سياسة الخصوصية
1. مقدمة
تهتم Lonik (المشار إليه فيما بعد بـ "التطبيق" أو "نحن") بخصوصيتكِ وحماية بياناتكِ الشخصية. توضّح هذه السياسة الطريقة التي نجمع بها بياناتكِ، والأغراض التي نستخدمها من أجلها، والأطراف التي قد نشاركها معها، وحقوقكِ بموجب نظام حماية البيانات الشخصية الصادر في المملكة العربية السعودية.
باستخدامكِ للتطبيق، فإنكِ توافقين على ممارسات جمع البيانات ومعالجتها الموضّحة في هذه السياسة. إذا كنتِ لا توافقين على أيّ بند منها، نرجو منكِ عدم استخدام التطبيق.
2. هوية المسؤول عن البيانات
المسؤول عن معالجة بياناتكِ هو مؤسسة فردية مسجّلة في المملكة العربية السعودية:
الاسم: سمارت لونك (Smart Lonik) — مؤسسة فردية
رقم السجل التجاري: 7054462135
المدينة: الجبيل، المنطقة الشرقية، المملكة العربية السعودية
البريد الإلكتروني للاستفسارات المتعلقة بالخصوصية: support@lonik.app
3. تعريفات
- البيانات الشخصية: كل بيان يخصّكِ ويمكن أن يُعرَف به عنكِ، مثل اسمكِ وصوركِ ومعلومات حسابكِ.
- البيانات الحساسة: البيانات البيومترية (مثل صور الوجه)، والبيانات الجسدية الاختيارية التي قد تُعدّ حساسة بحسب طبيعتها (مثل الطول والوزن والعمر)، وأي بيانات يصنّفها النظام السعودي على أنها حساسة.
- المعالجة: أي عملية تُجرى على البيانات الشخصية كالجمع والتخزين والتحليل والمشاركة.
- النظام: نظام حماية البيانات الشخصية في المملكة العربية السعودية.
4. البيانات التي نجمعها
4.1 بيانات الحساب
- معرّف مستخدم مجهول يُنشأ تلقائياً عند أول تشغيل للتطبيق.
- عنوان البريد الإلكتروني المرتبط بحساب Google أو Apple عند تسجيل الدخول. عند اختيارك «إخفاء البريد الإلكتروني» في تسجيل الدخول عبر Apple، نستلم عنوان تحويل خاص (بصيغة @privaterelay.appleid.com) بدلاً من بريدكِ الفعلي.
- الاسم المرتبط بحساب Google أو Apple (تتيح Apple مشاركة اسمكِ مرة واحدة فقط عند أول تسجيل دخول).
- الاسم المعروض الذي تختارينه يدوياً.
4.2 بيانات بيومترية (حساسة)
- صور سيلفي تلتقطينها لأغراض تحليل الألوان الشخصية، أو لميزات الردّ/التفاعل الشخصي التي تطلبينها داخل التطبيق. بعض ميزات تحليل السيلفي تتم على الجهاز فقط، بينما قد تتطلب ميزات أخرى إرسال الصورة إلى مزوّدي الذكاء الاصطناعي المذكورين في القسم 7.2 لمعالجة طلبكِ.
- صور تلتقطينها أثناء استخدام ميزة "المرآة اللونية" (Color Mirror).
- الخصائص اللونية المُستخرجة من تحليل صورتكِ: درجة لون البشرة، النغمة الأساسية (دافئة، باردة، محايدة)، لون الشعر، والفصل اللوني.
4.3 بيانات جسدية (اختيارية، قد تُعدّ حساسة)
- العمر.
- الطول.
- الوزن.
تُستخدم هذه البيانات حصراً لتخصيص توصيات الأسلوب، ولن تُطلب منكِ كشرط لاستخدام التطبيق.
4.4 المحتوى الذي تنشئينه
- صور قطع ملابسكِ في "خزانة الملابس" والمعلومات المستخرجة منها (النوع، اللون، الخامة، التصنيف، البراند).
- صور لوحة الإلهام التي ترفعينها وتحليلها.
- إجابات اختبار اكتشاف الأسلوب.
- ملف الأسلوب الناتج.
4.5 محادثات الدردشة
- النصوص الكاملة التي ترسلينها وتستلمينها من المستشار الذكي.
- الصور التي ترفعينها داخل المحادثة.
- النص المستخرج من رسائلكِ الصوتية. قد تتم معالجة التسجيل الصوتي محلياً على جهازكِ أو عبر خدمات التعرف على الكلام في نظام التشغيل بحسب جهازكِ وإعداداته (انظري القسم 7.4). لا نخزّن التسجيل الصوتي في خوادمنا، ونستخدم النص الناتج فقط.
4.6 بيانات تشغيلية
- تاريخ ووقت إنشاء كل بند في حسابكِ.
- إصدار التطبيق المستخدم.
- رمز إشعارات الجهاز (مثل FCM token على Android) عند تفعيل الإشعارات، لاستخدامه في إرسال تنبيهات التطبيق.
- حالة اشتراككِ المدفوع إن وُجد (نستلمها من المتجر للتحقق من صلاحية الميزات؛ لا نطّلع على بيانات بطاقتكِ البنكية ولا نخزّنها).
- تقارير الأعطال والأخطاء التقنية (تُجمع عبر Sentry — انظري القسم 7.7).
5. الأغراض من جمع البيانات
نعالج بياناتكِ للأغراض التالية حصراً:
- تقديم الخدمة الأساسية: توليد تحليل لوني شخصي، توصيات أسلوب، وتفاعل مع المستشار الذكي.
- تخصيص التجربة: ربط ما تنشئينه (خزانة، إلهام، إجابات اختبار) بحسابكِ لاستخدامه عبر الجلسات.
- تحسين الخدمة: فهم كيفية استخدام الميزات لتطويرها (دون الإفصاح عن هويتكِ).
- التواصل معكِ: الردّ على استفساراتكِ، وإبلاغكِ بالتحديثات الجوهرية للسياسة.
- الامتثال القانوني: الاستجابة للطلبات الرسمية من الجهات المختصة.
6. الأساس القانوني للمعالجة
نعتمد على الأسس التالية وفقاً للنظام السعودي لحماية البيانات الشخصية:
- الموافقة الصريحة: التي تقدّمينها عند إنشاء الحساب وقبول هذه السياسة.
- الضرورة التعاقدية: لأن جمع بعض البيانات شرط لتقديم الخدمة المطلوبة.
- المصلحة المشروعة: في تحسين جودة الخدمة وأمنها.
بالنسبة للبيانات الحساسة (البيومترية والجسدية)، نعتمد بشكل أساسي على الموافقة الصريحة التي تقدّمينها قبل تفعيل هذه الميزات.
7. الجهات الخارجية التي قد تصلها بياناتكِ
نستعين بمزوّدي خدمات تقنية لتشغيل التطبيق. تشمل قائمة مزوّدي الخدمة الحاليين ما يلي، ونحدّث هذه السياسة عند إضافة مزوّدين جوهريين يؤثرون على معالجة بياناتكِ:
7.1 خدمة قاعدة البيانات والتخزين السحابي
المزوّد: Supabase Inc.
الموقع: الولايات المتحدة الأمريكية
خوادم التخزين الفعلية تقع في: ap-south-1 (Mumbai, India)
ما يصلهم: جميع بياناتكِ المخزّنة (الحساب، الخزانة، الإلهام، المحادثات، ملف الأسلوب).
رابط سياستهم: https://supabase.com/privacy
7.2 خدمة الذكاء الاصطناعي للمحادثة والتحليل
نستعين بمزوّدَين للذكاء الاصطناعي: مزوّد أساسي يعالج طلباتكِ، ومزوّد احتياطي يُستخدم تلقائياً عند تعذّر الأساسي.
المزوّد الأساسي: OpenAI, L.L.C.
الموقع: الولايات المتحدة الأمريكية
ملاحظة: تُعالَج بياناتكِ عبر واجهة OpenAI البرمجية (API)، ولا تُستخدم لتدريب نماذجهم.
رابط سياستهم: https://openai.com/policies/privacy-policy
المزوّد الاحتياطي: Google LLC — Gemini API
الموقع: البنية التحتية العالمية لشركة Google
رابط سياستهم: https://policies.google.com/privacy
ما يصل المزوّدَين عند كل تفاعل:
- نص رسالتكِ مع آخر 30 رسالة من سياق المحادثة.
- اسمكِ المعروض، وعمركِ وطولكِ ووزنكِ (إن كانت متوفرة).
- الفصل اللوني وباقة الألوان الخاصة بكِ.
- صور قطع الملابس، وصور الإلهام، وصور السيلفي أو الصور الأخرى التي ترفعينها أو تلتقطينها داخل ميزات تتطلب تحليلاً بصرياً، وذلك عند طلب تحليلها أو التفاعل معها.
7.3 تسجيل الدخول
المزوّدان: Google Sign-In (OAuth) و Apple (Sign in with Apple).
الموقع: الولايات المتحدة الأمريكية.
ما يصلهم: طلب المصادقة فقط، ويرجعون لنا بريدكِ واسمكِ ومعرّفكِ الفريد لدى المزوّد. عند استخدام Sign in with Apple يمكنكِ إخفاء بريدكِ الفعلي، فنستلم عندها عنوان تحويل خاص فقط.
رابط سياسة Apple: https://www.apple.com/legal/privacy/
7.4 تحويل الصوت إلى نص
المزوّد: Google Speech Recognition (على أجهزة Android) أو Apple Speech Recognition (على أجهزة iOS).
ما يصلهم: قد تُرسل تسجيلاتكِ الصوتية إلى خوادم Google أو Apple خلال عملية التحويل، حسب جهازكِ وإصدار نظامه. يُفعَّل هذا فقط عند استخدامكِ زر الميكروفون.
7.5 المعالجة المحلية على الجهاز (لا تخرج البيانات)
نستخدم مكتبة Google ML Kit للكشف عن الوجه أثناء تحليل الألوان الأولي. تتم هذه المعالجة بالكامل داخل جهازكِ ولا تُرسل الصور إلى أي خادم خارجي خلال هذه الميزة تحديداً.
7.6 توزيع التطبيق
المزوّدان: Google Play Services (على Android) و Apple App Store — Apple Inc. (على iOS).
ما يصلهم: معلومات تشغيلية حسب سياسة كل متجر (معرّف الجهاز، عنوان IP، بيانات التثبيت والشراء، إلخ).
7.7 تتبّع الأعطال والأخطاء التقنية
المزوّد: Sentry (Functional Software, Inc.)
الموقع: خوادم الاتحاد الأوروبي (ألمانيا)
ما يصلهم: تقارير الأعطال والأخطاء التقنية — نوع الجهاز ونظام التشغيل، إصدار التطبيق، أثر الخطأ التقني (stack trace) — ومؤشرات استخدام تقنية محدودة تساعدنا على فهم مسار الخطأ وتحسين استقرار التطبيق، مثل أسماء أحداث داخلية عامة بعد تنقيتها من البيانات الشخصية. أوقفنا إرسال بياناتكِ الشخصية افتراضياً: لا عنوان IP، ولا بريد إلكتروني، ولا صور، ولا محتوى محادثات.
رابط سياستهم: https://sentry.io/privacy/
7.8 خدمة الإشعارات
المزوّد: Google Firebase Cloud Messaging (FCM) — على أجهزة Android.
ما يصلهم: رمز إشعارات الجهاز (token) لإرسال تنبيهات التطبيق إليكِ. يمكنكِ إيقاف الإشعارات في أي وقت من إعدادات التطبيق أو جهازكِ.
8. نقل البيانات خارج المملكة العربية السعودية
نلفت انتباهكِ إلى أن بياناتكِ ستُنقل وتُعالج خارج المملكة العربية السعودية، تحديداً:
- الهند: عبر خوادم Supabase.
- الولايات المتحدة: عبر OpenAI، وخدمات Google، وApple.
- الاتحاد الأوروبي (ألمانيا): عبر Sentry.
نقوم بهذا النقل استناداً إلى:
- موافقتكِ الصريحة التي تمنحينها عند قبول هذه السياسة.
- ضرورة النقل لتنفيذ الخدمة التي طلبتِها.
- ضمانات تعاقدية مع مزوّدي الخدمة تُلزمهم بمستوى حماية مناسب.
في حال عدم رغبتكِ في نقل بياناتكِ خارج المملكة، يرجى عدم استخدام التطبيق.
9. مدة الاحتفاظ بالبيانات
نحتفظ ببياناتكِ الشخصية ما دام حسابكِ نشطاً، وذلك لأن استمرارية الحساب تتطلب الاحتفاظ بسجل ملفكِ اللوني وخزانة ملابسكِ وتاريخ محادثاتكِ.
عند طلبكِ حذف الحساب، نحذف جميع بياناتكِ خلال 30 يوماً كحد أقصى، باستثناء البيانات التي يُلزمنا النظام بالاحتفاظ بها لفترة محددة (إن وُجدت).
النسخ الاحتياطية: قد تبقى بياناتكِ في النسخ الاحتياطية لفترة لا تتجاوز 90 يوماً بعد الحذف، ثم تُمحى تلقائياً.
10. حقوقكِ بموجب نظام حماية البيانات الشخصية
يكفل لكِ النظام السعودي الحقوق التالية، ويمكنكِ ممارستها بمراسلتنا على البريد المذكور في القسم 2:
- حق العلم: أن تعرفي ما إذا كنا نعالج بياناتكِ والأساس الذي نستند إليه.
- حق الوصول: الحصول على نسخة من بياناتكِ المخزّنة لدينا.
- حق التصحيح: طلب تصحيح أي بيانات غير دقيقة أو غير مكتملة.
- حق الإتلاف (الحذف): طلب حذف بياناتكِ كلياً.
- حق نقل البيانات: الحصول على نسخة بصيغة قابلة للقراءة الآلية لنقلها إلى مزوّد آخر.
- حق سحب الموافقة: سحب موافقتكِ على المعالجة في أي وقت، مع ملاحظة أن السحب لا يؤثر على معالجة سبقت السحب.
- حق تقديم الشكوى: تقديم شكوى للهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا) إذا رأيتِ أن معالجتنا لبياناتكِ مخالفة للنظام: https://sdaia.gov.sa
سنردّ على طلباتكِ خلال 30 يوماً من استلامها.
11. خصوصية القاصرات
التطبيق مخصّص للمستخدمات اللاتي يبلغن 18 عاماً فما فوق.
لا نسمح باستخدام التطبيق لمن هنّ دون 18 عاماً. في حال علمنا بمعالجة بيانات مستخدمة دون 18 عاماً، نحذفها فوراً.
12. أمن البيانات
نتّخذ تدابير تقنية وتنظيمية معقولة لحماية بياناتكِ، تشمل:
- التشفير أثناء النقل عبر بروتوكول HTTPS.
- التشفير أثناء التخزين على خوادم Supabase.
- ضبط صلاحيات الوصول داخل قاعدة البيانات عبر سياسات الأمان على مستوى الصفّ (Row-Level Security).
- المصادقة عبر مزوّدي هوية موثوقين.
مع ذلك، لا يمكن ضمان أمن تامّ لأي نظام إلكتروني، ولا نتحمّل المسؤولية عن الاختراقات الناتجة عن أسباب خارجة عن إرادتنا.
13. صلاحيات الجهاز التي يطلبها التطبيق
| الصلاحية | الغرض |
|---|---|
| الكاميرا | التقاط صور الخزانة والسيلفي والمرآة اللونية |
| الميكروفون | إدخال الرسائل الصوتية في المحادثة |
| الإنترنت | الاتصال بخوادم التطبيق |
| التخزين / الصور | حفظ صور المرآة في معرض الجهاز |
يمكنكِ سحب أي من هذه الصلاحيات في أي وقت من إعدادات جهازكِ، مع ملاحظة أن بعض الميزات لن تعمل بدون صلاحياتها.
14. ملفات تعريف الارتباط وتقنيات التتبّع
لا يستخدم التطبيق ملفات تعريف ارتباط بالمعنى المتعارف عليه في المتصفحات، لكنه يستخدم تخزيناً محلياً على الجهاز لحفظ تفضيلاتكِ. لا يستخدم التطبيق حالياً أدوات تتبّع إعلاني تجاري بداخله. وقد تستخدم صفحات موقعنا الإلكتروني أدوات لقياس أداء الحملات الإعلانية، بعد إشعاركِ بذلك وفق السياسة المعمول بها. نستخدم خدمة Sentry لتتبّع الأعطال والأخطاء التقنية ومؤشرات استخدام تقنية محدودة بعد تنقيتها من البيانات الشخصية، بهدف تحسين استقرار التطبيق وتجربة الاستخدام (انظري القسم 7.7).
15. تغييرات على هذه السياسة
قد نحدّث هذه السياسة من وقت لآخر. عند إجراء تغيير جوهري، سنُشعركِ داخل التطبيق قبل سريان التغيير. استمراركِ في استخدام التطبيق بعد التحديث يُعدّ موافقة على النسخة المحدّثة.
16. التواصل معنا
لأي استفسار أو طلب يتعلق بهذه السياسة أو ببياناتكِ، يمكنكِ التواصل معنا عبر:
البريد الإلكتروني: support@lonik.app
سنردّ خلال مدة لا تتجاوز 30 يوماً.
17. القانون الواجب التطبيق
تخضع هذه السياسة وتُفسَّر وفقاً لأنظمة المملكة العربية السعودية، وعلى وجه الخصوص نظام حماية البيانات الشخصية الصادر بالمرسوم الملكي رقم (م/19) لعام 1443هـ ولوائحه التنفيذية.
أي نزاع ينشأ عن هذه السياسة أو يتعلق بها يخضع للاختصاص الحصري للجهات القضائية المختصة في المملكة العربية السعودية.
Privacy Policy
1. Introduction
Lonik ("the App," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect your information when you use our mobile application, and describes your rights under the Saudi Arabian Personal Data Protection Law ("PDPL").
By using the App, you consent to the data collection and processing practices described in this Policy. If you do not agree with any term of this Policy, please do not use the App.
2. Data Controller Identity
The data controller responsible for processing your data is a sole proprietorship registered in the Kingdom of Saudi Arabia:
Name: Smart Lonik (سمارت لونك) — Sole Proprietorship
Commercial Registration No.: 7054462135
City: Jubail, Eastern Province, Kingdom of Saudi Arabia
Privacy Contact Email: support@lonik.app
3. Definitions
- Personal Data: Any data relating to you that can be used to identify you, such as your name, photos, and account details.
- Sensitive Data: Biometric data (such as face photos), optional body data that may be considered sensitive by nature (such as height, weight, age), and any data classified as sensitive under Saudi law.
- Processing: Any operation performed on personal data, including collection, storage, analysis, and sharing.
- PDPL: The Personal Data Protection Law of the Kingdom of Saudi Arabia.
4. Data We Collect
4.1 Account Data
- An anonymous user ID auto-generated upon first launch.
- The email address linked to your Google or Apple account when you sign in. If you choose "Hide My Email" with Sign in with Apple, we receive a private relay address (in the form @privaterelay.appleid.com) instead of your actual email.
- The name associated with your Google or Apple account (Apple shares your name only once, at first sign-in).
- The display name you choose manually.
4.2 Biometric Data (Sensitive)
- Selfie photos you take for personal color analysis, or for personal reaction/response features you request within the App. Some selfie-analysis features are processed only on your device, while other features may require sending the image to the AI providers listed in Section 7.2 to process your request.
- Photos you take while using the "Color Mirror" feature.
- Color attributes extracted from your photo analysis: skin tone, undertone (warm, cool, neutral), hair color, and seasonal color category.
4.3 Body Data (Optional, May Be Sensitive)
- Age.
- Height.
- Weight.
This data is used exclusively to personalize style recommendations and is never required to use the App.
4.4 User-Generated Content
- Photos of your wardrobe items and the AI-extracted metadata (type, color, fabric, category, brand).
- Photos uploaded to your inspiration board and their analysis.
- Your answers to the Style Discovery quiz.
- The resulting style profile.
4.5 Chat Conversations
- Full text of messages you send and receive from the AI assistant.
- Images you upload within the chat.
- Text extracted from your voice messages. The voice recording may be processed locally on your device or via your operating system's speech-recognition services, depending on your device and its settings (see Section 7.4). We do not store the voice recording on our servers; only the resulting text is used.
4.6 Operational Data
- Date and time of creation of each record in your account.
- App version in use.
- Device notification token (such as an FCM token on Android) when notifications are enabled, used to send App notifications.
- Your paid subscription status, if any (received from the app store to verify feature access; we do not access or store your payment card details).
- Crash and technical error reports (collected via Sentry — see Section 7.7).
5. Purposes of Data Collection
We process your data exclusively for the following purposes:
- Service Delivery: Generating your personal color analysis, style recommendations, and AI assistant interactions.
- Personalization: Linking your content (wardrobe, inspiration, quiz answers) to your account for use across sessions.
- Service Improvement: Understanding feature usage to improve the App (without disclosing your identity).
- Communication: Responding to your inquiries and notifying you of material policy updates.
- Legal Compliance: Responding to lawful requests from competent authorities.
6. Legal Basis for Processing
We rely on the following bases under the Saudi PDPL:
- Explicit Consent: Provided by you when creating your account and accepting this Policy.
- Contractual Necessity: Because collecting certain data is required to provide the requested service.
- Legitimate Interest: In improving service quality and security.
For sensitive data (biometric and body data), we rely primarily on your explicit consent, which you provide before enabling these features.
7. Third Parties That May Receive Your Data
We use technical service providers to operate the App. Our current service providers include the following, and we will update this Policy when we add material providers that affect how your data is processed:
7.1 Database and Cloud Storage
Provider: Supabase Inc.
Location: United States of America
Actual storage servers located in: ap-south-1 (Mumbai, India)
What they receive: All your stored data (account, wardrobe, inspiration, chats, style profile).
Their privacy policy: https://supabase.com/privacy
7.2 AI Conversation and Analysis Service
We use two AI providers: a primary provider that processes your requests, and a fallback provider used automatically if the primary is unavailable.
Primary Provider: OpenAI, L.L.C.
Location: United States of America
Note: Your data is processed via the OpenAI API and is not used to train their models.
Their privacy policy: https://openai.com/policies/privacy-policy
Fallback Provider: Google LLC — Gemini API
Location: Google's global infrastructure
Their privacy policy: https://policies.google.com/privacy
What both providers receive on each interaction:
- Your message text plus the last 30 messages of conversation context.
- Your display name, age, height, and weight (if provided).
- Your seasonal color category and palette.
- Clothing item images, inspiration images, selfie images, or other images you upload or capture within features that require visual analysis, when you request analysis or interaction with them.
7.3 Sign-In
Providers: Google Sign-In (OAuth) and Apple (Sign in with Apple).
Location: United States of America.
What they receive: Authentication requests only; they return your email, name, and a unique provider identifier to us. With Sign in with Apple you may hide your actual email, in which case we receive only a private relay address.
Apple privacy policy: https://www.apple.com/legal/privacy/
7.4 Voice-to-Text Conversion
Provider: Google Speech Recognition (on Android devices) or Apple Speech Recognition (on iOS devices).
What they receive: Your voice recordings may be transmitted to Google or Apple servers during conversion, depending on your device and OS version. This is activated only when you use the microphone button.
7.5 On-Device Processing (No Data Leaves the Device)
We use the Google ML Kit library for face detection during initial color analysis. This processing occurs entirely within your device, and no images are sent to any external server during this specific feature.
7.6 App Distribution
Providers: Google Play Services (on Android) and Apple App Store — Apple Inc. (on iOS).
What they receive: Operational information per each store's own policy (device ID, IP address, install and purchase data, etc.).
7.7 Crash and Error Reporting
Provider: Sentry (Functional Software, Inc.)
Location: European Union servers (Germany)
What they receive: Crash and technical error reports — device type and operating system, app version, technical error trace (stack trace) — plus limited technical usage indicators that help us understand the error path and improve app stability, such as sanitized internal event names stripped of personal data. We disable transmission of your personal data by default: no IP address, no email, no images, and no chat content.
Their privacy policy: https://sentry.io/privacy/
7.8 Notifications Service
Provider: Google Firebase Cloud Messaging (FCM) — on Android devices.
What they receive: Your device notification token, used to send you App notifications. You can disable notifications at any time from the App or device settings.
8. Cross-Border Data Transfer
Please be advised that your data will be transferred to and processed outside the Kingdom of Saudi Arabia, specifically:
- India: Via Supabase servers.
- United States: Via OpenAI, Google, and Apple services.
- European Union (Germany): Via Sentry.
We make these transfers based on:
- Your explicit consent, provided when you accept this Policy.
- The necessity of the transfer to perform the service you requested.
- Contractual safeguards with service providers that require an adequate level of protection.
If you do not wish your data to be transferred outside Saudi Arabia, please do not use the App.
9. Data Retention Period
We retain your personal data for as long as your account remains active, because account continuity requires preserving your color profile, wardrobe records, and chat history.
Upon your request to delete the account, we delete all your data within a maximum of 30 days, except for data we are legally required to retain for a specified period (if any).
Backups: Your data may remain in backups for a period not exceeding 90 days after deletion, after which it is automatically purged.
10. Your Rights Under the PDPL
The Saudi PDPL grants you the following rights, which you may exercise by contacting us at the email in Section 2:
- Right to Be Informed: To know whether we process your data and the basis for it.
- Right of Access: To obtain a copy of your data stored with us.
- Right to Correction: To request correction of inaccurate or incomplete data.
- Right to Erasure (Deletion): To request full deletion of your data.
- Right to Data Portability: To obtain a copy in a machine-readable format for transfer to another provider.
- Right to Withdraw Consent: To withdraw your consent to processing at any time. Withdrawal does not affect processing that occurred before withdrawal.
- Right to File a Complaint: To file a complaint with the Saudi Data and Artificial Intelligence Authority ("SDAIA") if you believe our processing violates the PDPL: https://sdaia.gov.sa
We will respond to your requests within 30 days of receipt.
11. Children's Privacy
The App is intended for users who are 18 years of age or older.
We do not permit use of the App by anyone under the age of 18. If we become aware that we are processing data from a user under 18, we will delete it immediately.
12. Data Security
We implement reasonable technical and organizational measures to protect your data, including:
- Encryption in transit via HTTPS.
- Encryption at rest on Supabase servers.
- Access controls within the database via Row-Level Security policies.
- Authentication via trusted identity providers.
However, no electronic system can be guaranteed to be fully secure. We are not liable for breaches resulting from causes outside our reasonable control.
13. Device Permissions Requested
| Permission | Purpose |
|---|---|
| Camera | Capture wardrobe, selfie, and Color Mirror photos |
| Microphone | Input voice messages in chat |
| Internet | Connect to App servers |
| Storage / Photos | Save Color Mirror photos to your device gallery |
You may revoke any of these permissions at any time from your device settings, noting that some features will not function without their permissions.
14. Cookies and Tracking Technologies
The App does not use cookies in the browser sense, but it does use local on-device storage to save your preferences. The App does not currently use in-app advertising or commercial tracking tools. Our website pages may use campaign-performance measurement tools, after notifying you in accordance with the applicable policy. We use Sentry for crash and technical error diagnostics and limited technical usage indicators, sanitized from personal data, to improve app stability and user experience (see Section 7.7).
15. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will notify you within the App before the change takes effect. Your continued use of the App after the update constitutes acceptance of the updated version.
16. Contact Us
For any inquiry or request related to this Policy or your data, you may contact us at:
Email: support@lonik.app
We will respond within a period not exceeding 30 days.
17. Governing Law
This Policy is governed by and construed in accordance with the laws of the Kingdom of Saudi Arabia, specifically the Personal Data Protection Law issued under Royal Decree No. (M/19) of 1443H and its executive regulations.
Any dispute arising out of or relating to this Policy is subject to the exclusive jurisdiction of the competent courts of the Kingdom of Saudi Arabia.