Privacy
Trial privacy notice
You can read TABAQAT without an account. Participation and Writer Studio use only the information needed to provide, protect, and moderate those features.
Trial draft · formal privacy and retention review pending
Information handled
- Guest participation: a random browser token is stored in an HTTP-only cookie. Only a one-way hash is stored with reactions, comments, edits, reports, and ownership records.
- Public discussion: your chosen public name, contribution text, language, timestamps, and moderation state are visible with the article.
- Google sign-in: Google supplies an account identifier, email address, display name, and basic profile details. These remain private account data and never become a public byline automatically.
- Passkey sign-in, when enabled: TABAQAT stores a credential identifier, public key, counter, and limited device/backup metadata. Your fingerprint, face scan, or device PIN stays with your device or passkey provider and is not sent to TABAQAT.
- Recovery codes, when created: TABAQAT stores only a one-way cryptographic digest for each code and whether it was used. The readable codes are shown once and are not recoverable by TABAQAT.
- Writer Studio: writing identities, biographies, drafts, submitted works, image descriptions, credits, source links, rights confirmations, and review history.
- Security operations: short-lived rate-limit events and service logs needed to detect errors or abuse.
How information is used
- Operate guest ownership, account sessions, editing, editorial review, publishing, moderation, and abuse prevention.
- Display only the public name and content you choose to submit for publication.
- Generate a separate translation draft only when a writer requests it; the source work is not replaced.
Service providers
Cloudflare hosts the application, database, media storage, image processing, and security controls. Google provides sign-in only when that option is chosen; a passkey may be stored or synchronized by the user's device or password-manager provider. OpenAI processes article text only when a signed-in writer requests an Arabic–English translation draft. Each provider handles data under its own terms and privacy practices.
Optional analytics
- If you choose Allow analytics, Google Analytics receives aggregated information about visits and selected actions such as article shares, reactions, comments, reports, sign-in starts, and writer submissions.
- The site does not send your name, email address, private account name, comment text, or private account identifiers to Google Analytics. Analytics is disabled until you choose it, and you can change the choice through Analytics settings.
- The analytics choice is stored in this browser's local storage so the site can remember your preference.
Control, retention, and deletion
A guest can edit or delete a contribution from the browser that created it while the browser token remains available. Clearing browser data removes that proof of ownership. Deleted discussion text may leave a neutral tombstone so replies retain context.
A private account can use one-time recovery codes, more than one passkey, or an explicitly linked Google account as backup access. A code works once; replacing the set disables every older unused code. Losing every available method can still make the account permanently inaccessible.
Self-service deletion removes credentials, sessions, recovery codes, Google access, and private ownership links. Published works, public profiles, discussion contributions, and necessary editorial audit records remain unless separately reviewed for removal. A formal production retention schedule is still pending.
What not to submit
Do not submit passwords, government identifiers, private correspondence, precise personal locations, medical or financial information, or another person’s personal data without a lawful and necessary reason. Public comments and approved works should be treated as public.