STATIC QA REVIEW · 8 OCTOBER 2026
مسودة خصوصية QAQA privacy draft
هذه نسخة للمراجعة فقط. لا يوجد هنا تسجيل دخول أو تفويض TikTok أو شراء خدمات.
This is a review copy only. There is no sign-in, TikTok authorization or service purchase here.
العربية
1. ما تفعله هذه الصفحات
هذه صفحات ثابتة للمراجعة. لا تستخدم ملفات ارتباط ولا JavaScript أو تحليلات أو نماذج، ولا تصل إلى توكنات TikTok أو خادم الحسابات. يعالج الخادم طلب الويب لتقديم الصفحة؛ تفاصيل سجلات البنية التحتية والنسخ لم يثبت اكتمالها بعد.
2. مسار الهوية المقصود، وهو مغلق حاليًا
عند تفعيل تجربة منفصلة بعد المراجعة، يهدف المسار إلى قراءة هوية حساب اختبار مصرح به: open_id وusername، وربط الاتصال بالعميل واللوحة وحفظ الصلاحيات والحالة والأوقات.
يستخدم المصدر توكنات وصول وتحديث مشفرة على الخادم، وسجلات محاولة تتضمن بصمات رمز الحالة وربط المتصفح. لا تعرض استجابة العميل التوكنات. عند التفويض تُستخدم وصلة متصفح مؤقتة لمدة عشر دقائق بخصائص Secure وHttpOnly وSameSite=Lax. هذه الآلية ليست مفعّلة في الصفحات الحالية.
جمع بيانات الفيديوهات واكتشاف المنشورات غير مركّبين في تجربة الهوية الحالية، ولم نثبت عملهما. لا تُرسل طلبات مورّد أو بيانات دفع في نطاق QA هذا.
3. مدد QA المختارة
- بيانات OAuth وحساب الاختبار والمنشورات: إزالة خلال 7 أيام من نهاية الاختبار.
- التوكنات المخزنة محليًا: إزالة فور الفصل المحلي.
- السجلات الأمنية المنقّحة: إزالة بعد 30 يومًا من إنشائها.
هذه مدد اختارها المشغّل لبيانات QA فقط، ولا تنطبق على عملاء الإنتاج أو سجلاتهم المالية. لا ندّعي أنها مدد يفرضها قانون.
4. ما ثبت وما بقي
أثبتت تجربة تركيبية على قاعدة QA إزالة توكنات محليًا، وحذف سجل اتصال مؤرّخ اصطناعيًا باستخدام مساعد يدوي ومعاملة قاعدة بيانات، مع بقاء سجلات حساب آخر. لم تكن التجربة انتظارًا فعليًا لسبعة أيام أو إثباتًا لوجود جدولة حذف تلقائية.
المساعد المحدود يعالج سجلات الاتصال ومحاولات OAuth، ولا يثبت حذف كل بيانات الحساب أو المنشورات. لم يكتمل إثبات حذف سجلات المضيف وCDN وAPM أو النسخ الاحتياطية بعد 30 يومًا. انتهاء رمز OAuth ليس حذفًا فوريًا لكل بياناته. الفصل المحلي لا يلغي صلاحيات TikTok عن بُعد.
5. المشغّل وطلبات الخصوصية
المشغّل المقدّم: Alfahad IT Corp، كندا. جهة التواصل Samer Areer على zorbagraphic@gmail.com. بلد المشغّل لا يثبت مكان معالجة البيانات أو النسخ.
يمكن طلب معلومات أو فصل أو حذف عبر هذا البريد. لم تُعتمد مدة معالجة الطلبات، وإرسال الطلب لا ينفّذ حذفًا تلقائيًا. هذه مسودة للمراجعة ولا تدّعي اعتمادًا قانونيًا أو امتثالًا مكتملًا.
English
1. What these pages do
These are static review pages. They use no cookies, JavaScript, analytics or forms and cannot access TikTok tokens or the account server. The server processes the web request to serve the page; complete infrastructure-log and backup handling has not been established.
2. The intended identity flow, currently closed
If a separate test is enabled after review, the flow is intended to read an authorized test account’s identity: open_id and username, associate its connection with the customer and panel, and store scopes, status and timestamps.
The source uses server-encrypted access and refresh tokens and attempt records containing state and browser-binding fingerprints. Client responses do not expose tokens. During authorization a temporary browser-binding cookie lasts ten minutes with Secure, HttpOnly and SameSite=Lax attributes. This mechanism is not enabled in the current pages.
Video-data collection and post discovery are not mounted in the current identity test and have not been proved working. No provider orders or payment data are sent within this QA scope.
3. Chosen QA periods
- OAuth, test-account and post data: remove within 7 days after the test ends.
- Locally stored tokens: remove immediately on local disconnect.
- Redacted security logs: remove 30 days after creation.
These are operator-selected periods for QA data only, not production customers or their financial records. No statutory retention period is claimed.
4. Evidence and remaining limits
A synthetic QA database test proved local token removal and deletion of a synthetically backdated connection using a manual helper and database transaction while another account’s records remained. It was not an actual seven-day wait or proof of an automatic deletion scheduler.
The bounded helper handles connection and OAuth-attempt records; it does not establish deletion of all account or post data. Thirty-day deletion of host, CDN and APM logs or backups has not been fully proved. OAuth state expiry is not immediate deletion of all its data. Local disconnect does not revoke TikTok permissions remotely.
5. Operator and privacy requests
The supplied operator is Alfahad IT Corp, Canada. Contact Samer Areer at zorbagraphic@gmail.com. The operator’s country does not establish processing or backup locations.
You may request information, disconnect or deletion using this email. Request-processing timing has not been approved, and sending a request does not trigger automatic deletion. This is a review draft and claims neither legal approval nor complete compliance.