Privacy Policy
Last updated: September 24, 2026
We are committed to protecting your privacy. This policy explains what we collect, how we use it, and your rights over your data.
1. INTRODUCTION
This Privacy Policy explains how Alrawidream ('we', 'us', or 'our') collects, uses, stores, shares, and protects your personal information when you use our mobile-first social dream-sharing platform. By creating an account or using Alrawidream, you consent to the practices described in this policy. We are committed to transparency, data minimization, and giving you control over your information.
2. INFORMATION WE COLLECT
We collect only the information necessary to provide and improve the service. This falls into the following categories:
- Account Information: Email address, encrypted password (email sign-up), and a public nickname or username you choose. Each display name may be used by only one account (compared without regard to capitalization or extra spaces). Your real email address is never shown publicly.
- Continue with Google: If you sign in with Google, Google sends us the Google account identifiers and email associated with that Google login so we can create or resume your Alrawidream session. We do not receive your Google password. Google's own privacy policy applies to Google's processing.
- Follows: When you follow another account we store the follower and followee account ids (and the time) on our servers so your following and followers lists work on every device. Follows are not public to third parties except as needed to show those lists in the app.
- 18+ confirmation: When you complete Sign Up or continue with Google (including the required 18+ confirmation and Terms/Privacy agreement), we store the time of that confirmation, the email used at that time, and the signup IP when available. This records that you completed the on-screen confirmation. It is not identity verification and does not prove your real age.
- Profile Information: Optional avatar image and display preferences you voluntarily set (for example nickname, Leaderboard Privacy, and how you appear on public posts). Alrawidream does not collect a biography or profile bio; the app has no bio field.
- Dream Content: Text posts, titles, tags, comments, and voice recordings you upload to your Private Journal. Voice recordings are private-journal only: they cannot be attached to public posts, and they are never shared on public feeds, author profiles, or search. Sharing a journal entry to Galaxy publishes the text only and strips the audio.
- In-app Reports: When you Report a live public post, we store the reporter account id, the post id, an optional reason, status (pending, dismissed, or actioned), review timestamps, and an internal AI note (cleared, removed, or unsure). The same two-layer OpenAI review used on Galaxy posts runs on the reported text. A clear violation hides the post without a content strike. A clear non-violation closes the Report, leaves the post up, and counts as False reporting against the reporter. An Unsure result stays in a human queue. Dismissing a Report does not email anyone. If an operator confirms a violation on an Unsure Report, we hide the post, record a strike on the author's account, and email the author the same type of strike notice described in Section 7 (count out of 3, and a short excerpt of the post). We do not send an automatic email to the person who Reported except a False reporting freeze or lock notice when that separate count reaches 3 or 6.
- In-app Flags: When you Flag from your own Profile, Flag is for a serious account issue only. We store the reporter account id, a category, optional details, status, an internal AI note (answered or unsure), and review timestamps. Spam, unserious Flags, and Flags already covered by published rules are closed and counted as False reporting (nickname + lifetime count in a separate folder). Count 3 pauses the account 24 hours. Count 6 locks the account permanently. The folder row stays. This is not a Galaxy content strike. Unsure serious Flags stay in a human queue. We do not send an automatic email to the person who Flagged except the freeze or lock notice when those counts are reached. Alrawidream does not offer an in-app Flag of another user's profile.
- Usage & Security Data: App interactions, feature usage, and technical logs such as IP address, device type, browser information, crash reports, timestamps of sign-up/gift/password attempts, unsuccessful-attempt counters, feature-pause expiry times, email sign-up volume per IP (including weekly cap hits), first-time Google account creates per IP (Google law), internal 'Red user', week-cap, and Google-law badges, account-freeze timestamps, and burst-abuse records (short-window violation or bad-request events, banned IP rows, and banned email rows). On your device we also keep a last-activity timestamp (in the browser's local storage) so we can end an idle session as described in Section 8, and — if you turn Diary Passcode Lock on — a salted hash of your 4-digit passcode in local storage only (never the digits, never uploaded). These are used for reliability, security, fraud prevention, and Terms enforcement — not for advertising.
- Cosmos Level & Moon Tickets: We store dream points, Cosmos Level, Moon Ticket balance, last grant time, and cycle allowance so we can run level perks and 30-day ticket top-ups.
- Dream Quests, XP & Quest Points: We store quest progress and awards, a spendable Quest XP wallet, a lifetime XP total, and Quest Points (capped at 100). Completing quests uses your likes, comments, wand casts, and streak activity. Convert XP to Point (1,000 XP = 1 Quest Point) spends the XP wallet only. Convert Quest Points to Wand spends Quest Points and credits Wand Energy; it does not spend XP or Moon Tickets.
- Wand Energy: We store three integer energy counts (1h, 3h, 6h) on your profile. A successful Magic Wand cast decrements one count and records the pin (dream id, duration, expiry) so the Feed can rank enchanted posts.
- Streaks: We store Night Owl / Early Bird streak kind, active seconds in the window, streak count, and related daily completion so Dream Quests and streak UI can work across devices.
- Communications: Emails or support messages you send to alrawidream@icloud.com, including moderation appeals and data-deletion requests. We also send the transactional emails described in Sections 3, 4, and 9, including sign-up confirmation, in-app gift notices, password-change notices, 24-hour feature-pause notices, moderation strike or ban notices, and False reporting 24-hour pause or permanent-lock notices. We do not send an automatic email merely because you filed a Report or Flag.
3. HOW WE USE YOUR INFORMATION
We use your information to operate, secure, and improve Alrawidream:
- To authenticate your account and keep it secure, including ending an idle signed-in session after 10 minutes without interaction as described in Section 8.
- To display public dream posts, account follows, and peer-to-peer community interaction.
- To run Cosmos Level, Moon Ticket cycles, Dream Quests, XP and Quest Point conversion, Wand Energy, Magic Wand pins, and streak windows.
- To run automated content moderation and optional language translation on public Galaxy posts and comments, and on written journal text only at the moment you choose to publish it to Galaxy — not on Private Journal saves or voice memos.
- To respond to support requests, in-app Reports, Flags, and appeals.
- To apply rate limits, feature pauses, email sign-up IP caps, Google-law new-account caps, account freezes, burst abuse IP/email blocks, and related automated abuse controls described in our Terms of Service.
- To send transactional notices (for example completed in-app ticket gifts, successful password changes, 24-hour pauses on gifting or password change, and moderation strike or account-ban warnings when content is rejected). We do not send a dedicated email when sign-up itself is rate-limited or paused.
- To monitor platform health, prevent abuse, and enforce our Terms of Service.
- We do not sell your personal data to advertisers or data brokers.
4. ABUSE PREVENTION, RATE LIMITS, ACCOUNT PAUSES & SECURITY LOGS
Alrawidream uses automated systems to limit abuse. This section describes the personal data involved. The numeric rules themselves are in the Terms of Service (Section 4) and may change; this Privacy Policy describes processing, not a promise that any particular number will never change.
- In-app user-to-user gifts (allowed): When the gift feature is available, you may send Moon Tickets to another Alrawidream account inside the app by that account's unique public display name. You cannot send tickets by typing an email address. We process the sender and recipient account identifiers, ticket amount, remaining balance, attempt counters, any 24-hour gift pause, and transactional emails to both parties. This in-app transfer is the only permitted user-to-user gift. Buying, selling, trading, gifting, or transferring tickets outside the app remains prohibited as stated in the virtual-items rules below.
- 3 / 15-minute attempt windows: We record each attempt to (a) create an email-and-password account, (b) send in-app Moon Tickets, and (c) change a password. We store a subject key (account, email, and/or IP), a fail count, status, and lock-until time. After three unsuccessful tries in 15 minutes we pause that feature for 24 hours. The pause is lifted automatically when the time expires (including by a periodic watchdog job).
- 15 / 30-minute, 50 / 24-hour, and 75 / UTC-week email sign-up caps: For successful new email-and-password accounts we store the client IP, the new user id, and the time of create. We also store per-IP state (burst strike count, lock-until, permanent sign-up block, weekly lock-until, weekly permanent flag) and which UTC weeks an IP hit the weekly cap. Google or other OAuth sign-in is not written to this email-sign-up IP ledger. Resending confirmation is not stored as a new account create.
- Google law: For first-time Google accounts on Alrawidream we store a separate ledger (client IP, new user id, time). Returning Google sign-ins are not written. We store per-IP Google-law state (burst strike count, lock-until, permanent Google sign-up block, weekly lock-until, weekly permanent flag) and which UTC weeks an IP hit 30 new Google accounts. If a new Google account is created while that IP is over a cap, we delete that Auth user and do not keep the session. We may set is_google_law_user on accounts from a violating burst or week. That badge is not a freeze.
- Red users and freezes: If an IP hits the 15/30-minute or 50/24-hour sign-up caps, we may set an internal is_red_user flag and account_frozen_until only on accounts created in that burst. Clean accounts that already existed on the same IP are not flagged or frozen for that event. Frozen users cannot use the app until the freeze ends (24 hours, or indefinitely on a second IP offense). Tickets and posts stay stored. After a first freeze ends, the Red flag may remain for security history. Separately, we store a journal-to-Galaxy ignore count on the profile. If the in-app edit notice is shown more than 5 times, we set account_frozen_until for 24 hours and may email you. That freeze is not a Red flag and not a content strike.
- Week-cap badge: If an IP hits 75 email sign-ups in a UTC week, we may set is_week_cap_user on accounts created from that IP in that week so operators can tell them apart from Red users. That badge is not a freeze and does not lock the account. An account may be both Red and week-capped. Operators may lift an IP sign-up lock (including the weekly lock); that does not by itself erase Red or week-cap badges.
- Google-law badge: If an IP hits Google-law burst or weekly volume, we may set is_google_law_user on the new Google accounts in that window. That badge is not a freeze. Operators may lift a Google-law IP lock without erasing yellow badges.
- Burst abuse firewall (5 / 45 seconds): Separate from content strikes (3 on the account) and from email sign-up caps. We record moderation violations and abusive/bad requests with the client IP, email when known, kind, optional short detail, and time. Five such events from the same IP or email in 45 seconds may permanently list that email as blocked and may block that IP for 48 hours (a further trigger may make the IP block permanent). We store those event rows and the resulting banned-IP / banned-email records so we can refuse later requests early. This is not advertising. Shared networks may be affected.
- Legal bases (where GDPR/UK GDPR or similar laws apply): we process this security data as necessary to provide the service (contract), to pursue our legitimate interests in preventing fraud, spam, and platform abuse, and where required to comply with law. You may object to legitimate-interest processing by emailing alrawidream@icloud.com; we may continue processing where we have compelling grounds (including ongoing abuse prevention).
- Automated decisions: Rate limits, pauses, IP sign-up locks (including the weekly email cap and Google law), Red flags, week-cap badges, Google-law badges, freezes (including a 24-hour freeze after more than five journal-to-Galaxy edit notices), and burst abuse IP/email blocks are applied automatically. They can restrict registration or use of the app. They are not credit, employment, or insurance decisions. You can request human review at alrawidream@icloud.com within 14 days.
- Shared IP addresses: We typically see the public IP of your network (home, school, workplace, VPN, mobile carrier). Many people can share one IP. Caps apply to that address, so someone else's volume can delay your ability to register. We do not claim to identify a unique person from IP alone.
- Retention: Security and abuse records (IP events, per-IP lock state, weekly cap hits, Google-law events and state, attempt counters, Red flags, week-cap badges, Google-law badges, freeze timestamps, burst-abuse events, banned IP rows, and banned email rows) may be kept for as long as reasonably needed to enforce caps, investigate abuse, and defend the service, including after a related account is deleted, because an IP or email block must still apply to the network or mailbox. We do not use these records to build advertising profiles.
- Your rights: You may request access or deletion of personal data as described later in this policy. We may refuse or limit deletion of security logs where we must retain them to prevent fraud, protect other users, or comply with law, and we will explain if we do.
5. PRIVATE JOURNAL — STRICT PRIVACY
Your Private Journal is a strictly personal space. Private writing and voice recordings are your exclusive property:
- Yours, your responsibility: Private Journal writing and voice recordings are your exclusive property while they remain Private. They belong to you. They are visible only to you and are never shown on public feeds, author profiles, search, or to other users. You bear full legal responsibility for every text entry and voice recording you store in the Private space of your own account, including content that is unlawful where you live. To the maximum extent permitted by law, Alrawidream accepts no civil or criminal liability for Private content you create and keep there.
- Storage and access: Private Journal files are stored separately from the public Galaxy feed. They are encrypted in transit (HTTPS/TLS) and at rest on our hosting infrastructure (Supabase standard encryption-at-rest). This is not end-to-end encryption with a key only you hold. The host still stores the encrypted files so the app can show them back to you. That is storage, not permission for staff or the moderator to open Private entries. Our personnel and moderation systems are not permitted to access, read, or listen to Private Journal writing or voice memos while they remain Private. Saving writing or voice does not run the two-layer AI scan. Administrator logins cannot browse Private Journal rows in the review dashboard. Voice memos cannot be published.
- Operating exceptions: Exceptions that match how the app actually runs: (1) If you choose Share to Galaxy or Publish with a Moon Ticket, only the written title, tag, and text are sent through the same two-layer review as public posts. The entry stays Private until both layers pass. A Moon Ticket is spent only if they pass. Voice is never included. (2) If a valid court order or other compulsory legal process requires production of stored files, we may produce them. That is not in-app moderation and does not give operators a dashboard to browse Private Journal. (3) Account deletion purges Private Journal from the App; independent providers may still keep copies on their own systems as described elsewhere in these documents.
- Weekly quota: The Private Journal is not unlimited. Each account may save 1 private write and 1 voice memo per week. Unused weeks bank up to 15 of each. We store these remaining write and voice balances on your profile to apply the quota. Writing and voice are saved as separate entries (1 write credit or 1 voice credit, not both on one save). Sharing a written journal entry to Galaxy spends a Moon Ticket and publishes the text only. Voice memos are never published.
- No in-app review while Private: Saving Private Journal writing or voice does not run the two-layer OpenAI moderator. Other users never see this content. If you try to publish written journal text to Galaxy, both layers run first on that text only. If the writing fails, it stays private and you are asked to edit it to match the app's rules. If that notice is shown more than 5 times because you keep publishing without passing, we freeze the account for 24 hours and may email you. Voice memos cannot be published. Direct Galaxy posts and comments still use the two-layer scan (including self-harm and sexual content involving minors).
- Passcode Protection: You may set an optional 4-digit Diary Passcode Lock. The digits are never sent to Alrawidream. This device stores only a salted hash in the browser's local storage, keyed to your account id. Forgot Passcode removes that hash on this device so the diary opens without a code; we cannot email you the old digits because we never had them. Clearing site data or using another browser also means that lock is not there.
- Row Level Security (RLS): Other users cannot read your private journal in the database. Administrator logins cannot browse Private Journal rows in the review dashboard.
- No Public Sharing by Default: A private entry can only become public if you explicitly choose to 'Share to Galaxy' and the written text passes our content moderation review. Voice recordings never take that path.
6. PUBLIC POSTS & COMMUNITY VISIBILITY
When you choose to publish a dream publicly, the following information becomes visible to the community:
- Your public nickname or 'Anonymous' label, depending on your publishing choice.
- The dream title, content, tag, and any public engagement metrics such as likes and comments. Voice recordings are never included in public posts.
- Optional translated versions of your title and content, generated solely for community accessibility.
- Your real email address, Private Journal entries, and voice recordings are never visible to other users.
- Share: The in-app Share control uses your device's share sheet or copies the public post URL to the clipboard. That URL is already public for an approved Galaxy post. We do not receive an extra copy of the clipboard.
- Comment deletion — dream author: If you published a public Galaxy post, you may delete any comment or reply on that post. When you do, we permanently remove that content from the community and from our database.
- Comment deletion — thread removal: If you wrote a top-level comment, deleting it permanently removes that comment and every reply posted under it, including replies from other users.
7. AI CONTENT MODERATION & PRIVACY
To keep the community safe, Galaxy posts and comments are processed by automated moderation systems. Written journal text is reviewed the same way only when you publish it to Galaxy. Here is exactly how that works:
- AI Provider: We use a two-layer OpenAI filter. Layer 1 is the free OpenAI Moderation API for general safety (hate, sexual content, violence, self-harm, sexual content involving minors, and similar). Layer 2 is gpt-4o-mini for Alrawidream custom rules: real-world politics or government criticism, financial/lottery scams, commercial fortune-telling, and a second pass on self-harm/suicide and sexual content involving minors. Optional translation also uses gpt-4o-mini.
- Purpose Only: AI is used exclusively for automated content moderation of public Galaxy posts and comments (and of written journal text at Galaxy-publish time), optional language translation of public posts, and routing in-app Flags against published product rules. It is not used to open Private Journal saves or voice memos.
- No Training Guarantee: Your private data, Private Journal entries, and public posts are NOT used to train, fine-tune, or improve third-party AI models. Private Journal saves are not sent to OpenAI. Public posts (and written journal text only when you publish to Galaxy) are processed only for immediate moderation or translation decisions. In-app Flag text is processed only for immediate routing (answered or unsure).
- No AI Advice: Alrawidream does not provide AI dream analysis, interpretations, consultations, or custom AI replies. Flag routing returns a canned in-app notice, not a generated support letter. AI functions solely as a safety filter and a Flag router against published rules.
- Optional Translation: The optional translation feature functions solely as an automated language conversion tool to assist readability across languages, without analyzing, interpreting, or providing opinions on dream content.
- Human Review: Automated moderation decisions on public Galaxy posts and comments may be reviewed by human moderators for appeals, edge cases, or administrative oversight. In-app Reports on live public posts are first re-checked by the two-layer AI filter. Clear outcomes are applied automatically (hide, or keep the post). Unsure Reports go to a human queue only. In-app Flags are first routed against published product rules. Clear matches are closed automatically. Unsure Flags go to a separate human queue. The AI bot does not email evidence to the person who sent a Report or Flag. Private Journal writing and voice memos are not opened for human review while they remain Private.
- Strike notices: When content is rejected — by the AI filter when it is submitted to Galaxy, or by a human operator confirming an Unsure in-app Report — we email the address on the author's account a community-standards warning. The message includes the current strike count (out of 3) and may include a short excerpt of the reported text as evidence. An automatic hide after a Report that the AI is sure about does not itself send a strike email. On the third strike we email that the account has been permanently locked. The third content strike bans the account only; it does not by itself ban the IP. Burst IP/email blocks are a separate process described in Section 4. These are safety notices, not marketing. You may appeal as described in the Terms.
- Pending Review: Direct Galaxy posts enter a moderation queue and are set to 'PENDING' until approved. They are not visible to the public during review. Written journal text shared to Galaxy is reviewed immediately (both layers). It stays private until both layers pass, then it goes live. Voice memos never enter this path.
8. DATA STORAGE & SECURITY
Protecting your data is a core priority. We implement the following safeguards:
- Infrastructure: All user data is stored on Supabase enterprise-grade cloud infrastructure.
- Row Level Security (RLS): Our database uses strict RLS policies to ensure users can only access their own data and content they are explicitly authorized to view.
- Authentication: Passwords are hashed and never stored in plain text. Sessions are managed securely.
- Idle sign-out (10 minutes): If you are signed in and there is no interaction (for example mouse, keyboard, tap, or scroll) for 10 minutes, the app signs you out on this device and you must sign in again. The last-activity time is stored in the browser's local storage so the timer is shared across tabs and still applies if the tab is hidden or the browser is minimised. This is a privacy and security control for an unattended device. It is not an account freeze, not a content strike, and not account deletion. We do not send that timestamp to our servers for advertising or profiling.
- Encryption: Data is encrypted in transit using HTTPS/TLS and protected by Supabase's standard encryption-at-rest practices.
- No Absolute Security Guarantee: While we follow industry-standard practices, no system can guarantee 100% security against all cyberattacks or breaches.
9. DATA SHARING & THIRD PARTIES
We do not sell your personal information. We share data only in limited circumstances:
- Service Providers: We use Supabase for database, authentication, and storage services. These providers are bound by strict confidentiality and security obligations.
- Google sign-in: If you choose Continue with Google, Google authenticates you and provides us the identifiers needed to open your Alrawidream account. Google processes that login under Google's terms and privacy policy.
- Email Delivery: We use Resend (or a successor processor) to send transactional email such as confirmations, in-app gift notices, password-change notices, 24-hour feature-pause notices, 24-hour journal-to-Galaxy freeze notices, and moderation strike or ban notices. The provider processes your email address and the message content solely to deliver that mail. A strike or ban notice may include a short excerpt of the flagged post or comment.
- AI Provider: Galaxy posts, comments, and written journal text at Galaxy-publish time are sent to OpenAI for moderation. Translation runs on public posts, not on private diary entries. Private Journal saves and voice memos are not sent to OpenAI for a safety scan.
- Legal Compliance: Exceptions that match how the app actually runs: (1) If you choose Share to Galaxy or Publish with a Moon Ticket, only the written title, tag, and text are sent through the same two-layer review as public posts. The entry stays Private until both layers pass. A Moon Ticket is spent only if they pass. Voice is never included. (2) If a valid court order or other compulsory legal process requires production of stored files, we may produce them. That is not in-app moderation and does not give operators a dashboard to browse Private Journal. (3) Account deletion purges Private Journal from the App; independent providers may still keep copies on their own systems as described elsewhere in these documents.
- Business Transfers: In the event of a merger, acquisition, or asset sale, user data would be transferred subject to the same privacy commitments.
10. COOKIES & DEVICE STORAGE
Alrawidream uses only what is needed to keep you signed in and to run the app on your device. We do not run advertising or third-party analytics products such as Google Analytics or the Facebook Pixel, and we do not use cookies to build advertising or behavioral profiles.
- Authentication cookies or similar session storage: Used to keep you signed in securely with our authentication provider (Supabase).
- Essential cookies or local data: Required for basic app function and security (for example remembering that you are signed in on this browser).
- Local storage (idle timer): The app stores a last-activity timestamp in the browser so it can sign you out after 10 minutes of inactivity, as described in Section 8. That timestamp stays on your device and is not an advertising tracker.
- Local storage (diary passcode): If Diary Passcode Lock is on, a salted hash of the 4-digit code is stored in this browser only, as described in Section 5. It is not an advertising tracker and is not sent to our servers.
- No advertising analytics: We do not place tracking pixels or advertising SDKs to measure campaigns or profile you for ads.
11. YOUR RIGHTS & CHOICES
Depending on your jurisdiction, you may have the following rights regarding your data:
- Access: You can view your account information, published dreams, and private journal entries within the app.
- Correction: You can update your nickname, avatar, and other profile information at any time.
- Deletion: You can delete individual posts or your entire account, which permanently removes associated data.
- Portability: You may copy your Private Journal from the app yourself. If you email alrawidream@icloud.com for an export, we fulfill it as a data-rights request and do not use the files for moderation.
- Objection & Restriction: You may request that we restrict or stop certain processing of your data, subject to legal and operational requirements.
- Withdraw Consent: You can delete your account at any time to withdraw consent for data processing.
12. ACCOUNT & DATA DELETION (RIGHT TO BE FORGOTTEN)
You have full control over your data. Deleting your account is permanent and comprehensive:
- How to Delete: You can request account deletion at any time via the in-app Profile/Settings screen or by contacting alrawidream@icloud.com.
- What Is Deleted: Upon deletion, Alrawidream does not keep any of your account, profile, 18+ confirmation record, Private Journal, posts, comments, likes, follows, voice recordings, avatars, Dream Quest awards, Quest XP, Quest Points, Wand Energy, wand-cast rows, streak rows, or other in-app records of you. Those items are purged from the App. A diary passcode hash on a device is not on our servers; clearing the browser or signing out of that device removes it locally.
- Third Parties: Independent providers (for example hosting, email delivery, or AI moderation) may keep copies or logs on their own systems. Alrawidream does not control those systems and, to the maximum extent permitted by law, is not responsible for what those third parties retain or how long they retain it.
- Irreversible: Once deletion is confirmed, the action cannot be undone. We cannot recover deleted data from the App.
- Timeline: Deletion requests are typically processed within 30 days, with most completed immediately upon confirmation.
13. AGE & CHILDREN'S PRIVACY
Alrawidream is for users 18 years of age or older. Completing Sign Up or continuing with Google, including the required 18+ confirmation and agreement to the Terms and this Privacy Policy, means you confirm that you are 18 or older. We store that confirmation as described in Section 2 (time, email at confirmation, and signup IP when available) while the account exists; it is deleted with the account. We do not knowingly collect personal data from anyone under 18. There is no parental-consent option: under-18 use is prohibited. A sign-up confirmation email is not sent, and Continue with Google stays locked, unless the 18+ confirmation is completed. If we discover an account we reasonably believe belongs to someone under 18, we will terminate it and permanently delete associated personal data from the App. You are solely responsible if you provide false age or other registration information. A parent or guardian who believes an under-18 child has an account may contact alrawidream@icloud.com.
14. INTERNATIONAL DATA TRANSFERS
Alrawidream is operated globally. Your data may be stored and processed in countries other than your own, including the United States and European Union data centers used by Supabase. We rely on standard contractual clauses and other legally recognized safeguards to protect your data during international transfers.
15. VIRTUAL ITEMS & TICKETS (NO MONETARY VALUE)
Alrawidream may offer in-app virtual credits such as Moon Tickets to unlock features. These virtual items are governed by the following rules:
- No Cash Value: All virtual credits have zero cash value, are not redeemable, and cannot be exchanged for real money, goods, or services outside the app.
- Cycle allowance: We store your Moon Ticket balance, Cosmos Level, last grant time, and 30-day cycle allowance so we can run each top-up (the greater of your current balance and your cycle allowance). Unused tickets stay. This is not a calendar-month reset.
- Quest XP, Quest Points & Wand Energy: These are also in-app virtual items with no cash value. Convert XP to Point and Convert Quest Points to Wand are final. We may modify, reduce, reset, or remove them as described in the Terms. They cannot be sold or transferred outside the app.
- In-app gifts (allowed): When the gift feature is available, you may send Moon Tickets from your account to another Alrawidream account inside the app by unique display name, not by email. That is the only permitted user-to-user transfer. We process sender and recipient identifiers, amount, balances, attempt limits, and related transactional emails as described in Section 4.
- Outside the app (prohibited): Buying, selling, trading, gifting, or transferring tickets outside Alrawidream — including for real money, goods, services, or any other consideration — is strictly prohibited.
- Zero Liability for External Transactions: Alrawidream accepts no liability for any scams, chargebacks, financial disputes, or losses arising from unauthorized external transactions involving virtual credits.
- Enforcement: Accounts involved in unauthorized ticket trading or attempts to monetize credits may be permanently banned without warning.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. We will notify you of material changes through the app or by email. Continued use of Alrawidream after any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
17. CONTACT US
For all privacy-related inquiries, including data access requests, data deletion requests, security-log questions, DMCA takedowns, moderation or freeze appeals, and general support, please contact us at:
- Email: alrawidream@icloud.com