revoked (see below).
- All sessions on every phone and the website (ended), and connected phones with their notification identifiers.
- Synced data: settings, favorites, alerts and their trigger history, notification choices and the archive.
Kept, and why:
- Purchase, course enrollment, playback license and certificate records — because they are financial and educational records, and an issued certificate must stay verifiable.
- If you hold a certificate that hasn't been revoked, your name is kept only for those certificates; a public verification page is meaningless without its holder's name.
- The account security log (section 2), including the record of the deletion itself, to handle disputes and prevent abuse.
Data on that phone (favorites, alerts, archive) isn't touched; deleting the app removes it. Anonymous statistics aren't linked to your account, so they can't be found and deleted with it; they are deleted automatically under the 180-day rule. Signing in again with the same mobile number or email creates a new account. The system administrator's account can't be deleted from the app.
12. Permissions
Internet, to fetch prices, sign in, sync and send statistics; notifications, for alerts and news; and, only when you ask for it, saving invoices to the gallery. The app doesn't ask for access to your contacts, location, camera or microphone. A sign-in code that arrives by SMS is offered through the operating system's autofill, and the app doesn't read your text messages.
13. Children
The app isn't made for children under 13 and doesn't knowingly collect data from them. If you believe a child has created an account, write to us and we'll delete it.
14. Changes to this policy
Any change is published on this page with a new date. If a change fundamentally alters how data is used, it will also be announced in the app.
15. Contact
Have a question about privacy or your data? Write to hello@hamedsaghafi.com, or use the “Send feedback” form in the app's Settings or our contact page (in Persian).