Who is responsible for your information
Operator. Roya operates the creator-clipping marketplace at royaapp.co. Brands publish campaigns, creators make short-form videos and post them on their own social accounts, and creators are paid for verified views. Roya decides what personal information is collected on the platform and why, and is responsible for it. In this policy, "Roya", "we" and "us" mean the operator of royaapp.co. Roya is a product of Hola Mundo Graphic Design, an individual establishment registered in the Kingdom of Bahrain under Commercial Registration number 135131-1. Its registered address is in the Contact section at the end of this document.
Payment provider. Roya's payment services provider is Tap Payments. Where a payout is made by bank transfer instead, it is executed by Roya's finance staff through a bank in Bahrain. Roya never holds your money and does not operate a wallet: our records show who is owed what, and the money sits with the payment provider or the bank.
Contact. For anything in this policy — a question, a request to see, correct or delete your information, an appeal against an automated decision, a complaint, or a report of a security problem or suspected data breach — write to founder@royaapp.co. A person reads it. None of it costs you anything.
Where Roya is available. Roya is a website. There is no released Roya mobile app. We will update this policy before one collects anything.
Languages. This policy is published in Arabic and English. If you find a difference between the two versions, tell us at founder@royaapp.co and we will correct it.
The short version
- There is no advertising, no analytics package, no tracking pixel, no session recording and no cross-site tracking anywhere in Roya. There is no cookie banner because there is nothing optional to consent to, and no part of the site is gated behind accepting cookies.
- We do not send marketing, and we do not sell personal information. We never have.
- Card details and the documents our payment provider asks you for never pass through Roya's systems. But we do hold identity-type documents ourselves: the advertising licence document a creator uploads where a country requires one, and anything you attach to an appeal.
- A deletion request now erases your account — 14 days after you make it. You can cancel at any point in those 14 days, and one thing is destroyed straight away and not restored by cancelling: the access tokens for your connected social accounts, which you would link again yourself. After the 14 days, your uploaded files, your sign-in credentials and your bank details are deleted outright, and your name, email address, phone number and social handles are overwritten in place. Money, fraud, verification and audit records are kept, without your identity attached, and several kinds of record cannot be reached at all. Section 15 sets out exactly what goes and what stays.
- Several kinds of record cannot be changed or deleted by anyone, including us — the database itself blocks it. An erasure cannot reach them either. Some of them contain personal information, and after an erasure we block access to it rather than removing it.
- An automated score can flag your clip and hold it out of approval with no person involved, and payouts can be held automatically. A flag in the highest band can only be cleared by a person, and you can require a person to look again, free of charge.
- Your information is processed outside Bahrain and outside Saudi Arabia, and some of it sits on storage we cannot pin to a single country.
- Where a country's advertising rules require it, your regulatory licence number appears in the post you publish yourself, and so becomes public.
- Once a contest's results are published, the leaderboard is public — handles, ranks and judge scores, visible without signing in.
- Some of what this policy describes is not yet switched on. Section 2 lists what, rather than leaving you to assume it is all running.
1. Section map
Sections 3 to 9 describe what we collect and who gets it. Sections 10 to 13 cover security, why we are allowed to process, marketing and cookies, and where your information is held. Sections 14 and 15 cover retention and what deleting your account actually erases. Sections 16 to 19 cover your rights, age, country rules and platform notices, and how to complain. Section 20 covers how we change this policy, and section 21 has our contact and registration details.
2. What is not yet switched on
We would rather tell you this than write the rest of the policy in a present tense it does not deserve.
- Instagram and TikTok connections are not offered. Both are switched off, and no Roya system reads an Instagram or TikTok view count. Today, view verification runs on YouTube (automatically) and Snapchat (by hand).
- There is no Roya mobile app and no push notification. We hold no device push token for you. Messages reach you in the platform and by email only.
- Our scheduled background jobs are not yet provisioned. The repeated reading of view counts described in section 6, the automatic deletion schedule in section 14, and the nightly account-erasure sweep in section 15 all run as scheduled jobs. Until that infrastructure is live, they describe what the system is configured to do rather than something happening every night. This matters most for deletion: a request is recorded and its 14-day clock starts, but the erasure itself only happens once that sweep is running.
- Our payment integration has not been exercised against Tap's live service. Section 7 describes what we send Tap when you become eligible for a payout. If Tap's own requirements turn out to be broader than that, we will update this policy before sending anything more.
We will change this policy before we turn any of these on.
3. What we collect, why, and what is mandatory
Where a field is mandatory, refusing it has a consequence, and that consequence is stated.
3.1 Your account
| What | Mandatory? | Why |
|---|---|---|
| Name | Mandatory | Identifies your account, and is the payout destination name we send to our payment provider |
| Email address | Mandatory | Your sign-in identity and the address every service message goes to |
| Password, a passkey, or a sign-in provider | Mandatory (at least one) | Authenticating you |
| Language, Arabic or English | Mandatory, defaulted | Sets the interface and the language of your emails |
| Account type and organisation role | Mandatory | Decides what you can see and do |
| Phone number | Optional | Recorded for payout and verification contact. Roya staff can search accounts by phone number, and it appears in internal staff lists |
| Profile image | Optional | Display only |
| Account status | Automatic | Active, suspended, deletion-requested, or erased |
| IP address and browser or app user agent of each sign-in session | Automatic | Account security and abuse detection |
| The email address used to request an invite code | Mandatory to request one | Private-beta access control. This record is kept even if you never finish signing up, so support can trace what happened |
Without the mandatory items we cannot create or secure an account.
If you use a password, we store a cryptographic hash of it and never the password itself. If you register a passkey, we store its public key, its credential identifier, and the device type. If you sign in with a provider such as Google, our sign-in system stores that provider's account identifier and the tokens it issues — see section 4 for an important limitation on how those particular tokens are held.
3.2 Creator profile, age and advertising licence
Collected once, when you complete creator onboarding:
- Country of residence — mandatory. It decides which campaigns you see and which country's advertising rules apply to your posts.
- Date of birth — mandatory. The full date is stored, not just a yes-or-no answer about being over 18.
- Languages — mandatory, for matching you to campaigns.
- Tax status and payout currency — mandatory.
- Advertising licence type, licence number, expiry date and the licence document you upload — mandatory where the country you post from requires a licence.
Refusing any of these means you cannot complete creator onboarding and cannot take part in campaigns.
These answers are recorded once. There is no screen in the product for editing them afterwards, and onboarding cannot be run a second time. Corrections are made by us, by email — see section 16.
The licence document is uploaded to Roya's own file storage at Cloudflare R2 and reviewed by a member of our compliance staff, who records a decision and a note. It is not held by our payment provider. It is deleted when your account is erased — that is the only thing that deletes it, and it deletes every file you uploaded rather than this one alone. See section 15.
Roya performs no biometric processing. There is no selfie capture, no face match and no liveness check anywhere in Roya's systems, and we do not ask you for a passport or a national identity card. Anything our payment provider asks you for within its own verification process is governed by that provider's own terms and privacy notice. If you attach an identity document to an appeal, it is stored with that appeal.
3.3 If you work for a brand
We store your organisation's legal name, country, billing email and logo, and the name, email address and role of each person invited into the organisation. Legal name and billing email are needed to run and bill the organisation. Commercial registration number, VAT number and billing address are optional — you can operate an organisation without them, though an invoice will be less complete.
When an invoice is issued we store a frozen copy of the organisation's legal details as they stood on that date. That copy is never updated, because an invoice has to stay accurate as a historical record.
3.4 Product feedback
After a payout we may ask you one question about how it went, with an optional free-text comment. Answering is voluntary and nothing depends on it. The comment has a retention period — see section 14.
4. Connected social accounts
To submit a clip you connect the account you will post from. For a connected account we store the public handle, the platform's own account identifier, the permissions granted, the token expiry, the date the account was created (it feeds one of the fraud signals in section 8), and how ownership was proven.
We never post, edit, delete or hide anything on your accounts. We do not read your direct messages. We do not look at media you have not submitted to a campaign.
YouTube — offered today. We do not ask you to sign in to Google, and we hold no Google authorisation for your channel. You prove the channel is yours by putting a short code we generate into your channel description; we read that description once to check it. The code is stored in readable form on purpose, because it is meant to be published. After that we read only the public statistics of the specific videos you submit, using YouTube API Services under our own developer key.
Snapchat — offered today, and manual. There is no automated connection. You supply screenshots, a member of our team reads the figures from them, and their identity is recorded against the entry. Those screenshots are stored in our file storage.
Instagram and TikTok — not yet offered. Both connections are switched off and no Roya system reads their view counts. Where an Instagram connection exists at all, the only request we make reads the account identifier, username and account type.
Encryption, stated accurately. Where we hold access and refresh tokens for a connected posting account, they are encrypted at rest with AES-256-GCM under keys we can rotate. That is not true of every token we hold. The tokens our sign-in system stores when you sign in with a provider such as Google sit in ordinary database columns without that extra layer. We would rather tell you that than write a sentence about "all tokens" that is untrue.
While a connection is being set up we briefly store the technical values that keep the exchange secure, including a verifier held in readable form by deliberate design. They expire in ten minutes and can be used once. They are also scheduled for deletion after seven days, by one of the background jobs that is not yet running (section 2).
Disconnecting. You can disconnect a social account. We destroy our copy of the tokens and ask the platform to revoke them. Disconnecting stops view verification for that account, and views we cannot verify do not earn. That is the cost of disconnecting, and you should weigh it before you do it.
5. Submissions
When you submit a clip we store the public URL of your post, the platform's identifier for it, which connected account it came from, the campaign, the time you submitted it, the rate per thousand views that applied at that moment, and the review outcome. If a reviewer rejects your clip, the reason is stored exactly as the reviewer typed it and you see it in full.
We also store the event history of a submission, any appeal you file including your written statement and uploaded evidence, and — in contest campaigns — the score each judge gave your clip against each judging criterion.
6. How views are verified, and what we store
Our system is configured to read the public statistics of the post you submitted — views, likes, comments and shares — repeatedly for as long as the campaign's verification window for that clip is open: hourly for the first 72 hours after submission, then every six hours. This is designed as ongoing polling, not a single reading. As section 2 explains, the scheduled-job infrastructure that performs it is not yet provisioned, so this is the configured behaviour rather than a service already running.
Two things about it you should know plainly.
- Each check writes a permanent snapshot holding the counts at that moment, the time of the check, and the platform's response stored word for word. That verbatim response contains whatever the platform chose to send about your post and, sometimes, about the account that published it. For Snapchat, the snapshot instead holds the screenshots supplied and the name of the staff member who entered the figures.
- These snapshots cannot be edited or deleted by anyone, including our own administrators. The database blocks it. They are the evidence for what you were paid, and payment evidence that can be quietly edited is worthless. It also means we cannot remove the raw platform responses inside them.
7. Money, payouts and the ledger
Identity verification. Before a creator can be paid, identity verification is carried out by Tap Payments, not by Roya. When you become eligible for a payout, Roya sends Tap your name, your email address and Roya's own internal identifier for you. Card details and any documents Tap asks you for go to Tap directly and do not pass through Roya's systems. As section 2 says, this integration has not been exercised against Tap's live service; if Tap requires more than those three items, we will update this policy before sending anything more. Until your verification status is approved, payouts are blocked.
Rejection reasons. If verification is refused, Roya deliberately does not store the payment provider's own wording. The reason is first mapped into Roya's own fixed list of reason codes, and only that code is written to our records.
Bank details. Your IBAN is stored encrypted with AES-256-GCM under a rotatable key. Only the last four digits are kept in readable form, for masked display to staff. The account holder name, bank name and account country are stored in readable form. Your full IBAN is never written to a log.
How the money reaches you, and who sees your IBAN. A payout can be executed through our payment provider, or by bank transfer. On the bank route, our finance staff export a file containing your full IBAN in plain text, along with the account holder name, bank name, amount, currency and reference, and submit it to a bank in Bahrain. The encryption protects your IBAN in our database; it is decrypted for that export. That receiving bank is a recipient of your bank details.
Payout records. We store the amount, currency, method, status, the payment provider's reference, the reason if a payout failed, every reason it was held for review, and the written explanation the staff member gave when resolving a hold — which is shown to you.
The ledger. Every movement of money is recorded in a double-entry ledger, linked to you by Roya's internal identifier rather than by name. Ledger records are permanent. A correction is made by adding a reversing entry, never by editing the original.
8. Automated checks and decisions
Some decisions about you are made automatically. These are exactly which.
Fraud scoring. Every submission is scored at intake against six signals: an unusually low ratio of engagement to views; a sudden spike in view velocity; a very new posting account; content that duplicates another submission; a pattern that looks like probing a campaign's payout cap; and an anomaly in the verification evidence. They combine into a single score from 0 to 100. The weights, thresholds and bands are configured by Roya, versioned, and recorded against every decision they produce.
- A score in the review band raises a flag for a person to look at. A flag in this band can clear automatically if nobody has picked it up and the score falls back below a lower band.
- A score in the higher band flags your clip and withholds it from approval automatically, with no person involved in that decision. A flag in this band is never cleared or downgraded by the system — only a Roya administrator can clear it.
Profiling that follows you between campaigns. We keep a fraud record about you as a creator, holding a strike count, the date of your last strike, and any probation period. It is checked every time you submit. Clips are also grouped into duplicate clusters, and brands are alerted to fraud patterns on their own campaigns.
Automatic payout holds. A payout is placed on hold automatically where your identity verification is not yet approved, where it is your first payout, where the amount is at or above the review threshold Roya has set (currently BD 100), or where you have an open fraud flag. There is also a random sampling rule, which is currently switched off. There is a minimum payout request amount, currently BD 5. Every reason that matched is recorded on the payout with the version of the rules that produced it.
The hold is automatic; the decision is human. A held payout is released or refused by a person, who must record a written rationale, and that rationale is shown to you. Our internal target for resolving a hold is 48 hours.
Are decisions made solely by automated processing? Yes for flagging a clip in the higher band and for placing a payout on hold. No for the final outcome: approval, rejection, clearing a high-band flag and releasing a hold are all made by a person.
Your right to a person. You can require that an automated decision affecting you be reconsidered by a person. Reconsideration is obligatory on us and free of charge. Use the appeal route in the platform — an appeal requires a written statement from you and lets you attach evidence — or write to founder@royaapp.co. Appeals are decided by Roya staff, never by the brand whose campaign you posted for.
Derived figures. We calculate your approval rate, your earnings over time and your results per campaign and per platform. These are shown to you and used internally to run the platform.
9. Who receives your information
Brands
A brand running a campaign you submitted to can see your social handle, the public URL of your post, the verified view and engagement figures, your submission and approval history for that campaign, whether a submission has been flagged, and the amount you earned on that clip. In a contest campaign, they also see judging scores.
A brand cannot see your email address, phone number, date of birth, licence number, licence document, verification status, bank details, the last four digits of your IBAN, or Roya's internal identifier for you. What a brand does with what it exports is that brand's responsibility.
The public
Contest leaderboards. Once a contest campaign's results are published, the leaderboard is accessible without signing in. Anyone holding the campaign identifier can see every approved creator's handle, platform, rank and per-criterion judging scores. The judges' identities are not published. If you would rather that were not public, do not enter contest campaigns.
Your own post. Where a country's advertising rules require a licence number in the content itself, the disclosure text we generate for you contains it — see section 18.
Service providers and other recipients
| Recipient | Role | What it receives |
|---|---|---|
| Tap Payments | Payments, payouts, identity verification | Your name, email address and Roya's internal identifier for you; plus anything you give Tap directly |
| A receiving bank in Bahrain | Executing bank payouts | Your full IBAN in readable form, account holder name, bank name, amount, currency and reference |
| Supabase | Our primary database | Everything this policy says we store |
| Vercel | Hosting and running the website | Requests to the service, and logs that carry Roya's internal identifiers for you and your organisation |
| Cloudflare | File storage (R2) and video (Stream) | Your licence document, Snapchat verification screenshots, appeal evidence, and brand assets |
| Resend | Sending email | Your email address, your language, and the content of each message |
| Trigger.dev | Running background jobs | Job data including internal identifiers and, for the job that revokes a social token, a still-encrypted copy of that token |
| Sentry | Error reporting | Filtered error reports, as described in section 10 |
| YouTube (Google) | The platform you post on | Requests about the public videos you submit |
We also disclose personal information where the law requires it, where a competent court or the Public Prosecution orders it, and where it is necessary to bring or defend a legal claim, such as a payment dispute.
We do not sell personal information, and we do not share it with advertisers or data brokers.
Information we get about you from someone else
Not everything we hold comes from you.
- From YouTube: for the videos you submit, the view, like, comment and share counts, the post identifier, public metadata about the post, and your public channel identity and creation date.
- From Tap Payments: your identity verification status and, where applicable, a rejection reason mapped into Roya's own list of codes.
- From the bank or payment rail: the outcome of a payout instruction.
This policy is your notice of that collection, of what it covers, and of where it comes from. If another platform is enabled in future, the same categories will come from that platform, and we will update this policy first.
10. Security, support and operational records
- Audit records. We write an audit record of administrative actions taken inside Roya and of attempts to do something the actor was not permitted to do. Each record holds who acted, what they did, what the data looked like before and after, the IP address and the user agent. Requesting deletion of your account is itself such an action and creates such a record. Audit records are permanent and cannot be changed or deleted by anyone, including us. The honest limit: the recorder is deliberately built so that it never blocks the action it is recording, so if writing the record fails, the action still goes ahead and the failure is reported to our error monitoring instead.
- Identity re-checks before sensitive account changes. Asking us to delete your account, and adding a new passkey to it, both require you to prove it is you first — by re-entering your password, or by typing a six-digit code we email to your address. Every attempt, successful or not, is recorded with the IP address and the user agent it came from, so that an attempt you did not make leaves a trace. Two different records are involved, and they are kept for different lengths of time. The challenge record itself — the one holding the attempt and its IP address — is not permanent: it is deleted automatically 30 days after the attempt. But a FAILED attempt also writes one of the permanent audit records described in the bullet above, and that record carries the IP address and the user agent too. So the trace of a failed identity check is permanent and cannot be deleted by anyone, including us; only the trace of a successful one expires after 30 days.
- Staff access to your account. A staff member can be granted temporary access to see your account as you see it, in order to help you. That access is read-only and enforced as read-only by the database, expires automatically after 30 minutes, requires a written reason recorded up front, cannot be used against another staff member's account, and records its own IP address and user agent.
- Internal staff lists. Two internal screens let Roya staff list every registered creator and every brand owner, with names, email addresses, phone numbers and lifetime earnings. Access is limited to Roya staff and its use is auditable. You should know that surface exists.
- Error reports. Errors are reported to Sentry with the automatic attachment of personal data switched off, performance tracing switched off, and session replay switched off — Sentry never records your screen. Before anything is sent, a filter removes fields whose names indicate a token, secret, verifier, password, signature, cookie or key, and fields indicating an email address, phone number, date of birth, licence number, IBAN, account number or national identity number.
- Hosting logs. Our hosting provider records requests to our servers. Those logs deliberately carry Roya's internal identifiers for you and your organisation, so that a fault can be traced back to the account it affected. They do not carry your name, email address or financial details.
- Background job reports hold error names, messages and summaries, passed through the same filter.
- Rate limiting. To stop password guessing and abuse we keep short-lived counters, often keyed on an IP address and a request path.
- Webhook records. Automated messages from our payment provider, our email provider and social platforms are stored word for word so that payment and delivery problems can be investigated. Where a message fails its signature check, only the failure reason and the length of the message are stored — never its contents.
How we protect your information, and the limits
- Field-level encryption. Your IBAN and the tokens for connected posting accounts are encrypted at rest with AES-256-GCM under rotatable keys. Your full IBAN is never logged, and even its last four digits are on the redaction list.
- What that does not cover. The tokens our sign-in system holds for third-party sign-in providers do not have that extra layer. Encryption of the database as a whole is provided by our hosting provider. Our finance staff decrypt your IBAN to run a bank payout.
- Authorisation in code. Requests that touch your account or your organisation's data are checked against your role and your organisation before they are allowed, and refused attempts are written to the audit record, subject to the limit noted above. A small number of endpoints are deliberately public and need no sign-in: the sign-in session check, public campaign pages, public organisation pages, and published contest leaderboards.
- Records that cannot be tampered with, as described in sections 6, 7 and 15.
No system is perfectly secure, and we do not claim ours is.
If a personal data breach happens
We will notify the Personal Data Protection Authority in Bahrain within 72 hours of becoming aware of a personal data breach, unless the breach would not affect the rights of data subjects. Where Saudi law applies, we will notify the Saudi Data and Artificial Intelligence Authority within 72 hours. Where a breach may cause you damage, we will tell you directly, without undue delay.
If you think you have found a security problem in Roya, or want to report a breach or a suspected violation to us, write to founder@royaapp.co.
11. Why we are allowed to use your information
| What we do | Why we are allowed to |
|---|---|
| Run your account, show you campaigns, accept submissions, verify views, calculate and pay what you are owed | Necessary to perform our contract with you |
| Verify your identity before paying you, and check your advertising licence | Necessary to perform our contract with you, and our legitimate interest in not sending money to someone we cannot identify. Our payment provider requires verified identity before it will release a payout |
| Detect fraud, duplicate content and abuse, and hold suspicious payouts | Our legitimate interest in protecting brands, honest creators and Roya. Saudi law expressly names detecting fraud and protecting network and information security as legitimate interests |
| Keep audit, security and financial records | Our legitimate interest in being able to prove what happened and be accountable for what our staff did, and our need to keep proper financial records as a business that pays people |
| Send you service, security, money, compliance and administrative messages | Necessary to perform our contract with you |
| Optional digest emails and the payout feedback survey | Your consent, withdrawn by switching the setting off or by emailing us |
We do not claim that a financial regulator obliges Roya itself to verify your identity. That requirement comes from our contract with you and from our payment provider.
We do not rely on your consent for anything you cannot switch off. That is deliberate: consent you withdraw would oblige us to stop, and your account could not function. And we do not make consent to unrelated processing a condition of using the service.
12. Marketing, notifications and cookies
Direct marketing: we do not do it. Roya does not use your personal information for direct marketing, profiling for marketing, or any advertising purpose, and does not pass it to anyone else to market to you. There is nothing to opt out of.
If that ever changes, we will ask for your separate, specific consent first, given through its own control and never bundled into signing up. We would identify ourselves in every message, every message would carry a way to stop them, and you could withdraw that consent at any time, free of charge, with no effect on the rest of your account.
Notifications. You can switch off campaign updates, submission updates and the digest. You cannot switch off messages in the security, compliance, money and administrative categories, because they concern the safety of your account, your payments and your legal position with us. Messages reach you in the platform and by email. We do not send push notifications and we hold no device push token for you.
Cookies. Roya sets only strictly necessary cookies: the cookies our sign-in system uses to keep you signed in, a short-lived security cookie during a third-party sign-in, and a cookie that remembers whether you want Arabic or English. There is no advertising, analytics or tracking cookie, and therefore no consent banner. No part of Roya is gated behind accepting cookies.
13. Where your information is held
Yes: your personal information is transferred to, and processed in, locations outside Bahrain and outside the Kingdom of Saudi Arabia. This is what we can state accurately.
- Our primary database is configured to be provisioned in the region nearest Bahrain. The exact provider region is recorded when that account is created; we will name it here once it is.
- Files you upload — your licence document, Snapchat verification screenshots and appeal evidence — are stored on Cloudflare R2, which distributes objects across a global network. Cloudflare does not offer us a way to pin them to a single country. We tell you this rather than implying your documents stay in Bahrain, because they do not.
- The operating regions of our error reporting, email delivery, background job and hosting providers, and our payment provider's contractual data-centre region, are not yet fixed and recorded. We will not name countries for them, because we would be guessing. When each is fixed, we will name it here.
Bahrain. Personal data may be transferred out of Bahrain to a country or territory on the record maintained by the Personal Data Protection Authority. That record is the schedule to the Order of the Minister of Justice, Islamic Affairs and Waqf No. (42) of 2022, and transfer to a listed destination needs no prior authorisation. The schedule lists 83 countries and territories, including the United States, Germany, the United Kingdom, the United Arab Emirates, the Kingdom of Saudi Arabia and the European Union member states. Because our file storage offers no region pinning, we do not claim that every location holding your uploaded files falls within that record. Where a transfer is not covered by it, we rely on the contractual protections in our agreement with the provider concerned and on the transfer being necessary to perform our contract with you.
Saudi Arabia. Transfers outside the Kingdom are made because they are necessary to run your account, verify your clips and pay you. Each recipient gets only the minimum it needs to perform its function. We do not assert that any specific destination has been assessed as providing an adequate level of protection.
14. How long we keep things, and how they are destroyed
The fixed periods our system defines:
| What | Period |
|---|---|
| The free-text comment on a payout survey | 24 months, then emptied |
| Background job diagnostic reports | 30 days if the job succeeded, 180 days if it failed |
| Rate-limiting counters, which can include an IP address | 7 days |
| In-progress social-connection values, including the security verifier | 7 days; the values themselves expire in 10 minutes and work once |
| Unproven YouTube channel claims | Removed where verification is never completed |
An honest note about all five. Each is carried out by a scheduled background job, and as section 2 says, that infrastructure is not yet provisioned. Until it is, data in these categories may remain beyond the periods stated. We publish the periods because they are the rules we are building to, not as a claim that the deletions have already happened.
Everything else — your account record, creator profile, date of birth, phone number, licence details and licence document, bank details, submissions, view snapshots, payouts, invoices, ledger records and audit records — has no automatic expiry in our systems today. We keep it for the life of your account and afterwards for as long as we need it to complete, evidence and reconcile payments including any dispute, to evidence a fraud decision or defend a claim, and for as long as any financial, tax or accounting record-keeping requirement that applies to us requires — counted from the end of our relationship with you or the date of the transaction, whichever is later. Where a legal requirement obliges us to retain a record for a set period, we retain it for that period. We are not printing a number we have not verified against the instrument that binds us; the test above is the test we actually apply. A deletion request changes that. Ask us to delete your account and, 14 days later, most of that list is deleted outright or overwritten in place — section 15 says exactly which parts, and which parts survive because we are required to keep them or unable to reach them.
How things are destroyed when they are destroyed. Records in our database are deleted outright, or overwritten in place with a placeholder, or — in the case of the survey comment — emptied. The files in our verification evidence storage now have a deletion path: erasing an account deletes every file that belongs to you — the licence document, Snapchat screenshots and appeal evidence — by clearing out the storage that belongs to you and then listing it again to prove it is empty. Outside an account erasure there is still no way to delete an individual evidence file, and the only files that can be removed one at a time are brand assets, removed by the brand that uploaded them.
Where we now meet that rule, and where we still do not. Bahraini law requires that personal data kept beyond the purpose it was collected for be held in anonymous form, or failing that with the identity of the person encrypted. An account erasure now does the first of those for the records it can reach: your account record itself is overwritten with a placeholder, so every retained ledger, payout, invoice and verification record points at an anonymised account rather than a named person. It does not reach inside audit records or view snapshots. Those tables cannot be changed by anyone, so a personal value already written into one of them — an IP address, a user agent, a name or licence number captured in the before-and-after of an admin action, a handle inside a platform's verbatim response — stays exactly as it was written. We do not anonymise it and we do not encrypt it. We block access to it instead, which is a smaller thing, and section 15 says so plainly.
15. Deleting your account — the 14-day grace period, and what erasure removes
You can request deletion in your account settings, or by writing to founder@royaapp.co. In your account settings we ask you to confirm it is you first — your password, or a 6-digit code we email you. If you sign in only through another provider and cannot receive that email, write to us at the address above and we will handle it by hand.
The first 14 days: your social connections are cut, and nothing else is destroyed yet
The moment you ask:
- Your account is marked as deletion-requested, and a 14-day clock starts. You can still sign in and use Roya during those days — deliberately, so that you can cancel — but we stop refreshing your connected social accounts and we stop asking you the payout survey question, so that you are not invited to write anything new about yourself.
- The access and refresh tokens for your connected social accounts are destroyed — the encrypted values are overwritten with nothing — and those connections are marked revoked. Roya loses its access to your social accounts. This one happens immediately and is not undone by cancelling.
- An audit record of the request is written. As section 10 explains, it captures the IP address and user agent of the request, and it is permanent.
- We send you a confirmation email.
Apart from those tokens, nothing is erased until the 14 days are up. Your account settings show the date. The window exists because erasure is irreversible, and because cancelling does not bring back the social-account connections cut on the first day. Asking to delete your account now requires you to prove it is you first — either your password, or a 6-digit code we email you and you type back into the same browser — so that a stolen sign-in session cannot start this on your behalf.
Cancelling during those 14 days
There is a Cancel button in your account settings, and it works at any point until an erasure run has actually begun. Cancelling puts your account back to active and stops the erasure. It does not reconnect your social accounts — those tokens were destroyed on the first day — and you would link them again yourself.
One limit is worth knowing, because the button reports that nothing is pending rather than explaining itself: it stops working once an erasure run has claimed your account, which is correct — by then your files may already be gone. Suspending and reinstating your account during the window no longer affects it. The button, the date you are shown and the erasure itself all read the same record, so a change to your account status cannot leave you with a request you can see but cannot stop. In that case, and in any other case where the button does not do what you expect, write to founder@royaapp.co before the date shown. That is handled by a person, not by the product.
What happens when the 14 days are up
A scheduled job runs once a night and erases the accounts whose 14 days have elapsed, longest-waiting request first, up to 50 accounts in a night. Your uploaded files go first, before anything in the database is touched. If that step fails for any reason the run stops, your account is left exactly as it was, and the whole erasure is retried the next night. We would rather delay than half-erase.
As section 2 says, our scheduled background jobs are not yet provisioned. Until that infrastructure is live, your request is recorded and its clock starts, but the erasure itself does not run. This section describes what the system is built and configured to do — not, yet, something happening every night.
What is deleted outright
- Every file you uploaded to our evidence storage — your advertising licence document, your Snapchat verification screenshots, and anything you attached to an appeal. We clear out the whole area of storage that belongs to you and then list it again to confirm it is empty, so a file left behind by an upload you abandoned goes too.
- Everything you sign in with — your password hash, your passkeys, every active session, and the sign-in provider tokens our authentication system holds unencrypted.
- Your bank details in full — the encrypted IBAN, its last four digits, the account-holder name and the bank name. The record of what you were actually paid stays in the payouts and the ledger; the instrument we paid it into does not.
- Your one-time email codes and password-reset entries, your sign-in rate-limiting counters, your in-progress social-connection attempts, unproven YouTube channel claims, your organisation memberships, your rebuildable earnings-consistency reports, and any invitation you sent that was never accepted.
What is overwritten in place
- Your account record. Your name becomes a fixed placeholder, your email address becomes a placeholder at a domain that can never receive mail, your phone number and profile picture are emptied, any staff role is removed, and the account is marked erased. Your internal account identifier does not change: it becomes the placeholder that every retained record points at, which is what lets those records stay meaningful without naming you.
- Your creator profile — date of birth, languages, licence number and licence expiry are cleared.
- Your licence review — the pointer to the document, the licence number and the reviewer's note are cleared.
- Your connected social accounts — the handle and the platform account id are replaced with placeholders, the account creation date is cleared, and the connection is marked revoked.
- Your submissions and appeals — the rejection reason, the appeal reason and decision note, and the pointers to evidence files are cleared.
- Free text written about you, wherever we can reach it: rejection and review notes in your submission timeline, the resolution note on a fraud flag raised against you, the signal detail inside a fraud flag, and the written reason recorded when a staff member accessed your account on your behalf.
- Other people's email addresses that your account caused us to store — an invite you redeemed, an invite code bound to your address — are replaced with placeholders.
- The free-text comment on your payout survey is emptied.
- Your notification preferences are set to off rather than deleted, so that erasing you can never have the side effect of switching your emails back on.
What is kept, and why
- Money records — payouts, invoices, ledger transactions, entries and adjustments. Kept for financial-record integrity and for the accounting, tax and dispute purposes in section 14. They carry amounts, dates and your account identifier, not your name.
- Fraud records. The fraud flag itself survives; its free text and signal detail do not. Erasure must not become a way to destroy the evidence of what an account did.
- Your submissions, and the public address of each post — the link, its normalised form, the platform's post id and the duplicate fingerprint. Those links embed your public handle, and we keep them deliberately: the normalised link is the check that stops the same post being submitted again from another account. This is a residual we are naming rather than hiding.
- Verification and compliance proof — your view snapshots, the country and type of your licence, its expiry and the decision made on it, your identity-verification status and the reference our payment provider holds for you. That is the record showing payouts happened only after the checks the law requires, minus the document and the number.
- The record that a notification was sent to you. It holds a message code and values such as dates and amounts, not free text.
The email we send when it is done
When the erasure completes we email you, in your language, at the address captured before it was overwritten. It says what was erased and what was kept. It is the last message you will receive from us: no email is ever sent to an erased account afterwards, and there is no way to sign in to read anything inside the platform.
An erased account cannot be signed in to, restored or reinstated. There is no appeal from erasure, because there is nothing left to put back.
What no erasure can reach
Several kinds of record are append-only, enforced by the database itself against every account including our own administrators: ledger transactions, entries and adjustments; audit records; brand kit licence acceptances; view snapshots; and payout survey responses, which permit the free-text comment to be emptied and nothing else. The erasure does not attempt to change any of them, and could not if it tried.
Be clear about what personal information stays there:
- Audit records hold the IP address and the user agent of the request that created them, and a before-and-after copy of what changed. That copy can contain your name, email address, phone number, account-holder name or licence number as they stood at the time.
- View snapshots hold each reading of your post's view count together with the platform's verbatim response, which can carry your handle or channel title.
- Brand kit licence acceptances record that you accepted a specific version of a licence at a specific time. They hold no name and no contact details — only your account identifier, which after erasure points at the anonymised record.
- Ledger records hold amounts, dates and your account identifier.
Retaining these is lawful — financial-record integrity and audit integrity — but retained is not the same as readable. Once an account is erased, every part of our platform that reads audit records or snapshot payloads masks that content, so no staff screen, export or admin tool displays it. The bytes remain. We block access to that information through every part of our platform, and we do not call that erasure, because it is not.
Our database backups hold earlier copies of everything above until those backups age out on their own. An erasure does not reach into a backup.
When erasure is held back
An erasure is postponed, never refused. It is held while:
- Money is still moving, or still owed to you — a payout that is requested, on hold for review, awaiting identity verification or processing; a bank transfer instalment not yet confirmed; a balance that has never been paid out; earnings still accruing on a clip; or an approved bounty or contest fee that has not yet been recorded in the ledger. These holds have no time limit. Erasing you destroys the only instrument we can pay you into, so we wait until you have been paid. A hold that lasts is put in front of our staff automatically, a week after your date passes.
- You are the only owner of an organisation. Ownership has to be transferred, or the organisation closed, before your account can go. That is a gap in the product, and it is handled by a person.
- Your account is suspended, or a fraud review of one of your posts is open. In one sentence: if your account is suspended, or a fraud review of one of your posts is still open when your deletion request comes due, we hold the erasure until that case is decided — and in any event no longer than 90 days from the day you asked. After 90 days the erasure proceeds regardless, so the hold can never turn into a refusal. It exists because erasure destroys the working parts of a fraud case — the evidence files, and the live handle a flag points at — even though the flag itself survives. Only a review a person can actually close will hold your deletion. The automatic note we file when you submit the same link twice, or when you try to connect a posting account somebody else already connected, is a record, not a review: nobody can close it, so it never delays your erasure by a single day.
One limit on the platforms' side
On account deletion we almost never call the social platform to revoke the authorisation on their side. Your tokens are destroyed the moment you request deletion, and the erasure can only attempt a provider-side revocation if some encrypted token still remains — which, on the ordinary path, it does not. Destroying our copy means we can no longer use them, but the authorisation may still appear in that platform's settings until you remove it. Please remove it yourself. For Google permissions, use https://security.google.com/settings/security/permissions. (When you disconnect a single account rather than deleting your whole account, we do ask the platform to revoke it.)
The Meta route
Where a deletion request arrives through Meta's own data deletion mechanism for a connected Instagram account, we act on that account rather than on your whole profile, and we act immediately rather than after 14 days: we attempt a provider-side revocation, and delete the connection record entirely where no submission depends on it. Where a submission does depend on it, we replace the handle with a placeholder and clear the account creation date, keeping only the link that ties clips to payments. Instagram-sourced view snapshots remain on that route, including the verbatim platform responses inside them — as they do on every route, for the reason above. Where we give you a reference code for such a request, you can check its status at royaapp.co/en/legal/data-deletion-status.
What this means for your rights
Bahraini law gives you a right to rectification, blocking or erasure where the processing breaches the law — in particular where data is inaccurate, incomplete, out of date, or processed unlawfully. It does not give a general right to have lawfully held records erased on request. Saudi law gives a right to request destruction, expressly subject to the rule that a controller must retain data where a legal basis requires it.
We go beyond that where we can, and we stop where we cannot. A deletion request now erases your identity from our systems whether or not either law compels it. The money, verification, fraud and audit records listed above are retained on the footing those laws allow, and the append-only records cannot be reached by anyone. That is the whole of it: what is above is what the system does, not what we would like it to do.
If you believe we hold information about you unlawfully, tell us and we will act on it.
16. Your rights, and how to use them
Write to founder@royaapp.co. Everything below is free of charge.
You can ask us to:
- Tell you what personal information we hold about you, and where we got it.
- Correct, complete or update anything inaccurate or out of date.
- Give you a copy of your information in a readable and clear format. Saudi law grants this right; Bahraini law does not. We will do it for anyone who asks.
- Block or erase information where the processing breaches the law, and request destruction where Saudi law grants it. Separately from both, you can ask us to delete your account, and we erase it — section 15 sets out exactly what that reaches and what it does not.
- Object to processing that causes you material or moral damage.
- Object to direct marketing. We do none; the right stands regardless.
- Require a person to reconsider an automated decision about your clip, your account or your payment.
- Withdraw any consent you gave, easily, at any time, free of charge, and without consequence for the rest of your account.
What you can change yourself, and what you cannot. In your account settings you can change your password, add and remove passkeys, sign out of active sessions, change your language, request deletion, and cancel that request while it is still pending. There is no self-service editor for your name, email address, phone number or creator profile — the creator profile is recorded once at onboarding and is not editable in the product. Rectification of those is therefore handled by us, by email, on request.
Two further limits: rows in the append-only records described in section 15 cannot be corrected — an error there is addressed by adding a corrective record, not by changing the original. And a correction cannot travel backwards into a post you have already published yourself.
How quickly we answer. We work to the Bahraini deadlines for everyone.
| Request | We respond within |
|---|---|
| Being told what we hold about you | 15 working days |
| Correction, blocking or erasure | 10 working days |
| Objection to processing, including direct marketing | 10 working days |
| Telling recipients about a correction or erasure we made | 15 days after we answer you |
| Human reconsideration of an automated decision | Without undue delay |
Where we refuse a request in whole or in part, we tell you why. Where a request is repetitive or clearly unfounded, we may decline it, and we will say so and explain. We may ask you to confirm who you are first, so that we do not hand your information to someone else.
Complaints. Tell us first at founder@royaapp.co. You can also complain to the Personal Data Protection Authority in the Kingdom of Bahrain, or, if you are in the Kingdom of Saudi Arabia, to the Saudi Data and Artificial Intelligence Authority (SDAIA).
17. Age
Roya is only for people aged 18 and over. A creator profile cannot be created without a date of birth, and our server refuses the profile if that date makes you under 18. Your attestation is recorded before the check is applied.
We are precise about what that check is: it is a declaration you make, checked against the date you type. It is not verification. We do not check your date of birth against a document or a government record.
We do not knowingly collect personal information from anyone under 18. If you believe an account belongs to someone under 18, tell us at founder@royaapp.co. We will investigate, close the account, stop any payouts to it and stop reading its connected social accounts. Because of the limits in section 15, records already written to the ledger, the audit log and the view snapshots cannot be removed.
18. Country notes
Your licence number becomes public in your own post. Where the advertising rules of the country you post from require a regulatory licence or permit number to appear in the content — a Mawthooq registration in the Kingdom of Saudi Arabia, or an advertiser permit in the United Arab Emirates — Roya generates the disclosure text for your clip, and that text contains your licence number. You copy it into your own public post, and your licence number becomes public, because that country's rules require it. Roya does not publish it anywhere else, does not show it to brands, and does not include it in any export.
Bahrain. Bahraini personal data protection law is the law this policy is built to, including its response deadlines, which are shorter than Saudi Arabia's and which we therefore apply to everyone.
Saudi Arabia. If you reside in the Kingdom, Saudi personal data protection law applies to our processing of your information wherever we process it. Everything in this policy applies to you, your information is transferred and processed outside the Kingdom as set out in section 13, and your rights include being informed, access, correction, a copy in a readable and clear format, destruction where the law grants it, and reconsideration of automated decisions by a person.
19. Platform notices
YouTube. Roya uses YouTube API Services to read the public statistics of the videos you submit, and stores each reading in a permanent, append-only snapshot as described in section 6. By using Roya you are also bound by the YouTube Terms of Service. Google's Privacy Policy, at https://policies.google.com/privacy, explains how Google handles data. You can review and revoke the access any application has to your Google data at https://security.google.com/settings/security/permissions.
Meta. Roya operates the data deletion request callback that Meta requires. Where an Instagram connection exists on your account, you can request deletion from your Roya account settings or by removing Roya in your Instagram settings, and check the status of that request with the reference code we return, at royaapp.co/en/legal/data-deletion-status. Section 15 states exactly what that request does and does not erase.
20. Changes to this policy
If we change what we collect, why we collect it, who receives it or how long we keep it, we will publish the new version at this address and update the date at the top. Where a change materially affects how we use your information, we will tell you by email or in the platform before it takes effect. The Arabic and English versions are updated together.
We use personal information only in the ways this policy describes. If we want to do something new — including offering Instagram or TikTok connections, releasing a mobile app, or sending push notifications — we change this policy first.
21. Contact
Roya is a product of Hola Mundo Graphic Design, an individual establishment registered in the Kingdom of Bahrain.
Commercial Registration: 135131-1 Registered address: Flat 121, Building 10, Road 81, Block 419, Jidhafs, Kingdom of Bahrain
Privacy, data protection, rights requests, corrections, deletion, appeals against automated decisions, complaints, security problems and suspected data breaches: founder@royaapp.co