1. Scope and contact
This Privacy Policy explains how the Sawalef website and Windows application handle information. Sawalef is a Saudi-focused communication project in active development, with a private Windows preview for authorized testers.
For privacy questions, requests or complaints, contact the Sawalef founder at [email protected]. Product-support enquiries can be sent to [email protected].
2. Visiting the website and contacting us
The website contains no analytics or advertising scripts. It does not set cookies, use browser storage, collect a waiting list, submit forms or ask you to sign in. Styles, scripts and images are served from the website host.
The website is prepared for Cloudflare Pages. Hosting and network services can process IP addresses, requested URLs, request time and browser or protocol information to deliver and protect the site. Host-level processing is separate from the website's own scripts.
If you email Sawalef, your address, message and any information you include are processed to handle the enquiry. Sawalef's business email is provided through Lark Mail. Your own email provider also handles your message. Do not include passwords, verification codes, recovery keys or private conversation contents in an enquiry.
3. Information used by the application
| Category | Examples and purpose |
|---|---|
| Account and profile | Email, account identifier, display/profile information and preferences support sign-in and the app experience. |
| Authentication and devices | Authentication challenges, session metadata, approved device identifiers and public identity certificates support account access, approval, revocation and recovery. Private device keys and recovery material are held in the client's protected storage. |
| Communications and delivery | Encrypted message and attachment contents, sender and recipient identifiers, conversation membership, timestamps, delivery acknowledgements and signed event metadata support communication and synchronization. |
| Calls and connectivity | Call membership, signaling and network connection information support call setup. Network addresses can be visible to the service, network discovery providers and call participants during WebRTC negotiation. |
| Technical and security information | Request information, device status, connection errors and security or administrative events support operation and abuse prevention. The desktop also allows a local diagnostics export; this does not mean that every report is uploaded automatically. |
| Usage and account limits | Application payload totals, estimated call traffic, voice/screen duration and quota or entitlement records support limits and operation. Usage summaries do not include call audio or screen payloads. |
| Optional integrations | Provider identity references, authorization-flow metadata, protected local backup credentials or Store entitlement records can be used when the corresponding integration is configured and used. Availability depends on which integrations are enabled for your access. |
| Support and enquiries | Your email address, enquiry and relevant details you choose to share are used to respond to product, business, partnership or privacy questions. |
Account, authorization and delivery information is necessary for the corresponding service functions. You choose whether to send messages or files, share a screen, contact Sawalef or use an offered optional integration.
4. Communications and protection
The app uses OpenMLS for message encryption, encrypts attachment contents and stores encrypted local history records. On Windows, the local vault key is protected using operating-system-backed storage. The service handles encrypted delivery contents and the metadata needed to authorize and deliver them.
Voice and screen streams use WebRTC over a verified direct peer-to-peer path when available. Service infrastructure still handles sign-in, permission checks, call membership and signaling. A reachable direct route is required by the current documented call path. Call audio and screen packet payloads are kept out of service analytics.
Communication content and account or signaling metadata have different roles and protections. These mechanisms do not mean that every data category is end-to-end encrypted or that the service collects no information. Recipients can see, save or record what you share. Encryption cannot protect an unlocked or compromised endpoint.
5. Providers and disclosures
Cloudflare Pages is the intended website host, and Lark Mail provides Sawalef's business email. Hosted application infrastructure supports identity, authorization, encrypted delivery and signaling. Direct call setup references Cloudflare and Google STUN services for network discovery.
Microsoft Store handles preview distribution and its account-access requirements. If optional sign-in or encrypted cloud-backup integrations are enabled and used, their respective providers also process the information needed for those functions under their own terms and privacy practices. This website does not start those integrations or collect payment details.
Processing locations and applicable provider arrangements depend on the services used; this policy does not promise that all information stays in one country. Information may need to be disclosed where required by applicable law or necessary to address a lawful security or abuse issue. Privacy questions about providers or disclosures can be sent to [email protected].
6. Retention and deletion
Different records have different lifetimes. The implementation uses expiring authentication state, temporary delivery records and configurable attachment expiry. Acknowledged recipient mailbox copies are removed, and certain temporary records are pruned. Aggregate usage, account, security and local-history records are handled separately.
Retention depends on the information's purpose, service operation, security needs and applicable requirements. This policy does not specify an unverified fixed period for every category or promise automatic account deletion. Expiry of a delivery record does not mean that all related backups, logs or recipient copies disappear at the same time. Local history may remain on an approved device.
For a deletion or account-closure request, email [email protected]. Requests are assessed according to the information involved, the available technical process and applicable requirements. Device revocation or sign-out should not be treated as deletion of all previously shared content.
7. Choices and privacy rights
The app provides available device and preference controls. You decide when to share your screen, send attachments or use an offered integration. Keep recovery information safe and review which devices remain approved.
Depending on applicable law and the processing involved, rights may include being informed, requesting access or a copy, seeking correction, requesting destruction and withdrawing consent where relevant. Contact [email protected] to make a request or raise a complaint. Identify the request clearly and provide only the information needed to understand it.
Reasonable identity confirmation may be needed to protect account information. Do not send passwords, one-time codes or recovery keys. Requests are considered under applicable requirements and any lawful exceptions. For official information on Saudi privacy rights and complaint channels, see the Saudi Data & AI Authority knowledge center.
8. Policy updates
The effective date appears at the top of this page. Changes to the product, providers or processing practices may require updates to this policy. Material updates will be identified with an updated effective date and communicated through an appropriate available channel where required.
Contact [email protected] if you need clarification about the policy or its application to your information.