Privacy policy

Last updated

This Privacy Policy was last updated in July 2026.

Who we are

Mathla operates mathla.org (community platform), related subdomains, and production services on api.mathla.org. For privacy inquiries contact [email protected].

Our purpose for your data

We collect and process data to build a trusted Arabic Sign Language community resource: to operate accounts, review contributions, support learning, protect safety, and — only with your explicit choices — improve public dictionary coverage and responsible model training. We do not sell personal data.

UAE context

We design privacy practices for users in the United Arab Emirates and beyond, with reference to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and with respect for national inclusion goals for People of Determination. Mathla is an independent community platform, not a government website.

Scope

This policy applies to accounts, sign-language video submissions, community activity, learning progress, and support communications on Mathla. It covers visitors who reach us via mathla.org (which redirects to the community platform) and registered users. Production translation apps on api.mathla.org may have additional notices where required.

Lawful basis (UAE PDPL)

We process personal data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and applicable best practices. We rely on: your consent (especially for videos and optional uses), contract performance (providing the platform), legitimate interests (security, abuse prevention, service improvement), and legal obligations where applicable.

Data we collect

Account data (name, email, password hash, locale, roles); sign-language videos and metadata you submit; versioned consent choices; review and moderation records; optional profile fields; community posts and messages; organization and campaign participation; technical logs (browser, device type, timestamps, hashed IP for abuse prevention); cookies and session identifiers needed to keep you signed in.

Biometric-like and sensitive data

Sign-language videos may show your face, hands, and upper body. We treat this as sensitive personal data. Recording requires explicit, versioned consent before upload. You choose separately whether each submission may be used for AI training, public dictionary display, research, or partner sharing.

Approximate location

To organize contributor diversity we may infer your approximate country once when you open the collect flow from your network connection. Your IP address is not stored in plain form — only a one-way hash for abuse prevention. The country field can be edited or cleared in your profile.

How we use data

Operate accounts and authentication; store and review submissions; publish approved dictionary entries you opted into; run learning paths and community features; train and evaluate sign-language models only with your explicit opt-in; produce consent-filtered dataset exports; prevent fraud and abuse; respond to support and legal requests; improve accessibility and platform reliability.

Automated processing

Videos may be analyzed with automated tools (pose detection, hand tracking, quality checks). AI-assisted features provide feedback only — human reviewers remain authoritative for dictionary quality. We do not make solely automated decisions with legal or similarly significant effects about you.

Sharing

We do not sell your personal data. We may share data with: infrastructure providers under contract; academic or accessibility research partners only under ethics approval and consent filters you approved; authorities when required by law. Public dictionary entries show only what you chose to share publicly and reviewers approved.

International transfers

Data may be processed on secure infrastructure inside or outside the UAE. When we transfer data internationally we apply appropriate safeguards consistent with PDPL requirements.

Retention

We keep account data while your account is active. Videos and consent records are retained according to your choices, review status, and dataset needs — including long-term retention where needed for model training you consented to. You may request deletion subject to technical and legal limits (e.g. backups, already-exported training sets).

Security

We use access controls, encryption in transit, restricted storage for private videos, and staff training. No online system is perfectly secure; report concerns promptly to [email protected].

Your rights

Under PDPL you may request access, correction, portability, restriction, or erasure of your personal data, and withdraw consent where processing is consent-based. Use Profile → data requests or email [email protected]. We respond within reasonable timeframes required by law.

Children

See our Child participation policy. Contributors under 18 require guardian consent. Videos involving minors default to training-only and receive additional review.

Changes

We may update this policy. Material changes will be posted here with a new date. Continued use after notice constitutes acceptance where permitted by law.

Contact

Privacy inquiries: [email protected] · Legal: [email protected]