1. Who controls your data
The data controller is MATHIEU BEST STUDIO, a SAS (société par actions simplifiée) registered in France under SIREN 101 981 108 and SIRET 101 981 108 00018, with its registered office at BAT B 2EME LOT 23 PT J, 27 RUE DU MESNIL, 78600 MAISONS-LAFFITTE, FRANCE. Privacy contact: privacy@dripordrop.app. Data Protection Officer: not appointed.
2. Scope
This Policy covers the Drip or Drop website, iOS application, TestFlight beta, account services, fit grading, Fits archive, Arena, public profiles, support, contact, and public fit-check submission forms. A third-party website or social network applies its own privacy notice once you leave our Service or share content there.
3. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account and authentication | Email, provider identifier, password hash, verification status, sessions | You; Apple or Google when selected |
| Profile | Username, bio, avatar, Instagram/TikTok/Snapchat handles, spotlight and public-fit order | You |
| Fit content | Photos, capture time, selected style lens, public/private choice, captions | You and your device camera/photo picker |
| AI and fit results | Scores, gauges, archetype, detected garments/colours, verdict and comments | Generated from your submission |
| Arena | Entry, competition day, opponents, outcome, rank, winner history | Your actions and service calculations |
| Usage and entitlements | Daily/bonus scan use, plan, subscription or entitlement state | Your use; purchase provider if enabled |
| Device and security | Install identifier, platform, device-integrity identifiers, IP and server/security logs | Your device and service systems |
| Website submissions | Uploaded photo, email, optional handle/platform, beta interest, consent records | You |
| Communications | Contact category, subject, message, support history | You |
We do not intentionally collect precise location, contacts, microphone recordings, health data, or payment-card numbers through the current Service. We do not create facial-recognition templates or use photos to identify you. A photo may nevertheless reveal sensitive information incidentally; avoid submitting anything you do not want processed.
4. Why we process data and our legal bases
| Purpose | Legal basis |
|---|---|
| Create accounts, authenticate, provide grading, save fits, operate profiles and Arena | Performance of our contract |
| Provide optional public-profile, public-fit, social-link, marketing fit-check, or beta communications | Your action/consent; contract where necessary for a requested feature |
| Secure accounts, prevent fraud/cheating, enforce rules, diagnose failures, defend claims | Legitimate interests in a safe and reliable service; legal obligation where applicable |
| Respond to support, privacy, and legal requests | Contract, legitimate interests, and legal obligations |
| Manage paid services, accounting, tax, and refunds if launched | Contract and legal obligations |
| Send optional product marketing | Consent where required; you may withdraw it at any time |
Required fields are identified in the interface. Without required account or photo data, we cannot provide the requested account, grading, submission, or support feature.
5. Photos, device checks, and AI processing
The app may use on-device checks to determine whether a photo appears gradable—for example, whether a person and sufficient outfit detail are visible. Camera and selected-photo permissions provide technical access only; we separately explain the relevant processing in this Policy and the interface.
For grading, the selected image and grading context are sent through our authenticated backend to Google’s Gemini API. Google returns structured outfit observations, scores, and commentary. We use the production paid-service configuration and applicable data-processing terms so submitted prompts, images, and responses are not used by Google to improve its general products. Google may retain limited data for abuse monitoring and legal compliance under its applicable terms.
We do not use your fit photos to train our own general-purpose AI model. If that changes, we will provide clear notice and obtain consent where required before using existing photos for that new purpose.
6. Public profiles, Arena, and social sharing
Private fits remain visible only to you and authorised service providers, except where disclosure is legally required. If you enter Arena, the fit, username, avatar, score, and ranking information needed for the competition may be shown to other users. If you publish a fit or profile, selected profile and fit information becomes public.
Public information can be copied, screenshotted, indexed, or reshared by others. Changing visibility or deleting content stops our future display but cannot guarantee deletion of independent copies. Sharing through Instagram, TikTok, Snapchat, or another platform is initiated by you and governed by that platform.
7. Who receives data
Access is limited to personnel and vendors that need data for the stated purposes. Current categories include:
- Cloudflare for DNS, Pages website hosting, Email Routing aliases, and private R2 object storage;
- Umami Cloud for optional website analytics when you allow it;
- Google for the Gemini API and Gmail SMTP email delivery;
- the private VPS infrastructure provider selected by MATHIEU BEST STUDIO for the API, database, and server logs;
- Apple and Google when you choose their authentication or distribution services;
- Discord for restricted team notifications about website fit-check submissions; notifications are limited to the information needed for review; and
- professional advisers, authorities, or claimants where disclosure is legally required or necessary to protect rights. No payment or subscription provider is currently used; any provider will be identified before paid plans launch.
We do not sell personal data. We do not disclose fit photos to data brokers or advertisers for behavioural advertising.
8. International transfers
Some providers may process data outside France or the European Economic Area. Where required, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, and supplementary safeguards. Details or copies of relevant safeguards may be requested at privacy@dripordrop.app.
9. How long we keep data
| Data | Planned retention |
|---|---|
| Private, non-public fit records and photos | Seven days from creation, then deleted by scheduled cleanup |
| Public fit records and photos | Until unpublished, deleted, or the account is deleted; an unpublished fit then follows the applicable private-history window |
| Deleted fit that participated in Arena | Hidden immediately; retained up to seven days to preserve daily results, then deleted |
| Daily result snapshots | Seven days |
| Textual Arena outcomes/statistics | For the account lifetime or until no longer needed for displayed statistics; anonymised or deleted on account deletion unless legally retained |
| Account, profile, settings, active sessions | For the account lifetime; deleted when the account is deleted, subject to backups and legal exceptions |
| Security and technical logs | Up to twelve months, unless a longer period is required for an active security incident or legal claim |
| Contact/support records | Up to three years after closure, shorter where no longer needed |
| Website fit-check photo and request | Fourteen days after submission unless selected for publication or a longer period is separately disclosed and consented to |
| Unsuccessful beta request | Fourteen days after submission, unless a longer period is requested and separately disclosed |
| Accounting/purchase records if launched | Duration required by tax and accounting law, commonly up to ten years in France |
| Backups | Retained only for the active backup rotation and overwritten on schedule; restoration copies are deleted when the rotation expires |
Deletion from active systems may take a short operational period. We may retain narrowly scoped evidence longer where required by law or necessary for legal claims, fraud prevention, or enforcement, with access restricted.
10. Security
We use measures appropriate to the risk, including hashed passwords and tokens, authenticated APIs, private object storage, short-lived signed URLs, access controls, transport encryption, device-integrity measures, secret separation, and deletion workflows. No system is perfectly secure. Please report suspected incidents through the Contact page and do not send secrets in free-text fields.
11. Your privacy rights
Depending on the processing and your location, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and give instructions regarding data after death where French law applies. You also have the right not to be subject to solely automated decisions producing legal or similarly significant effects; Drip or Drop fit scoring is not used for such decisions.
Submit a request through the Contact page using “Privacy request” or email privacy@dripordrop.app. We may request proportionate identity verification. We normally respond within one month, subject to lawful extensions. You may complain to the CNIL in France or your local supervisory authority.
12. Minors
The Service is not intended for children under 16. We do not knowingly accept their accounts or public fit-check submissions. If you believe a child has provided data, contact us so we can investigate and delete it. Where a lower age is expressly supported under applicable law, required parental authorisation and age-appropriate information must be implemented first.
14. Changes to this Policy
We may update this Policy when the Service, providers, or law changes. We will update the effective date and provide prominent notice of material changes. If consent is required for a new purpose, we will ask before processing on that basis.
15. Contact and complaints
Use our Contact page or email privacy@dripordrop.app. Controller postal address: BAT B 2EME LOT 23 PT J, 27 RUE DU MESNIL, 78600 MAISONS-LAFFITTE, FRANCE. You may also lodge a complaint with the CNIL or the competent authority where you live or work.