Privacy Policy
Last updated: May 24, 2026
Raad Allsalim ("we", "us", or "our") operates the RimoRosh mobile application (the "App"). This Privacy Policy explains how we collect, use, protect, and share your personal information when you use our App.
1. Information We Collect
When you use RimoRosh, we may collect the following types of information:
- Account Information: Name, email address, profile picture, gender, and date of birth (optional) when you register.
- User Content: Photos, videos, audio recordings, stories, posts, and messages you create or share within the App.
- Device Information: Device type, operating system, unique device identifiers, IP address, and crash logs.
- Location Data: Approximate or precise location, only when you grant permission for location-based features.
- Camera & Microphone: Access only when you choose to record videos, take photos, or send voice messages.
- Usage Data: How you interact with the App, including features used, time spent, and content viewed.
2. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the App's features.
- Authenticate users and manage accounts.
- Enable social features such as posts, messaging, and stories.
- Process Stars purchases and virtual gift transactions.
- Send important notifications about your account or the App.
- Detect, prevent, and address fraud and abuse.
- Display relevant in-app advertisements.
- Comply with legal obligations and respond to lawful requests.
3. Third-Party Services
RimoRosh uses the following third-party services that may collect information:
- Firebase (Google): Authentication, Firestore database, Cloud Storage, App Check, Cloud Messaging (notifications), and Cloud Functions.
- Google Sign-In: For login with Google accounts.
- Sign in with Apple: For login with Apple ID.
- Google AdMob: For displaying advertisements.
- Apple In-App Purchase: For Stars purchases on iOS devices.
- Stripe: For Stars purchases on Android devices and creator withdrawals.
- Stripe Connect: For processing creator earnings withdrawals.
- Geolocation services: For location-based features.
Each third-party service has its own privacy policy that governs its use of your information.
4. Payment Information
4.1 What We Collect
When you purchase Stars (⭐) or send/receive virtual gifts, we collect:
- For Stars Purchasers: Stars package selected, transaction amount, payment method, transaction timestamp, and transaction ID.
- For Senders: Stars used per gift, selected gift type, recipient user ID, optional message, anonymous status preference, and timestamp.
- For Recipients: Stars received, EUR balance, transaction history, Stripe Connect account information, and withdrawal request history.
4.2 Payment Processors
iOS (Apple devices): All Stars purchases are processed through Apple In-App Purchase. We receive only transaction ID, product ID, and verification receipt. Apple's Privacy Policy
Android (Google devices): Stars purchases are processed by Stripe Inc. Stripe handles credit/debit cards, SEPA, Klarna, Google Pay, and other regional methods. Stripe's Privacy Policy
Creator Withdrawals: Processed through Stripe Connect, available in 40+ countries, with built-in KYC/AML verification.
4.3 What We Do NOT Store
We do
not store on our servers:
- Full credit card numbers
- CVV codes
- Bank account numbers
- Apple ID passwords
- Stripe login credentials
This sensitive information is handled directly by Apple and Stripe in compliance with PCI-DSS standards.
4.4 Identity Verification (KYC/AML)
To comply with anti-money laundering (AML) and Know Your Customer (KYC) regulations, Stripe Connect requires:
- Government-issued photo ID
- Proof of address
- Tax identification number
- Additional verification for withdrawals exceeding €1,000
This verification is handled directly by Stripe during the onboarding process.
4.5 Payment Data Retention
Payment records are retained for 7 years to comply with German tax law (Abgabenordnung §147) and EU financial regulations. After this period, transaction data is anonymized or deleted.
5. Data Sharing
We do not sell your personal information. We may share information only in the following situations:
- With your consent.
- With service providers who assist us in operating the App (under confidentiality agreements).
- With payment processors (Apple, Stripe) to process transactions.
- To comply with legal obligations or respond to lawful requests.
- To protect the rights, property, or safety of RimoRosh, our users, or others.
- With other users (only what you post publicly).
6. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including:
- Apple Inc. (USA) - for iOS Stars purchases
- Stripe Inc. (USA) - for Android purchases and creator withdrawals
- Google LLC (USA) - for Firebase services
These transfers are protected by Standard Contractual Clauses approved by the European Commission, the EU-US Data Privacy Framework (where applicable), and industry-standard encryption.
7. Data Retention
We retain your personal information for as long as your account is active. You may delete your account at any time from within the App, and your data will be removed from our active systems within 30 days, except where retention is required by law (e.g., payment records retained for 7 years).
8. Your Rights
Depending on your location (including the EU under GDPR), you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (subject to legal retention requirements).
- Object to or restrict certain processing.
- Data portability - Receive a copy of your data in a portable format.
- Withdraw consent at any time where processing is based on consent.
To exercise these rights, contact us at the email below.
9. Stars Wallet Privacy
Your Stars balance and EUR wallet:
- Are private to your account and not visible to other users.
- May be displayed publicly in Top Supporters lists (only if you support a creator and choose not to be anonymous).
- Are stored encrypted in Firebase Firestore.
- Can be reviewed at any time within the App.
You can choose to send gifts anonymously to hide your identity from the recipient and the public Top Supporters list.
10. Children's Privacy
RimoRosh is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can remove it.
11. Security
We protect your information through:
- TLS/SSL encryption for all data transmission.
- Tokenization of payment credentials by Apple/Stripe.
- Firebase Security Rules limiting data access to authorized users.
- Cloud Functions authentication for all sensitive operations.
- Regular security audits.
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
12. Tax Obligations (For Creators)
If you receive gifts and withdraw earnings, you are solely responsible for:
- Reporting received gift income to your local tax authority.
- Paying any applicable income tax, VAT, or other taxes.
- Complying with self-employment regulations in your jurisdiction.
RimoRosh provides transaction history but does not issue tax forms. We recommend consulting a tax professional.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date.
14. Contact Us
If you have any questions about this Privacy Policy or want to exercise your rights, please contact us: