Privacy Policy
Last updated — April 26, -
1. Data controller
- • [À COMPLÉTER : legal name]
- • Email: data@palettebuddy.com
- • DPO: data@palettebuddy.com
2. Photo commitment
Your photos never leave your browser and are never stored on our servers.
3. Data we collect and purposes
- Email, username, password — authentication (contract)
- Gender, language, avatar — personalization (consent)
- Selected season, analysis history — service (contract)
- Name, billing address — invoicing (legal obligation)
- Subscription status, Stripe ID — subscription (contract)
- Technical logs — security (legitimate interest)
4. Retention
- Active account: while active, deletion within 30 days of request.
- Inactive account: auto-deletion after 36 months.
- Invoices: 10 years (legal obligation).
- Technical logs: max 12 months.
5. Recipients
- Supabase (DB + auth) — EU.
- Stripe Payments Europe Ltd — Ireland.
- Lovable (frontend hosting) — EU.
No data is sold or shared for advertising purposes.
6. Your rights (GDPR)
- Access, rectification, erasure, portability (export JSON in "My account"), objection.
- Withdraw consent anytime.
- Complaint to CNIL: https://www.cnil.fr/fr/plaintes
7. Cookies
Only strictly necessary technical cookies (auth + language). No tracking.
8. Security
HTTPS/TLS encryption. Passwords hashed (bcrypt). Row-level security on database.
9. Minors
The Service is restricted to users 15+ (French digital consent age).
10. Contact
For any question: data@palettebuddy.com