Last updated: [TO COMPLETE — publication date]
Publisher note (remove before publishing): template written for the app's actual architecture. Fill in every
[TO COMPLETE]and have it reviewed by a legal professional. The French version prevails in case of discrepancy.
This policy explains which personal data Morphly (the "App") processes, why, on what legal basis, who receives it, how long it is kept and how to exercise your rights under the EU General Data Protection Regulation (GDPR).
[TO COMPLETE — legal entity name, legal form, address, company registration number]. Privacy contact: kaisbenaoun01@gmail.com.
| Category | Data | Source |
|---|---|---|
| Account | Random technical identifier (guest account), email address if you choose to add one, creation date | You / App |
| Imported photos | Photos you select, cropped and re-compressed on your phone; EXIF metadata (including GPS location) is removed before upload | You |
| Generated videos | Video and thumbnail created from your photos, settings (duration, format, quality) | App |
| Credits & usage | Credit balance and history, generation history, rewarded ads watched (timestamp, transaction id) | App / Google |
| Subscription | Status, plan, start and renewal dates, store. We never receive your payment card details. | Apple / Google via RevenueCat |
| Advertising | Device advertising ID (IDFA/AAID) depending on your choices, IP address, device data, consent choices | Google AdMob |
| Technical | Server logs (IP address, date, request, errors) | App |
We do not process special categories of data. Faces in your photos are never used for biometric recognition or identification.
| Purpose | Legal basis |
|---|---|
| Account, video generation, storage and download | Performance of contract (Art. 6(1)(b)) |
| Credits, subscription and usage quota | Performance of contract (Art. 6(1)(b)) |
| Fraud and abuse prevention (rewarded ad limits, cryptographic reward verification, security) | Legitimate interest (Art. 6(1)(f)) |
| Rewarded ads (free plan) | Contract for non-personalised ads; consent (Art. 6(1)(a)) for personalised ads and advertising ID access |
| Cost and profitability monitoring (aggregated) | Legitimate interest (Art. 6(1)(f)) |
| Support requests | Legitimate interest / contract |
We never sell your data. Processors:
| Provider | Role | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, photo & video storage | European Union [TO COMPLETE — region] |
| [TO COMPLETE — server host, e.g. Fly.io] | Video generation and assembly server | [TO COMPLETE] |
| [TO COMPLETE — PixVerse or Kling] | AI generation of transitions; your photos are sent for processing | [TO COMPLETE] |
| Google Ireland Ltd (AdMob) | Rewarded ads and consent management | EU / USA |
| RevenueCat Inc. | Subscription management | USA |
| Apple Inc. / Google LLC | Payment | EU / USA |
Transfers outside the EU rely on adequacy decisions (including the EU-US Data Privacy Framework for certified companies) or the European Commission's Standard Contractual Clauses. [TO COMPLETE — confirm per provider.]
| Data | Retention |
|---|---|
| Imported photos | Automatically deleted from our servers when the generation ends (usually within an hour). Retention by the AI provider follows its own policy [TO COMPLETE]. |
| Videos and thumbnails | 30 days after creation, or until you delete them |
| Account, credits, history | Until you delete your account |
| Subscription data | Subscription duration, then the applicable statutory limitation period |
| Technical generation & ad records | Kept anonymised after account deletion, for statistics |
| Server logs | Up to 30 days |
You have the rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent at any time.
You may lodge a complaint with your data protection authority (in France: CNIL, www.cnil.fr).
The App is not intended for people under 15. Contact us if you believe a child has provided personal data.
TLS encryption, private storage reachable only through short-lived signed links, per-user isolation enforced by the database, API keys kept server-side only, cryptographic verification of ad rewards.
We may update this policy; significant changes will be announced in the App.