Last updated: 12 July 2026.
This policy explains what Sanad collects, why we hold it, who can see it, and what happens when you ask us to delete your account. We have tried to describe what the software actually does, including the parts that are uncomfortable. Where something works in a way you might not expect, we say so instead of hiding it.
- Your identity in Sanad is your phone number. We do not ask for an email address, a home address, or an identity document.
- We do not run any identity check. There is no KYC in Sanad.
- Inside a room, other members do not see you. The organiser does — because they approve who joins.
- An anonymous donation is genuinely anonymous to the organiser. They never learn who gave.
- Your account is not protected by a secret code today. The app asks for a verification code, but the system does not actually send you one, and the value it accepts is a fixed value, not a secret generated for you. In practice, anyone who knows your phone number can sign in as you. Do not keep money in Sanad that you cannot afford to lose.
- Sanad staff can see everything, including who made an anonymous donation. Anonymity protects you from other users, not from us.
- Sanad staff can also act on your money — cancel a room (which refunds what is in its pot), reverse a transaction that already went through, and hide a room from discovery.
- We cannot delete your financial records. They are the record of other people's money too.
What we collect
Your account
- Your phone number. This is how you log in and how we tell one account from another. It is required.
- Your first and last name and, if you give it, your date of birth. These are optional. Your name is what a room organiser sees when you join their room.
- Your language preference, so we show the app in Arabic or English.
- A push notification token for your device, if you allow notifications. We clear it when you log out.
That is the whole account record. There is no email field, no address field, no profile photo, and no identity document anywhere in Sanad.
When you ask for a one-time code
Every time a one-time code is requested for your number, we store a row containing: the phone number, the code itself, the IP address the request came from, a device identifier sent by the app, the time it was requested, the time it expires, what it was for (logging in, changing your number, or deleting your account), and how many times it was tried.
We keep this log to stop someone from hammering your number with code requests, to limit how many wrong guesses are allowed, and to have a record if an account is taken over. Be aware of two things. The code is stored as it is, not scrambled. And the code our system currently accepts is a fixed value that is never actually delivered to your phone — it is not a secret only you hold. The rate limits above slow down someone hammering your number, but they do not protect an account from someone who simply knows your phone number. We are fixing this, and we would rather you knew than found out.
When you log in
A successful login records your IP address, the device and app identification string your phone sends, and the time. Sanad keeps only your most recent session — logging in on a new device replaces the old record and signs the old device out.
Your money
Every movement of money is a permanent record: who sent it, who received it, how much, in which currency, when, and who approved it. That includes transfers, top-ups, deposits and withdrawals, contributions to a room, savings-circle payouts, donations, releases, refunds and reversals.
When you request a deposit or a withdrawal you also give us what that request needs: a payout destination (for example a Whish number or a USDT address), and, depending on the method, a proof screenshot or a reference such as a blockchain transaction hash. Our staff read these, because cash in and cash out are settled by hand, off the platform.
Files you upload
Room cover images, deposit proof screenshots, and the photos, documents and notes an organiser posts as proof of what a room's money was spent on. A proof can be set to public by the organiser, which means anyone who can see the room — including people who are not members — can open the files in it.
How you use the app
For a long list of events — opening the app, registering, logging in and out, updating your profile, changing your phone number, sending a transfer, requesting a deposit or a withdrawal, creating a room, joining one, accepting an invitation, contributing, withdrawing, donating (including when you donate anonymously), releasing a donation pot, posting a proof, paying into a savings circle, and requesting account deletion — we write an activity record containing the event name, your user id, your IP address, your device and app identification string, your device type and operating system, the address of the request, and an approximate location derived from your IP address (city, region, country and rough coordinates).
That location is a guess made from the IP address, not GPS. We do not read your device's location. The lookup is done on our own servers against an offline database — your IP is not sent to any outside geolocation service.
When something breaks
When a request to our servers fails, we log the error and, with it, the contents of that request. We strip passwords, tokens, secrets and one-time codes from that log. We do not strip everything else: a phone number, an amount, a note, or a payout destination in a failing request will end up in the error log. We keep these logs to find and fix bugs.
Phone numbers of people who are not users
You can invite someone to a room by phone number before they have a Sanad account. We store that number so the invitation is waiting for them if they ever sign up. If you invite someone, you are giving us their number — please only do it if they would expect you to.
What we do not collect
To be explicit, because these absences matter:
- No identity documents and no KYC. We never ask for a passport, a national ID, a selfie, a proof of address or a bank statement. There is no identity verification, no sanctions screening and no age check anywhere in Sanad. We ask for your date of birth, but we do not check it and nothing in the app depends on it.
- No email address. We have no email channel to you, and no email-based way to recover an account.
- No password. You sign in with your phone number and a verification code. Understand what that means as the app stands today: the code is not actually sent to your phone, and it is not unique to you, so holding your SIM is not what protects your account. Anyone who knows your phone number can currently sign in as you, see your balance, your rooms and your history, and move your money. Until we fix that, your phone number is the only thing between someone and your account.
- No home address, no profile photo, no contacts list, no advertising identifiers.
- No bank or card details. No payment processor is connected to Sanad. Money in and out is arranged manually with our staff.
One consequence follows from all of this and you should hold on to it: we have not vetted anybody. When you hand money to a room organiser, you are trusting that person, not a verified identity we checked.
Why we hold each thing
- Phone number — to identify your account and let you log in. Without it there is no account.
- Name — so a room organiser knows who is asking to join their room, and so you are recognisable to the people you deal with.
- Date of birth and language — profile details you chose to give; language sets the app's language.
- One-time-code log (phone, IP, device, attempts) — to rate-limit code requests, cap wrong guesses, and investigate account takeovers.
- Login session (IP, device, time) — to keep you signed in on one device and to show and end that session.
- Transaction records — because they are the money. Balances in Sanad are not stored as a number we edit; they are recalculated from these records. Delete a record and someone's balance changes.
- Payout destinations and deposit proofs — so staff can actually pay you, and can check that you paid us, since this is settled by hand.
- Uploaded proof files — so people who put money into a room can see what it was spent on.
- Push token — to send you notifications about your rooms and your money. Nothing else.
- Activity log and approximate location — to spot abuse and fraud patterns, to understand which parts of the app are used, and to support you when something goes wrong.
- Error logs — to diagnose failures. Nothing more.
We do not sell your data. We do not use it for advertising. There is no advertising or tracking SDK in Sanad.
Who can see what inside a room
This is the part worth reading twice.
Other members do not see you
A room is anonymous between members by default. In such a room a regular member sees the room's totals — how much is in the pot, how many members, how many slots are taken — plus the organiser's name, plus their own slots, contributions and payouts. They do not see the list of members. They do not see who contributed, who withdrew, or who was paid.
But the organiser can switch that anonymity off. In a room with anonymity turned off, every member — and anyone with a request to join still pending — sees the full roster: the first and last name of every other member, yours included. The organiser sets this, not you, and it can be changed on a room you have already joined. One thing does not leak either way: other members never see anyone's phone number. Only the organiser sees that.
The organiser sees the roster
They have to. The organiser approves who joins and sets the payout order, so they cannot do their job blind. When you join a room, you disclose your first name, last name and phone number to that room's organiser. Join a room only if you are willing for that person to have your number.
The reverse is also true: an organiser's own name is shown to anyone who can see their room.
A room can be set to show who did what
Separately from the roster, an organiser can set a room's activity feed to public, which means the room's participants can see which member put money in or took it out. The default is private. Either way, the feed is never visible to people outside the room.
An anonymous donation is anonymous — including to the organiser
This is a real guarantee and it is worth understanding why it holds.
When you donate anonymously, Sanad does not create a membership record for you at all. You are not on the roster, because there is nothing to put on it. The donation exists as a line in the financial ledger, flagged anonymous — and nowhere else the organiser can reach. (It does also appear in our internal activity log, which records that you used the donate feature, with your IP address. That log is staff-only — see the next section — and the organiser never sees it.) The organiser's list of donations shows the amount, the date and the fact that it was anonymous — and nothing else. The activity feed never attributes it to anyone, even in a room the organiser has set to public: the anonymous flag on the ledger line beats the room's setting.
So the organiser cannot learn who you are. Not from the roster, not from the feed, not from the donation list.
And yet they can still send you proof of what your money did. When the organiser posts a proof against a specific donation, Sanad works out who should receive it from the ledger line, not from any list the organiser can see. They address the donation; we deliver it to the donor. You get the evidence; they never get the name.
Two caveats, stated plainly. First, the organiser sets the room's anonymity policy: a room can be set so that every donation is forced anonymous, or so that anonymous donations are refused outright and you must be named to give at all. Check the room before you donate. Second, see the next section.
Sanad staff can see everything — and can act on your money
Anonymity in Sanad protects you from other users. It does not protect you from us.
Our staff tools apply no redaction. Every ledger line is linked to a wallet, and every wallet is linked to a user. That means staff with the right permission can identify the person behind an anonymous donation, can see any room's full roster, and can see any user's complete transaction history. Staff also operate an internal reporting tool that reads the production database directly.
And staff can do, not only see. A staff member with the right permission can hide a room from discovery, cancel a room outright — which moves money, returning what is left in the pot to the people who put it there — trigger a savings-circle payout, approve or reject a withdrawal that is waiting on approval, reverse a transaction that has already gone through, and credit a wallet. Every one of those lands in the same audited ledger as everything else. They are real powers over your money, and you should know they exist.
We hold that access for three reasons: to investigate fraud and abuse, to support you when a transaction goes wrong (someone has to be able to see what happened), and to comply with a lawful obligation if one is imposed on us. We restrict it by permission and we do not use it to satisfy an organiser's curiosity about a donor. But you should know it exists.
Third parties, and where your data physically sits
The list is short, and we would rather state it exactly than gesture at "trusted partners".
- File storage. Files you upload are stored on our own servers, or on Amazon Web Services (S3), or on a remote file server we operate, depending on how the deployment you are using is configured. Where S3 is used, Amazon is a processor holding your uploaded images and documents.
- Push notifications. Push is delivered through Google Firebase Cloud Messaging. Where it is enabled, Google receives your device's push token and the title and body of the notification we send you. Nothing else.
- Virus scanning. Uploaded files may be scanned by ClamAV, which runs on our own servers. No file is sent to an outside scanning service.
- Location lookup. The city and country we derive from your IP address are resolved on our own servers from an offline database. Your IP is not sent to a geolocation provider.
- Analytics. Our analytics tool is self-hosted and reads our own database. There is no third-party analytics service and no tracking SDK in the app.
There is no advertising network, no CRM, no email provider, no SMS provider, and no payment gateway connected to Sanad. No outside payment processor sees your money, because there isn't one: cash in and cash out are handled manually by our staff.
How long we keep things, and what deletion really does
You can delete your account from the app: you request deletion, confirm with a one-time code, and the account is closed. Here is exactly what that does, and what it does not do.
What happens. Your account is marked deleted and you can no longer log in with it. Your first name, last name and phone number are obfuscated in our database so they no longer identify you or match your number on login.
What does not happen. The record is not erased. The obfuscated fields still contain your original number inside them, and your date of birth, your last login and your session record remain in the row. Your transaction history remains in full and permanently.
We are not being evasive about the ledger: we cannot erase it. Your transactions are also somebody else's transactions. A contribution you made to a savings circle is the record of what four other people are owed. Balances in Sanad are recomputed from these records rather than stored as an editable number, so deleting a line does not remove a fact — it corrupts other people's money. The ledger is append-only and there is no path in the software to delete from it. That is deliberate.
Two warnings, because deletion is sharper than it looks:
- Deleting your account does not withdraw your balance, does not close your wallets, and does not take you out of your rooms. Cash out and leave or cancel your rooms before you delete. Money left behind is not automatically returned to you.
- Deletion cannot be undone. If you register again with the same phone number you get a brand-new, empty account and a new wallet. The old balance and history stay attached to the closed account.
Our operational logs are not all kept for the same length of time. Activity records, error logs and the log of staff actions are deleted automatically once they are 60 days old — a job runs once a day and removes them permanently. The one-time-code log is different: it is currently kept indefinitely, and it holds your phone number, the codes themselves, the IP addresses and the device identifiers. We have no retention window on it yet. We would rather tell you that than imply a schedule we do not run.
Your rights
Depending on where you live, you may have the right to ask for a copy of the data we hold about you, to have it corrected, to have it deleted, to object to how we use it, or to restrict that use. You can exercise these rights with us regardless of whether the law where you live grants them.
- Access. Ask us and we will tell you what we hold about you.
- Correction. You can change your name and profile details in the app at any time. To change your phone number, use the change-number flow in the app.
- Deletion. Delete your account in the app. Read the section above first, so you know what is and is not removed. We will not delete financial ledger records, and we will tell you honestly that we are refusing rather than pretend they are gone.
- Objection. Tell us and we will look at it. If you object to something we genuinely cannot stop doing while you have an account with money in it, we will say so.
Contact us through the support option in the app, or the contact page on our website. Because we hold no email address for you, we will reply through the same channel you reached us on.
Children
Sanad is not for children. It is intended for adults who can lawfully enter an agreement and handle money.
We should be honest about the limits of that statement: we ask for a date of birth but we do not verify it, and there is no age check anywhere in the app. Nothing in the software stops a minor from registering with a phone number. If you are a parent or guardian and you believe a child has an account, contact us and we will close it and remove what we can — with the same limits on the financial ledger described above.
Changes to this policy
If we change how Sanad handles your data, we will update this page and change the date at the top. If a change is significant — new data collected, a new third party receiving it, a change to who can see what inside a room — we will tell you in the app rather than quietly editing this page and hoping you re-read it.
Contact
Questions about this policy, or about what we hold on you, go through the support option in the Sanad app or the contact page on our website. If something here is unclear or reads as evasive, tell us — that is a bug in the document and we will fix it.