Company MASHROUA AL-THALITH ASHAR For IT Systems
PRIVACY POLICY
Governing the “Thirteen” Mobile Application and Related Services
Effective Date: August 1, 2026
Jurisdiction: Kingdom of Saudi Arabia
1. Introduction
This Privacy Policy (“Privacy Policy” or “Policy”) explains how Company MASHROUA AL-THALITH ASHAR For IT Systems, a company registered in the Kingdom of Saudi Arabia (“KSA” or the “Kingdom”) under Commercial Registration No. 4030367847, with its registered office at 7562 King Abdulaziz Rd, Ashati 3569, Jeddah 23513, Kingdom of Saudi Arabia (the “Company,” “we,” “us,” or “our”), collects, uses, stores, discloses, and protects Personal Data when you use the mobile application known as “Thirteen” and any related websites, features, and services (collectively, the “Services”).
We process Personal Data in accordance with the Saudi Personal Data Protection Law and its Implementing Regulations (the “PDPL”), under the oversight of the Saudi Data and Artificial Intelligence Authority (“SDAIA”), and with other Applicable Law of the Kingdom, including the Anti-Cybercrime Law and any rules issued by the Communications, Space and Technology Commission (“CST”) or the National Cybersecurity Authority (“NCA”).
Capitalized terms used but not defined in this Policy (including “Account,” “Anonymous Mode,” “Group,” “User Content,” and “Applicable Law”) have the meanings given to them in our Terms and Conditions of Use (the “Terms”). This Policy is incorporated into the Terms by reference. Where the Terms and this Policy conflict on matters of data protection, this Policy controls.
By registering for, accessing, or using the Services, you acknowledge that you have read and understood this Policy. Where processing is based on your consent, you may withdraw that consent as described in Section 12.
2. Our Key Privacy Commitments
End-to-End Encryption. All messages, images, videos, and voice notes exchanged through the Services are protected by end-to-end encryption. Encryption and decryption occur exclusively on Users’ devices, and the cryptographic keys required to read your communications are generated and stored on those devices only. As a result, the Company sees, transmits, and stores only ciphertext — the encrypted form of your communications. We do not have, and cannot obtain, access to the plain-text content of your messages, and we cannot read them, in the ordinary course of providing the Services.
Anonymous Mode. During each Anonymous Mode window, your display name and profile identifiers are hidden from other members of your Group. Anonymous Mode does not hide your identity from the Company at the account level: the only additional information the Company holds in connection with Anonymous Mode is a record mapping your real Account to the temporary display identity assigned to you during each Anonymous Mode session. The Company still cannot read the content of messages you send during Anonymous Mode, because they remain end-to-end encrypted like all other messages.
3. Information We Collect
The Company must receive or collect some information to operate, provide, secure, support, and improve the Services. The types of information we receive and collect depend on how you use the Services. Certain information is required to deliver the Services; if you do not provide it, we will not be able to provide the Services to you.
3.1 Information You Provide
Account Information. You must provide your mobile phone number and a display name of your choice to create an Account. If you do not provide this information, you will not be able to create an Account or use the Services. You may optionally add other information to your Account, such as a profile picture.
Your Messages and Other User Content. We do not retain your messages in the ordinary course of providing the Services, and we could not read them even if we did: all User Content is end-to-end encrypted before it leaves your device, and the Company handles only ciphertext. Messages are stored on your device and are not typically stored on our servers. If a message cannot be delivered immediately (for example, because the recipient is offline), we hold it in its end-to-end encrypted form on our servers for up to thirty (30) days while we attempt delivery, after which it is deleted. Media may be held temporarily in end-to-end encrypted form to enable efficient delivery.
Groups. When you create or join a Group, the Group and its membership become associated with your Account. Group names, Group profile pictures, and Group descriptions provided by Users are visible to the members of that Group.
Customer Support and Other Communications. When you contact us for support, report a problem, or otherwise communicate with us, you may choose to provide us with information related to your use of the Services, including copies of specific messages you decide to share with us, and contact details (such as an email address) so we can respond. Because your messages are end-to-end encrypted, we can review the content of a message only where you (or another participant in the conversation) voluntarily transmit that content to us from your own device — for example, when submitting an abuse report as described in Section 3.3.
3.2 Information Collected Automatically
Usage and Log Information (Metadata). We collect service-related, diagnostic, and performance information. This includes metadata about your activity, such as the time, frequency, and duration of your use of the Services; delivery and routing records (which Account sent a message to which Group and when — but not the content of the message, which remains encrypted); Group membership records; when you registered; whether you are online; crash logs; and performance reports.
Anonymous Mode Session Records. For each Anonymous Mode window, our systems generate and retain a record mapping your real Account identity to the temporary display identity shown to other Group members during that window, together with the start and end time of the window. This mapping is the only additional information created by Anonymous Mode. It exists so that abusive conduct can be attributed to the responsible Account (see Section 7) and so that we can comply with valid legal process (see Section 9). It is never visible to other Users.
Device and Connection Information. We collect device- and connection-specific information when you install, access, or use the Services, such as hardware model, operating system and app version, battery level, signal strength, mobile network and connection information (including your phone number and mobile operator), language and time zone, IP address, and device identifiers.
Approximate Location. We do not collect precise device location. We may use your IP address and phone number country/area code to estimate your general location (such as country and city) for security, diagnostics, and compliance purposes.
3.3 Information Others Provide About You
Other Users. Other Users may provide information relating to you, for example by adding you to a Group or by mentioning you in their communications. Please keep in mind that, as with any messaging service, members of your Groups can capture screenshots of chats, record content, and share it with the Company or with others.
User Reports. When a User submits an in-app report of abusive conduct or content, the reporting User’s device transmits to us the reported message(s) and limited surrounding context in decrypted form, together with information identifying the reporting and reported Accounts. This is the mechanism by which the Company can review the content of specific reported messages notwithstanding end-to-end encryption. Where the reported message was sent during Anonymous Mode, we may consult the Anonymous Mode session records described in Section 3.2 to identify the sending Account for the purpose of investigating the report.
Third-Party Service Providers. Service providers that support the operation of the Services (see Section 6.2) may provide us with information in certain circumstances; for example, app stores may provide reports that help us diagnose and fix service issues.
4. Information We Do Not Have Access To
Because of the design of the Services, the Company does not have access to, and cannot produce, the following in the ordinary course of operating the Services:
the plain-text content of your messages, images, videos, or voice notes (we hold ciphertext only);
your private encryption keys, which are generated and stored only on your device; and
your precise device (GPS) location.
If you lose access to your device or delete the app without backing up your data, the Company cannot recover your message history, because we never hold a readable copy of it.
5. How We Use Information
We use the information described in Section 3 (subject to the choices you make and to Applicable Law) for the following purposes:
To Operate and Provide the Services. Including creating and maintaining your Account, routing and delivering encrypted messages, operating Groups and Anonymous Mode, providing customer support, and troubleshooting.
Safety, Security, and Integrity. Including verifying Accounts, preventing spam and abuse, investigating reports and suspected violations of the Terms (including conduct during Anonymous Mode), attributing conduct to the responsible Account by means of the Anonymous Mode session records, protecting Users, and ensuring the Services are used lawfully.
To Improve the Services. Including understanding how the Services are used at an aggregate level, evaluating and improving features, and developing and testing new features. We use metadata and diagnostics for these purposes; we never use the content of your communications, which we cannot read.
To Communicate With You. Including notifying you about updates to the Services, the Terms, or this Policy, and responding to your enquiries.
Marketing and Promotional Communications. With your consent where required by the PDPL, we may use your Personal Data — such as your phone number, Account information, and usage information — to send you marketing and promotional communications about the Services and offerings we believe may interest you, and to measure the effectiveness of those communications. We never use the content of your communications for marketing, because we cannot read it. You may opt out of marketing communications at any time, free of charge, through the in-app settings or by contacting us at [email protected]; opting out does not affect your use of the Services or communications that are necessary to provide them.
Legal Compliance. Including complying with our obligations under the PDPL, the Anti-Cybercrime Law, and other Applicable Law, and responding to valid legal process as described in Section 9.
6. Information You and We Share
6.1 Information Shared With Other Users
Your display name, profile picture, and other profile information are visible to members of the Groups to which you belong, except during Anonymous Mode windows, when they are hidden from other Group members as described in the Terms. The content you send is visible to the members of the Group to which you send it (that is where it is decrypted). Users with whom you communicate may store or reshare information you send them, on or off the Services; the Company cannot control what other Users do with content once they have received it.
6.2 Third-Party Service Providers
We work with a limited number of third-party service providers to help us operate, provide, secure, and support the Services, such as: cloud hosting providers; an SMS/OTP verification provider (used to verify your phone number at registration); push-notification services operated by Apple and Google (notification payloads do not include message content in readable form); and crash-reporting and diagnostics providers. These providers process information only on our behalf, on our documented instructions, under contracts consistent with the PDPL, and they receive only the information necessary to perform their function. They never receive readable message content, because we do not have it.
6.3 Corporate Transactions
If the Company is involved in a merger, acquisition, restructuring, bankruptcy, or sale of all or some of its assets, we will share your information with the successor entity or new owner in connection with that transaction, in accordance with the PDPL and other applicable data-protection requirements, and we will notify you as required by Applicable Law.
6.4 What We Never Do
We do not, and cannot, share the content of your end-to-end encrypted communications with anyone.
7. Anonymous Mode and Your Data
Anonymous Mode is a recurring feature of the Services during which display names and profile identifiers of Group members are hidden from other members of that Group, as described in the Terms. From a data-protection perspective, you should understand the following:
Hidden from Users, not from the Company. Anonymous Mode conceals your identity from other Group members only. The Company retains a record mapping your real Account to the temporary display identity used during each Anonymous Mode session (the “Anonymous Mode session records” described in Section 3.2). Every message you send during Anonymous Mode therefore remains attributable to your Account in our internal systems.
Content remains unreadable to us. Messages sent during Anonymous Mode are end-to-end encrypted like all other messages. The Company knows which Account sent a message during an Anonymous Mode window and to which Group, but not what the message says, unless a participant voluntarily reports it to us as described in Section 3.3.
No legal anonymity. Anonymous Mode does not create any form of legal anonymity and provides no protection against lawful requests for information made by a competent Saudi authority (see Section 9). You remain fully responsible for your conduct during Anonymous Mode under the Terms and Applicable Law, including the Anti-Cybercrime Law.
8. Legal Bases for Processing (PDPL)
We rely on the following lawful bases under the PDPL for the processing described in this Policy:
Contractual / actual interest necessity. Processing your phone number, Account information, metadata, and Anonymous Mode session records is necessary to provide the Services you have requested under the Terms.
Consent. Where required by the PDPL, we rely on your consent — for example, for direct marketing and promotional communications (see Section 5) and for optional features. You may withdraw consent at any time as described in Section 12; withdrawal does not affect processing carried out before withdrawal or processing based on another lawful basis.
Legitimate interest. To the extent recognized under the PDPL and its Implementing Regulations, we process limited information for the safety, security, and integrity of the Services, provided this does not prejudice your rights and interests.
Legal obligation. Processing necessary to comply with Applicable Law, including retention obligations and responses to valid legal process.
9. Disclosure in Response to Legal Process; Law, Our Rights, and Protection
We may access, preserve, and disclose the information described in Section 3 where we believe in good faith that it is reasonably necessary to: (a) comply with a valid order, subpoena, or request issued by a competent Saudi court, the Public Prosecution, CST, SDAIA, or another authorized Saudi governmental or regulatory authority; (b) enforce the Terms, including investigating potential violations; (c) detect, investigate, or prevent fraud, security incidents, or technical issues; or (d) protect the rights, property, or safety of the Company, its Users, or the public, in each case as permitted or required under Applicable Law, including the Anti-Cybercrime Law and the PDPL.
What we can and cannot produce. Because the Services are end-to-end encrypted and the Company does not hold decryption keys, the categories of information the Company is capable of producing in response to valid legal process are limited to: (i) Account and registration information (such as your phone number, display name, profile picture, and registration date); (ii) metadata, such as delivery and routing records, Group membership records, device and connection information, and IP addresses; (iii) Anonymous Mode session records, i.e. the mapping between an Account and the temporary display identities it used during Anonymous Mode windows; and (iv) message content only in its encrypted (ciphertext) form. The Company cannot produce the plain-text content of Users’ communications, because it does not possess it and does not possess the keys required to decrypt it.
Where a User has voluntarily submitted specific message content to us through the reporting mechanism described in Section 3.3, that reported content is held by the Company in readable form and may be preserved and disclosed in accordance with this Section 9.
10. Data Retention
We store Personal Data only for as long as necessary for the purposes identified in this Policy, including providing the Services, complying with legal obligations, enforcing the Terms, and protecting or defending our rights and our Users, in accordance with the PDPL. Our standard retention periods are:
Account information: for the life of the Account and for six (6) months after deletion or deactivation, unless a longer period is required by Applicable Law.
Undelivered messages (ciphertext): up to thirty (30) days, after which they are deleted whether or not delivered.
Delivery, routing, and usage metadata: six (6) months.
Anonymous Mode session records (identity mappings): six (6) months from the end of the relevant Anonymous Mode window, unless the record is subject to an active investigation, report, or preservation request, in which case it is retained until that matter is resolved or for such longer period as required by Applicable Law.
User reports and reported content: twelve (12) months from resolution of the report, or longer where required by Applicable Law or legal process.
When retention periods expire, we delete or irreversibly anonymize the relevant data in accordance with the PDPL and its Implementing Regulations.
11. Managing and Deleting Your Information
You can manage certain information directly in the app, including changing your display name and profile picture, and leaving Groups. You may deactivate or request deletion of your Account at any time by contacting us at [email protected]. When your Account is deleted, we delete your Account information and profile picture, remove you from Groups, and delete any undelivered messages held for you on our servers, together with other information we no longer need to operate the Services, subject to the retention periods in Section 10 and any retention required by Applicable Law. Deleting your Account does not affect the copies of messages you sent that are stored on the devices of the Users who received them.
12. Your Rights Under the PDPL
Subject to the conditions and exceptions set out in the PDPL and its Implementing Regulations, you have the right to:
be informed about how we process your Personal Data (which this Policy is intended to provide);
access your Personal Data held by us and request a copy of it in a readable format;
request correction, completion, or updating of your Personal Data;
request destruction (deletion) of your Personal Data where it is no longer needed for the purposes for which it was collected;
withdraw your consent to processing based on consent, at any time; and
object to certain processing as provided under the PDPL, including the right to opt out of direct marketing communications at any time, free of charge.
You may exercise these rights by contacting us at [email protected] or our data protection contact at [email protected]. We will respond within the timeframes required by the PDPL. Please note that some rights are limited by the nature of the Services: for example, we cannot provide access to, correct, or selectively delete the content of end-to-end encrypted messages, because we do not hold a readable copy of that content. If you believe your rights under the PDPL have been infringed, you may lodge a complaint with the competent authority (SDAIA).
13. Where Your Data Is Stored; Cross-Border Transfers
Personal Data collected through the Services is primarily stored in the Kingdom of Saudi Arabia and the United Arab Emirates. Because part of our infrastructure is located in the United Arab Emirates, the storage and processing of Personal Data there constitutes a transfer of Personal Data outside the Kingdom. Any such transfer, and any other transfer of Personal Data outside the Kingdom, is made only in accordance with the PDPL and the Regulation on the Transfer of Personal Data Outside the Kingdom, in reliance on an adequacy determination, appropriate contractual or technical safeguards (such as standard contractual clauses approved by SDAIA), or another basis recognized by SDAIA. Please keep in mind that message content transferred through our infrastructure is at all times end-to-end encrypted, wherever the infrastructure is located.
14. Data Security and Breach Notification
We implement appropriate technical, organizational, and administrative measures to protect Personal Data against unauthorized access, disclosure, alteration, and destruction, consistent with the PDPL, its Implementing Regulations, and applicable NCA cybersecurity controls. These measures include end-to-end encryption of all User Content, encryption of data in transit, access controls and logging restricting internal access to metadata and Anonymous Mode session records to authorized personnel on a need-to-know basis, and regular security reviews. No system is perfectly secure, and you are responsible for safeguarding your device and your Account credentials.
In the event of a personal data breach that poses a risk to your Personal Data or to your rights and interests, we will notify SDAIA within seventy-two (72) hours of becoming aware of the breach, and will notify you without undue delay where the breach is likely to result in harm to you, in each case in accordance with the PDPL and its Implementing Regulations.
15. Children
The Services are intended for Users who are at least eighteen (18) years of age, as set out in the Terms. We do not knowingly collect Personal Data from persons under 18. Where processing of Personal Data of a person who has not reached full legal capacity is exceptionally permitted under the Terms, we will process that data only with the verified consent of a parent or legal guardian, in accordance with the PDPL’s requirements for consent given on behalf of a person lacking legal capacity. If you believe a person under 18 has provided Personal Data to us, please contact us at [email protected] so that we can take appropriate action, including deleting the data and terminating the Account.
16. Updates to This Policy
We may amend or update this Privacy Policy from time to time. Where a change is material, we will provide notice through the Services or by email at least three (3) days before the change takes effect, except where an immediate change is required for legal, security, or safety reasons, and we will update the Effective Date at the top of this Policy. Where a change requires renewed consent under the PDPL, we will seek that consent. Your continued use of the Services after a revised Policy takes effect constitutes your acknowledgment of the revised Policy.
17. Contact Us
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, or wish to exercise your rights under the PDPL, please contact us at:
Company MASHROUA AL-THALITH ASHAR For IT Systems
Email: [email protected]
Data Protection / Privacy inquiries: [email protected]
7562 King Abdulaziz Rd, Ashati 3569, Jeddah 23513
Kingdom of Saudi Arabia
