‹ Back to Sejeli

Privacy Policy

Last updated: 13 September 2026

This policy explains what personal data Sejeli ("the app", "we", "us") collects, why we collect it, how long we keep it, and what rights you have over it. It applies to both the web app and the mobile app.

1. Who is responsible for your data

Sejeli is operated by Hossameldin Haridy, an individual developer based in Egypt, who acts as the data controller for account data. Contact: hossam.e.faisal@gmail.com.

Where an instructor uploads a course roster, that instructor and their university determine what student data is entered and why. In that respect the university is the controller and Sejeli acts as a processor, handling the data only on the instructor's instructions and only to run attendance for their courses.

2. What we collect

Instructor accounts

DataWhy
Name, email addressTo identify your account and let you sign in
Password (stored only as a one-way Argon2id hash, never in readable form)To authenticate you
UniversityTo scope your courses and rosters to your institution
Course, room, schedule and attendance-policy settingsTo run the features you set up

Students

DataWhy
Name and university student ID numberEntered by your instructor to build the course roster; used to match you to your record
Email address (optional)Only if your instructor includes it in the roster
Lecture/lab groupTo show you the correct sessions
A device identifier and device tokenTo bind your account to one phone, so nobody can check in on your behalf
Location coordinates at check-in, and your distance from the roomTo confirm you were actually in the classroom
A flag if mock/spoofed location is detectedTo let your instructor identify fraudulent check-ins
Check-in time, attendance status, and any note your instructor addsTo form your attendance record
A photo of your university ID card (optional)Only if you choose to add one, so an instructor can identify you if you turn up without your card. It is shown to the instructors on your courses and to nobody else. You can remove it at any time from your Profile.
A photo attached to an appeal (optional)Only if you choose to attach one as evidence when you contest an absence — a medical note, for instance. It is shown to the instructors on that course and to nobody else. You can remove it at any time from the appeal.

Feedback and support messages

If you use Help & feedback to send us an idea, report a problem, or ask a question, we store:

The technical details are collected so you do not have to describe them, and they exist only to help us reproduce a problem. They are attached to the message you sent and nothing else — they are not used to build a profile, and they are not linked to your attendance records.

You can see everything you have sent us, and any reply, under Help & feedback in the app.

What we do not collect

3. Cookies and browser storage

Sejeli sets no cookies of its own. Not one, of any kind — there is no cookie banner on this site because there is nothing we need to ask you about. Our hosting provider's network may set a strictly necessary security cookie of its own to protect the site against automated abuse; it carries no information about you, is not used for advertising or analytics, and is exempt from consent.

This section is about the website. Advertising appears only in the mobile app, never on these pages. See section 12.

The website does store a small amount of data in your browser, using local storage rather than cookies. All of it is necessary for the service to work, and none of it leaves your device except as part of an ordinary request to us:

WhatWhy
Your sign-in tokenSo you stay signed in between visits
A random device identifierTo bind your account to one phone, so nobody can check in on your behalf. It is a random number and carries no name or address.
Display preferencesYour light/dark theme, text size and date format
Whether you have dismissed the tutorialSo it is not shown to you again

None of it is used for analytics, advertising, profiling or tracking, and none of it is shared with anyone. Because it is strictly necessary for the service you asked for, we do not ask for consent to store it. You can clear all of it at any time by signing out, or through your browser's "clear site data".

Reading these pages stores nothing. This policy, the terms, the account deletion page and the home page write nothing to your device at all.

No third-party services. The site loads no analytics, no advertising scripts, no embeds, and no fonts or code from anybody else's servers — everything is served from sejeli.com. The one exception is Cloudflare Turnstile, a bot check that appears only on the form for adding a university that is missing from our list; it is there to stop automated submissions and is not used to track you.

4. Camera

If your instructor enables QR check-in, the app asks for camera access to scan the code displayed in the room. Images are processed on your device to read the code and are never uploaded or stored.

5. Legal basis for processing (UK/EU users)

PurposeLawful basis
Creating and running your instructor accountPerformance of a contract (Art. 6(1)(b))
Recording student attendance on behalf of a universityThe university's own basis — normally public task or legitimate interests (Art. 6(1)(e) or (f)). Sejeli processes it under Art. 28 as a processor.
Using location to verify presence, and device binding to prevent proxy check-insLegitimate interests (Art. 6(1)(f)) — producing an attendance record that is actually trustworthy. Location is captured only at the moment of check-in and only as coordinates and a distance, which is the least intrusive way we could achieve this.
Keeping the service secure (rate limiting, abuse prevention)Legitimate interests (Art. 6(1)(f))
Answering a feedback or support message you sent us, including the technical details attached to itLegitimate interests (Art. 6(1)(f)) — we cannot answer a question or fix a fault without knowing who asked and what they were using. You chose to contact us, and you can ask us to erase the message at any time.
Showing non-personalised advertisements to adult studentsLegitimate interests (Art. 6(1)(f)). Advertising is how a service that is free to students is paid for, and no information about you is used to select the advertisement.
Showing personalised advertisements, and the storing or reading of information on your device that this involvesConsent (Art. 6(1)(a), and the ePrivacy rules on device storage). Asked separately, adults only, through Google's consent form. Declining does not remove advertising; it means what you see is not chosen using information about you. If the form is dismissed or cannot be shown, advertising falls back to non-personalised.

6. Who we share data with

We do not sell or rent personal data. It is shared only with:

Administrative access

Sejeli's operator can look up an account and, where necessary, correct or delete it. This is limited to what running the service requires:

Two things constrain it. The operator's dashboard shows counts, not people — there is no screen that lists students or displays attendance records, and finding an individual requires deliberately searching for them. And every change made through the admin console — every edit, every deletion — is written to an append-only log recording what was done, to which record, and when. Nothing in the application deletes from that log.

Both are bound by their own data-processing terms. We do not share data with any other third party unless legally required to.

International transfers

Our hosting and database providers operate data centres outside the UK/EEA, including in the United States. Where personal data of UK/EEA individuals is transferred, it is protected by the providers' Standard Contractual Clauses.

7. How long we keep it

8. Your rights

Under the UK GDPR and EU GDPR you have the right to:

To delete your account: open Sejeli, go to Profile, and use Delete account at the bottom under Account — or, without installing the app, use sejeli.com/delete-account.html. Both verify that the address is yours and then erase the account immediately. See the note in section 7 about what is and is not removed.

To remove a photo without deleting your account: your university ID photo can be removed at any time from Profile, and a photo you attached to an appeal can be removed from that appeal. Both take effect immediately. The appeal itself and what you wrote stay, because they are part of your attendance record — your instructor sees that the photo was withdrawn.

Students: because your record belongs to your course, the fastest route is usually to ask your instructor, who can correct or remove your roster entry directly.

How quickly we answer. Anything you can do yourself — deleting your account, removing a photo — happens immediately, with no request to us and no waiting. Where you do need to contact us, we answer within six working days, which is the limit Egypt's Personal Data Protection Law (Law 151 of 2020, Art. 32) sets for a controller replying to a request like this. That is shorter than the one month the UK and EU GDPR allow, so it is the deadline we work to for everyone.

9. Automated decision-making

Sejeli does not make automated decisions with legal or similarly significant effects. The app flags check-ins that appear to use a spoofed location, but this is only surfaced to your instructor for review — no consequence follows automatically, and a human always decides.

10. Children

Sejeli is intended for use in higher education. We do not knowingly create accounts for children under 13. Some university students are under 18; where that is the case, the institution is responsible for ensuring it has an appropriate basis to enrol them.

Advertising is treated differently for anyone under 18. Their account is flagged to Google as restricted, which turns off personalised advertising and remarketing, stops third-party advertising vendors being called, and withholds the advertising identifier. They are never shown the personalised-advertising consent form, because personalised advertising is not offered to them. The same restricted setting applies before anyone has signed in, so it is what is in force by default rather than something switched on afterwards. Section 12 has the detail.

11. How we protect data

No system is perfectly secure, but if a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users where required.

12. Advertising

The Sejeli website carries no advertising. The mobile app shows advertisements to students, supplied by Google AdMob. Instructors are shown no advertisements at all.

Core functionality is never gated by an advertisement. Checking into a session, seeing your courses and viewing your attendance record are always available. A small number of optional extras may offer a short rewarded video; if no advertisement is available the feature is unlocked anyway rather than withheld.

What Google receives, and what it does not

To show an advertisement, Google receives your device's advertising identifier, a resettable number held by your phone's operating system rather than by us, along with technical information about the device and the fact that an advertisement was requested.

We do not send Google your name, email address, university ID number, date of birth, location, or any attendance record. Nothing from your academic record is used to choose an advertisement.

One thing we cannot withhold, and would rather name than let you discover. Every request made over the internet carries your device's IP address, and a request for an advertisement is no exception. An IP address allows a rough area to be estimated — a city, usually, not a street. We do not send it: it is how the internet works, and it reaches Google the same way it reaches any website you open. The location this app actually measures — accurate to a few metres, taken only to confirm you are in the classroom — is never sent to Google and never leaves our own servers.

You can reset or delete the advertising identifier yourself at any time, in your phone's settings rather than in Sejeli: on Android under Settings → Privacy → Ads, and on iOS under Settings → Privacy & Security → Tracking.

If you are under 18

Your account is flagged to Google as restricted. Personalised advertising and remarketing are turned off, third-party advertising vendors are not called, and the advertising identifier is withheld. You are not asked to consent to personalised advertising, because it is not offered to you.

Whether an account is adult is worked out from the date of birth you already gave at registration. It is worked out on our server, which tells the app only whether the account belongs to an adult: your date of birth is never sent to Google and is never used to choose an advertisement. The restricted setting is also what applies before anyone has signed in, and if the check cannot be completed for any reason it stays restricted.

Personalised advertising, if you are an adult

Where the law requires it, adults are asked separately whether Google may use information about them to choose which advertisements to show. That is a question about personalisation, not about whether advertisements appear at all: declining does not remove advertising. It means what you are shown is not selected using information about you, and the app is otherwise identical. Your answer is stored and applied by Google's own consent framework. If the form is dismissed, or cannot be shown, advertising falls back to non-personalised.

You can change that answer at any time. Where you were asked in the first place, the app carries the choice under Settings → Advertising choices, and withdrawing is exactly as easy as agreeing was. If you were never asked — because the law where you are does not require it, or because you are under 18 — no personalised advertising is taking place for the row to change.

What is never advertised

All advertising in Sejeli is limited to the strictest content rating Google offers (“G”), for every user, adult or not. Advertisements for dating, alcohol, gambling and comparable categories are excluded.

13. Changes to this policy

We may update this policy from time to time. The "last updated" date above always reflects the current version, and material changes will be communicated in the app.

14. Contact

To exercise any of the rights above, or to ask anything about this policy, open Help & feedback in the app and send us a message. It reaches us directly, you get a reference number, and you can see the reply in the same place. It works whether or not you can sign in, so being locked out of your account is not a barrier to asking us to erase it.

You can also write to hossam.e.faisal@gmail.com, which reaches Hossameldin Haridy directly.

Read the Terms of Service ›