ConstelaConstela

Privacy Policy

Last updated : August 15, 2026

Last updated
August 15, 2026
Controller
AtypiConnect
Registration
Company ID: KXXX00XX (to be completed later)
Address
Place Fernand Texier, 38400 Saint-Martin-d'Hères, France
Privacy & DPO
AtypiConnect@gmail.com
EU representative
AtypiConnect@gmail.com

This Privacy Policy explains how AtypiConnect collects, uses, processes, and protects your personal data when you use the Constela mobile application (the "Service").

Constela is a dating and friendship mobile application designed for neurodivergent individuals, focusing on emotional, sensory, and lifestyle compatibility.

1. Data Controller and Contact Information

Data Controller: AtypiConnect

Registration / Company ID: KXXX00XX (to be completed later)

Registered Address: Place Fernand Texier, 38400 Saint-Martin-d'Hères, France

Privacy & DPO Email: AtypiConnect@gmail.com

EU Representative (Art. 27 GDPR): AtypiConnect@gmail.com

2. Information We Collect

2.1 Account Information

  • Authentication: email address and hashed password (never stored in plain text).
  • Profile identity: first name / display name, username.
  • Third-party sign-in: if you use Apple Sign-In or Google Sign-In, we receive your OAuth token and the basic profile / email from the provider.

2.2 Profile Information (voluntarily provided)

  • Visuals & demographics: up to 3 profile photos, age, gender identity, city, country, height, weight.
  • Background & lifestyle: relationship status, languages spoken, education level, smoking / alcohol habits, pets, activity level, dietary habits.
  • Personality & preferences: self-descriptive qualities, interest tags, relationship intention (Friendship / Long-term / Casual / Exploring).

2.3 Sensitive Data & Biometric Verification

  • Emotional & sensory data: neurodivergence tags, sensory preferences, recharge / exhaustion triggers, soothing methods, communication style.
  • Biometric verification data: 3-angle facial captures (front, left, right) and pose metrics (yaw / roll) taken solely to verify account authenticity.

2.4 Usage, Interactions & Technical Data

  • In-app activity: swipes (likes, passes, super-likes), mutual matches, friend requests, room messages, direct messages, media attachments, emoji reactions.
  • Safety & moderation: user reports, blocks, reason logs.
  • Technical logs: device identifiers (FCM / APNs push tokens), OS version, app version, connection timestamps, IP address, crash logs.

2.5 Subscription & Purchase Records

Subscription tier (Freemium, Premium Light, Premium Plus), transaction IDs, and plan expiration dates. Payment details (credit card numbers) are handled directly by the Apple App Store and Google Play via RevenueCat; we never store your payment card numbers.

4. Special Category Data & Biometrics

  • Explicit consent required: data concerning your neurotype, emotional profile, and sensory triggers, as well as facial verification data, are processed strictly upon your explicit, separate opt-in consent during onboarding.
  • Biometric handling: the facial images collected during verification are evaluated automatically to detect real human presence and photo matching. Verification frames are permanently deleted immediately after the verification status is confirmed; only the verification confirmation badge (boolean true / false) is retained.
  • Consent withdrawal: you can remove sensitive tags or withdraw consent at any time via your profile settings without closing your account.

5. Device Permissions

You can manage or revoke permissions at any time in your device settings:

  • Camera: used strictly to take profile pictures or complete the facial verification check.
  • Photo library: to upload existing pictures for your profile or in-chat attachments.
  • Push notifications: to receive alerts about matches and messages (opt-in).

6. Data Sharing and Third-Party Sub-Processors

We do not sell your personal data. Data is shared only with vetted third-party service providers acting as processors:

ProviderRole / PurposeData SharedLocation / Safeguards
Firebase / Google CloudPush notifications (FCM), cloud databasePush tokens, encrypted user dataUSA / EU (EU-US DPF / SCCs)
RevenueCatSubscription & receipt validationApp user ID, transaction event IDsUSA (SCCs)
Apple / GoogleIn-app purchases, authentication, receipt validationAuthentication tokens, receiptsUSA / EU (DPF)

In exceptional cases, data may also be disclosed to law-enforcement authorities where strictly mandated by statutory provisions or court orders.

7. International Data Transfers

When personal data is transferred outside the European Economic Area (EEA), the UK, or Switzerland, we ensure adequate protection through approved legal transfer mechanisms:

  • EU–U.S. Data Privacy Framework (DPF) (and Swiss / UK extensions) for certified US recipients.
  • Standard Contractual Clauses (SCCs) adopted by the European Commission (Art. 46.2.c GDPR), supplemented by risk assessments and technical safeguards (encryption in transit and at rest).

8. Data Retention

  • Active accounts: profile data and interactions are maintained for as long as your account remains active.
  • Biometric verification images: deleted immediately after processing and verification completion.
  • Chat logs: retained for up to 12 months for community safety, abuse investigations, and moderation purposes, after which they are routinely purged.
  • Account deletion: when you request account deletion, all personal data is permanently deleted or irreversibly anonymized within 30 days, with the exception of transaction records retained up to statutory commercial / tax retention limits (e.g., 5 to 10 years depending on jurisdiction).

9. Your Data Subject Rights (GDPR)

If you reside in the EEA, the UK, or Switzerland, you hold the following rights:

  • Right of access (Art. 15): request a copy of your processed personal data.
  • Right to rectification (Art. 16): update or correct inaccurate profile details.
  • Right to erasure (Art. 17): request the deletion of your account and related data.
  • Right to restriction of processing (Art. 18): limit the processing of your data under specific legal grounds.
  • Right to data portability (Art. 20): receive your personal data in a structured, machine-readable format (JSON / CSV).
  • Right to object (Art. 21): object to processing based on legitimate interests.
  • Right to withdraw consent (Art. 7.3): revoke consent previously given (e.g., sensitive profile traits, notifications) at any time.
  • Right to lodge a complaint (Art. 77): you have the right to file a complaint with your local Data Protection Authority (e.g., CNIL in France, APD in Belgium, DPC in Ireland, or ICO in the UK).

To exercise any of these rights, contact us at AtypiConnect@gmail.com. We will respond to your request within 30 days.

10. Data Security

All data transmissions use TLS / HTTPS encryption. Sensitive fields and database records are encrypted at rest using industry-standard protocols (AES-256). Strict role-based access control (RBAC) restricts internal access to user data.

11. Age Limitation (Children's Privacy)

Constela is strictly intended for individuals aged 18 and older. We do not knowingly register minors. If we detect that an account belongs to a user under 18, the account and associated data are purged immediately.

12. Updates to This Policy

We may update this Privacy Policy to reflect operational or legal changes. When significant modifications occur, we will notify you through an in-app notice or by email prior to the changes taking effect. If changes involve new processing activities requiring consent, your explicit consent will be requested.