سجلات نظامٌ لسجلّات القسم المدرسي. يحفظ ما يلزم السجلّ: أسماء المعلمات وأرقام ملفاتهن، والحضور، والتكاليف. ولا يحفظ الرقم المدني ولا الهاتف ولا العنوان ولا تاريخ الميلاد ولا الصورة ولا الراتب. لا يوجد في النظام أي تتبّعٍ أو إعلانات أو تحليلات — ولا سطر واحد.
عن المعلمة: اسمها، ورقم ملفها الوزاري، واسم المستخدم، وتاريخ تركها القسم إن تركته. هذا هو السجل كاملاً.
حضورها: اليوم، ونوعه (غياب، غياب خصم، تأخير، استئذان)، وعدد دقائق التأخير، وسببٌ إن كُتب. حقل السبب هو أكثر ما في النظام حساسية، لأنه المكان الذي قد يُكتب فيه سببٌ صحّي — فاكتبن فيه بقدر الحاجة.
تكاليفها: نوع التكليف، والفصل الدراسي، ونص الرسالة من رئاسة القسم، والاعتماد أو الاعتذار، وملاحظة الاعتذار إن كُتبت، ووقت الإرسال ووقت الرد.
المرفقات: اسم المستند وحجمه فقط. المستند نفسه لا يُحفظ اليوم — يسجّل النظام أنّ ملفاً بهذا الاسم أُرفق، ولا يحتفظ بمحتواه.
عن المدرسة: اسمها، والوزارة، والمنطقة التعليمية، والقسم، والعام الدراسي، ونوع المدرسة (بنين/بنات)، واسم رئاسة القسم.
سِجل الدخول: تسجّل خدمةُ الحسابات (Supabase) واقعةَ الدخول ووقتها وعنوان IP الذي جاءت منه. هذا من صنع الخدمة لا من صنعنا، ولا نستعمله في شيء — ولكنه مُسجَّل، فنذكره.
لا رقم مدني. كان الحقل موجوداً وحُذف في ١٤ سبتمبر ٢٠٢٦ — حُذف العمود نفسه لا محتواه، حتى لا يقرأه أحدٌ لاحقاً على أنه «لم يُملأ بعد» فيبدأ بملئه.
ولا هاتف، ولا عنوان، ولا تاريخ ميلاد، ولا صورة، ولا راتب، ولا موقع جغرافي، ولا مُعرِّف إعلاني.
ولا يُطلب بريدٌ إلكتروني. لكل حساب عنوانٌ مُصطنع يُستعمل مُعرِّفاً داخلياً فقط: ليس صندوق بريدٍ لأحد، ولا يُرسل إليه شيء. والنظام لا يرسل بريداً إلكترونياً إطلاقاً.
ولا تحليلات ولا تتبّع. لا Google Analytics ولا Tag Manager ولا تقارير أخطاء ولا بكسل تتبّع.
لا نحفظ كلمة مرورٍ لأحد. تحفظ خدمة الحسابات (Supabase) بصمةً أحادية الاتجاه لا يُستخرج منها الأصل. وكلمة المرور الجديدة تُعرض مرةً واحدة على الشاشة لتُطبع في البطاقة، ولا تُكتب في سجلّ المعلمة ولا تُرسل إلى قاعدة البيانات. والبطاقة المطبوعة تحمل اسم المستخدم فقط، لا كلمة المرور.
في خوادم Supabase بمدينة فرانكفورت في ألمانيا (الاتحاد الأوروبي). أي أنّ سجلّات موظفاتٍ في مدرسةٍ كويتية تُحفظ خارج الكويت. نذكر هذا صراحةً لأنه سؤالٌ تسأله الجهات الرسمية، وإجابته أوضح مكتوبةً من متروكةً.
المعلمة ترى سجلّها هي وحده.
رئاسة القسم ترى قسمها.
المدارس منفصلةٌ بعضها عن بعض على مستوى قاعدة البيانات، لا على مستوى الصفحة.
صفحة الإدارة في كور كود ترى أسماء المدارس ومناطقها وأقسامها وأعداد المعلمات والحسابات — ولا ترى اسم معلمةٍ واحدة ولا سجلّاً واحداً. هذا مُتحقَّقٌ منه باختباراتٍ آلية تعمل على المشروع الحقيقي.
وهذان استثناءان نذكرهما لأن السكوت عنهما يجعل ما سبق غير صحيح: تستطيع كور كود ضبط كلمة مرور رئاسة القسم — وهي الطريقة الوحيدة لإعادة رئاسة قسمٍ فقدت دخولها — ومن فعل ذلك يستطيع الدخول بحسابها ورؤية ما تراه. وكذلك من يملك صلاحية الوصول المباشر إلى قاعدة البيانات يقرأ كل شيء؛ ولذلك نُبقي هذه الصلاحية في أضيق نطاق.
السجلّات تبقى. المعلمة التي تترك القسم يبقى سجلّها وحضورها وتكاليفها كما هي — فالسجل هو المقصود، وحذف الشخص يحذف سنةً من العمل.
ويمكن حذف مرفقٍ أو غيابٍ أو تكليفٍ يدوياً من داخل النظام، حذفاً فعلياً.
لا يوجد حذفٌ تلقائي ولا مدةُ صلاحية. تُحذف سجلّات مدرسةٍ حين تطلب المدرسة ذلك، ويجريه شخصٌ بيده لا زرٌّ في الواجهة.
وحساب الدخول يبقى قائماً حتى يُغلق. إن تركت معلمةٌ القسم فاطلبوا إغلاق حسابها منّا أو من رئاسة القسم.
Supabase — قاعدة البيانات والحسابات. ألمانيا.
Cloudflare — يقف أمام Supabase ويتولّى تشفير الاتصال. يأتي مع Supabase ولم نخترْه.
DigitalOcean — الخادم الذي يقدّم الصفحات.
ولا يحمّل النظام أي شيفرةٍ أو خطٍّ من جهةٍ خارجية. الخطوط والمكتبات البرمجية كلّها من خوادمنا، فلا يعلم أحدٌ بزيارتك سوى من ذُكر أعلاه. (كانت الصفحات حتى ١٥ سبتمبر ٢٠٢٦ تجلب خطَّين من Google ومكتبةً من jsDelivr؛ أُزيل الاثنان.)
لا يُسلَّم أيٌّ من هؤلاء السجلّات ليستعملها؛ وإنما يرى كلٌّ منهم ما يراه ناقلُ الاتصال.
يحفظ المتصفح رمز جلستك ودورك ورقم المعلمة ورمز المدرسة، حتى لا تُطالَبي بالدخول في كل مرة. وتسجيل الخروج يُبطل الجلسة عند Supabase لا على جهازك فقط.
في demo.corescode.com/sejlat نسخةٌ تجريبية أشخاصُها كلّهم من نسج الخيال. لم تمرّ بها بياناتُ أي مدرسةٍ قط، ولن تمرّ.
إن تغيّر شيءٌ مما سبق غيّرنا هذه الصفحة وحدّثنا تاريخها. ولا نضيف تتبّعاً ولا تحليلاتٍ دون أن يُكتب هنا أولاً.
Sejlat keeps a school department's records: teachers' names and ministry file numbers, attendance, and assignments. It does not store civil IDs, phone numbers, addresses, dates of birth, photographs or salaries. There is no tracking, no advertising and no analytics anywhere in it — not one line.
About a teacher: her name, her ministry file number, her username, and the date she left if she leaves. That is the entire record.
Her attendance: the day, the kind (absence, deductible absence, lateness, permission), the minutes for a lateness, and a reason if one is typed. The reason field is the most sensitive thing in the system, because it is where a medical reason may be written — write only what is needed.
Her assignments: the kind, the term, the message from the head of department, whether she accepted or declined, her note if she declined, and when each happened.
Attachments: a document's name and size only. The document itself is not stored today — the system records that a file of that name was attached, and keeps none of its contents.
About the school: its name, ministry, educational district, department, academic year, whether it is a boys' or girls' school, and the head of department's name.
Sign-in records: the accounts service (Supabase) records that a sign-in happened, when, and the IP address it came from. That is the service's doing rather than ours and we make no use of it — but it is recorded, so we say so.
No civil ID. The field existed and was removed on 14 September 2026 — the column itself was dropped, not emptied, so that nobody later reads a blank as "not filled in yet" and starts filling it.
No phone number, no address, no date of birth, no photograph, no salary, no location, no advertising identifier.
No email address is asked for. Each account is given a synthetic address used only as an internal identifier: it is nobody's mailbox and nothing is ever sent to it. The system sends no email at all.
No analytics and no tracking. No Google Analytics, no tag manager, no error reporting, no pixel.
We store nobody's password. The accounts service (Supabase) keeps a one-way hash that the original cannot be recovered from. A newly generated password is shown once on screen so it can be printed on a badge; it is not written into the teacher's record and never reaches our database. The printed badge carries the username only, never the password.
On Supabase servers in Frankfurt, Germany (European Union). Records about employees of a Kuwaiti school are therefore held outside Kuwait. We say so plainly because it is a question official bodies ask, and the answer is clearer written down than left out.
A teacher sees her own record and nothing else.
A head of department sees her department.
Schools are separated from one another in the database itself, not merely in the page.
CoreCode's administration page shows school names, areas, departments and counts of teachers and accounts — and no teacher's name and no record. This is checked by automated tests that run against the real project.
Two exceptions, stated because leaving them out would make the above untrue: CoreCode can set a head of department's password — it is the only way to restore a head who has lost access — and whoever does that can then sign in as her and see what she sees. And anyone with direct database access can read everything; that is why we keep that access to as few people as possible.
Records are kept. A teacher who leaves keeps her record, her attendance and her assignments — the record is the point, and deleting the person deletes a year of work.
An attachment record, an absence or an assignment can be deleted by hand from inside the system, and the deletion is real.
There is no automatic deletion and no expiry. A school's records are deleted when the school asks, and it is done by a person rather than by a switch in the interface.
A sign-in account stays active until it is closed. If a teacher leaves, ask us or your head of department to close her account.
Supabase — database and accounts. Germany.
Cloudflare — sits in front of Supabase and handles the encrypted connection. It comes with Supabase; we did not choose it.
DigitalOcean — the server that delivers the pages.
The application loads no third-party code and no third-party fonts. Every typeface and every library is served from our own machines, so nobody outside the list above learns that you visited. (Until 15 September 2026 the pages fetched two typefaces from Google and a library from jsDelivr. Both were removed.)
None of them is handed the records to use; each sees what carrying the connection shows it.
The browser keeps your session token, your role, your teacher number and your school code, so you are not asked to sign in every time. Signing out revokes the session at Supabase, not only on your device.
At demo.corescode.com/sejlat there is a demonstration copy in which every person is invented. No school's data has ever been in it, and none ever will be.
If any of the above changes, this page changes and its date is updated. We do not add tracking or analytics without writing it here first.