1. Scope and responsible party
This policy applies to the Hajjan Android app and its pages at hajjan.tik.sa. The app is published and operated by TIK Information Technology, based in Riyadh, Saudi Arabia, referred to as the “Publisher,” “we,” or “us.”
Hajjan does not create a user account with the Publisher. The current version does not use Publisher-controlled servers to receive SMS messages, forwarding rules, destination numbers, or backups. The app contains no integrated ads or analytics. Google Play and providers you select for channels or files may process data under their own policies, as explained below.
2. SMS access and purpose
After Receive SMS permission is granted, the app receives every new SMS on the device, not only messages that later match a rule. This includes the originating address, which may be a phone number or alphanumeric sender ID, the message content, and its received time.
Messages are matched locally against rules you create. Hajjan does not request access to the historical SMS inbox and does not read earlier messages. Send SMS permission allows matching content to be sent automatically to numbers configured in the rules. Carrier charges may apply.
This processing is necessary to provide the forwarding service you configure, improve reliability through pending work and retries, and show the operation status in the app.
3. Contacts and SIM information
Contacts
Hajjan does not request broad address-book access. When you use Android’s contact picker, the app reads only the phone number you explicitly select and stores it locally as a rule destination.
SIM information
Phone-state access is optional. If granted, Hajjan reads the subscription ID, SIM slot, display name, and carrier name of active SIMs so you can choose a sending SIM. It does not read the IMEI, IMSI, ICCID, or line phone number. The default SIM can be used without this permission, and the selected subscription ID is stored locally in the rule.
4. Rules and local settings
Hajjan stores the rules you create in the app’s private storage. They may include a rule name, matching conditions, sender identifiers or keywords, destination numbers, a template, active hours, and the selected SIM and channel.
The app also stores settings such as language, appearance and notification preferences, local free-quota status, Premium status, product identifier, and the last Google Play verification time. These data are used to apply your settings and provide the features you select.
Telegram, SMTP, and Webhook secrets are encrypted locally using a non-exportable Android Keystore key. They are not sent to the Publisher.
5. Local storage and retention
A new message is temporarily written to the app’s private database so it can be processed reliably if the system process stops. After processing, its body is removed from the incoming-message record. If job creation fails after the configured attempts, the body may remain until the record is at least 30 days old and the next cleanup runs.
When a forwarding job is created, its full formatted payload remains while it is pending, sending, or retrying, for up to three attempts when processing runs. The full payload is cleared after successful sending or exhausted retries, but a preview of up to the first 120 characters remains in the operation log.
A log entry may contain the sender identifier, destination, time, rule, channel, status, error, and preview. The interface displays the latest 500 operations, but the underlying database is not automatically capped at 500 records. Older completed entries may remain until you clear them, clear app data, or uninstall Hajjan.
Clearing logs does not remove pending or retrying jobs, and deleting a rule does not necessarily delete earlier logs for that rule. Cryptographic fingerprints and quota records that do not contain the original message text may remain until app data is cleared or the app is uninstalled.
6. Forwarding to destinations you select
When a message matches a rule, Hajjan automatically sends data according to your configuration:
- SMS: your carrier and destination number receive the formatted content and ordinary network metadata.
- Telegram: Telegram receives the chat ID and formatted text, and the bot token is used for authentication.
- Email: your configured SMTP server receives credentials, sender and recipient addresses, a subject containing the original SMS sender identifier, and the formatted body.
- Webhook: the endpoint you configure receives a JSON request containing the sender identifier, message, rule name, and timestamp.
Providers may process data in other countries depending on their infrastructure. Their own privacy and retention policies apply. Deleting local Hajjan data does not delete copies already held by recipients, carriers, Telegram, an SMTP provider, or a Webhook operator.
Learn more in the Telegram Privacy Policy.
7. Backups and exported files
Encrypted rule backups
Hajjan uses Android’s Storage Access Framework. You choose Google Drive or another document provider through Android’s file picker; the app does not obtain broad access to your Drive account.
Rule backups are encrypted on the device with your password using AES‑256‑GCM before being handed to the selected provider. A backup may contain rule names, sender identifiers or keywords, phone numbers, templates, schedules, and channel selections, so it can contain personal data even though it excludes messages, forwarding history, Telegram/SMTP/Webhook secrets, subscription and quota status, and SIM selection. Hajjan cannot recover a forgotten backup password.
The selected document provider may see the file name, size, time, and encrypted content, and its own policy applies. You must delete external backups yourself when they are no longer needed.
CSV log exports
Premium users can export the latest 500 displayed records as an unencrypted CSV. It contains time, sender, destination, status, rule name, and error, but not the message content or preview. The share-target app you choose receives the file. A temporary copy may remain in Hajjan’s cache until overwritten, cleaned by the system, or removed by clearing app data.
The message and log database, channel data, and subscription entitlement are excluded from Android automatic backup and device transfer. Non-sensitive preferences such as language and appearance may be backed up under Android and the backup provider’s settings.
8. Google Play Billing
The Google Play build uses Google Play Billing to retrieve plans, check subscription status when the app starts, complete purchases, and restore subscriptions. Google processes Play account, payment, purchase, device, and technical data under the Google Privacy Policy.
Hajjan may receive a purchase token temporarily while processing a purchase, but it does not persist the token and never receives payment-card details. It stores only local Premium status, a product identifier, and the last Play verification time.
Clearing app data or uninstalling Hajjan does not cancel a subscription. You must manage or cancel it separately through your Google Play account.
9. Security
App data is stored in Android private app storage. Telegram, SMTP, and Webhook configuration is encrypted locally with AES‑256‑GCM using a non-exportable Android Keystore key. Other local database data relies on Android application sandboxing and is not separately encrypted as a database file.
Telegram and Webhooks use HTTPS, while email requires TLS and SMTP server identity verification. Standard SMS is not end-to-end encrypted. No storage or transmission method can be guaranteed completely secure, so protect your device, passwords, channel credentials, and exported files.
10. Your controls and deletion
You can:
- revoke SMS permissions, which stops the app’s core function;
- decline optional SIM access and continue with the default SIM;
- disable or delete rules and change destinations or channel settings;
- clear completed log entries in the app;
- clear Hajjan’s app data or uninstall it to remove locally managed data;
- delete backup and CSV files from the providers or apps to which you sent them; and
- cancel Premium separately through Google Play.
Because messages and rules remain on your device or with destinations you select, the Publisher cannot remotely retrieve or delete them for you.
11. Lawful use and other people’s data
Hajjan is a user-configured tool. You are responsible for having lawful authority to access the device and messages and to forward sender data to selected recipients and services, including providing any notices or obtaining any consents required by applicable law.
Do not use Hajjan to monitor or transfer another person’s messages without permission or another valid legal basis.
12. Children
Hajjan is a productivity tool not designed for or directed to children and is not intended for use by anyone under 18. It does not ask for a date of birth or create a Publisher account. If messages you forward contain information about a minor, you are responsible for ensuring that the processing is lawful.
13. Applicable rights
Applicable law may give you rights to be informed, access data, obtain a copy, correct data, request destruction, and withdraw consent. Rights concerning on-device data can be exercised through Hajjan and Android controls.
If you contact us for support, you may request access, correction, or deletion of your correspondence by using the email below, subject to any legal retention duty. You may also complain to the data-protection authority in your country. In Saudi Arabia, see the National Data Governance Platform.
14. Data from this website
This is a static website with no marketing cookies or analytics. Web hosting may automatically log your IP address, request time, requested page, and browser type for operation, security, and troubleshooting. These logs remain with the server provider under its technical settings and are not used by us to build advertising profiles.
When you select an email or external link, you move to the service you chose and its privacy policy applies.
15. Changes to this policy
We may update this policy when Hajjan’s features or legal requirements change. We will post the revised version here and change the “Last updated” date. Where the law requires additional notice or new consent before different processing begins, it will be provided first.
16. Contact
For privacy questions, rights requests, or support, contact:
Publisher and controller: TIK Information Technology
Address: Ishbiliyah District, Imam Abdullah bin Saud Road, Riyadh, Saudi Arabia
Email: info@tik.sa
Contact page: tik.sa/contact