Privacy Policy — Albassara | البصارة
Version 1.1 — draft. Last updated: 5 July 2026.
This is a secondary translation. The Arabic version (privacy-policy-ar.md) is authoritative.
A short opening
Hello.
This is our privacy policy. We wrote it the way we'd talk to you — direct, in plain language. Not because regulation forced us, but because you came to us with questions you couldn't ask elsewhere. That kind of trust deserves matching honesty about what we do with your data.
If you only have time for one section, read section 2 — that's the one that matters.
1. Who we are
Albassara | البصارة — a private ritual companion for coffee-cup reading, dream interpretation in the Ibn Sirin tradition, palmistry (palm reading), and astrology (horoscopes and natal chart).
Albassara is a product of Soliest studio - F.Z.E, a Free Zone Establishment registered in the United Arab Emirates. Soliest studio - F.Z.E operates the app and is the data controller responsible for your information.
Registered address: Ajman Free Zone C1 Building, Premises B.C. 1308444, Ajman Free Zone, Ajman, United Arab Emirates. Commercial Licence No. 55208.
Contact about your privacy: support@albassarah.app
Direct in-app control: Settings → My Data → "Delete my entire account".
2. What we collect, and what we don't
What we collect
- Anonymous session identifier — a random token generated on your device and stored in your system's secure store (Keychain on iOS / Keystore on Android). When it reaches us, we store only its hashed form (SHA-256). Not your name. Not your number. Not your email.
- Dialect + gender + country code — what you chose at onboarding, so we can address you correctly.
- Platform + app version — iOS or Android + version number.
- Cup photo (only when you choose to take one) — uploaded for processing only. Deleted from our server within one hour after the reading.
- Palm photo(s) (only when you choose to photograph your palm for a reading) — one or more guided photos (full palm / major lines / lower palm and wrist / mounts). Uploaded for processing by the reading engine (Gemini) only, exactly like the cup photo — deleted from our server within one hour after the reading, and not retained on our server after a successful reading.
- Dream text (only when you choose to type or speak it) — sent to Gemini for interpretation. Your original dream text is not retained on our server after interpretation.
- Birth details for astrology (only when you choose an astrology / natal-chart reading) — birth date (required), birth time (optional — the app handles "time unknown" honestly), and birth place (city name). We use these transiently only to compute your natal chart. The birth-place name is resolved to coordinates (latitude/longitude) on our own server, using a static, offline, bundled GeoNames dataset held in memory — the place name is never sent to any third party. Your raw birth details (date + time + place + coordinates) are never logged and never placed in analytics (Founder Principle FP1). What is stored is only derived data: the chart summary text, ten natal ecliptic longitudes for the principal bodies, and wheel geometry (ascendant, midheaven/MC, house cusps — house cusps are null when the birth time is unknown). This derived data is stored on your device (on-device), not as raw birth details on our server. For the daily horoscope, the app resends only the derived longitudes (never your raw birth details) to compute the day's transits.
- Subscription state — when you subscribe (Tier 2), Apple or Google tells us the state of your subscription. We never see your card — it stays with Apple / Google.
- Crash + error reports — via Sentry. We scrub Arabic content and sensitive field names before they leave your device. Retained 90 days.
- Content-free analytics events — how often you opened the app, how many readings you finished, how long a reading took — not the text of the reading, not what you said. Fully anonymized.
What we don't collect
- ❌ Your email
- ❌ Your phone number
- ❌ Your name or family name or address
- ❌ Your contacts
- ❌ Biometrics (fingerprint, face)
- ❌ Real-time location (country comes from your choice or the App Store, not from GPS). The astrology birth place is a city you type yourself, not your device location — we do not read GPS and we do not track your location.
- ❌ Advertising identifier (IDFA / Google Advertising ID)
- ❌ Browsing history outside the app
- ❌ Religious beliefs, health data, or sexual orientation
- ❌ Audio on our server — speech recognition runs only on your device in Tier 1
We operate on an anonymous-by-default principle: we don't ask you to identify yourself, we don't build a profile about you, and we don't tie your readings to any known person.
3. Lawful basis for processing
| Data |
Basis |
| Dream text + cup photo + palm photo + astrology birth details |
Your explicit consent at the start of each reading |
| Subscription state + usage limits |
Performance of contract |
| Content-free analytics + crash reports |
Legitimate interest (improving the app + detecting failures) — you can object |
| Cloud backup (if you enable it) |
Your explicit consent + we cannot decrypt your backup |
4. Where your data is processed (geographic transparency)
Our primary server is in Frankfurt, Germany — with the provider Fly.io.
You may notice: not in the Gulf or the Levant. The honest reason: our infrastructure provider does not currently operate servers in Bahrain, the UAE, or Saudi Arabia. We chose Frankfurt because it is the closest legally-safe point + the fastest for internet routing from the Levant and the Gulf via undersea cables + subject to the strict European data-protection framework.
At Tier 2 (paid public launch), we plan to add a regional server for Gulf and Levant users; the decision will be announced then.
Sub-processors (technical partners that help us run)
5. How long we keep your data
| Data |
Duration |
| Cup photo |
Less than 1 hour on the server + deleted on successful reading |
| Palm photo |
Less than 1 hour on the server + deleted on successful reading (exactly like the cup photo) |
| Astrology birth details (date + time + place + coordinates) |
Not retained on our server — used transiently to compute the chart only; only the derived chart is stored on your device |
| Dream text |
Not retained on our server after interpretation |
| Voice recording |
On your device only — never reaches our server in Tier 1 |
| Local reading history |
On your device with local encryption — until you delete it or uninstall |
| Cloud backup (optional) |
5 years or until you delete it — whichever is first |
| Anonymous session identifier |
Until you request deletion or 12 months of inactivity |
| Crash reports |
90 days |
| Analytics events |
90 days hot + potentially 1 year in cold archive |
| Sample-reading cache |
30 days |
| Cost-audit logs |
90 days |
6. Your rights (and how to exercise them)
Under the privacy regimes of Saudi Arabia (PDPL), the UAE (PDPL), Lebanon (Law 81), and Jordan (Personal Data Protection Law 24/2023), your rights are:
- Right to be informed — to know what data of yours is stored and how it's processed.
- Right of access — to request a copy of your data.
- Right to rectification — to correct erroneous data (limited usefulness with us — we hold little).
- Right to deletion — to request full deletion of your data.
- Right to object — to refuse specific processing.
- Right to restriction — to temporarily pause specific processing.
- Right to portability — to receive your data in a portable format.
How to exercise them
The easiest way: inside the app.
- Go to Settings → My Data → "Delete my entire account".
- Tap twice to confirm.
- We erase everything tied to you from our server within 24 hours — and from your R2 backups within 30 days at most.
The second way: email to support@albassarah.app — but we want to be honest: because the app is anonymous by default, we cannot identify you from your email. We will reply explaining this and pointing you to the in-app tool.
Response window: 30 days (may extend an additional 30 days in complex cases, per your country's law).
For formal complaints
| Country |
Authority |
| Saudi Arabia |
Saudi Data and AI Authority (SDAIA) — Personal Data Protection Office |
| UAE |
UAE Data Office (uaedataoffice.gov.ae) |
| Lebanon |
Ministry of Economy and Trade — Consumer Protection Directorate (in absence of a dedicated DPA) |
| Jordan |
Personal Data Protection Council (established under Law 24/2023) |
| EU (Tier 2) |
The DPA of your Member State |
| UK (Tier 2) |
ICO — ico.org.uk |
7. AI-generated readings — transparency
Albassara uses Google's Gemini model to generate readings. We tell you this plainly. We don't hide it behind the "wise Bassara voice" facade.
What this transparency means:
- The reading is interpretive — not religious authority, not a fatwa. We work within the Ibn Sirin tradition for dreams. This disclaimer is permanently visible on the dream surface. The same interpretive posture applies to coffee-cup reading, palmistry, and astrology: all are for reflection, not a promise about the future. Astrology and the natal chart in particular are for reflection and entertainment, not prediction.
- Cache-served readings — sometimes, if the AI engine call fails, we serve a close-match reading from cache. We mark this clearly inside the reading itself, not hidden.
- We do not use your readings to train AI models. Google handles data according to its own policy — at Tier 2 we'll move to Vertex AI, which guarantees no training on input.
The verified corpus — invite-only beta (Tier 1)
We want to be honest with you about something that's worth your time:
In the invite-only beta that you are using now, Albassara draws on a verified subset of Ibn Sirin tradition symbols — currently 12 starter entries ratified by the app's founder directly. It is not a complete corpus, and it has not yet been reviewed by a specialist scholar of dream interpretation.
What this means in practice:
- When your dream contains a symbol that is present in the verified subset, Albassara reads from it directly.
- When your dream contains a symbol that is outside the verified subset, Albassara follows the spirit of Ibn Sirin's interpretive method, but we cannot guarantee that the reading matches every known edition of his classical work. If there is any doubt about a specific attribution to Ibn Sirin, the system is built to say plainly "I don't have a verified reading for this symbol" rather than invent one for you.
- If we ever add an entry that is disputed among the classical copyists (DISPUTED tier), Albassara will surface the disagreement clearly inside the reading — never as if it were certain.
Why this transparency matters:
Because Albassara offers the Ibn Sirin tradition for reflection — not as religious counsel. That is a foundational commitment for us. Whenever the line between "interpretation within the tradition" and "religious ruling" risks getting blurry, our commitment is to keep it visible.
Our commitment for Tier 2 (paid public launch):
Before any paid public release, we will engage a specialist scholar of dream-interpretation tradition to review the existing corpus, author additional canonical entries, and put a recurring review cadence in place. This is a written commitment, not an open intention. When the corpus expands, we will update this section to reflect the new scope.
We know this disclosure surfaces a deliberate scope limitation. We chose to surface it because trust deserves directness — not because regulation required it.
7.1 The optional in-reading rating button — transparency
Below each reading in the app (whether a coffee-cup reading, a dream interpretation, a palm reading, or an astrology reading), you'll see two small buttons: thumbs-up / thumbs-down. If you tap either one, an optional text field appears (200-character cap) where you can type a one-sentence note if you wish. You can also scroll past the buttons entirely — they're never a gate to closing the reading.
What we store when you tap the rating button
- The rating itself — thumbs-up or thumbs-down (a single boolean).
- The optional note — if you typed one (200-character cap). If you didn't, we store no text.
- A
was_cache_served flag — a boolean indicating whether this reading came from our cache rather than a live AI generation (see §7 above). This flag lets us separate cache-quality feedback from live-engine-quality feedback during weekly review.
- Your hashed anonymous session identifier — the same one introduced in §2 above (SHA-256). Not your name. Not your email. Not your phone.
What we don't store or log
- ❌ Your optional-note text in analytics logs or in our error-tracking system (Sentry). The text is stored in the database only; it is never sent to logs.
- ❌ In our technical logs we record only the length bucket of the note (0–50 chars / 50–150 / 150–200 / null) — never the content of the note itself.
- ❌ We do not link the rating to your name, email, or phone number — because we don't have any of those (see §2).
- ❌ We do not share the rating or the note text with any third party or sub-processor in plaintext form (not Google, not Sentry, not analytics).
How we use this data
- Our LLM Engineer reviews ratings weekly (every Monday at 10:00 KSA) to detect recurring patterns — not individual readings, but patterns.
- High-signal patterns become proposed new cases in our internal evaluation suite (eval suite).
- The founder ratifies every proposed eval case via our internal cultural-review cadence (FA-FOUNDER-CR-2) — no proposal becomes an eval case without founder sign-off.
- We never display ratings in aggregate in the app ("8% of users liked this reading") — this is a foundational commitment for us (the no-broadcast principle). See §7 above + §7.2 below.
- We never sell this data to any third party.
An honest disclosure — where the optional note intersects data-protection law
The optional note you may type could contain information that qualifies as special-category data under European data-protection law (e.g., GDPR Art. 9 — religious, cultural, or personal data) — for example, if you describe the content of your dream or what you saw in the cup. The risk profile here is identical to the "Report this reading" button (see §7). The protective controls are identical:
- Access to the optional-note text is restricted to 3 named individuals: the LLM Engineer + the weekly-review lead + the founder. No one else inside or outside the team reads the notes.
- No automated export to any sub-processor. All review happens inside the Frankfurt database via a secure connection — no download, no copy, no transfer outside the EU.
- The Compliance Engineer signs off on any future expansion of how this field is used — analytics expansion, access expansion, sub-processor expansion — before such a change ships.
- Logging discipline: technical logs contain only the length bucket (0–50 / 50–150 / 150–200 / null) — not the source text. Sentry's beforeSend hook is configured to scrub this field before it leaves your device.
Lawful basis for processing
- Legitimate interest (GDPR Art. 6(1)(f)) for service-quality improvement — balanced against: minimal data collection + user-controlled retention + clear disclosure (this section) + no profile-building.
- We do not rely on explicit consent as the sole basis because the rating is entirely optional — if you don't tap a button, no data is collected. Tapping the button constitutes operational consent to the processing described here.
Retention and deletion
- Rating rows (with the optional note if you typed one) remain in the database until you choose to delete your data via Settings → My Data → "Delete my entire account".
- On deletion: we erase rating rows in the same database transaction as your reading-report rows — both go away together, with no exceptions.
- Your rights under GDPR Art. 15 (access) + GDPR Art. 17 (erasure) + the equivalent California rights under CCPA are exercised via the same in-app button.
What's the difference between the rating button and the "Report this reading" button?
- The rating button (this section): thumbs-up / thumbs-down + an optional note. A general quality signal. Continuous.
- The "Report this reading" button (see §7 + ToS §8): a specific report about a bad reading using fixed categories (wrong interpretation / religious-claim discomfort / bad citation / off-Ibn-Sirin voice / other) + an optional note. A targeted mechanism for catching fabricated Ibn Sirin attributions specifically.
The two signals are independent — you may use both on the same reading, or one, or neither. The choice is always yours.
8. Emotional safety — a clarification
Albassara is a private ritual companion, not a crisis line and not a substitute for therapy.
This app is not a crisis line.
If you need urgent emotional support, please contact your local mental-health support services.
(The Bassara voice softens automatically when distress signals are detected — but it does not replace a professional.)
9. Age of use
The app is for adults 18 and older. We ask you to confirm this at onboarding. If you are younger, please do not use the app and erase your data from Settings.
We cannot verify age technically — the confirmation is honor-system.
10. Security
- In transit: TLS-encrypted (HTTPS).
- At rest: server encryption (Postgres + R2).
- Keys: in system stores (macOS Keychain / Fly Secrets) — never in plaintext files, never in git.
- Content scrubbing: before anything reaches our error-tracking or logging systems, we scrub Arabic content and sensitive fields across five layers (Sentry + structlog + backend analytics + app analytics + database).
- Cloud backup: encrypted with a key derived from your recovery phrase (12-word BIP39) — we cannot decrypt it. If the phrase is lost, the backup is lost.
11. Changes to this policy
- If we change anything material, we'll show a notice inside the app on next launch.
- Cosmetic changes (rephrasing, typos) don't trigger a notice.
- Document version + last-updated date always at the top.
12. Contact
- Privacy: support@albassarah.app
- In-app: Settings → My Data
This document is the Tier-1 draft. It will be reviewed by counsel before Tier-2 public launch.
— Albassara | البصارة