Skip to content
DiouaneENTERTAINMENT
Home/Legal information
LEGAL & PRIVACY

Privacy policy

Last updated · August 24, 2026

Privacy policyTerms of serviceDisclaimerData deletion
On this page
1. Data Controller & Studio Identification2. Scope & Distinction of Processing Roles3. Fundamental Principles of Data Processing4. Website & Mobile App System Telemetry (Logfiles)5. Comments, Contact Forms & Direct Communications6. Google AdSense & Editorial Advertising7. Essential Cookies & Technically Necessary Technologies8. Consent Management Platform (CMP), Tracking & Usercentrics9. Realert: Chat & Media Recover (com.diouane.realert)10. Mobile Advertising Networks & Mediation Partners (Comprehensive Disclosures)11. Memory Clash Online (com.diouane.android)12. Account & Data Deletion for Memory Clash Online13. Cloud Infrastructure, Diagnostics & Google Services14. Purposes of Data Processing15. Legal Bases for Processing under GDPR & International Law16. Data Sharing with Third Parties17. Notice to United States Residents (CCPA / CPRA & State Laws)18. Data Retention Periods19. Data Security Measures20. Data Breach & Incident Response21. International Data Transfers & Third-Country Safeguards22. Data Subject Rights under GDPR (EU, EEA & UK)23. California Consumer Privacy Act (CCPA / CPRA) Disclosures24. Brazil (Lei Geral de Proteção de Dados - LGPD)25. Indonesia (Personal Data Protection Law)26. Morocco Data Protection (Law 09-08 & CNDP)27. Users in Other International Jurisdictions28. Children's Privacy (COPPA & Family Policies)29. Managing App Permissions in Android30. Application Uninstallation & Local Database Purge31. External Links & Third-Party Platforms32. Courses & Educational Mentorship via Diouane.com33. Educational Nature of Training Services34. Earnings Disclaimer & No Financial Promises35. Independent Platform Policy Evolution36. Course Updates & Content Evolution37. Course Access Duration & Continuity38. Digital Content & Mentorship Refund Policy39. Pricing, Currencies & Payment Processing40. Personal Single-User Educational License41. Prohibited Uses of Course Content42. Intellectual Property & Copyright43. Lawful & Ethical Use of Educational Knowledge44. Third-Party Platform Decisions & Account Actions45. Non-Affiliation with Google LLC & Third Parties46. Limitation of Studio Liability47. Technical Content Accuracy & Disclaimer48. Force Majeure & External Disruptions49. Consumer Protection in Morocco (Law 31-08)50. Consumer Rights for European Union Residents51. Preservation of Mandatory Statutory Rights52. Modifications to Applications & Digital Services53. Updates to This Privacy Policy54. Special Information on the Right to Object (Art. 21 GDPR) & Exercising Rights55. Data Controller & Data Protection Contact Details56. Official External Resources & Policy FrameworksAddendum: Diouane Blog Android Application (com.diouane.diouaneblog)

1. Data Controller & Studio Identification

The applications, games, web services, and digital resources referenced on this page are operated and controlled by Diouane Entertainment / Mohamed Diouane, established in the Kingdom of Morocco.

Age Requirement & Parental Consent: Our applications and services are available to users who are at least 16 years of age. If you are under 16 years old, the explicit consent of your parent or legal guardian is required in accordance with Art. 8 (1) sentence 2 GDPR and international youth protection standards.

To ensure rapid, transparent assistance, we maintain dedicated communication channels for privacy rights, app telemetry, and support inquiries:

  • Google Play Applications, In-App Privacy & Data Erasure: playstore@diouane.com
  • Diouane.com Web Services, Technical Blog & Mentorship: blog@diouane.com
  • Designated Data Protection Contact: Mohamed Diouane (playstore@diouane.com)

2. Scope & Distinction of Processing Roles

We establish a strict, transparent operational distinction between data we directly control and process, data stored strictly locally on your physical device, and data processed independently by certified third-party infrastructure and ad mediation partners (including Google LLC, Unity Technologies, AppLovin Corporation, Meta Platforms, Firebase, and payment processors).

Using third-party SDKs or cloud services does not grant our studio custody over all underlying telemetry handled by those providers. Each external service operates under its own legal terms and privacy disclosures.

This unified privacy policy governs the following products, mobile applications, and services:

  • Diouane.com web platform, technical engineering blog, and programming tutorials.
  • Realert: Chat & Media Recover (Package ID: com.diouane.realert).
  • Memory Clash Online (Package ID: com.diouane.android).
  • Esato - Memory Game (Package ID: com.diouane.esato) and Flappy Ball (Package ID: com.diouane.aurafoot).
  • Diouane Blog Android Application (Package ID: com.diouane.diouaneblog).
  • Educational mentorship, blogging courses, and digital tools provided through Diouane.com.

3. Fundamental Principles of Data Processing

For all data falling under our direct custody, we adhere strictly to recognized global privacy principles: lawfulness, fairness, transparency, explicit purpose limitation, data minimization, accuracy, storage limitation, and technical integrity.

App Store Download Telemetry: When you download our applications from mobile application stores (such as Google Play or Apple App Store), necessary transaction data is transmitted directly to the store operator (including username, email address, customer account number, download timestamp, payment information, and device hardware identifiers). We have no influence over this store-level data collection and are not responsible for it; we process such data only to the extent necessary to deliver the application to your mobile device.

Zero Message Monetization Guarantee: We never collect excessive personal information. Under no circumstances do we sell, rent, monetize, or broker notification content, private messages, or recovered media files processed locally by our applications.

4. Website & Mobile App System Telemetry (Logfiles)

When you access Diouane.com or launch our mobile applications, our systems and hosting infrastructure automatically collect technical connection metrics and device telemetry:

Purposes & Legal Basis: The analysis of logfile records in pseudonymized or anonymized form serves to optimize software functionality, control server capacity, monitor technical stability, diagnose crashes, and prevent unauthorized tampering. These purposes constitute our overriding legitimate interest in data processing pursuant to Art. 6 (1) f) GDPR. The telemetry is not analyzed for marketing purposes in this context.

Storage Duration: Technical logfile data and connection records are permanently purged after at most 365 days.

Device Deletion: You can uninstall our mobile apps at any time, immediately terminating future telemetry collection.

  • Application version and application language.
  • Operating system, build architecture, and OS version.
  • Device type, model name, device manufacturer, and system language.
  • City and country of access (derived from IP address).
  • Timestamps of access, visited paths, and session duration.
  • IP address (anonymized at the earliest possible stage).
  • Internal session ID and unique app instance identifier.
  • Chat content user agent and in-app purchase receipts (where applicable).

5. Comments, Contact Forms & Direct Communications

If you submit a comment on our blog, complete an inquiry form, or email our support desks, we process the information you voluntarily provide, such as your name, email address, message body, and relevant technical details.

This data is used exclusively to answer inquiries, provide technical support, investigate bug reports, or satisfy legal obligations. We instruct all users never to submit sensitive passwords, payment details, or personal credentials through public comments or unencrypted email.

6. Google AdSense & Editorial Advertising

Diouane.com may feature digital advertisements managed by Google AdSense.

Google and its certified ad partners process technical telemetry, device identifiers, cookies, and interaction data to serve ads, detect click fraud, prevent invalid traffic, and deliver personalized advertising where permitted by user consent and regional privacy regulations.

You can review Google\'s advertising policies and manage personalization preferences at any time through Google My Ad Center.

7. Essential Cookies & Technically Necessary Technologies

Our website and applications utilize technically necessary cookies and local device storage (such as localStorage and shared preferences) to enable essential functions and ensure proper operation.

These essential technologies preserve your session preferences (such as cookie consent states, language settings, and interface themes) and secure communication channels.

Legal Basis: The processing of technically necessary storage elements is based on our overriding legitimate interest in providing a functional, secure digital service pursuant to Art. 6 (1) f) GDPR.

You may manage, block, or erase cookies at any time through your browser settings. If essential cookies are disabled, certain interactive platform functions may be restricted.

8. Consent Management Platform (CMP), Tracking & Usercentrics

When launching our applications or visiting our web portal, users in the European Economic Area (EEA), the United Kingdom, and Switzerland are presented with an interactive Consent Management Platform (CMP) dialog (utilizing Usercentrics or Google User Messaging Platform compliant with IAB TCF v2.2 and Google Consent Mode v2).

Users are asked for affirmative, granular consent before tracking technologies, advertising SDKs, or device identifiers are shared with third-party partners. This complies with applicable regional data protection guidelines and Google Play / Apple store standards.

Revoking or Modifying Consent: You can review, modify, or revoke your consent choices at any time via the in-app 'Privacy' / 'Datenschutz' settings menu or through our floating cookie preferences banner on the web.

Partner Updates: If we modify our partner roster or data processing purposes, the consent dialog is automatically re-displayed upon your next app launch to permit an updated review.

Purposes Processed via Consent (IAB TCF Framework):

  • Create profiles for personalised advertising.
  • Use profiles to select personalised advertising.
  • Create profiles to personalise content.
  • Use profiles to select personalised content.
  • Measure advertising performance and viewability.
  • Measure content performance and user engagement.
  • Understand audiences through statistics or combinations of data from different sources.
  • Develop and improve services, gameplay algorithms, and user interfaces.
  • Store and/or access information on a device (cookies, mobile ad IDs).
  • Use precise geolocation data and actively scan device characteristics for identification.

9. Realert: Chat & Media Recover (com.diouane.realert)

Architectural Guarantee: Realert operates strictly as an on-device utility. All intercepted notifications and media recovery caches are stored exclusively within your local Android device storage. We do not operate remote servers to collect, upload, or sync your private chat messages.

Realert: Chat & Media Recover is an Android utility engineered to detect and archive notification banners, enabling users to review deleted text messages and recover media files received through instant messaging platforms.

Notification Listener Service (android.permission.BIND_NOTIFICATION_LISTENER_SERVICE): Realert requires this Android system permission to inspect incoming notification events. When granted, the sender name, message preview text, timestamp, and originating application package are stored strictly inside a local, private SQLite database on your device.

Zero Cloud Upload: We do NOT upload, backup, synchronize, or transmit captured notification contents to our studio servers, cloud databases, or any third party. Your messages remain private and offline.

Media Recovery Mechanism: Realert monitors accessible shared storage directories (such as WhatsApp, Telegram, or camera media folders) to detect newly downloaded photos, videos, voice notes, and documents before they can be deleted by the sender, storing backup copies locally.

User Control & Deletion: You retain absolute control over your data. You can delete individual messages or media items within the app, clear the application database via Android Settings, or revoke notification access at any time via Android Settings > Apps > Special App Access > Notification Access.

10. Mobile Advertising Networks & Mediation Partners (Comprehensive Disclosures)

To support free access to our mobile applications and games, we integrate certified advertising SDKs and mediation networks. When consent is granted (Art. 6 (1) a) GDPR) or on the basis of legitimate interests (Art. 6 (1) f) GDPR for contextual fraud prevention and ad measurement), these partners process device telemetry and advertising identifiers (such as Google Advertising ID / GAID, IDFA, IP address, and ad interaction events).

Below is the complete inventory of our data processing services, ad mediation networks, and advertising partners:

1. Google Advertising Products (Google Ads, Google AdMob, Google Ad Manager, Google Ad Exchange): Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Parent: Google LLC, USA). Processes Advertising ID, IP address, device specs, location, and ad events. Purpose: Personalised advertising, ad delivery, fraud prevention, and frequency capping. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer to third countries: USA (Standard Contractual Clauses / Data Privacy Framework). Retention: Up to 24 months. Privacy Policy & Opt-Out: https://policies.google.com/privacy

2. Unity Ads & Unity Engine: Unity Technologies ApS, Niels Hemmingsens Gade 24, 1153 Copenhagen, Denmark (Unity Software Inc., USA). Processes IP address, Advertising ID (GAID/IDFA), hardware model, operating system, and gameplay session metrics. Purpose: In-game video/interstitial ad delivery, rewarded ads, attribution, and analytics. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 13 months. Privacy Policy: https://unity.com/legal/privacy-policy

3. AppLovin & AppLovin Max SDK: AppLovin Corporation, 1100 Page Mill Road, Palo Alto, CA 94304, USA. Processes mobile advertising IDs, IP address, network connection type, device make/model, and ad engagement. Purpose: Ad mediation, real-time bidding, personalized advertising, and attribution. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://www.applovin.com/privacy/

4. Meta Audience Network & Facebook SDK: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (Meta Platforms, Inc., USA). Processes Advertising ID, app install events, device attributes, and coarse geolocation. Purpose: Targeted advertising, campaign optimization, conversion tracking. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 2 years. Privacy Policy: https://www.facebook.com/privacy/policy

5. Chartboost: Chartboost Inc., 85 2nd Street, Suite 100, San Francisco, CA 94105, USA. Processes device IDs, IP address, OS version, and ad interaction timestamps. Purpose: Mobile interstitial and rewarded video ad serving. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://www.chartboost.com/privacy/

6. InMobi: InMobi Pte. Ltd., 7th Floor, Block Delta, Embassy Tech Square, Kadubeesanahalli, Bengaluru 560103, India / InMobi US. Processes device identifiers, coarse location, and ad impression data. Purpose: Ad serving, ad performance measurement, fraud detection. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA / Singapore (Standard Contractual Clauses). Retention: Up to 13 months. Privacy Policy: https://www.inmobi.com/privacy-policy/

7. Liftoff Monetize & Vungle Exchange: Liftoff Mobile, Inc., 900 Middlefield Road, Redwood City, CA 94063, USA. Processes GAID/IDFA, IP address, device model, and ad view records. Purpose: Video ad delivery, programmatic bidding, and performance analytics. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://liftoff.io/privacy-policy/

8. Mintegral SDK: Mintegral International Limited, 40/F, Sunlight Tower, 248 Queen's Road East, Wan Chai, Hong Kong / Mobvista. Processes device identifier, operating system version, carrier, and IP address. Purpose: Ad mediation and monetization. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: Standard Contractual Clauses. Retention: Up to 12 months. Privacy Policy: https://www.mintegral.com/en/privacy

9. DT Exchange (Fyber Monetization Ltd. / Digital Turbine): Digital Turbine, Inc., 110 San Antonio St, Austin, TX 78701, USA. Processes device IDs, IP address, app session data, and ad engagement telemetry. Purpose: Ad mediation and programmatic monetization. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://www.digitalturbine.com/privacy-policy/

10. Tapjoy: Tapjoy, Inc., 353 Sacramento Street, 6th Floor, San Francisco, CA 94111, USA (IronSource / Unity). Processes advertising ID, device type, IP address, and offerwall interaction data. Purpose: Rewarded ads, offerwalls, and monetization. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://dev.tapjoy.com/en/legal/Privacy-Policy

11. Amazon Advertising: Amazon.com, Inc., 410 Terry Ave N, Seattle, WA 98109, USA. Processes advertising identifiers, IP address, and ad impression telemetry. Purpose: Ad delivery and measurement. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 13 months. Privacy Policy: https://www.amazon.com/gp/help/customer/display.html?nodeId=468496

12. Moloco (Moloco Ad Cloud): Moloco, Inc., 601 Marshall St, Suite 500, Redwood City, CA 94063, USA. Processes advertising IDs, device model, network info, and programmatic bid requests. Purpose: Programmatic machine-learning ad bidding and attribution. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://www.moloco.com/privacy-policy

13. Start.io: Start.io Inc., 584 Broadway, Suite 610, New York, NY 10012, USA. Processes device identifiers, coarse location, device specs, and ad interaction records. Purpose: Mobile ad delivery and audience analytics. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://www.start.io/policy/privacy-policy/

14. BidMachine: BidMachine Inc., 2855 Kifer Road, Suite 205, Santa Clara, CA 95051, USA. Processes advertising identifiers, device model, and ad auctions telemetry. Purpose: Programmatic header bidding and in-app ad auctions. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA (Standard Contractual Clauses). Retention: Up to 12 months. Privacy Policy: https://bidmachine.io/privacy-policy/

15. Nefta: Nefta Ltd., London, United Kingdom. Processes anonymous gameplay events, token identifiers, and ad interactions. Purpose: Ad personalization and game analytics. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: Standard Contractual Clauses. Retention: Up to 12 months. Privacy Policy: https://nefta.io/privacy-policy

16. IAB TCF Global Vendor Partners (PubMatic, Magnite, Outbrain): PubMatic Inc. (Redwood City, CA), Magnite Inc. (New York, NY), Outbrain UK Ltd (London, UK). Process standard ad exchange telemetry, device IDs, and bid data. Purpose: Programmatic ad exchange, yield optimization, and viewability measurement. Legal Basis: Consent (Art. 6 (1) a) GDPR). Transfer: USA / UK (Standard Contractual Clauses). Retention: Up to 13 months. Privacy Policies: https://pubmatic.com/legal/privacy-policy/ , https://www.magnite.com/legal/marketplace-privacy-policy/ , https://www.outbrain.com/privacy/

17. Analytics, Attribution & Auxiliary SDKs: Singular (Singular Labs, Inc., USA), GameAnalytics SDK (GameAnalytics ApS, Denmark), Appodeal (Appodeal Inc., USA), Stream (Stream.io Inc., USA), Apple Search Ads (Apple Inc., USA). Process usage telemetry, crash logs, attribution data, and search ad impressions to optimize game mechanics and deliver features. Legal Basis: Consent (Art. 6 (1) a) GDPR) or Legitimate Interest (Art. 6 (1) f) GDPR). Transfer: Standard Contractual Clauses.

  • Opt-Out via Android: Settings > Privacy > Ads > Reset or Delete Advertising ID.
  • Opt-Out via iOS: Settings > Privacy & Security > Tracking > Toggle off 'Allow Apps to Request to Track'.
  • Consent Management: Access the in-app 'Privacy' menu at any time to modify partner consent.

11. Memory Clash Online (com.diouane.android)

Memory Clash Online is a competitive real-time multiplayer card and memory challenge game published by Diouane Entertainment.

Authentication (Firebase Auth & Google Sign-In): Players authenticate using Google Sign-In or guest modes. Firebase Auth processes your public display name, email address, unique Firebase User ID (UID), and profile avatar.

Cloud Gameplay Data: Match records, competitive ranks, trophies, achievements, and virtual coin balances are stored in Google Cloud Firestore and Firebase Realtime Database to facilitate live multiplayer matchmaking.

In-App Purchases: Virtual items and coin bundles are processed securely through the official Google Play Billing Library. We do not collect or store credit card numbers or payment credentials.

12. Account & Data Deletion for Memory Clash Online

In compliance with Google Play Developer Policies and global data privacy laws, Memory Clash Online users have the unconditional right to delete their gaming account and all associated cloud data.

In-App Deletion: Navigate to Settings > Account > Delete Account directly within the game.

Web Deletion Portal: Submit an erasure request anytime via our official Data Deletion Portal at https://diouane.com/deletion

Direct Support Request: Email playstore@diouane.com with your registered player email or UID.

Execution Timeline: All cloud player profiles, match histories, and associated identifiers are permanently expunged within 30 days of verified request.

13. Cloud Infrastructure, Diagnostics & Google Services

Our connected services utilize enterprise cloud infrastructure provided by Google Ireland Limited / Google LLC, including:

Firebase Authentication & Google Sign-In: Securely handles player authentication, email validation, and unique user identifiers (UID). Legal Basis: Performance of contract (Art. 6 (1) b) GDPR).

Google Cloud Firestore & Firebase Realtime Database: Hosts synchronized multiplayer scores, player profiles, and game economies. Data is protected by strict Firebase Security Rules restricting read/write access to authenticated account owners.

Firebase Crashlytics & Analytics for Firebase: Collects crash stack traces, OS versions, device hardware specifications, and application launch latency to identify and resolve stability bottlenecks. Legal Basis: Legitimate interest (Art. 6 (1) f) GDPR) in maintaining app stability and fixing software bugs.

All telemetry managed through Google enterprise cloud services is protected by ISO/IEC 27001, SOC 1/2/3 certifications, Standard Contractual Clauses (SCCs), and the Google Cloud Privacy Notice (https://cloud.google.com/terms/cloud-privacy-notice ).

14. Purposes of Data Processing

We process personal and technical telemetry strictly for legitimate, transparent operational purposes in accordance with global data protection laws:

1. Providing core application functionality, multiplayer matchmaking, and educational resources.

2. Maintaining player game state, cloud saves, trophy leaderboards, and virtual item records.

3. Monitoring application performance, detecting software crashes, and resolving technical bottlenecks.

4. Preventing fraud, bot automation, illegitimate game tampering, and security breaches.

5. Serving compliant digital advertisements (contextual or personalized with consent) to fund ongoing development.

6. Providing customer support, responding to data erasure requests, and fulfilling statutory recordkeeping obligations.

15. Legal Bases for Processing under GDPR & International Law

Under the European Union General Data Protection Regulation (GDPR) and comparable international privacy statutes, our data processing activities rely exclusively on defined legal bases:

Consent (Art. 6 (1) a) GDPR): The data subject has given affirmative consent to the processing of personal data for one or more specific purposes (such as personalized advertising profiles, tracking cookies, and non-essential analytics). Where consent is required for users under 16 years of age, parental consent is obtained pursuant to Art. 8 (1) sentence 2 GDPR.

Performance of a Contract (Art. 6 (1) b) GDPR): Processing is strictly necessary for the execution of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (such as delivering multiplayer gaming, account sync, and educational mentorship).

Compliance with Legal Obligations (Art. 6 (1) c) GDPR): Processing is required to satisfy statutory obligations under applicable laws (such as tax compliance, commercial records, and statutory disclosure mandates).

Legitimate Interests (Art. 6 (1) f) GDPR): Processing is necessary for the purposes of legitimate interests pursued by the controller or a third party, except where overridden by the interests, rights, or freedoms of the data subject. Our legitimate interests encompass maintaining system stability, crash diagnostics, network security, fraud prevention, and essential website operations.

National Data Protection Regulations: In addition to the GDPR, relevant national privacy laws apply in users' jurisdictions, including the German Federal Data Protection Act (BDSG), the Moroccan Law No. 09-08, and statutory laws of individual jurisdictions.

16. Data Sharing with Third Parties

We never sell, trade, or broker your personal information to data aggregators. Data is disclosed only in strictly limited scenarios:

Certified Infrastructure Providers: Google Cloud, Firebase, AdMob, Vercel, and payment gateways solely to execute services.

Statutory Authorities: When required by a valid judicial subpoena, court order, or binding law enforcement request.

Corporate Reorganization: In the event of a studio merger, acquisition, or asset reorganization where privacy commitments are maintained.

17. Notice to United States Residents (CCPA / CPRA & State Laws)

Residents of California, Virginia, Colorado, Connecticut, Utah, and other US states with enacted comprehensive privacy laws enjoy statutory rights regarding their personal data:

Right to Know & Access: You may request details on the categories and specific pieces of personal information collected over the preceding 12 months.

Right to Deletion: You have the right to request deletion of personal information maintained by us, subject to statutory exemptions.

Right to Opt-Out of Sale / Sharing: We do not sell personal data for monetary compensation. Where targeted advertising is defined as sharing under state laws, you may opt out via device ad settings or our consent controls.

Non-Discrimination: Exercising your privacy rights will never result in penalties, degraded service quality, or differential pricing.

18. Data Retention Periods

We retain personal data and technical telemetry only for the duration strictly necessary to accomplish the operational purposes articulated in this policy:

1. Server Logfiles & System Telemetry: Automatically purged after at most 365 days.

2. On-Device Local Data (Realert, Esato, Flappy Ball): Maintained strictly within local sandboxed device storage until deleted by the user or upon application uninstallation.

3. Cloud Gaming Profiles (Memory Clash Online): Retained while your account remains active; permanently expunged within 30 days of receiving a verified deletion request.

4. Customer Support Correspondence: Retained for up to 24 months to address follow-up inquiries or defend against legal claims.

5. Commercial & Financial Records: Maintained in accordance with mandatory statutory accounting and tax retention periods (up to 10 years where required by law).

19. Data Security Measures

We implement robust industry-standard technical and organizational security controls:

HTTPS / TLS 1.3 encryption across all website and API transmissions.

Granular Firebase Security Rules restricting database access strictly to authenticated account owners.

Android operating system sandboxing isolating application databases from unauthorized external inspection.

Periodic security audits and vulnerability monitoring across all software assets.

20. Data Breach & Incident Response

In the unlikely event of a security compromise affecting personal data under our direct custody, we maintain an active incident response protocol.

We will assess risks, initiate containment measures, and notify affected individuals and competent data protection authorities within 72 hours where required by applicable data protection laws.

21. International Data Transfers & Third-Country Safeguards

Because our cloud providers, hosting networks (Vercel, Google Cloud), and ad mediation partners operate global infrastructure, personal data may be transferred to and processed in third countries outside the European Economic Area (EEA), including the United States.

Third-Country Transfer Safeguards: Where data is transferred to a third country lacking an adequacy decision under Art. 45 GDPR, transfers are governed by appropriate safeguards in accordance with Art. 44 to 49 GDPR:

1. European Commission Standard Contractual Clauses (SCCs): Enforced with all global infrastructure and advertising providers to bind them to European data protection standards.

2. EU-US Data Privacy Framework: Utilized for certified recipients in the United States.

3. Technical Security Measures: Comprehensive transport layer encryption (TLS 1.3), encryption at rest, and IP anonymization at the earliest possible stage.

Further information on international transfer mechanisms is available from the European Commission information portal: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en

22. Data Subject Rights under GDPR (EU, EEA & UK)

Under the General Data Protection Regulation (GDPR) and UK GDPR, users residing in the European Economic Area and the United Kingdom enjoy comprehensive statutory rights regarding their personal data:

1. Right of Access (Art. 15 GDPR): Obtain confirmation of whether your personal data is being processed, and receive a portable copy along with full processing disclosures.

2. Right to Rectification (Art. 16 GDPR): Demand the immediate correction of inaccurate or incomplete personal details.

3. Right to Erasure / 'Right to be Forgotten' (Art. 17 GDPR): Request the permanent deletion of personal data where processing is no longer necessary or consent has been withdrawn.

4. Right to Restriction of Processing (Art. 18 GDPR): Request restriction of data processing under specified statutory circumstances.

5. Right to Data Portability (Art. 20 GDPR): Receive your personal data in a structured, commonly used, and machine-readable format.

6. Right to Withdraw Consent (Art. 7 (3) GDPR): Revoke granted consent at any time with effect for the future.

7. Right to Object (Art. 21 GDPR): Object to data processing based on legitimate interests (Art. 6 (1) f) GDPR) or direct marketing.

8. Right to Lodge a Complaint (Art. 77 GDPR): File a complaint with a competent data protection supervisory authority in your EU member state of residence or workplace.

23. California Consumer Privacy Act (CCPA / CPRA) Disclosures

California residents can submit privacy requests by emailing playstore@diouane.com with the subject line "California Privacy Request".

We do not collect sensitive personal information for the purpose of inferring characteristics about consumers, and we do not sell or share personal information of consumers known to be under 16 years of age.

24. Brazil (Lei Geral de Proteção de Dados - LGPD)

For users residing in Brazil, personal data handling complies with Law No. 13.709/2018 (LGPD). Brazilian data subjects may confirm processing, access information, correct inaccuracies, anonymize unnecessary data, and petition the Autoridade Nacional de Proteção de Dados (ANPD).

25. Indonesia (Personal Data Protection Law)

For users in Indonesia, data handling adheres to Law No. 27 of 2022 on Personal Data Protection (PDP Law). Users can exercise rights to access, correct, and terminate processing by reaching out to our privacy desk.

26. Morocco Data Protection (Law 09-08 & CNDP)

Data processing conducted within the Kingdom of Morocco is governed by Law No. 09-08 regarding the protection of individuals with respect to the processing of personal data, regulated by the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP).

Moroccan citizens and residents may exercise their statutory rights of access, rectification, and opposition directly by writing to blog@diouane.com.

27. Users in Other International Jurisdictions

Diouane Entertainment applies universal privacy safeguards worldwide: transparency in all processing activities, purpose limitation, zero sale of private communication records, and accessible data erasure tools.

28. Children's Privacy (COPPA & Family Policies)

Protecting the safety of children and minors across the digital sphere is an essential priority:

Our applications, games, and website services are not directed toward children under 13 years of age (or under 16 in certain EU member states).

We do not knowingly solicit or collect personal identifiable information from children.

All advertisements served in our general-audience mobile games comply with Google Play Families Policy guidelines, prohibiting age-inappropriate ad categories.

If a parent or guardian discovers that a child has provided us with personal data, please contact playstore@diouane.com immediately, and we will delete the data without delay.

29. Managing App Permissions in Android

Android operating systems provide users with direct, granular control over permissions:

Notification Access: Grant or revoke anytime via Settings > Apps > Special App Access > Notification Access.

Media & Storage: Adjust via Settings > Apps > [App Name] > Permissions > Photos & Videos.

Alert Notifications: Customize or silence notifications via Settings > Apps > [App Name] > Notifications.

30. Application Uninstallation & Local Database Purge

When you uninstall any of our Android applications (such as Realert, Esato, or Flappy Ball), the Android OS completely and irrevocably purges all local sandboxed databases, cached notification snippets, and application preferences from device memory.

31. External Links & Third-Party Platforms

Our website and applications may display links to external websites, developer tools, social networks, and app marketplaces (including Google Play, GitHub, Discord, and YouTube).

We do not control and are not responsible for the privacy practices, content, or policies of third-party platforms. We encourage you to review their individual privacy statements.

32. Courses & Educational Mentorship via Diouane.com

Diouane.com offers practical technical training, including 1-on-1 Blogging Mentorship (delivered via Discord) and software tutorials:

Registration Details: Upon purchasing training, we collect your name, email address, Discord handle, and payment transaction receipt.

Mentorship Communications: 1-on-1 Discord training sessions are conducted confidentially to coach you through technical blogging, SEO architecture, AdSense configurations, and monetization setups.

Payment Processing: Transactions are handled through certified third-party payment gateways. We never receive, process, or store credit card numbers on our infrastructure.

33. Educational Nature of Training Services

All courses, guides, and mentorship sessions are provided solely for educational and skill-building purposes.

Mentorship represents technical coaching; it does not constitute employment, partnership, financial advice, or investment counseling.

34. Earnings Disclaimer & No Financial Promises

We make NO promises, projections, or guarantees of financial earnings, traffic numbers, or ad revenue from blogging, AdSense, or app development.

Monetary outcomes depend entirely on individual technical competence, effort, market dynamics, niche selection, and external search engine / store algorithms. Case studies and past performance cited in lessons serve solely as educational examples and do not guarantee future success.

35. Independent Platform Policy Evolution

Third-party corporations (including Google LLC, Google AdSense, Google Search, Google Play, Blogger, and Discord) continually modify their algorithms, technical guidelines, and approval policies.

Diouane Entertainment has no influence over external platform decisions, and we cannot guarantee that any specific blog or application will be approved or monetized by third-party services.

36. Course Updates & Content Evolution

We continually update and refine training materials to reflect contemporary developer tools and search industry standards. We reserve the right to revise curriculum modules, replace outdated workflows, or publish updated materials without compromising the core value of purchased training.

37. Course Access Duration & Continuity

Access to purchased courses or mentorship programs is granted for the specific term indicated at enrollment:

Personal Discord mentorship covers the active training duration agreed upon at purchase.

Online course materials remain accessible for as long as the learning platform is maintained by the studio. In the event of planned portal deprecation, active students will be provided reasonable advance notice.

38. Digital Content & Mentorship Refund Policy

Because our educational offerings provide immediate access to proprietary digital frameworks, code assets, and 1-on-1 mentorship time:

Digital Downloads & Tutorials: Sales are non-refundable once access credentials or materials have been delivered, in accordance with applicable digital consumer protection statutory provisions.

Mentorship Sessions: Once 1-on-1 Discord training has begun, fees are non-refundable. Cancellations requested before the initial session may receive a refund minus administrative gateway fees.

Contact blog@diouane.com for any billing or refund inquiries.

39. Pricing, Currencies & Payment Processing

Course fees are clearly stated in Moroccan Dirham (MAD) or US Dollars (USD). We reserve the right to revise pricing for future cohorts without affecting previously confirmed registrations.

All payments are processed securely through certified PCI-compliant gateways.

40. Personal Single-User Educational License

Enrolling in a course grants you a limited, non-exclusive, non-transferable, revocable single-user license to review educational content for personal learning.

This license is strictly personal and may not be transferred, shared, or assigned to another individual.

41. Prohibited Uses of Course Content

Students and purchasers strictly agree NOT to:

1. Screen record, download, reproduce, or publicly redistribute video or written lessons.

2. Share Discord access credentials or course login links with unauthorized third parties.

3. Resell, white-label, or commercially exploit our proprietary curriculum or code templates.

4. Deploy automated scrapers or bots against our learning resources.

Violations will trigger immediate revocation of access without refund and potential civil litigation for copyright infringement.

42. Intellectual Property & Copyright

All curriculum, code architectures, written guides, diagrams, audiovisual recordings, and trademarks associated with our services are the exclusive intellectual property of Mohamed Diouane / Diouane Entertainment.

All rights not expressly granted under these terms are fully reserved.

43. Lawful & Ethical Use of Educational Knowledge

Skills and techniques taught across our tutorials must be applied strictly in compliance with all relevant laws and platform terms of service.

We strictly condemn and refuse to support click fraud, black-hat SEO manipulation, unauthorized data scraping, or copyright infringement.

44. Third-Party Platform Decisions & Account Actions

Application approvals on Google Play, blog monetization via Google AdSense, and search ranking on Google are determined solely by Google LLC.

Diouane Entertainment is not liable for account suspensions, traffic fluctuations, or policy enforcement actions enacted by third-party platforms.

45. Non-Affiliation with Google LLC & Third Parties

Diouane Entertainment is an independent software studio. We are NOT affiliated with, sponsored by, authorized by, or an official representative of Google LLC, Alphabet Inc., Discord Inc., or any other third-party corporation.

Trademarks including Android, Google Play, Google AdSense, and Blogger belong to their respective holders and are used solely for descriptive and compatibility identification.

46. Limitation of Studio Liability

To the maximum extent permitted under applicable law, Diouane Entertainment shall not be liable for any indirect, incidental, special, consequential, or punitive damages—including lost profits, ad revenue loss, or data disruption—arising from the use of our applications, courses, or website.

Where mandatory consumer protection laws prohibit certain exclusions, our liability is restricted to the maximum extent permitted by applicable statutes.

47. Technical Content Accuracy & Disclaimer

While we strive to provide reliable and accurate technical guides, software environments and web standards change frequently.

All content is provided on an "as is" basis without warranties of uninterrupted completeness. Developers should always test code within their own staging environments.

48. Force Majeure & External Disruptions

Diouane Entertainment is not responsible for performance failures or delays resulting from causes beyond reasonable control, including cloud infrastructure outages (Google Cloud, Vercel), fiber cable cuts, cyber attacks, civil unrest, or statutory prohibitions.

49. Consumer Protection in Morocco (Law 31-08)

Transactions involving consumers in Morocco are interpreted in compliance with Law No. 31-08 enacting consumer protection measures, preserving all non-waivable statutory rights.

50. Consumer Rights for European Union Residents

Consumers residing in the European Union retain all mandatory consumer rights afforded by EU consumer protection directives and national consumer statutes.

51. Preservation of Mandatory Statutory Rights

If any term in this policy is adjudicated to be invalid or unenforceable, that specific clause shall be severed without impairing the validity of the remaining provisions.

52. Modifications to Applications & Digital Services

We reserve the right to deploy updates, enhance features, modify systems, or deprecate software to maintain security, improve compatibility, or adapt studio roadmaps.

53. Updates to This Privacy Policy

We may update this policy periodically to reflect product changes, technical enhancements, or legislative updates.

The "Last Updated" timestamp at the top of this document denotes the active revision date. Continued usage constitutes acceptance of updated terms.

54. Special Information on the Right to Object (Art. 21 GDPR) & Exercising Rights

Right to Object on Grounds Relating to Your Particular Situation: If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) sentence 1 f) GDPR, you hold the unconditional right under Art. 21 GDPR to object to such processing at any time for reasons arising from your particular situation.

Right to Object to Direct Marketing: If personal data is processed for direct advertising or marketing purposes, you hold an absolute right to object at any time without providing reasons. Upon receiving your objection, we will immediately cease processing your data for these purposes.

Exercising Your Rights: To exercise your right of revocation, objection, erasure, or access, simply send an email specifying your request to our data protection contact at playstore@diouane.com (for mobile applications) or blog@diouane.com (for web services and courses).

You may also submit automated erasure requests at any time via our official Data Deletion Portal at https://diouane.com/deletion

55. Data Controller & Data Protection Contact Details

To exercise any of the rights articulated in this privacy policy, or to submit questions, inquiries, or complaints regarding the handling of your personal data, you may contact our designated privacy controller:

Data Controller: Diouane Entertainment (Mohamed Diouane)

Contact Person: Mohamed Diouane

Applications, Google Play & Account Erasure: playstore@diouane.com

Diouane.com Web Services & Editorial Desk: blog@diouane.com

Online Deletion Portal: https://diouane.com/deletion

Official Website: https://diouane.com

Country of Registration & Governance: Kingdom of Morocco

56. Official External Resources & Policy Frameworks

For further reference on regulatory frameworks and platform policies, consult the official resources below:

1. Google Privacy Policy: https://policies.google.com/privacy

2. Google Play Developer Program Policies: https://play.google.com/about/developer-content-policy/

3. How Google Uses Information from Partner Apps: https://policies.google.com/technologies/partner-sites

4. EU GDPR Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj

5. Morocco CNDP Official Portal: https://www.cndp.ma/

Addendum: Diouane Blog Android Application (com.diouane.diouaneblog)

Specific Addendum for Diouane Blog App (com.diouane.diouaneblog): This section governs the official mobile blog reader app and must be read alongside the complete Privacy Policy above.

Firebase Infrastructure: The production release incorporates Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, and Firebase Cloud Messaging (FCM). Telemetry includes randomized installation IDs, app versions, OS version, device model, crash stack traces, startup latencies, and network performance metrics to diagnose crashes and maintain high stability.

Push Notifications: Firebase Cloud Messaging sends notifications for newly published tutorials. No phone numbers or private emails are collected for notification dispatch.

Local Storage & Home Screen Widget: The app stores font preferences, visual theme, offline reading caches, and headline summaries locally on device. The Android Home Screen Widget accesses this local cache to display recent articles.

No Central Account: The Diouane Blog app does not require account creation. Clearing app data or uninstalling the app permanently purges all local cached data.

Support Contact: playstore@diouane.com

DiouaneENTERTAINMENT

Building useful technology.
Sharing what we learn.

Google Play GitHub

Our company

About DiouaneContact usBlogDocumentation

Apps & games

EsatoFlappy BillRealertExplore all apps

Build & learn

App developmentGame developmentBlogging & BloggerCybersecurity

Support & legal

Help centerPrivacy policyTerms of serviceDisclaimerData deletion
© 2026 Diouane Entertainment
EnglishSitemapBack to top