Privacy Policy

Last updatedApril 26, -

1. Data controller

  • [À COMPLÉTER : legal name]
  • • Email: data@palettebuddy.com
  • • DPO: data@palettebuddy.com

2. Photo commitment

Your photos never leave your browser and are never stored on our servers.

3. Data we collect and purposes

  • Email, username, password — authentication (contract)
  • Gender, language, avatar — personalization (consent)
  • Selected season, analysis history — service (contract)
  • Name, billing address — invoicing (legal obligation)
  • Subscription status, Stripe ID — subscription (contract)
  • Technical logs — security (legitimate interest)

4. Retention

  • Active account: while active, deletion within 30 days of request.
  • Inactive account: auto-deletion after 36 months.
  • Invoices: 10 years (legal obligation).
  • Technical logs: max 12 months.

5. Recipients

  • Supabase (DB + auth) — EU.
  • Stripe Payments Europe Ltd — Ireland.
  • Lovable (frontend hosting) — EU.

No data is sold or shared for advertising purposes.

6. Your rights (GDPR)

  • Access, rectification, erasure, portability (export JSON in "My account"), objection.
  • Withdraw consent anytime.
  • Complaint to CNIL: https://www.cnil.fr/fr/plaintes

7. Cookies

Only strictly necessary technical cookies (auth + language). No tracking.

8. Security

HTTPS/TLS encryption. Passwords hashed (bcrypt). Row-level security on database.

9. Minors

The Service is restricted to users 15+ (French digital consent age).

10. Contact

For any question: data@palettebuddy.com