Where your record lives, and who can reach it.
Where HULUL keeps an event’s records, who can see them, and how people get in — stated plainly, and only what is true today.
Last updated 30 September 2026
Where the data is stored
The platform — its records, photographs, documents and positions — runs on Google Cloud in the Dammam region, in the Kingdom of Saudi Arabia. Google Cloud encrypts stored data by default. The database is backed up every night, and restoring from those backups has been tested.
What leaves the Kingdom, and why
A few things have to reach a service outside the Kingdom. This is all of them.
| Email, including notifications | Sent through Microsoft 365, the email service of ASK LLC. An email carries the notice and a link to the record, not the photographs. |
|---|---|
| Signing in with Google or Microsoft | If your organisation signs in this way, that provider confirms who you are. |
| Map imagery on the website | Fetched from Google through HULUL’s own server, so the map provider does not learn who is looking, or from where. The phone’s map comes from HULUL’s own servers. |
| Phone app updates | The app asks Expo’s update service whether a newer version exists. No event data is sent. |
| “Open in Google Maps” on a photograph | Only if you press it: the photograph’s position is then opened in Google Maps. |
Inspectors’ live positions never leave the platform.
Who can get in
- Invitation only. Nobody can create an account from the app or this website. An organisation invites its own people, and a sign-in by someone who was not invited is refused and recorded.
- Single sign-on. People sign in with the Google or Microsoft account they were invited with, or with a passkey.
- Every sign-in is recorded: how, whether it succeeded, when, and the network part of the address — the rest of the address is dropped before it is stored.
- Accounts end when you say so. An organisation’s administrator can deactivate any of its accounts at any time.
Who can see what
Each organisation sees only the events it works on, and within them only what its roles allow. Every permission is a tick in a grid on the platform’s Roles and permissions page, set by the organisation’s own administrator, within limits HULUL sets for each kind of organisation.
The record cannot be quietly changed
- An audit log of every action, which nobody can edit, and which the people allowed to can filter and download.
- The platform as of a moment. Anyone allowed can read the whole platform as it stood at a past time. Nothing can be changed while they look.
- Evidence from the spot. Evidence photographs are taken only with the app’s camera, never picked from a gallery, with location and Wi-Fi on, and a log cannot be raised from outside the venue. The photograph’s embedded data is removed; where and when it was taken is kept separately, and can be stamped on the image.
Acting on someone’s behalf
For support, an authorised administrator can act as a user. The person is told when it starts, and when it ends with a list of what was done; they can refuse it in advance; and the audit log records who really did each thing.
On the way, and on the phone
Every connection to hulul.co and app.hulul.co is encrypted; the sites answer only over HTTPS. On the phone, the session is kept in the phone’s secure storage, and signing out removes your data from the phone.
This website
hulul.co sets no cookies, runs no analytics or advertising, and loads nothing from any other site: its fonts and pictures are served from here. It receives only what you choose to send, when you write to us.
Questions and security reports
To report a security problem, write to support@hulul.co with “Security” in the subject. The same address is published for researchers at /.well-known/security.txt.
We do not claim certifications we do not hold. If your review needs more — a security questionnaire, a data processing agreement, or a call with the people who run the platform — ask us.