ALOSTORA WORLD

Privacy policy

The text below is a draft that the owner of the project has not approved yet. It is written from what the application actually does rather than standing in for something, but it is not the final version and its wording may change before it is approved. Until then it should not be relied on as final.

What this policy is

ALOSTORA WORLD is a social application for adults. This policy says what the application does with your personal data. Every statement in it was written from the behaviour of the software itself, not from a template, and where the software and a comfortable sentence disagreed, the software won.

It describes the version you can install today. A few things are written into the code but are switched off in this version. They are named below, in the section on what is not active in this version; nothing is collected for any of them while they are off, and this policy is updated before any of them is switched on.

The age rule

The application is for adults only, eighteen and over. For a full account, after you sign in for the first time, and before you can use anything else, you are asked for your date of birth, and the application checks that it puts you at eighteen or over on that day. A date of birth that does not is refused and you cannot go on. The refusal itself is recorded: its time is kept against your profile and a line is written in the security record, so that answering again with a different date does not hide that the question was once failed. We do not ask you for a document to prove your age and we keep no such document. If we learn that an account belongs to someone under eighteen, the account is closed.

What we collect, and where it comes from

Sign-in identifiers. A phone number, an e-mail address, or both. One of them is how you sign in and how your account is recovered. To confirm that an identifier is yours we send a short numeric code to it and store the challenge until it is used or expires.

An installation code. The first time the application is opened on a phone, it creates a random code and keeps it on that phone. It is not taken from your phone's hardware, and it is not your phone's advertising identifier. Each time you sign in, the application sends a scrambled form of that code, and we store another scrambled form of it with your sign-in session; neither can be turned back into the code. We use it only to stop people who were banned from a voice room, or blocked by its host, from returning to that room through a guest session on the same phone, and to limit how many guest sessions one phone can create. It is not used for advertising or analytics and is not shared with anyone. Reinstalling the application creates a new code.

Your password, if you set one. It is never stored in a form anyone can read, including us. It is stored as a one-way scrypt hash with a per-account random salt, and the hash carries its own cost parameters so they can be raised later without anyone needing your password again.

A check that your password is not already in a public leak. Before a password is accepted, the first five characters of its SHA-1 fingerprint are sent to a public breached-password service, which answers with a list of fingerprints beginning with those five characters. The comparison happens on our side. Your password never leaves the application, and the service is never told which account, which e-mail address or which phone number the request is about. If that service cannot be reached, the check is skipped rather than your sign-up being refused.

Your profile. A username, a display name, a short description of yourself, a profile picture and your date of birth.

When you first set up your account you are also asked to choose the subjects that interest you, at least three of them, or to skip the question. What you choose is kept with your profile, and you can change it afterwards.

Your profile picture is checked before anyone else can see it. The check is built in two layers: a comparison against fingerprints of known illegal images (Microsoft PhotoDNA), and an image-classification service that bands the picture (Google Cloud Vision SafeSearch). Until those services are switched on for the running deployment, every new profile picture waits, unpublished, for a person on our team to look at it and publish or reject it; the decision and the person who took it are recorded. A picture is never recorded as safe on the grounds that nothing looked at it.

Your messages. In this version a message is text or an emoji, sent from one person to one person. We keep what you wrote, who it was for, and when. Message requests, which is how someone you have not spoken to before reaches you, are kept the same way. The application does not let you attach a picture, a voice note or a file to a message in this version, so there is nothing of that kind to keep.

Every message is checked before it is delivered. The check is a plain word match against a short fixed list of child-exploitation indicators. It runs on our own servers, it uses no outside service and no learning model, and the text of your message is never written to a log. What is stored with the message is the result of that check, as a code. If a message matches the list it is hidden, its text is not stored at all, and a moderation record is written against the account that sent it.

Your voice rooms. A room has a host, moderators the host names, speakers and listeners. When you create or join a room we keep the room and its title, who is in it and in which role, the seat and microphone requests you make and how they were answered, the moderation actions taken in the room, and the room's chat messages. Room chat is text only. A chat message is deleted seven days after it was written by a scheduled job, unless it was attached to a report, in which case the copy kept as evidence follows the moderation rules below. The host chooses who can find and enter a room: anyone, followers, friends, or people the host lets in. A person you have blocked cannot interact with you inside a room. Sound in a room is carried live and is not kept; the section on voice rooms below says when the microphone is asked for and where your voice goes.

Your connections. The people you follow, the people who follow you, your friends, your friend requests, and the accounts you have blocked.

Your presence. Whether you are online, and activity signals such as read receipts. Both are under your control in your privacy settings, and both can be turned off.

Your settings. The privacy and notification choices you make are stored with your account, so that they apply on every device you sign in on. If you set quiet hours for notifications, the hours you chose and the time zone they are counted in are stored with them. Your content choices are stored the same way: whether trending is shown to you, whether content that has been reported is hidden from you, when a video may start by itself, and the languages you want to be shown content in.

Your devices and sessions. Each signed-in device has a session with a label you can see, and you can end any of them. The session also keeps the platform it signed in from and the application version. Sessions expire by themselves after thirty days without use.

A device identifier, if you turn notifications on. When you allow notifications, the application registers that device so a notification can reach it. The registration carries an identifier the device itself supplies, which stays the same for as long as the application is installed, together with the application version and the language you are using, and it is stored against your account as a one-way hash and an encrypted copy rather than as readable text. If you never allow notifications, no such registration is made.

The notifications you are sent are also kept in your account, so that the notifications tab can show them to you, with what each one was about and whether you have read it. A notification you have read or dismissed is deleted 90 days after you read or dismissed it; one you never read is deleted one year after it was sent to you.

Reports and moderation records. What you reported, what was reported about you, what a moderator decided, and evidence kept with the case. When a private message is reported, the reported message and a few messages before and after it in the same conversation are copied into the case at that moment, so that a moderator can understand it. The moderator sees that copy and never the rest of the conversation, and every time anyone opens a case our server records who opened it and when.

Your hidden words. If you add words to the list of words you never want to see, the list is stored with your account so that it applies on every device. Messages and room chat lines containing one of those words are folded away for you — only for you, and you can still open one to read it. The list is never shown to anyone else and is not used for anything but this.

Whether your account is hidden. If you hide your account, we store that it is hidden and since when.

Your support requests. When you open a support request we keep the category you chose, the subject, what you wrote, and an e-mail address if you gave one so that we can answer you.

Which version of this policy and of the terms you accepted, in which language, and when. The text itself is not stored against you; only which version it was.

Technical and security data. Your network address is used to limit abuse, and for that purpose it is reduced to a one-way hash rather than being kept against your account. Important actions on an account — signing in, a failed sign-in, changing a phone number or an e-mail address, an action taken by a moderator or an administrator — are written to a security record with the time, and with the network address reduced to that same one-way hash.

Usage measurement. The application sends a small number of counted events, such as the application starting, a screen being opened, a search being run, or a support request being sent. The list of event names is fixed in the code and anything not on it is rejected. The values attached to those events are limited to true or false, numbers, and short codes; free text is dropped before it is stored, so the text of a message or a search cannot reach the measurement data.

Crash reports. If the application meets an error it did not expect, it sends one report: the platform it was running on, the application version, a short name for the kind of error, and the technical trace of where in the code it happened, which can run to a few thousand characters. The report is stored against your account on our own servers — no outside crash service receives it — and it is used to group the same fault together and fix it. That trace is written by the application and not by you, but it is technical text rather than a short code, so it is named here separately from the measurement events above.

Using Alostora as a guest

You can try the application without a phone number or an e-mail address. This is available only when we switch it on.

What is created: a random account number; the installation code described above; your date of birth and your answer to the age question, which we ask before anything else and before any account exists (if you are under 18, nothing is created and nothing is kept except a count that a refusal happened); the public voice rooms you listen to; any report you send; diagnostics; and the private settings you choose.

What is not collected: no phone number, no e-mail address, no name and no photo.

Guests are invisible to others: a guest does not appear in search, in suggestions, in who is online, or by name in a voice room. The room's host sees only how many guests are listening.

A guest can listen in public voice rooms and read public content. To speak, send a message, follow, or do anything else, you are asked to link a phone number, an e-mail address or a Google account. Linking keeps the same account and your settings. If that identifier already belongs to another account, the two are never merged: you choose what to do.

Reports sent by a guest are always reviewed by a person; they never trigger anything automatically.

Deletion: a guest account is deleted after 30 days without use, or at any time from Settings. What is kept after that is listed under "How long things are kept".

What we do not collect

The application has no map, no nearby-people feature and no location sharing, and it never asks for your location. It does not read your contacts. It asks for no access to your camera: the Android build does not request that permission. It does request the microphone, for one purpose only — speaking in a voice room — and asks for it only at that moment, or when you press Allow on the Microphone card in Settings → App Permissions; the section on voice rooms below says how. When you set a profile picture you choose it through the system picture chooser, which hands the application the one picture you picked and gives it no access to the rest of your gallery.

What is not active in this version

These are built into the code and switched off. While one is off, the application refuses to perform it rather than quietly doing something else, nothing is collected for it, and no record of it exists against your account. If any of them is ever switched on, this policy is updated first, and the update comes before any collection begins, not after it.

The fixed list of measurement event names also contains a few names belonging to the features above. This version has no screen that can send them, so they are never sent.

Voice rooms

Voice rooms are part of this version, so they are described here rather than on the list above.

What a room has: the Live tab, creating a room, entering a room as a listener, seats, requests to take a seat or the microphone and the host's or a moderator's answer to them, moderation inside the room — muting a speaker, removing a person, banning a person from that room — a text chat inside the room, and live sound between the people in it. What is recorded for all of that is listed above under what we collect.

The microphone:

application asks for it at one of two moments only: when you turn your microphone on in a seat the host or a moderator has given you, or when you press Allow on the Microphone card in Settings → App Permissions, a screen that says what the microphone is for — not at install, not on opening the application, not on entering a room, and not when you ask for a seat. Listening needs no permission at all. If you refuse, you stay in the room as a listener and the application tells you why you cannot be heard.

application or lock the screen, and Android shows a notification for as long as that lasts. Turning the microphone off, leaving the seat or leaving the room stops it.

Where your voice goes:

media server that the operator of this application runs itself. Wherever that server is hosted — on the same machine as the rest of the application or on one of its own — it is ours to run, and no outside company receives your voice. To let your device into the room, our server gives it a pass for that media server, valid for up to an hour, that carries your account identifier, the room and your role in it; the pass goes nowhere else. If the operator ever has to fall back to a hosted media service, that is a new recipient of your voice and this policy is updated before it happens.

and when a room ends there is no recording of it anywhere on our side. The text chat is the only part of a room that is kept, for the seven days stated above.

Who your data is shared with

The application is built to work with a small number of outside services. Each of them is off unless it has been configured for the running deployment, and where one is not configured the application refuses the action rather than quietly using something else. Each receives only what it needs to do its job and nothing more.

The breached-password service described above receives five characters of a fingerprint and nothing that identifies you, and it is contacted only when a password is being set.

Picture checking, once switched on: Google Cloud Vision SafeSearch receives your profile picture so that it can band it, and Microsoft PhotoDNA receives a fingerprint of it to compare with known illegal images. They receive the picture or its fingerprint and nothing else about you. Until they are switched on, the picture is sent to neither and waits for a person on our team, as described above.

For this version to work, the deployment that serves you configures: a text-message sender for the verification codes (the operator's chosen provider is CEQUENS), which receives the phone number the code is sent to; an e-mail sender for codes and security notices, which receives the e-mail address the message is sent to; push notification delivery (Google Firebase Cloud Messaging), which receives the device registration for a device you allowed notifications on; and file storage (Google Cloud Storage) for profile pictures and for the file we prepare when you ask for a copy of your data, which holds that file until its download link expires. Each of these is named here before it is switched on; while one is not configured, the action it serves is refused rather than routed anywhere else.

Live audio transport for voice rooms is described in its own section above: it runs on a media server the operator hosts, not on an outside service. Video transport, in-application purchases through the store, and sign-in with a Google account are written into the code and are not used in this version. Nothing is sent to any of them, and this policy is updated before that changes.

We do not sell personal data. We do not share it for advertising. We share it outside the application only as described here, or where a law or a valid legal order requires it.

How long things are kept

Your account data is kept while your account exists.

A guest account is deleted after 30 days without use, or when you delete it from Settings, at once and with no cooling window. The reports it sent are kept, marked as sent by a deleted guest. We also keep, for the limits and protections described above: a record of each guest-creation attempt for 90 days; a block on guest creation from a phone for 30 days after a guest is suspended, or 90 days after a guest is banned; and, for 24 hours, a count of the sign-in codes a guest asked for, with the code itself removed, so that deleting a guest cannot be used to send unlimited codes.

When you delete a full account, there is a cooling window before anything is erased, so that a deletion made in anger or by someone else can be undone. It is seventy-two hours unless the deployment is configured differently. During it you can cancel and keep your account. After it, the erasure is carried out and cannot be undone.

Some records survive the deletion of an account, and we would rather say so here than promise otherwise. Moderation and report records are kept to protect other people and to prevent fraud and abuse. Security audit records are kept because we have to be able to show what happened and when. None of it is kept for marketing. The deletion rule also spares financial records, of which this version has none because nothing is bought or sold in it, and the copy of a room chat message that was attached to a report, which is kept with the moderation case like any other evidence. A room chat message that nobody reported is deleted seven days after it was written, whether or not the account that wrote it still exists.

A file you asked for as a copy of your data is stored only until its download link expires.

Keeping a banned person from coming back — this paragraph applies only once this policy is approved, and nothing it describes is collected before then. When an account is closed permanently for a serious violation, we keep the phone number, the e-mail address and the installation code described above that were used with it, each reduced to a one-way hash, so that the same person cannot simply open a new account. These hashes are kept for as long as the ban stands, are used for nothing else, and are removed if the ban is overturned on appeal.

What you can do

See and change your profile at any time from inside the application.

Choose who can reach you. Your privacy settings control who can follow you, who can send you a friend request, who can send you a message, who can see when you are online, whether your account is private, whether your activity status is shown, whether read receipts are sent, whether a sensitive-content filter is applied, and a list of words you never want to see.

Hide your account for a while. While it is hidden, people who are not already your friends cannot find you in search, suggestions or discover, cannot open your profile, and cannot send you a new friend request or a new message request; everyone sees you as offline. Your existing friends and conversations keep working, you can still use everything yourself, and you can show your account again at any time. Nothing is deleted.

Ask for a copy of your data. The application prepares a file for you and gives you a link to it. The link expires after a period, and you can ask again.

Delete your account. You can do it from inside the application, and you can ask for it by writing to us if you can no longer sign in. The account deletion page explains both.

Block anyone, and report anything. A report reaches a moderation queue that people read.

How we protect your data

Passwords are stored only as one-way hashes. Sensitive actions can require you to verify yourself a second time. Changing a phone number, an e-mail address or a recovery credential starts a cooling period before the change takes effect, and a device that has only just signed in cannot evict your older trusted sessions. Every signed-in device is listed to you and can be ended. Requests are rate limited to make automated abuse expensive.

No system is perfect, and this section describes what is built rather than a promise that nothing can go wrong.

How to reach us

Write to support@alostoraworld.com. You can also open a support request from inside the application. We do not publish a telephone number or a postal address, and no personal mailbox of anyone working on the project is a contact route for it.

Changes to this policy

When the application starts doing something this text does not describe, the text is changed before that happens, not afterwards. That is the same rule as the one above about the features that are not active: the words change first, and the collection begins after. The date at the top is the date of the version you are reading.