سياسة خصوصية طويق
تاريخ السريان: 19 أغسطس 2026
توضح سياسة الخصوصية هذه كيفية قيام [LEGAL ENTITY NAME] (ويُشار إليها باسم "طويق" أو "نحن" أو "لنا") بجمع المعلومات واستخدامها ومشاركتها وحمايتها عند استخدام تطبيق طويق للهواتف المحمولة، وموقع طويق العام، والخدمات المرتبطة بهما (ويُشار إليها مجتمعة باسم "الخدمات"). والمالك القانوني مسجل في [REGISTERED COUNTRY]. ويمكن إرسال الأسئلة أو طلبات الخصوصية إلى tuwaiqapp2@gmail.com.
تصف هذه السياسة الخدمات المطبقة حاليًا. وقد تعرض بعض الشاشات معاينات لخصائص اجتماعية وألعاب ومحفظة وVIP وإشعارات وغيرها من الخصائص المستقبلية باستخدام معلومات تُحفظ على جهازك فقط. ولا يعني ظهور تلك المعاينات أن نظامًا إنتاجيًا على الخادم لتلك الخصائص يعمل حاليًا.
1. المعلومات التي نجمعها
معلومات الحساب والمصادقة
يدعم طويق المصادقة برقم الهاتف باستخدام رمز مرور لمرة واحدة (OTP)، وتسجيل الدخول عبر Google وApple. وبحسب الطريقة التي تختارها، قد نقوم نحن ومزوّد المصادقة بمعالجة:
- رقم هاتفك وحالة المصادقة؛
- معرّف يخصصه Google أو Apple؛
- عنوان بريدك الإلكتروني ومعلومات الحساب الأساسية التي يتيحها المزوّد المختار وفق الأذونات التي تمنحها، مثل الاسم أو صورة الملف الشخصي؛ و
- سجلات المصادقة ومعلومات الجلسة وبيانات الأمان اللازمة لتسجيل دخولك والإبقاء على جلستك نشطة.
لا نتلقى كلمة مرور حسابك لدى Google أو Apple. وقد يزوّدنا Apple بمعلومات محدودة عن الحساب أو بعنوان بريد إلكتروني خاص لإعادة التوجيه. وتُستخدم رموز OTP للتحقق من الوصول إلى رقم الهاتف، ولا يطلب طويق إذنًا لقراءة رسائلك النصية تلقائيًا.
معلومات الملف الشخصي
عند إنشاء ملف طويق أو تحديثه، نخزن المعلومات التي تقدمها، ومنها:
- معرّف طويق عام من 12 رقمًا ينشئه الخادم؛
- اسم العرض واسم المستخدم/المعرّف؛
- مرجع صورة الملف الشخصي؛
- رمز الدولة والمدينة المختارة؛
- اللغة المفضلة (العربية أو الإنجليزية)؛
- النبذة التعريفية؛
- حالة اكتمال خطوات الإعداد؛ و
- أوقات إنشاء الملف وتحديثه.
يتيح التطبيق الحالي أيضًا اختيار قيمة الجنس. وتُحفظ هذه القيمة محليًا على الجهاز للحساب الذي سجل الدخول، ولا تُخزن حاليًا في قاعدة بيانات ملف طويق السحابية.
صور الملف الشخصي والملفات
إذا اخترت صورة للملف الشخصي، يصل التطبيق إلى الصورة التي تحددها ويرفعها إلى حاوية خاصة في Supabase Storage. ويقبل الإعداد الحالي صور JPEG وPNG وWebP بحد أقصى 5 ميبيبايت. وتخزن قاعدة بيانات الملف مسار الكائن التخزيني، وليس بيانات الصورة الخام أو رابطًا عامًا دائمًا. وتُستخدم روابط موقعة مؤقتة عندما يحتاج مستخدم أو مسؤول مخول إلى عرض الصورة.
الغرف والدردشة والمحتوى الذي ينشئه المستخدم
عند استخدام خصائص الغرف المطبقة، قد نخزن أو نعالج:
- عنوان الغرفة وموضوعها وتصنيفها ونوع الوصول إليها وسعتها ومرجع خلفيتها وحالتها ومالكها وأوقات الإنشاء والتحديث؛
- عضوية الغرفة والدور فيها (مالك أو مشرف أو عضو) ووقت الانضمام ومقعد المتحدث وحالة طلب الميكروفون؛
- الرسائل النصية المرسلة في دردشة الغرفة، بما يشمل المحتوى والمرسل ونسخة دور المرسل وقت الإرسال والطابع الزمني للخادم؛
- الحظر داخل الغرفة وقيود الدردشة وإجراءات الإشراف؛ و
- بيانات حضور لحظية قصيرة العمر لإظهار المتصلين حاليًا، بما يشمل معرّف طويق العام واسم العرض ودور الغرفة ومعرّف جلسة مؤقت ووقت الاتصال.
تُخزن رسائل الغرفة النصية في قاعدة البيانات. أما الحضور اللحظي فهو مؤقت ويُزال عند انتهاء الاتصال، مع احتمال بقاء العضوية والمقاعد والرسائل وسجلات الإشراف وفق ما توضحه هذه السياسة. وتعالج كلمات مرور الغرف المحمية في صورة مُحقِّقات محمية ولا تُعاد من خلال واجهات قراءة الغرف العامة.
أما محادثات الرسائل المباشرة الظاهرة في التطبيق الحالي فهي محتوى تجريبي/محلي ولا تُرفع حاليًا إلى خادم طويق.
الغرف الصوتية والصوت
لا يهيئ الكود الحالي مزوّدًا إنتاجيًا للصوت/الاتصال اللحظي (RTC)، ولا يرسل صوت الغرف المباشر إلى خدمة صوت خارجية. وتدير أدوات الميكروفون والمتحدث في الغرفة حاليًا صلاحيات الغرفة وحالة العرض فقط.
يمكن للتطبيق تسجيل رسالة صوتية داخل محادثة رسائل مباشرة. وتُحفظ الرسالة الصوتية محليًا في مساحة مستندات التطبيق لتشغيلها على ذلك الجهاز، ولا تُرفع حاليًا إلى Supabase ولا تُزامن مع مستخدم آخر. ولا تُعالج بيانات الميكروفون إلا بعد منحك الإذن وبدء التسجيل.
الألعاب والخصائص الاجتماعية والمحفظة والنشاط
تستخدم شاشات الألعاب الحالية والروابط الاجتماعية المباشرة وطلبات الصداقة والمقتنيات وتسجيل الدخول اليومي وأرصدة المحفظة وسجل المعاملات ومعاينات VIP والتفاعلات التجريبية المشابهة بيانات محلية أو عينات مرفقة بالتطبيق. وقد تُحفظ حالة تجريبية مرتبطة بالحساب على جهازك ضمن التفضيلات المحلية للمحافظة على اتساق التجربة بعد التنقل أو إعادة التشغيل. ولا يحتوي الخادم الحالي على جداول إنتاجية للألعاب أو الصداقات أو المدفوعات أو المحفظة أو المقتنيات أو VIP أو الرسائل المباشرة.
ولا نعالج حاليًا مدفوعات حقيقية أو نجمع تفاصيل بطاقات الدفع أو الحسابات البنكية.
معلومات الجهاز والمعلومات التقنية
لا يتضمن التطبيق حاليًا حزمة مخصصة للتحليلات أو الإعلانات أو الإحالة الإعلانية أو تقارير الأعطال. ولا نجمع حاليًا معرّفات إعلانية لأغراض التتبع، ولا نبيع المعلومات لاستخدامها في الإعلانات السلوكية.
عندما يتصل جهازك بـSupabase أو بمزوّد هوية، تتلقى تلك الخدمات بالضرورة معلومات الشبكة والطلب، مثل عنوان IP ووقت الطلب والبيانات التقنية للطلب اللازمة لتشغيل خدماتها وتأمينها. وقد تسجل سجلات خدمة Supabase الطلبات والأخطاء. ولا يضيف طويق حاليًا نظامًا منفصلًا لبصمة الجهاز.
الإشعارات
لا يسجل التطبيق الحالي ولا يرفع رموز أجهزة خدمة Apple Push Notification أو Firebase Cloud Messaging. وعناصر الإشعارات وتفضيلاتها الظاهرة حاليًا هي حالة محلية/تجريبية. وإذا أُضيفت إشعارات فورية لاحقًا، فيجب تحديث هذه السياسة وإفصاحات المتاجر قبل بدء ذلك الجمع.
2. أذونات الجهاز
قد يطلب طويق، بحسب نظام التشغيل والخاصية التي تختارها:
- الميكروفون: لتسجيل رسالة صوتية محلية على الجهاز. ولا يرسل التطبيق الحالي صوت الغرفة المباشر إلى مزوّد RTC.
- الصور/مكتبة الوسائط: لتمكينك من اختيار صورة للملف الشخصي ورفعها. ولا يطلب التطبيق وصولًا واسعًا إلى ملفات لا علاقة لها بالصورة المختارة متى أتاح منتقي النظام وصولًا محدودًا.
- الإنترنت/الشبكة: للمصادقة واسترجاع الملفات وتحديثها ورفع صور الملف واستخدام الغرف والدردشة والحضور اللحظي والإشراف.
لا يطلب التطبيق الحالي أذونات الموقع أو جهات الاتصال أو الكاميرا أو قراءة الرسائل النصية أو المكالمات الهاتفية أو التتبع الإعلاني. كما أن رمز الموقع أو حقل الدولة في الواجهة لا يصل إلى موقع GPS.
3. كيفية استخدام المعلومات
نستخدم المعلومات من أجل:
- إنشاء الحسابات ومصادقتها واستعادة الجلسات؛
- إنشاء ملف طويق واحد لكل هوية مصادق عليها وتخصيص معرّف طويق عام ثابت؛
- تقديم وظائف الملف والصورة والغرف ودردشة الغرفة والحضور اللحظي ومقاعد المتحدثين والإشراف؛
- عرض المعلومات والمحتوى الذي تختار مشاركته مع المستخدمين المخولين؛
- تذكر اللغة والمظهر وتفضيلات الخصوصية والإشعارات والحالة التجريبية على جهازك؛
- الحفاظ على سلامة الخدمة وتطبيق الصلاحيات ومنع إساءة الاستخدام والتحقيق في أحداث الأمان والاحتفاظ بسجلات التدقيق؛
- تشخيص الأخطاء والمحافظة على موثوقية الخدمة؛ و
- الامتثال للالتزامات القانونية أو الطلبات القانونية الصحيحة عند انطباقها.
4. كيفية مشاركة المعلومات
قد نشارك المعلومات أو نتيحها:
- للمستخدمين الآخرين: قد تظهر معلومات الملف العامة ومعرّف طويق واسم العرض ودور الغرفة ومعلومات الغرفة وحالة الحضور ورسائل الغرفة بحسب سياق الغرفة والخاصية. ولا تتيح سياسات قاعدة البيانات الحالية اكتشافًا عامًا واسعًا للمستخدمين.
- للمسؤولين المخولين: قد يصل المسؤولون والمسؤولون الأعلى إلى معلومات الملفات والأدوار وصور الملفات الخاصة من خلال روابط موقعة قصيرة العمر ومعلومات التدقيق بالقدر اللازم لتشغيل الخدمات وحمايتها.
- لمقدمي الخدمات: يعالج Supabase ومزوّد المصادقة الذي تختاره المعلومات لأغراض الاستضافة والتخزين والمصادقة وتسجيل الدخول كما هو موضح أدناه.
- لأسباب قانونية وأمنية: قد نفصح عن المعلومات عندما يكون ذلك ضروريًا بصورة معقولة للامتثال للقانون أو حماية الأشخاص أو الحقوق أو التحقيق في إساءة الاستخدام أو تأمين الخدمات.
- ضمن صفقة تجارية: قد تُنقل المعلومات في إطار اندماج أو تمويل أو استحواذ أو إعادة هيكلة أو بيع، مع مراعاة القانون الساري وتقديم الإشعار المناسب عند اللزوم.
لا ندمج حاليًا شبكة إعلانية ولا نبيع المعلومات الشخصية لأغراض الإعلان السلوكي.
5. خدمات الأطراف الثالثة
يستخدم التطبيق الحالي الخدمات التالية أو يدمجها:
- Supabase: للمصادقة وقاعدة بيانات PostgreSQL والتخزين الخاص والحضور/البث اللحظي والوصول إلى الواجهات وسجلات التشغيل. ويتلقى Supabase معرّفات الحسابات وبيانات الملفات والغرف والصور المرفوعة ورسائل الغرف ونشاطها ورموز الجلسات وبيانات الشبكة/الطلب اللازمة لتقديم تلك الخدمات. راجع المعلومات القانونية ومعلومات الخصوصية لدى Supabase.
- تسجيل الدخول عبر Google: إذا اخترت Google، يتحقق Google من حسابك ويوفر بيانات اعتماد الهوية ومعلومات الحساب التي تسمح بها نطاقات
emailوprofileالمطلوبة. راجع سياسة خصوصية Google. - تسجيل الدخول باستخدام Apple: إذا اخترت Apple، يتحقق Apple من حسابك وقد يوفر معرّف هوية Apple والبريد الإلكتروني (بما فيه عنوان إعادة توجيه خاص) وبيانات محدودة للملف. راجع سياسة خصوصية Apple.
- خدمات منصتي Apple وGoogle: يوفر نظام التشغيل توزيع التطبيق ومطالبات الأذونات ومنتقي الصور وقوائم المشاركة. وتخضع المعلومات التي تختار مشاركتها عبر تطبيق آخر لسياسة خصوصية ذلك التطبيق.
لا يوجد مزوّد إنتاجي للصوت/RTC أو الإعلانات أو تحليلات المنتج أو تقارير الأعطال أو الإشعارات الفورية مهيأ في كود التطبيق الحالي.
6. تخزين البيانات وأمنها
يستخدم طويق خدمات Supabase المستضافة للمصادقة وقاعدة البيانات والتخزين الخاص والاتصال اللحظي. وتستخدم قاعدة البيانات المطبقة ضوابط وصول على مستوى الصفوف وتخزينًا خاصًا للصور ووظائف يصرح بها الخادم لإجراءات الغرف الحساسة وأدوارًا منفصلة للمسؤولين ذوي الامتيازات. وتستخدم تطبيقات العميل مفتاحًا عامًا مخصصًا للنشر ولا تحتوي على مفتاح دور الخدمة.
لا توجد وسيلة أمنية آمنة بصورة مطلقة. وعليك حماية الوصول إلى هاتفك وحسابات مزودي الهوية وعدم مشاركة رموز OTP أو معلومات الجلسة. ولا ندعي تشفير كل فئة من البيانات أو إخفاء هويتها عندما لا يثبت التنفيذ ذلك.
7. معالجة البيانات دوليًا
قد يعالج طويق ومقدمو خدماته المعلومات في دول غير الدولة التي تقيم فيها. ويجب قبل الإطلاق تأكيد المالك القانوني والاختصاص الحاكم وآلية النقل عبر الحدود وترتيب الاستضافة الإنتاجية النهائي. وعندما يتطلب القانون الساري ضمانات للنقل الدولي، تكون [LEGAL ENTITY NAME] مسؤولة عن اختيارها وتوثيقها.
8. الاحتفاظ بالبيانات
لا يحدد التنفيذ الحالي جدولًا زمنيًا مكتملًا للاحتفاظ بالبيانات.
- قد تبقى بيانات الحساب والملف والدور والصورة طوال مدة نشاط الحساب.
- قد تبقى رسائل الغرف والعضويات والمقاعد والطلبات والحظر والقيود وسجلات الإشراف إلى أن تُحذف الغرفة أو الحساب المرتبط أو يزيلها مشغل مخول. وقد أُعدت عدة سجلات للغرفة بحيث تُحذف تلقائيًا عند حذف الغرفة الأم أو الحساب المرتبط.
- قد يُحتفظ بسجلات تدقيق الإدارة للأمان والمساءلة؛ وقد يؤدي حذف الحساب إلى إزالة المرجع المباشر للفاعل مع بقاء واقعة التدقيق.
- الحضور اللحظي حالة اتصال مؤقتة وليس سجلًا دائمًا للغرفة.
- قد تبقى التفضيلات المحلية والحالة التجريبية واختيار الجنس وملفات الرسائل الصوتية المسجلة على الجهاز إلى أن تُمسح بيانات التطبيق أو يُلغى تثبيته أو تُزال البيانات المحلية ذات الصلة بطريقة أخرى.
- قد تخضع سجلات مقدمي الخدمات ونسخهم الاحتياطية لمدد احتفاظ يحددها هؤلاء المزودون.
يجب على طويق قبل الإطلاق العام اعتماد مدد إنتاجية محددة وإجراء تشغيلي للحذف. وقد نحتفظ بالمعلومات مدة أطول إذا تطلب القانون ذلك أو كان لازمًا لحل النزاعات أو حماية الأمن أو إنفاذ الاتفاقيات.
9. حقوقك وخياراتك
بحسب مكان إقامتك، قد تكون لك حقوق في طلب الوصول إلى المعلومات الشخصية أو تصحيحها أو حذفها أو تقييد معالجتها أو الاعتراض عليها أو الحصول على نسخة قابلة للنقل منها، وسحب الموافقة عندما تعتمد المعالجة عليها. وقد تخضع هذه الحقوق للتحقق والاستثناءات القانونية.
يمكنك تعديل حقول الملف المدعومة والتفضيلات المحلية داخل التطبيق. ويمكنك سحب إذن الميكروفون أو الصور من إعدادات الجهاز وقطع وصول Google أو Apple من خلال أدوات تحكم المزوّد المعني. ولا يؤدي قطع وصول المزوّد وحده إلى حذف حساب طويق أو البيانات المخزنة لدى طويق.
لتقديم طلب خصوصية، تواصل مع tuwaiqapp2@gmail.com. ولا ترسل كلمات المرور أو رموز OTP أو رموز الوصول أو أسرار مزودي الهوية. وقد نطلب معلومات لازمة بصورة معقولة للتحقق من ارتباط الطلب بحسابك.
10. حذف الحساب والبيانات
يعرض تطبيق الهاتف الحالي خيار حذف الحساب، لكن مسار الحذف داخل التطبيق لم يكتمل بعد. وإلى أن يكتمل، اطلب الحذف باتباع تعليمات حذف البيانات العامة أو بمراسلة tuwaiqapp2@gmail.com.
بعد التحقق من طلب صحيح، سيحذف طويق بيانات الحساب أو يزيل ارتباطها بالهوية وفق إجراء الحذف المعتمد والقانون الساري، مع مراعاة المعلومات الواجب الاحتفاظ بها للأمان أو منع الاحتيال أو الالتزامات القانونية أو النزاعات أو النسخ الاحتياطية أو الإنفاذ. ولا يؤدي حذف بيانات طويق تلقائيًا إلى حذف المعلومات التي يحتفظ بها بصورة مستقلة Google أو Apple أو مزوّد نظام التشغيل أو أي خدمة أخرى اخترت استخدامها.
11. خصوصية الأطفال
لم يُعتمد بعد الحد الأدنى النهائي لعمر مستخدم طويق. والحد المقصود هو [MINIMUM USER AGE]. والخدمات غير مخصصة للأطفال دون الحد النهائي المعتمد، ولا ينبغي لهم إنشاء حساب أو تقديم معلومات شخصية. وإذا كنت تعتقد أن طفلًا قدم معلومات بالمخالفة لمتطلب العمر الساري، فتواصل مع tuwaiqapp2@gmail.com لمراجعة الأمر.
وقبل الإطلاق يجب أن يحدد المالك القانوني الحد الأدنى للعمر وما إذا كانت موافقة ولي الأمر أو إجراءات التحقق من العمر مطلوبة في الدول المستهدفة.
12. التغييرات على هذه السياسة
قد نحدّث هذه السياسة مع تغير الخدمات أو المزودين أو المتطلبات القانونية. وسننشر السياسة المعدلة مع تاريخ سريان جديد، ونقدم إشعارًا إضافيًا عندما يلزم. وأي خاصية تستحدث جمعًا جوهريًا جديدًا—مثل الإشعارات الفورية أو النقل الصوتي الإنتاجي أو المدفوعات أو التحليلات أو الإعلانات أو الأنظمة الاجتماعية الجديدة—تتطلب مراجعة للسياسة وإفصاحات المتاجر قبل إطلاقها.
13. التواصل معنا
[LEGAL ENTITY NAME] دولة التسجيل: الكويت بريد الخصوصية: tuwaiqapp2@gmail.com
Tuwaiq Privacy Policy
Effective Date: August 19, 2026
This Privacy Policy explains how [LEGAL ENTITY NAME] ("Tuwaiq," "we," "us," or "our") collects, uses, shares, and protects information when you use the Tuwaiq mobile application, Tuwaiq public website, and related services (collectively, the "Services"). The legal owner is registered in [REGISTERED COUNTRY]. Questions or privacy requests may be sent to tuwaiqapp2@gmail.com.
This Policy describes the current implemented Services. Some screens preview future social, game, wallet, VIP, notification, and other product features using information stored only on your device. Those previews do not mean that a production server system for those features is currently operating.
1. Information We Collect
Account and authentication information
Tuwaiq supports phone-number authentication using a one-time password (OTP), Google Sign-In, and Sign in with Apple. Depending on the method you choose, we and our authentication provider may process:
- your phone number and authentication status;
- an identifier assigned by Google or Apple;
- your email address and basic account information that the selected provider makes available under your permissions, such as a name or profile image; and
- authentication records, session information, and security metadata needed to sign you in and keep your session active.
We do not receive your Google or Apple password. Apple may provide limited account information and may provide a private relay email address. Phone OTP codes are used to verify access to the phone number; Tuwaiq does not request permission to read your SMS messages automatically.
Profile information
When you create or update a Tuwaiq profile, we store information you provide, including:
- your server-generated 12-digit public Tuwaiq ID;
- display name and username/handle;
- profile photo reference;
- country code and selected city;
- preferred language (Arabic or English);
- biography;
- whether onboarding is complete; and
- profile creation and update times.
The current app also lets you select a gender value. That value is stored locally on the device for the signed-in account and is not currently stored in the Tuwaiq cloud profile database.
Profile photos and files
If you choose a profile photo, the app accesses the image you select and uploads it to a private Supabase Storage bucket. The current configuration accepts JPEG, PNG, and WebP images up to 5 MiB. The profile database stores the storage object path, not the image bytes or a permanent public URL. Temporary signed links are used when authorized users or administrators need to display the image.
Rooms, chat, and user-generated content
When you use implemented room features, we may store or process:
- room title, topic, category, access type, capacity, visual background reference, status, owner, and creation/update times;
- room membership and room role (owner, moderator, or member), join time, speaker seat, and microphone-request state;
- text messages sent in room chat, including message content, sender, sender room-role snapshot, and server timestamp;
- room bans, chat restrictions, and moderation actions; and
- short-lived room Presence data used to show who is currently connected, including public Tuwaiq ID, display name, room role, a temporary session identifier, and online time.
Room text messages are stored in the database. Realtime Presence is ephemeral and is removed when a connection ends, although persistent room membership, seats, messages, and moderation records may remain as described in this Policy. Password-protected room passwords are processed as protected verifiers and are not returned through public room-reading interfaces.
Direct-message conversations shown in the current app are demo/local content and are not currently uploaded to the Tuwaiq backend.
Voice rooms and audio
The current code does not configure a production voice/RTC provider and does not transmit live room audio to a third-party voice service. Room microphone and speaker controls currently manage room permissions and presentation state only.
The app can record a voice note in a direct-message conversation. A recorded voice note is saved locally in the app's documents area so it can be played on that device. It is not currently uploaded to Supabase or synchronized to another user. Microphone audio is processed only after you grant microphone permission and start recording.
Games, social features, wallet, and activity
Current game screens, direct social connections and friend requests, collectibles, daily check-in, wallet balances, transaction history, VIP previews, and similar demo interactions use local or bundled sample data. Account-scoped demo state may be saved on your device through local preferences so the experience remains consistent after navigation or restart. The current backend does not contain production game, friendship, payment, wallet, inventory, VIP, or direct-message tables.
We do not currently process real payments or collect payment-card or bank-account details.
Device and technical information
The app does not currently include a dedicated analytics, advertising, attribution, or crash-reporting SDK. We do not currently collect advertising identifiers for tracking or sell information for targeted advertising.
When your device communicates with Supabase or an identity provider, those services necessarily receive network and request information such as an IP address, request time, and technical request metadata needed to operate and secure their services. Supabase service logs may record requests and errors. Tuwaiq does not currently add a separate device-fingerprinting system.
Notifications
The current app does not register or upload Apple Push Notification service or Firebase Cloud Messaging device tokens. Notification items and notification preferences currently shown in the app are local/demo state. If push notifications are introduced later, this Policy and store disclosures must be updated before that collection begins.
2. Device Permissions
Depending on your platform and the feature you choose, Tuwaiq may request:
- Microphone: to record a device-local voice note. The current live room implementation does not send audio to an RTC provider.
- Photos/media library: to let you select a profile image for upload. The app does not request broad access to files unrelated to the image you select where the platform's picker can provide limited access.
- Internet/network access: to authenticate, retrieve and update profiles, upload profile images, and use room, chat, Presence, and moderation features.
The current app does not request location, contacts, camera, SMS-reading, phone-call, or advertising-tracking permission. A location-style icon or country field in the interface does not access GPS location.
3. How We Use Information
We use information to:
- create and authenticate accounts and restore sessions;
- provision one Tuwaiq profile for an authenticated identity and assign a stable public Tuwaiq ID;
- provide profile, avatar, room, room chat, Presence, speaker-seat, and moderation functionality;
- display the information and content you choose to share with authorized users;
- remember language, appearance, privacy, notification, and demo preferences on your device;
- maintain service integrity, enforce permissions, prevent abuse, investigate security events, and keep audit records;
- troubleshoot errors and maintain service reliability; and
- comply with legal obligations or valid legal requests where applicable.
4. How We Share Information
We may share or make information available:
- With other users: public-facing profile information, Tuwaiq ID, display name, room role, room information, Presence status, and room messages may be shown according to the room and feature context. Broad public user discovery is not currently enabled by the database policies.
- With authorized administrators: administrators and super administrators may access profile information, roles, private avatar images through short-lived signed links, and audit information as necessary to operate and protect the Services.
- With service providers: Supabase and the authentication provider you select process information for hosting, storage, authentication, and sign-in as described below.
- For legal and safety reasons: we may disclose information where reasonably necessary to comply with law, protect people or rights, investigate abuse, or secure the Services.
- In a business transaction: information may be transferred as part of a merger, financing, acquisition, restructuring, or sale, subject to applicable law and appropriate notice where required.
We do not currently integrate an advertising network or sell personal information for behavioral advertising.
5. Third-Party Services
The current implementation uses or integrates the following services:
- Supabase: authentication, PostgreSQL database, private object storage, Realtime Presence/Broadcast, API access, and operational logs. Supabase receives account identifiers, profile and room data, uploaded avatars, room messages and activity, session tokens, and network/request metadata needed to provide those services. See Supabase's legal and privacy information.
- Google Sign-In: if you choose Google, Google authenticates your account and provides identity credentials and the account information permitted by the requested
emailandprofilescopes. See Google's Privacy Policy. - Sign in with Apple: if you choose Apple, Apple authenticates your account and may provide an Apple identity identifier, email (including a private relay address), and limited profile data. See Apple's Privacy Policy.
- Apple and Google platform services: the operating system provides app distribution, permission prompts, platform image pickers, and share sheets. Information you choose to share through another app is then handled under that app's privacy terms.
No production RTC/voice provider, advertising provider, product analytics provider, crash-reporting provider, or push-notification provider is configured in the current application code.
6. Data Storage and Security
Tuwaiq uses Supabase-hosted authentication, database, private storage, and Realtime services. The implemented database uses row-level access controls, private avatar storage, server-authorized functions for sensitive room actions, and separate privileged administrator roles. Client applications use a publishable key and do not contain a service-role key.
No security method is completely secure. You should protect access to your phone and identity-provider accounts and avoid sharing OTP codes or session information. We do not claim that every category of data is encrypted or anonymous where the implementation does not establish that fact.
7. International Data Processing
Tuwaiq and its service providers may process information in countries other than the country where you live. The legal owner, governing jurisdiction, cross-border transfer mechanism, and final production hosting arrangement must be confirmed before release. Where applicable law requires safeguards for international transfers, [LEGAL ENTITY NAME] will be responsible for selecting and documenting them.
8. Data Retention
The current implementation does not define a complete time-based retention schedule.
- Account, profile, role, and avatar data may remain while the account is active.
- Room messages, memberships, seats, requests, bans, restrictions, and room moderation records may remain until the related room or account is deleted, or an authorized operator removes them. Several room records are configured to be deleted automatically when their parent room or associated account is deleted.
- Administrative audit records may be retained for security and accountability; deleting an account may remove the direct actor reference while the audit event remains.
- Realtime Presence is temporary connection state rather than persistent room history.
- Local preferences, demo state, gender selection, and recorded voice-note files may remain on the device until app data is cleared, the app is uninstalled, or the relevant local data is otherwise removed.
- Service-provider logs and backups may follow provider-controlled retention periods.
Before public release, Tuwaiq must adopt specific production retention periods and an operational deletion procedure. We may retain information longer where required by law, necessary to resolve disputes, protect security, or enforce agreements.
9. Your Rights and Choices
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or a portable copy of personal information, and to withdraw consent where processing relies on consent. These rights may be subject to verification and legal exceptions.
You can edit supported profile fields and local preferences in the app. You can revoke microphone or photo access in device settings and can disconnect Google or Apple access through the relevant provider controls. Revoking provider access does not by itself delete the Tuwaiq account or data already stored by Tuwaiq.
To make a privacy request, contact tuwaiqapp2@gmail.com. Do not send passwords, OTP codes, access tokens, or identity-provider secrets. We may ask for information reasonably necessary to verify that the request concerns your account.
10. Account and Data Deletion
The current mobile app displays an account-deletion option, but a completed in-app deletion workflow is not yet implemented. Until it is implemented, request deletion by following the public data-deletion instructions or by emailing tuwaiqapp2@gmail.com.
After verifying a valid request, Tuwaiq will delete or de-identify account data in accordance with the adopted deletion procedure and applicable law, subject to information that must be retained for security, fraud prevention, legal obligations, disputes, backups, or enforcement. Deleting Tuwaiq data does not automatically delete information held independently by Google, Apple, the operating-system provider, or another service you chose to use.
11. Children's Privacy
Tuwaiq's minimum permitted user age has not yet been finalized. The intended minimum is [MINIMUM USER AGE]. The Services are not intended for children below the finalized minimum age, and they should not create an account or provide personal information. If you believe a child has provided information contrary to the applicable age requirement, contact tuwaiqapp2@gmail.com so the matter can be reviewed.
Before release, the legal owner must decide the minimum age and whether parental consent or age-assurance measures are required in the target countries.
12. Changes to This Policy
We may update this Policy as the Services, providers, or legal requirements change. We will post the revised Policy with a new effective date and provide additional notice where required. Features that introduce materially new collection—such as push notifications, production voice transport, payments, analytics, advertising, or new social systems—require a policy and store-disclosure review before launch.
13. Contact Us
[LEGAL ENTITY NAME] Registered country: الكويت Privacy email: tuwaiqapp2@gmail.com