Privacy policy

Dandesh privacy policy

Dandesh app · developed by Hananel Apps·Last updated: August 10, 2026
This policy explains the data the Dandesh app processes to provide its service, how we use and protect it, and your rights. The data described here is based on the app’s actual functionality, and details are reviewed and updated as the app changes.

1. Who we are & policy scope

The Dandesh app is developed by the Hananel Apps studio, which is responsible for processing your data inside the app. For privacy matters, contact: hananelqh@gmail.com.

This policy covers the Dandesh app on Android and iOS. This informational website has its own studio privacy policy and does not collect data from you through browsing.

2. Data the app collects

Dandesh collects the data needed to run the chat service and manage your account:

  • Account & sign-in — When you sign in with Google we collect only your email address and the sign-up method (“google”) — not your name, photo, or contacts. When you use the app as a guest, an anonymous server-side account with only an identifier is created, with no email. The app uses no password.
  • Sign in with Apple (iOS) — When you choose “Sign in with Apple”, we receive the identifier Apple generates for you and only the email address you agree to share (if you pick “Hide My Email”, Apple sends us a private relay address). No password.
  • In-app purchases (iOS) — iOS purchases are processed by Apple through the App Store; we do not see or store your card or payment details. We verify Apple’s signed transaction and retain the minimum purchase record needed to grant entitlements, process refunds, and prevent replay. When you delete your account, purchase audit records required for entitlement integrity remain without your user identifier.
  • App Attest protection (iOS) — We use Apple’s App Attest service to verify app integrity and protect store and entitlement requests from tampering. We store the attestation key and security counter linked to your account for security and fraud prevention; that link is deleted when the account is deleted.
  • Profile information — Your display name, gender, age/birth date, and consent time — as you enter them in the app.
  • Conversations & messages — Your message content and the companion’s replies, to keep your history and provide the service.
  • Conversation memory — Short facts the AI extracts from your chat to improve context. You can disable memory or delete items from within the app.
  • Companion — Your companion’s name, persona, and settings, and an optional image you can pick from your device library, stored with your account to display it (you may choose no image).
  • Usage & purchases — Your daily message counter, Pulse balance, VIP or permanent Remove Ads entitlement, and redemption codes linked to your account.
  • Feedback & support — Feedback or support requests you send in the app, and any replies.
  • Device identifier (hashed) — A hashed (HMAC) fingerprint of your Android device id, used to prevent abuse and enforce free limits. We do not store the raw device id.

3. Why we use your data

We use data only for the following purposes:

  • Operate the service — Manage your account, enable chat, store your history, and enforce usage limits.
  • Security & abuse prevention — Protect accounts and prevent limit circumvention and abuse.
  • Support & improvement — Respond to feedback and resolve issues.

4. AI and processing of your messages

To generate the companion’s replies, your messages are sent to external large-language-model providers: we route requests through OpenRouter to external model providers, and the model used may change. For factual questions we may use a web-search service (Tavily) to fetch current information.

Replies are AI-generated and may be inaccurate or incomplete, and are not a substitute for professional advice.

5. Service providers (sub-processors)

We use trusted service providers to run the app; they process data on our behalf or under their own policies:

We do not sell your personal data, nor share it for marketing.

  • Supabase — Authentication and application data storage.
  • Railway — Hosting the backend service and internal administration dashboard.
  • OpenRouter — Routing your messages to external large-language-model providers to generate AI replies; the model used may change.
  • Tavily — Web search for factual questions when needed.
  • Google Firebase — Aggregated technical usage analytics (Firebase Analytics) and crash reports (Firebase Crashlytics) with privacy-restricted settings — see “Analytics & crash reporting” below.
  • Google AdMob & bidding partners — Serving, measuring, and personalizing ads, with partner networks competing in AdMob’s auction (currently Unity Ads on Android) — see “Advertising” below.
  • Apple — “Sign in with Apple” for authentication and processing of in-app purchases on iOS through the App Store — without passing your payment details to us. If you switch it on yourself, limited consumption data is sent when you request a refund — see “Refund requests on iOS” below.

6. Advertising

Dandesh shows ads via Google AdMob (banner, interstitial, and rewarded ads), and partner networks may compete for each impression in a real-time auction run by AdMob — currently Unity Ads on Android. Ads may be personalized based on your interests: ad networks process your device’s advertising identifier and approximate IP-derived location (such as country) to serve, measure, and personalize ads under Google’s and its partners’ policies.

In the European Economic Area, the United Kingdom, and Switzerland, personalized ads are shown only after your explicit consent through the in-app consent form; declining means you only see non-personalized ads. You can limit ad personalization or reset/delete your advertising identifier at any time in your device settings (Android: Settings → Google → Ads).

Ads are not shown to VIP members or users who purchased permanent Remove Ads, and are suppressed in sensitive conversations. Rewarded ads are optional, and a reward is granted only after Google and the server confirm that the ad was completed.

7. Analytics & crash reporting

Dandesh uses Google Firebase Analytics with privacy-restricted settings: automatic data collection is disabled, no Advertising ID (ADID) is collected, no ad-personalization signals are sent, and no personal user identifier is set (setUserId stays empty/null).

Only aggregated usage events are recorded — such as app opens, sessions, screen navigation, feature interactions, and rewarded-ad events — with no conversation content, messages, AI replies, or personal data (PII). Analytics is enabled only after you accept the consent screen, and is fully suppressed during sensitive conversations.

For crash diagnostics, Dandesh uses Google Firebase Crashlytics under the same controls: collection is disabled at build time and is enabled only after you consent, and no user identifier is ever set. A crash report carries only your account type, UI language, release channel, and the name of the last screen; the error message and stack trace are redacted of email addresses and access tokens before they are sent. No conversation content is sent, and screen names are not recorded during sensitive conversations.

On iOS only: when you request a refund from Apple, Apple asks us for consumption data to help it decide your request. We send nothing unless you switch this on yourself — it is off by default, entirely separate from accepting the Terms and from marketing consent, and you can turn it on or off at any time in Settings. Only three things are sent: that the purchase was actually delivered, what share of it was used, and that we offer free credit before any purchase. No conversation content, name, email address, or account identifier is sent.

We keep aggregated or anonymized operational logs (such as model cost and ad performance) that contain no chat content and do not identify you.

8. Protection & access

Data is stored in Supabase with row-level security (RLS) that limits your access to your own data. On your device, session tokens are stored encrypted in iOS Keychain or Android Keystore.

Never send your password, verification code, or any secret to us by email; the app does not use a password at all.

9. Data retention

We keep your account and conversation data for as long as your account exists or as needed to provide the service.

When you delete your account, associated data is deleted, except limited records no longer linked to your user identifier: safety/moderation logs, aggregated ad and cost analytics, anti-abuse records, and Apple transaction records required to prevent replay and preserve entitlement/refund integrity. The consumable Pulse ledger linked to the account is deleted with the account.

10. Account & data deletion

You can delete your account from within the app, or by emailing hananelqh@gmail.com if you lose access. Full details and exactly what is deleted are on the “Delete account” page.

11. Your rights

To the extent applicable law allows, you may:

  • Access — Know what data is associated with your account.
  • Correction — Request correction of inaccurate data.
  • Deletion — Request deletion of your account and data.

12. Age & children’s privacy

Dandesh is intended for adults aged 18 and over only, and the consent screen requires you to confirm your age. AI companions are also limited to 18 and over.

The app is not directed to anyone under 18; if an account is found to belong to someone underage, we delete it once we become aware.

13. Policy updates

We may update this policy as the app or legal requirements change, and we will update the “Last updated” date above.

Privacy questions?

Email us with any question or request about your data.

hananelqh@gmail.com
سياسة الخصوصية

سياسة خصوصية دندوشة

تطبيق دندوشة · من تطوير حنانيل آبس·آخر تحديث: 10 أغسطس 2026
توضّح هذه السياسة البيانات التي يعالجها تطبيق دندوشة لتقديم خدمته، وكيف نستخدمها ونحميها، وحقوقك بشأنها. وصف البيانات هنا مبني على وظائف التطبيق الفعلية، وتُراجع التفاصيل وتُحدّث عند تغيّر التطبيق.

1. من نحن ونطاق السياسة

تطبيق دندوشة من تطوير استوديو حنانيل آبس، وهو المسؤول عن معالجة بياناتك داخل التطبيق. للتواصل بشأن الخصوصية: hananelqh@gmail.com.

تغطّي هذه السياسة تطبيق دندوشة على نظامَي Android وiOS. أمّا هذا الموقع التعريفي فله سياسة خصوصية الاستوديو الخاصة، ولا يجمع بيانات منك عبر تصفّحه.

2. البيانات التي يجمعها التطبيق

يجمع دندوشة البيانات اللازمة لتشغيل خدمة المحادثة وإدارة حسابك:

  • الحساب وتسجيل الدخول: عند الدخول عبر Google نجمع بريدك الإلكتروني وطريقة التسجيل ("google") فقط — دون اسمك أو صورتك أو جهات اتصالك. وعند الاستخدام كضيف يُنشأ حساب مجهول على الخادم بمعرّف فقط، بلا بريد. والتطبيق لا يستخدم كلمة مرور.
  • تسجيل الدخول عبر Apple (iOS): عند اختيار «تسجيل الدخول عبر Apple» نستلم المعرّف الذي تُنشئه Apple لك، والبريد الإلكتروني الذي توافق على مشاركته فقط (نحترم خيار «إخفاء بريدي» فيصلنا بريد وسيط من Apple). بلا كلمة مرور.
  • المشتريات داخل التطبيق (iOS): تتم مشتريات iOS عبر App Store من Apple؛ لا نرى ولا نخزّن بيانات بطاقتك أو دفعك. نتحقق من معاملة Apple الموقّعة ونحتفظ بالحد الأدنى من سجل الشراء اللازم لتفعيل الاستحقاق ومعالجة الاسترداد ومنع تكرار المعاملة. عند حذف الحساب تبقى سجلات تدقيق الشراء الضرورية لسلامة الاستحقاق دون معرّف المستخدم.
  • حماية App Attest (iOS): نستخدم خدمة App Attest من Apple لإثبات سلامة نسخة التطبيق وحماية طلبات المتجر والاستحقاقات من التلاعب. نخزّن مفتاح الإثبات وعداد الحماية مرتبطين بالحساب لأغراض الأمان ومكافحة الاحتيال، ويُحذف هذا الربط عند حذف الحساب.
  • معلومات الملف الشخصي: الاسم الظاهر، والجنس، والعمر/تاريخ الميلاد، ووقت موافقتك — كما تُدخلها أنت في التطبيق.
  • المحادثات والرسائل: محتوى رسائلك وردود الرفيق الذكي، للاحتفاظ بسجل محادثاتك وتقديم الخدمة.
  • ذاكرة المحادثة: حقائق مختصرة يستخلصها الذكاء الاصطناعي من محادثتك لتحسين السياق. يمكنك تعطيل الذاكرة أو حذف عناصرها من داخل التطبيق.
  • الرفيق: اسم الرفيق وشخصيته وإعداداته، وصورة اختيارية تختارها من مكتبة جهازك وتُحفظ مع حسابك لعرضها (يمكنك عدم اختيار صورة).
  • الاستخدام والمشتريات: عدّاد الرسائل اليومي، ورصيد النبضات، واستحقاق VIP أو إزالة الإعلانات، وأكواد الاستبدال المرتبطة بحسابك.
  • الملاحظات والدعم: ما ترسله من ملاحظات أو طلبات دعم داخل التطبيق وأي ردود عليها.
  • معرّف الجهاز (مجزّأ): بصمة مجزّأة (HMAC) لمعرّف جهاز Android، تُستخدم لمنع إساءة الاستخدام وضبط الحدود المجانية. لا نخزّن المعرّف الخام.

3. لماذا نستخدم بياناتك

نستخدم البيانات للأغراض التالية فقط:

  • تشغيل الخدمة: إدارة حسابك وتمكين المحادثة وحفظ سجلك وتطبيق حدود الاستخدام.
  • الأمان ومنع الإساءة: حماية الحسابات ومنع التحايل على الحدود وإساءة الاستخدام.
  • الدعم والتحسين: الرد على ملاحظاتك ومعالجة المشاكل.

4. الذكاء الاصطناعي ومعالجة رسائلك

لتوليد ردود الرفيق، تُرسل رسائلك إلى مزوّد نماذج لغوية خارجي: نوجّه الطلبات عبر OpenRouter إلى مزوّدي نماذج لغوية خارجيين، وقد يتغيّر النموذج المستخدم. وعند الأسئلة المعرفية قد نستعين بخدمة بحث (Tavily) لجلب معلومات حديثة.

الردود مولّدة آلياً وقد تكون غير دقيقة أو غير مكتملة، وليست بديلاً عن استشارة مهنية.

5. مزوّدو الخدمة (المعالجون الفرعيون)

نستعين بمزوّدي خدمة موثوقين لتشغيل التطبيق، يعالجون البيانات نيابةً عنا أو وفق سياساتهم:

لا نبيع بياناتك الشخصية، ولا نشاركها لأغراض تسويقية.

  • Supabase: المصادقة وتخزين بيانات التطبيق.
  • Railway: استضافة الخادم الخلفي ولوحة الإدارة الداخلية.
  • OpenRouter: توجيه رسائلك إلى مزوّدي نماذج لغوية خارجيين لتوليد ردود الذكاء الاصطناعي؛ وقد يتغيّر النموذج المستخدم.
  • Tavily: بحث الويب للأسئلة المعرفية عند الحاجة.
  • Google Firebase: تحليلات استخدام تقنية مجمّعة (Firebase Analytics) وتقارير الأعطال (Firebase Crashlytics) بإعدادات مقيَّدة للخصوصية — التفاصيل في قسم «التحليلات وتتبّع الأعطال» أدناه.
  • Google AdMob وشركاء المزايدة: عرض الإعلانات وقياسها وتخصيصها، مع شبكات شريكة تتنافس في مزاد AdMob (حالياً Unity Ads على أندرويد) — التفاصيل في قسم «الإعلانات» أدناه.
  • Apple: «تسجيل الدخول عبر Apple» للمصادقة، ومعالجة المشتريات داخل التطبيق على iOS عبر App Store — دون تمرير بيانات دفعك إلينا. وإذا فعّلتَ الخيار بنفسك، تُرسَل بيانات استهلاك محدودة عند طلبك استرداداً — التفاصيل في قسم «طلبات الاسترداد على iOS» أدناه.

6. الإعلانات

يعرض دندوشة إعلانات عبر Google AdMob (بانر، وإعلانات كاملة بين التصفّح، وإعلانات بمكافأة)، وقد تتنافس شبكات شريكة على عرض الإعلان في مزاد لحظي تديره AdMob — حالياً Unity Ads على أندرويد. قد تكون الإعلانات مخصّصة بناءً على اهتماماتك: تعالج الشبكات الإعلانية معرّف إعلانات جهازك وعنوان IP التقريبي (مثل البلد) لعرض الإعلانات وقياسها وتخصيصها وفق سياسات Google وشركائها.

في المنطقة الاقتصادية الأوروبية وبريطانيا وسويسرا لا تُعرض إعلانات مخصّصة إلا بعد موافقتك الصريحة عبر نموذج الموافقة داخل التطبيق، ورفضُك يعني إعلانات غير مخصّصة فقط. وتستطيع في أي وقت الحدّ من تخصيص الإعلانات أو إعادة تعيين/حذف معرّف الإعلانات من إعدادات جهازك (أندرويد: الإعدادات ← Google ← الإعلانات).

لا تظهر الإعلانات لمشتركي VIP أو لمن اشترى إزالة الإعلانات الدائمة، وتُكتم في المحادثات الحسّاسة. إعلانات المكافأة اختيارية، ولا تُمنح المكافأة إلا بعد تأكيد Google والخادم اكتمال الإعلان.

7. التحليلات وتتبّع الأعطال

يستخدم دندوشة خدمة Google Firebase Analytics بإعدادات مقيَّدة للخصوصية: الجمع التلقائي للبيانات معطّل، ولا يُجمع أي معرّف إعلاني (Advertising ID)، ولا تُرسَل أي إشارات لتخصيص الإعلانات، ولا يُضبط أي معرّف مستخدم شخصي (setUserId يبقى فارغاً/null).

تُسجَّل فقط أحداث استخدام مجمّعة — مثل فتح التطبيق والجلسات والتنقّل بين الشاشات والتفاعل مع خصائص التطبيق وأحداث إعلانات المكافأة — دون أي محتوى محادثات أو رسائل أو ردود ذكاء اصطناعي أو بيانات شخصية (PII). تُفعَّل هذه التحليلات فقط بعد موافقتك على شاشة الموافقة، وتُكبَح تماماً أثناء المحادثات الحسّاسة.

ولتشخيص الأعطال يستخدم دندوشة Google Firebase Crashlytics بالضوابط نفسها: الجمع معطّل عند بناء التطبيق ولا يُفعَّل إلا بعد موافقتك، ولا يُضبط أي معرّف مستخدم إطلاقاً. لا يُرسَل مع تقرير العطل إلا نوع الحساب ولغة الواجهة وقناة الإصدار واسم آخر شاشة، وتُنقَّح رسالة الخطأ وأثر المكدّس من عناوين البريد ورموز الدخول قبل الإرسال. لا يُرسَل أي محتوى محادثة، ولا تُسجَّل أسماء الشاشات أثناء المحادثات الحسّاسة.

وعلى iOS وحده: عند طلبك استرداداً من Apple تطلب Apple منّا بيانات استهلاك تساعدها على البتّ في طلبك. لا نرسل شيئاً إلا إذا فعّلتَ الخيار بنفسك — وهو مطفأ افتراضياً، ومنفصل تماماً عن قبول الشروط وعن الموافقة التسويقية، ويمكنك تشغيله أو إيقافه في أي وقت من «الإعدادات». والمُرسَل ثلاثة أشياء فقط: أن الشراء سُلّم فعلاً، ونسبة ما استُهلك منه، وأننا نقدّم رصيداً مجانياً قبل أي شراء. لا يُرسَل أي محتوى محادثة ولا اسم ولا بريد ولا معرّف حساب.

نحتفظ بسجلات تشغيلية مجمّعة أو مجهّلة الهوية (مثل تكلفة النماذج وأداء الإعلانات) لا تتضمّن محتوى محادثاتك ولا تحدّد شخصك.

8. الحماية والوصول

تُخزَّن البيانات في Supabase مع سياسات وصول على مستوى الصف (RLS) تقصر وصولك على بياناتك أنت. وعلى جهازك تُحفظ رموز الجلسة بشكل مشفّر في iOS Keychain أو Android Keystore.

لا تُرسل كلمة المرور أو رمز التحقق أو أي رمز سري لنا عبر البريد إطلاقاً؛ والتطبيق أصلاً لا يستخدم كلمة مرور.

9. مدة الاحتفاظ

نحتفظ ببيانات حسابك ومحادثاتك طالما ظل حسابك قائماً أو بالقدر اللازم لتقديم الخدمة.

عند حذف الحساب تُحذف البيانات المرتبطة به، باستثناء سجلات محدودة لا تعود مرتبطة بمعرّف المستخدم: سجلات الإشراف/السلامة، وتحليلات الإعلانات والتكلفة المجمّعة، وسجلات مكافحة إساءة الاستخدام، وسجلات معاملات Apple اللازمة لمنع التكرار وحفظ سلامة الاستحقاقات والاستردادات. يُحذف سجل النبضات الاستهلاكية المرتبط بالحساب مع الحساب.

10. حذف الحساب والبيانات

يمكنك حذف حسابك من داخل التطبيق، أو بإرسال طلب إلى hananelqh@gmail.com عند فقدان الوصول. التفاصيل الكاملة وما يُحذف فعلياً في صفحة «حذف الحساب».

11. حقوقك

يحق لك، بالقدر الذي يتيحه القانون المعمول به:

  • الوصول: معرفة البيانات المرتبطة بحسابك.
  • التصحيح: طلب تصحيح بيانات غير دقيقة.
  • الحذف: طلب حذف حسابك وبياناتك.

12. الأعمار وخصوصية الأطفال

دندوشة مخصّص للبالغين بعمر 18 عاماً فأكثر فقط، وتتطلب شاشة الموافقة تأكيد عمرك. كما أن شخصيات الرفيق محدّدة بـ18 عاماً فأكثر.

التطبيق غير موجّه لمن هم دون 18 عاماً، وإذا تبيّن أن حساباً يخص شخصاً دون السن نحذفه عند العلم به.

13. تحديث السياسة

قد نحدّث هذه السياسة عند تغيّر التطبيق أو المتطلبات القانونية، وسنحدّث تاريخ «آخر تحديث» أعلاه.

أسئلة حول الخصوصية؟

راسلنا لأي استفسار أو طلب متعلق ببياناتك.

hananelqh@gmail.com