سياسة الخصوصية
Privacy Policy
عوكل سيستم داخلي لوكالة Mongz Media بيتابع أداء صفحات فيسبوك بتاعة الوكالة. الصفحة دي بتقول بالظبط إيه اللي بنقراه من فيسبوك، وليه، وفين بيتخزن، وإزاي تمسحه.
آخر تحديث: 21 سبتمبر 2026 — Last updated: 21 September 2026
مين إحنا
«عوكل» (3okal.com) سيستم داخلي بتشغّله وكالة Mongz Media لمتابعة أداء صفحات فيسبوك اللي الوكالة بتديرها.
الخدمة مش مفتوحة للجمهور: مفيش تسجيل حساب جديد من الموقع، والأدمن هو اللي بيعمل حسابات الموظفين بالإيميل والباسورد. اللي بيستخدم السيستم هم موظفو الوكالة بس.
إيه اللي بنطلبه من فيسبوك وليه
الربط بيتم بـ «تسجيل دخول فيسبوك للأعمال» (Facebook Login for Business) من أدمن الوكالة بس، مرة واحدة من شاشة الإعدادات. الأذونات كلها قراءة:
- public_profile — فيسبوك بيديه مع أي تسجيل دخول. إحنا مبنقراش ولا بنخزّن اسم الشخص ولا صورته.
- pages_show_list — عشان نعرف الصفحات اللي الأدمن مسؤول عنها ونجيب توكن كل صفحة. من غيره مش هنعرف نستورد ولا صفحة.
- pages_read_engagement — عشان نقرا أرقام الصفحة نفسها: المتابعين، والإعجابات والتعليقات والمشاركات على البوستات (أرقام مجمّعة بس).
- pages_read_user_content — عشان نقرا قايمة بوستات الصفحة المنشورة (النص، النوع، اللينك، وقت النشر). من غيره الصفحة بتبان فاضية.
- read_insights — عشان نقرا رؤى البوستات (المشاهدات والوصول) وأرباح المحتوى اليومية للصفحة. ده أساس الداشبورد كله.
- business_management — الصفحات مملوكة لمحفظة أعمال الوكالة (Mongz Media)، والصفحات اللي تحت محفظة أعمال مبتديش توكناتها من غير الإذن ده.
البيانات اللي بنخزّنها من فيسبوك
- الصفحة: رقمها عند فيسبوك، اسمها، توكن الصفحة، وقت آخر مزامنة وآخر غلط لو حصل.
- عدد المتابعين — لقطة يومية لكل صفحة.
- البوستات المنشورة: رقم البوست، نوعه، نص البوست، اللينك، وقت النشر، وأرقام الإعجابات والتعليقات والمشاركات والمشاهدات والوصول — ولقطة يومية لكل بوست.
- أرباح المحتوى اليومية لكل صفحة (content_monetization_earnings).
- توكن المستخدم اللي عمل الربط — صف واحد، بنعيد استخدامه لما نضيف صفحة جديدة بلينكها.
مبنخزّنش أي بيانات عن الناس اللي بتتفاعل مع الصفحة: مفيش أسماء ولا حسابات ولا تعليقات بأصحابها — أرقام مجمّعة بس.
فين بتتخزن ومين بيشوفها
كل البيانات في قاعدة بيانات واحدة (PostgreSQL) على سيرفر الوكالة الخاص، والموقع كله على HTTPS. توكنات الصفحات وتوكن الربط متخزنين في نفس القاعدة، مبيظهروش في أي شاشة ومبيتبعتوش لأي طرف تاني.
الوصول محصور في السيرفر نفسه وفي أدمن الوكالة. الموظف بيشوف الصفحات المسنودة ليه بس، والأرباح للأدمن لوحده. باسوردات الدخول متخزنة مشفّرة بـ bcrypt.
اللي مبنعملوش خالص
- مبنعملش إعلانات ولا بنوصل لحسابات إعلانية.
- مبننشرش ولا بنعدّل ولا بنمسح أي بوست أو تعليق على أي صفحة.
- مبنقراش ولا بنبعت رسايل صندوق الصفحة.
- مبنبيعش ولا بنأجّر ولا بنبادل أي بيانات مع حد.
- مفيش أي أدوات تتبع أو تحليلات خارجية ولا بكسل إعلانات على الموقع.
- مبنشاركش البيانات مع أي طرف تالت غير Meta (مصدر البيانات) ومزوّد السيرفر اللي شغّال عليه الموقع.
مدة الاحتفاظ
- بيانات الصفحة (بوستاتها ولقطاتها وأرباحها) بتفضل طول ما الصفحة متابعة في عوكل، لأن قيمة السيستم في المقارنة بالتاريخ.
- أول ما الصفحة تتشال من عوكل، بوستاتها ولقطاتها وأرباحها وتوكنها بيتمسحوا معاها في نفس اللحظة.
- طلب حذف جاي من فيسبوك أو منك: بنخلّصه في مدة أقصاها 30 يوم.
- رسايل الواتساب الجاية للسيستم بتتمسح تلقائيًا بعد 60 يوم.
الواتساب
عوكل بيبعت تنبيهات تشغيلية (ملخص الصبح، صفحة سكتت، نزول مشاهدات، مهام) على واتساب لأرقام موظفي الوكالة بس — الأرقام دي الأدمن هو اللي بيكتبها في السيستم. مفيش أي رسايل لأي حد بره الوكالة، ومفيش رسايل تسويقية.
لو الأدمن رد على السيستم بأمر من واتساب، بنسجّل نص الرسالة ورقم الباعت عشان ننفّذ الأمر ومنكررهوش — والسجل ده بيتمسح تلقائيًا بعد 60 يوم.
الكوكيز
كوكي واحدة بس: كوكي جلسة الدخول اللي بتفضّلك مسجّل. مفيش كوكيز إعلانات ولا تتبع.
حقوقك وحذف بياناتك
تقدر في أي وقت تشيل «عوكل» من إعدادات فيسبوك بتاعتك، وساعتها بنوقف قراءة أي حاجة. وتقدر تطلب منّنا نمسح كل حاجة متخزنة.
الخطوات كاملة (وكود التأكيد) في صفحة حذف البيانات.
تغييرات وتواصل
لو غيّرنا حاجة في السياسة دي هنحدّث تاريخ «آخر تحديث» فوق. لأي سؤال أو طلب: dolfndolfn@gmail.com.
English version below
Who we are
Awkal («عوكل», 3okal.com) is an internal tool operated by Mongz Media, a media agency, to track the performance of the Facebook Pages the agency manages.
It is not a consumer service. There is no public sign-up: the agency admin creates email/password accounts for staff, and only agency staff use the system.
Facebook permissions we request, and why
Only the agency admin connects, once, through Facebook Login for Business. Every permission is read-only:
- public_profile — granted by Facebook with any login. We do not read or store the person's name or profile picture.
- pages_show_list — to list the Pages the admin manages and obtain each Page access token. Without it we cannot import a single Page.
- pages_read_engagement — to read Page-level numbers: follower count, and reaction/comment/share counts on posts (aggregate counts only).
- pages_read_user_content — to read the Page's published posts (text, type, permalink, publish time). Without it every Page looks empty.
- read_insights — to read post insights (views and reach) and the Page's daily content monetization earnings. This is the whole point of the dashboard.
- business_management — the Pages are owned by the agency's Business Portfolio (Mongz Media), and business-owned Pages do not return their tokens without this permission.
What we store from Facebook
- Page: Facebook Page id, name, Page access token, last sync time and last sync error.
- Follower count, as a daily snapshot per Page.
- Published posts: post id, type, message text, permalink, publish time, and the like / comment / share / view / reach counters, plus a daily snapshot per post.
- Daily content monetization earnings per Page (content_monetization_earnings).
- The access token of the admin who connected, one record, reused when a new Page is added by link.
We store nothing about the people who interact with a Page: no names, no accounts, no individual comments. Aggregate counters only.
Where it is stored and who can see it
Everything lives in a single PostgreSQL database on the agency's own server, and the site is served over HTTPS. Page access tokens and the connection token are stored in that same database, are never displayed in any screen, and are never sent to any third party.
Access is limited to the server itself and to the agency admin. A staff member only sees the Pages assigned to them; earnings are admin-only. Login passwords are stored as bcrypt hashes.
What we never do
- We run no ads and never touch ad accounts.
- We never publish, edit or delete any post or comment on any Page.
- We never read or send Page inbox messages.
- We never sell, rent or trade any data.
- There are no third-party trackers, analytics or advertising pixels on the site.
- We share data with no third party other than Meta (the source) and the hosting provider that runs the server.
Retention
- Page data (posts, snapshots, earnings) is kept for as long as the Page is tracked in Awkal, because the value of the tool is historical comparison.
- When a Page is removed from Awkal, its posts, snapshots, earnings and its access token are deleted with it, immediately.
- A deletion request from Facebook or from you is completed within 30 days at most.
- Inbound WhatsApp command messages are deleted automatically after 60 days.
Awkal sends operational alerts (morning summary, a Page that stopped posting, a drop in views, task reminders) over WhatsApp to the agency's own staff numbers, which the admin enters into the system. Nobody outside the agency is messaged, and nothing marketing-related is sent.
When the admin replies to the system with a command, we store the message text and the sender number so the command runs once and only once. That log is deleted automatically after 60 days.
Cookies
One cookie only: the login session cookie that keeps you signed in. No advertising or tracking cookies.
Your rights and deleting your data
You can remove Awkal from your Facebook settings at any time, and we immediately stop reading anything. You can also ask us to delete everything we hold.
Full steps, including the confirmation code, are on the Data Deletion page.
Changes and contact
If we change this policy we update the «Last updated» date above. For any question or request: dolfndolfn@gmail.com.
عوكل · السيستم الداخلي لـ Mongz Media