Document status: Complete version — ready for publication.
Version: 2.0.0
Last updated: April 17, 2026
Official reference language: French. In the event of any discrepancy between language versions, the French text shall prevail.
Apps covered:
- Basmala — iOS & Android
- Basmala Kids — iOS & Android
Canonical URL: https://www.basmala.app/privacy-policy
1. Who is the data controller?
The data controller within the meaning of Article 4(7) GDPR is:
- Legal name of publisher: MADOUI Mohamed
- Legal form: Sole proprietorship (French "entrepreneur individuel" / "auto-entrepreneur")
- Trade name: Basmala Studio
- French business registry (SIRET): 527 672 547 00033
- Postal address: 95 B Rue de la Pyramide, 59220 Denain, France
- Country of establishment: France
- Privacy contact email: support@basmala.app
- Website: https://www.basmala.app
The data controller publishes the Basmala and Basmala Kids applications on the Apple App Store and Google Play Store.
Competent supervisory authority (France):
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy — TSA 80715
75334 Paris Cedex 07 — France
Phone: +33 (0)1 53 73 22 22
Website: https://www.cnil.fr/en
Any user residing in the European Union or EEA has the right to lodge a complaint with the CNIL (or their own national data protection authority) if they believe the processing of their data does not comply with the GDPR.
2. Scope of this policy
This single policy applies to both applications published by the same data controller:
"Basmala" application
- Intended audience: general public, all ages
- Primary applicable regulations: GDPR (EU), French Data Protection Act
"Basmala Kids" application
- Intended audience: children under 13 and their parents / legal guardians
- Primary applicable regulations: GDPR-K (Article 8 GDPR), COPPA (United States), Google Play Families Policy, Apple Kids Category Guidelines
Sections marked 🧸 Basmala Kids-specific section apply exclusively to the Basmala Kids application.
3. Core principles
We apply the following principles by default to all of our applications:
- Data minimization: we collect only what is strictly necessary for the service to function.
- No advertising, no third-party tracking: our applications contain no advertising SDK, no third-party analytics tool (no Google Analytics, no Firebase Analytics, no Meta SDK, no AppsFlyer, no Branch, no behavioral Sentry, etc.).
- No sale of data: we never sell, rent or trade your data with third parties for commercial purposes.
- Encryption in transit: all communications with our servers are protected by HTTPS/TLS.
- Local-first storage: your personal playlists, favorites, language preferences and listening history are stored locally on your device. They are not transmitted to our servers.
4. What data do we collect, and why?
4.1 — Exhaustive list of data
Device UUID
- Description: random v4 identifier, generated locally, cannot be traced back to an individual.
- Collected by: the app on first launch.
- Sent to our servers: yes — essential for authentication.
- Purpose: anonymous device authentication to access audio content.
- GDPR legal basis: performance of a contract (Art. 6.1.b GDPR).
Technical platform
- Description: free-form string identifying the operating system (e.g., "iOS 17.1", "Android 14").
- Collected by: the app.
- Sent to our servers: yes, at authentication time.
- Purpose: debugging, aggregated compatibility statistics.
- GDPR legal basis: legitimate interest (Art. 6.1.f GDPR).
IP address
- Description: source IP address of HTTP requests.
- Collected by: our servers, at HTTP request time.
- Sent to our servers: kept only in technical logs for a maximum of 30 days; never in the application database.
- Purpose: security (abuse detection, rate limiting).
- GDPR legal basis: legitimate interest (Art. 6.1.f GDPR).
"Track played" event
- Description: signal sent when a track starts playing.
- Collected by: the app.
- Sent to our servers: yes, but aggregated immediately into a global anonymous popularity counter. No per-user history is maintained, neither on the device nor on the server.
- Purpose: global popularity statistics ("this track has been played X times in total, across all users combined").
- GDPR legal basis: legitimate interest (Art. 6.1.f GDPR).
Preferred language (fr / en / ar)
- Collected by: the app, set in preferences by the user.
- Sent to our servers: no — stays on your device.
- Purpose: display the UI in the right language.
- GDPR legal basis: performance of a contract.
Personal playlists, favorites, chosen avatar, playback position, settings
- Collected by: the app.
- Sent to our servers: no — stays on your device.
- Purpose: local personalization.
- GDPR legal basis: performance of a contract.
RevenueCat internal anonymous ID
- Collected by: the RevenueCat SDK.
- Sent to our servers: no. Sent to RevenueCat only — never to our servers.
- Purpose: manage and restore a Premium subscription on the same device.
- GDPR legal basis: performance of a contract.
Subscription transaction data
- Description: product ID, date, status.
- Collected by: Apple / Google Play / RevenueCat.
- Sent to our servers: no. Sent to the payment platforms.
- Purpose: payment processing and purchase restoration.
- GDPR legal basis: performance of a contract + legal obligation (accounting).
4.2 — Data we do NOT collect
We explicitly confirm that our applications do not collect any of the following:
- X Name, first name, pseudonym
- X Email address, phone number, postal address
- X Date of birth, gender, age
- X Advertising identifiers (IDFA on iOS, GAID on Android)
- X Geolocation (precise or approximate)
- X Contacts, calendar, photos, files
- X Microphone, camera, biometric sensors
- X Social network identifiers
- X Device fingerprinting
- X Web browsing history
No data is sold, rented or exchanged with anyone.
4.3 — No behavioral analytics
Our applications contain no third-party analytics SDK (no Google Analytics, no Firebase Analytics, no Meta/Facebook SDK, no AppsFlyer, no Branch, no Mixpanel, no Amplitude, no behavioral Sentry).
The internal analytics module present in our code is an empty component that keeps events only in volatile memory: they are never transmitted to anyone and disappear when the app is closed.
5. Third parties we work with
The following is the exhaustive list of third parties that may receive your data, and why. This list is deliberately short.
5.1 — Amazon Web Services (AWS) — our infrastructure host
- Role: processor (within the meaning of GDPR Art. 28).
- Data received: device UUID, platform, IP address (logs), play events.
- Location: US-East-1 region (Virginia, United States).
- Legal basis for the transfer outside the EU: see section 13 below.
- AWS privacy policy: https://aws.amazon.com/privacy/
- DPA signed: yes (AWS Data Processing Addendum, including EU Standard Contractual Clauses).
5.2 — RevenueCat (activated only during a subscription action)
- Role: processor — technical management of Premium subscriptions.
- Data received: anonymous identifier auto-generated by RevenueCat, transaction data (product ID, status, dates), platform.
- Location: United States.
- What is NOT sent: no personal identifier (no email, no account, no UUID from our authentication system).
- RevenueCat privacy policy: https://www.revenuecat.com/privacy
5.3 — Apple Inc. (only for iOS users purchasing a subscription)
- Role: independent data controller for the purchase process.
- Data received: according to their own rules — we have no control over this data.
- Location: United States, Ireland (Apple European servers).
- Policy: https://www.apple.com/legal/privacy/
5.4 — Google LLC (only for Android users purchasing a subscription)
- Role: independent data controller for the Google Play Billing purchase process.
- Data received: according to their own rules.
- Location: United States.
- Policy: https://policies.google.com/privacy
6. Data retention
We strictly apply the principle of minimization (GDPR Art. 5.1.e).
Device record (device_id + platform)
- Retention: 12 months of rolling inactivity. Any device whose last activity is older than 12 months is automatically deleted.
- Deletion method: daily scheduled server-side task.
Session authentication token
- Retention: 90 days maximum from last use.
- Deletion method: automatic expiration.
Technical server logs (containing IP, timestamps)
- Retention: 30 days maximum.
- Deletion method: automatic rotation and purging.
Global playback counter
- Retention: no limit — this is an aggregated, anonymous, non-personal statistic.
- Deletion method: not applicable.
User-initiated deletion request
- Processing time: within 30 days maximum (operational target: under 72 hours).
- Deletion method: on request at support@basmala.app.
Subscription billing data (accounting obligations)
- Retention: 10 years — retained by Apple, Google Play and RevenueCat under their own policies, pursuant to the French Commercial Code (Art. L.123-22) and applicable tax laws.
- Deletion method: managed by the platforms.
7. Hosting and data location
Our technical infrastructure is hosted on Amazon Web Services (AWS), in the US-East-1 region (Virginia, United States).
The data that transits through our servers (device UUID, platform, aggregated play events) is stored in this region. Communications between your device and our servers are protected by industry-standard encryption (HTTPS/TLS).
See section 13 for the legal safeguards that govern this transfer outside the European Union.
8. Basmala Kids-specific section — Protection of children
This section applies exclusively to the Basmala Kids application, whose primary target audience is children under 13 and their parents/legal guardians. The general-audience Basmala app is not covered by this section.
8.1 — COPPA (Children's Online Privacy Protection Act — United States)
Basmala Kids is designed to comply with COPPA (15 U.S.C. §§ 6501-6506) and its implementing rule (16 C.F.R. Part 312) administered by the Federal Trade Commission (FTC).
Basmala Kids' COPPA compliance:
- No collection of "personal information" as defined by COPPA § 312.2: no name, no address, no email, no phone number, no photo, no precise geolocation, no persistent advertising identifier, no audio, no video of the child.
- The device UUID used for authentication is covered by the "support for internal operations" exception set out in COPPA § 312.5(c)(7): it is used solely to authenticate the device for service delivery, is not used for profiling or advertising, and is retained only for as long as necessary (12 months of inactivity maximum — see section 6).
- No child-to-child communication (no messaging, no comments, no social sharing).
- No advertising, neither contextual nor behavioral.
- No third-party analytics SDK.
- Verifiable parental consent obtained indirectly through in-app purchases that are subject to platform-native parental controls (see section 8.5).
- Parents have a mechanism to exercise their rights (see section 8.6).
8.2 — GDPR-K (Article 8 GDPR — European Union)
Article 8 of the GDPR imposes enhanced obligations for the processing of children's data. EU Member States set the digital age of consent between 13 and 16; in France, the amended Data Protection Act sets this age at 15.
Basmala Kids' GDPR-K compliance:
- Data processing is minimal and relies on solid legal bases (performance of a contract and legitimate interest), not on the consent of the child or the parent — which avoids the need for a verifiable consent mechanism.
- The minimization principle (GDPR Art. 5.1.c) is strictly enforced: no personally identifiable data is collected.
- Child-adapted transparency: the language of this policy is deliberately clear and structured, avoiding unnecessary legal jargon.
- No profiling or automated decision-making (GDPR Art. 22) — the app makes no behavior-based personalized recommendations.
- No targeted advertising (prohibited by Art. 22 GDPR applied to children).
8.3 — Google Play Families Policy & Designed for Families
Basmala Kids is enrolled in the Google Play Designed for Families program and complies with the full Families Policy Requirements:
- Declared target audience: children under 13 only (age groups "Ages 5 and under", "Ages 6-8", "Ages 9-12") in the Target Audience section of the Google Play Console.
- No third-party advertising or analytics SDK is integrated in the application.
- No access to sensitive permissions: no location, no camera, no microphone, no contacts, no calendar.
- The only foreground service permission declared is
FOREGROUND_SERVICE_MEDIA_PLAYBACK, used exclusively for user-visible audio playback (see our declaration in the "Foreground Services" section of the Play Console). - Parental control over purchases: in-app subscriptions are subject to Google's native parental policies (see 8.5).
- Content rating: 3+ / All ages (PEGI 3 / ESRB EC).
8.4 — Apple Kids Category Guidelines
Basmala Kids complies with the §1.3 Kids Category section of the Apple App Store guidelines:
- No outbound links to external websites without explicit parental gating.
- No in-app purchases directly accessible to the child without going through native parental mechanisms (Ask to Buy, Screen Time).
- No third-party analytics or advertising SDK.
- No collection of identifiable information without verifiable parental consent (and in our case, no collection at all).
8.5 — Parental consent (implementation)
Basmala Kids collects no personal data requiring explicit parental consent (only an anonymous UUID covered by COPPA's "internal operations" exception).
The only action requiring parental approval is the purchase of a Premium subscription. Such approval is obtained through the platforms' native parental controls:
- On iOS and iPadOS: Apple Family Sharing's Ask to Buy feature blocks any in-app purchase until a parent approves the request from their own device.
- On Android: the Google Family Link app and the Google Play Store's parental control settings require parental validation of any in-app purchase.
- Subscription set up by a parent on their own account: in this case, the parent, by subscribing, gives their own direct consent.
This mechanism is recognized by the FTC (COPPA) and European regulators as a valid means of obtaining verifiable parental consent for financial transactions.
Basmala Kids does NOT include an age-verification screen at launch ("neutral age screen") because the application is publicly and unambiguously declared as intended for children under 13 only. No differential data is collected based on age, which makes an age gate pointless for data-protection purposes.
8.6 — Rights of parents and legal guardians
Pursuant to COPPA § 312.6 and GDPR, any parent or legal guardian may at any time, regarding the data of a child using Basmala Kids:
- Request what data is associated with their child's device — in practice, this will always be the device UUID and the platform (see section 4.1).
- Demand immediate deletion of such data.
- Refuse any future collection (simply by uninstalling the app, since we collect nothing outside of active use).
- Refuse that existing data be transmitted to a third party (not applicable in our case, as we transmit nothing of this kind).
To exercise these rights:
Write to support@basmala.app with the subject line "Parental request COPPA / GDPR". We respond within 30 days maximum (operational target: under 72 hours). No proof of identity is required, as we hold no identifying information.
9. Your rights (GDPR — applicable to all users residing in the EU/EEA)
- Right of access to your data
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw consent at any time
- Right to lodge a complaint with the CNIL (France) or your competent data protection authority
How to exercise these rights:
Send your request by email to support@basmala.app with the subject line "GDPR rights exercise".
We respond to any request within a maximum of 30 days (operational target: under 72 hours), in accordance with Article 12.3 GDPR.
No proof of identity will be asked of you, since we hold no identity data allowing verification.
10. Rights of California residents (CCPA/CPRA) and other U.S. jurisdictions
Residents of the State of California are entitled, under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), to additional rights:
- Right to know what categories of personal information are collected about them.
- Right to request deletion of their personal information.
- Right to correct inaccurate information.
- Right to non-discrimination for exercising these rights.
- Right to opt out of the sale or sharing of personal data.
We confirm that we do not sell, rent or share any personal information with third parties for commercial or advertising purposes. All categories of information listed in section 4 remain strictly limited to the operational purposes described.
To exercise your CCPA/CPRA rights, use the email channel listed in section 9 or 15.
For residents of other U.S. jurisdictions with comparable legislation (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, etc.), the same rights and safeguards apply.
11. Security
We implement the following technical and organizational measures to protect your data (GDPR Art. 32):
Technical measures:
- In-transit encryption of all communications via industry-standard HTTPS/TLS.
- At-rest encryption of the database by our hosting provider (industry-grade symmetric encryption).
- API request authentication via short-lived cryptographic tokens.
- Cryptographic signing of authentication requests to prevent impersonation.
- Storage of the device identifier in the OS-provided secure vault (Keychain on iOS, Keystore on Android).
- No sensitive information (API keys or secrets) is embedded in clear text in the distributed application code.
Organizational measures:
- Access to production systems is limited to the data controller only (no third parties).
- Multi-factor authentication (MFA) enabled on AWS, App Store Connect, Google Play Console, RevenueCat and GitHub consoles.
- Automated auditing of software dependencies to detect known vulnerabilities.
In the event of a data breach (GDPR Art. 33-34): we commit to notifying the CNIL within 72 hours of becoming aware of it, and to informing affected users if the breach is likely to result in a high risk to their rights and freedoms.
No system is infallible; in the event of a security incident, consult https://www.basmala.app for up-to-date information.
12. Cookies, local storage and technical identifiers
12.1 — HTTP cookies
Our mobile applications do not use any cookies in the traditional sense (we are not a website).
12.2 — Local storage on your device
Our applications use two local storage mechanisms, accessible only to the app itself and your device:
Device secure vault (Keychain on iOS / Keystore on Android)
- Content stored: device UUID, session authentication token.
- Encryption: yes — managed natively by the operating system.
Local app storage (isolated by the application sandbox)
- Content stored: personal playlists, favorites, preferred language, avatar, playback position, UI settings.
- Encryption: not encrypted, but isolated from the rest of the system by the app's sandbox.
This data never leaves your device unless explicitly mentioned in section 4. You can erase it at any time by uninstalling the application.
12.3 — Advertising identifiers (IDFA / GAID)
Our applications do not read or transmit Apple's advertising identifier (IDFA) or Google's advertising identifier (GAID / AAID). No App Tracking Transparency (ATT) permission prompt is shown on iOS, as no tracking is performed.
13. International data transfers
As indicated in section 7, some of your data (device UUID, platform, temporary IP address in logs) is stored on Amazon Web Services infrastructure in the US-East-1 region (Virginia, United States).
This transfer outside the European Economic Area is governed by two complementary legal mechanisms compliant with GDPR (Art. 44 to 50):
- EU-U.S. Data Privacy Framework (DPF) — AWS Inc. is DPF-certified (successor to Privacy Shield, approved by the European Commission's adequacy decision of July 10, 2023). AWS's certification is publicly verifiable at https://www.dataprivacyframework.gov/list
- Standard Contractual Clauses (SCC) of the European Commission (decision 2021/914 of June 4, 2021), incorporated into the Data Processing Addendum signed between the data controller and AWS.
None of your data is transferred to third countries other than those mentioned for our RevenueCat, Apple and Google processors (section 5).
14. Changes to this policy
We reserve the right to amend this privacy policy at any time to reflect changes in our applications, our processors or applicable legislation.
Transparency commitments we impose on ourselves:
- Any change is dated at the top of this document ("Last updated" field).
- The full version history is kept and can be consulted at https://www.basmala.app/privacy-policy/changelog.
- For any substantial change (new data use, new processor, change of retention period, modification of legal bases), the "Last updated" date at the top of this document is advanced and the reason for modification is recorded in the version log.
- No change may retroactively extend our right to use data beyond what was declared at the time of collection, without explicit consent.
We recommend that you consult this page periodically. Continued use of the applications after publication of a new version of the policy constitutes acceptance of the new version, except for changes requiring explicit consent.
15. Contact
For any question, information request or exercise of your rights regarding this privacy policy:
📧 General questions, technical support
- Email: support@basmala.app
- Response time: 72 business hours (target)
📧 GDPR / CCPA / COPPA rights exercise
- Email: support@basmala.app
- Subject line: "Rights exercise"
- Response time: 30 days maximum (target: under 72 hours)
📧 Data breach or security issue report
- Email: support@basmala.app
- Subject line: "Urgent — security"
- Response time: immediate
📧 Parental request (Basmala Kids)
- Email: support@basmala.app
- Subject line: "Parental request COPPA / GDPR"
- Response time: 30 days maximum
Postal address of the data controller:
MADOUI Mohamed (sole proprietorship — trade name: Basmala Studio)
95 B Rue de la Pyramide
59220 Denain — France
SIRET: 527 672 547 00033
Supervisory authority (France): Commission Nationale de l'Informatique et des Libertés (CNIL) — https://www.cnil.fr/en
Any user may lodge a complaint directly with the CNIL or with the data protection authority of their country of residence.
Reference document for publication on:
- Apple App Store (iOS) — Basmala, Basmala Kids
- Google Play Store (Android) — Basmala, Basmala Kids
- Website: https://www.basmala.app/privacy-policy
Pour toute question concernant cette politique, veuillez nous contacter.
Retour à l'accueil