Privacy Policy
Last updated : August 15, 2026
- Last updated
- August 15, 2026
- Controller
- AtypiConnect
- Registration
- Company ID: KXXX00XX (to be completed later)
- Address
- Place Fernand Texier, 38400 Saint-Martin-d'Hères, France
- Privacy & DPO
- AtypiConnect@gmail.com
- EU representative
- AtypiConnect@gmail.com
This Privacy Policy explains how AtypiConnect collects, uses, processes, and protects your personal data when you use the Constela mobile application (the "Service").
Constela is a dating and friendship mobile application designed for neurodivergent individuals, focusing on emotional, sensory, and lifestyle compatibility.
1. Data Controller and Contact Information
Data Controller: AtypiConnect
Registration / Company ID: KXXX00XX (to be completed later)
Registered Address: Place Fernand Texier, 38400 Saint-Martin-d'Hères, France
Privacy & DPO Email: AtypiConnect@gmail.com
EU Representative (Art. 27 GDPR): AtypiConnect@gmail.com
2. Information We Collect
2.1 Account Information
- Authentication: email address and hashed password (never stored in plain text).
- Profile identity: first name / display name, username.
- Third-party sign-in: if you use Apple Sign-In or Google Sign-In, we receive your OAuth token and the basic profile / email from the provider.
2.2 Profile Information (voluntarily provided)
- Visuals & demographics: up to 3 profile photos, age, gender identity, city, country, height, weight.
- Background & lifestyle: relationship status, languages spoken, education level, smoking / alcohol habits, pets, activity level, dietary habits.
- Personality & preferences: self-descriptive qualities, interest tags, relationship intention (Friendship / Long-term / Casual / Exploring).
2.3 Sensitive Data & Biometric Verification
- Emotional & sensory data: neurodivergence tags, sensory preferences, recharge / exhaustion triggers, soothing methods, communication style.
- Biometric verification data: 3-angle facial captures (front, left, right) and pose metrics (yaw / roll) taken solely to verify account authenticity.
2.4 Usage, Interactions & Technical Data
- In-app activity: swipes (likes, passes, super-likes), mutual matches, friend requests, room messages, direct messages, media attachments, emoji reactions.
- Safety & moderation: user reports, blocks, reason logs.
- Technical logs: device identifiers (FCM / APNs push tokens), OS version, app version, connection timestamps, IP address, crash logs.
2.5 Subscription & Purchase Records
Subscription tier (Freemium, Premium Light, Premium Plus), transaction IDs, and plan expiration dates. Payment details (credit card numbers) are handled directly by the Apple App Store and Google Play via RevenueCat; we never store your payment card numbers.
3. Legal Bases and Purposes of Processing
In accordance with Articles 6 and 9 of the GDPR, we only process your personal data under a valid legal basis:
| Purpose of Processing | Data Categories Involved | Legal Basis (GDPR) |
|---|---|---|
| Account creation & service delivery | Email, username, profile details, match history, chats | Performance of a contract (Art. 6.1.b) |
| Matching algorithm | Profile details, interests, lifestyle parameters | Performance of a contract (Art. 6.1.b) |
| Sensory & neurotype matching | Sensory triggers, neurodiversity tags, emotional needs | Explicit consent (Art. 9.2.a) |
| Facial authenticity verification | 3-angle verification photos, facial geometry metrics | Explicit consent (Art. 9.2.a) |
| Safety, fraud prevention & moderation | Reports, blocks, usage logs, chat reports | Legitimate interests (Art. 6.1.f) |
| Subscription & billing management | Transaction history, tier status, transaction IDs | Legal obligation (Art. 6.1.c) & contract (Art. 6.1.b) |
| Push notifications | Device push tokens, activity triggers | Consent (Art. 6.1.a) |
| App maintenance & error debugging | Crash logs, technical diagnostics | Legitimate interests (Art. 6.1.f) |
4. Special Category Data & Biometrics
- Explicit consent required: data concerning your neurotype, emotional profile, and sensory triggers, as well as facial verification data, are processed strictly upon your explicit, separate opt-in consent during onboarding.
- Biometric handling: the facial images collected during verification are evaluated automatically to detect real human presence and photo matching. Verification frames are permanently deleted immediately after the verification status is confirmed; only the verification confirmation badge (boolean true / false) is retained.
- Consent withdrawal: you can remove sensitive tags or withdraw consent at any time via your profile settings without closing your account.
5. Device Permissions
You can manage or revoke permissions at any time in your device settings:
- Camera: used strictly to take profile pictures or complete the facial verification check.
- Photo library: to upload existing pictures for your profile or in-chat attachments.
- Push notifications: to receive alerts about matches and messages (opt-in).
7. International Data Transfers
When personal data is transferred outside the European Economic Area (EEA), the UK, or Switzerland, we ensure adequate protection through approved legal transfer mechanisms:
- EU–U.S. Data Privacy Framework (DPF) (and Swiss / UK extensions) for certified US recipients.
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Art. 46.2.c GDPR), supplemented by risk assessments and technical safeguards (encryption in transit and at rest).
8. Data Retention
- Active accounts: profile data and interactions are maintained for as long as your account remains active.
- Biometric verification images: deleted immediately after processing and verification completion.
- Chat logs: retained for up to 12 months for community safety, abuse investigations, and moderation purposes, after which they are routinely purged.
- Account deletion: when you request account deletion, all personal data is permanently deleted or irreversibly anonymized within 30 days, with the exception of transaction records retained up to statutory commercial / tax retention limits (e.g., 5 to 10 years depending on jurisdiction).
9. Your Data Subject Rights (GDPR)
If you reside in the EEA, the UK, or Switzerland, you hold the following rights:
- Right of access (Art. 15): request a copy of your processed personal data.
- Right to rectification (Art. 16): update or correct inaccurate profile details.
- Right to erasure (Art. 17): request the deletion of your account and related data.
- Right to restriction of processing (Art. 18): limit the processing of your data under specific legal grounds.
- Right to data portability (Art. 20): receive your personal data in a structured, machine-readable format (JSON / CSV).
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7.3): revoke consent previously given (e.g., sensitive profile traits, notifications) at any time.
- Right to lodge a complaint (Art. 77): you have the right to file a complaint with your local Data Protection Authority (e.g., CNIL in France, APD in Belgium, DPC in Ireland, or ICO in the UK).
To exercise any of these rights, contact us at AtypiConnect@gmail.com. We will respond to your request within 30 days.
10. Data Security
All data transmissions use TLS / HTTPS encryption. Sensitive fields and database records are encrypted at rest using industry-standard protocols (AES-256). Strict role-based access control (RBAC) restricts internal access to user data.
11. Age Limitation (Children's Privacy)
Constela is strictly intended for individuals aged 18 and older. We do not knowingly register minors. If we detect that an account belongs to a user under 18, the account and associated data are purged immediately.
12. Updates to This Policy
We may update this Privacy Policy to reflect operational or legal changes. When significant modifications occur, we will notify you through an in-app notice or by email prior to the changes taking effect. If changes involve new processing activities requiring consent, your explicit consent will be requested.