Privacy Policy for Unbubl

Last Updated: 19/08/2025

At Unbubl, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how and why we process your data when you use our app, in compliance with the General Data Protection Regulation (GDPR) and other applicable laws.

1. Information We Collect

  • Email: For authentication and account management.
  • Device Information: Pseudonymous identifiers (e.g., device ID) for app functionality and analytics.
  • Location Data: With your consent, temporarily processed to deliver geo-based stories. Anonymized before sharing with third parties.
  • Payment Information: When you make a purchase, payment details (e.g., card number, billing information) are processed securely by Stripe. We do not store or have access to your full payment card details.

2. How We Use Your Data

  • Authentication: To log you into the app.
  • Payments: To process subscriptions or purchases securely through Stripe.
  • Analytics: To improve the app (Amplitude, pseudonymous only).
  • Content Delivery: To generate stories via anonymized location context sent to OpenAI.
  • Notifications: To send push notifications, if enabled.

3. Third-Party Services

We work with trusted processors who help us deliver our services:

  • Stripe: Handles payment processing securely. Stripe may collect identifiers (e.g., card details, billing address) to process transactions. Unbubl does not store this data. You can read more at Stripe’s Privacy Policy.
  • Amplitude: For app usage analytics (pseudonymous identifiers only).
  • Supabase Auth: For secure authentication and account management.
  • OpenAI: Processes anonymized location context for content generation.

These providers act on our behalf and do not use your data for advertising or profiling.

4. Legal Basis for Processing

  • Contract: To provide core services (account access, payments).
  • Consent: For optional features like geolocation and push notifications.
  • Legitimate Interests: To improve security and performance (pseudonymous analytics).

5. Data Retention

- Account data is retained while your account is active.
- Location data is processed ephemerally and not stored.
- Analytics data is retained in aggregated or pseudonymous form.
- Payment records are retained as required by financial regulations and tax law (typically up to 7 years).
You may request deletion of your account data at any time.

6. International Data Transfers

Some providers (e.g., Stripe, OpenAI, Amplitude) may process data outside the European Economic Area (EEA). Where this occurs, we ensure adequate safeguards such as the European Commission’s Standard Contractual Clauses.

7. Your Rights

Under GDPR, you have the following rights:

  • Access – to know what data we hold about you.
  • Rectification – to correct inaccurate information.
  • Erasure – to request deletion of your data.
  • Restriction – to limit certain processing.
  • Data Portability – to receive a copy of your data in a machine-readable format.
  • Objection – to object to processing based on legitimate interests.
  • Withdrawal of Consent – at any time, for consent-based processing.

To exercise your rights, contact us at clement@deckart.xyz. You also have the right to lodge a complaint with your local Data Protection Authority.

8. International Data Transfers

Some of our third-party providers (e.g., OpenAI, Amplitude) may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards (such as Standard Contractual Clauses) are in place to protect your data.

9. Security

We implement technical and organizational measures to protect your personal data, including encryption, access controls, and secure authentication via Supabase Auth.

10. Children’s Privacy

Our app is not intended for children under 13. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us and we will delete it promptly.

11. Push Notifications

With your consent, we may send push notifications. You can manage or disable these at any time in your device settings.

12. Changes to This Policy

We may update this Privacy Policy when necessary. Any updates will be posted here with a revised “Last Updated” date. Where required, we will notify you of significant changes and obtain renewed consent.

13. Contact Us

If you have any questions about this Privacy Policy or your data rights, please contact us:

Email: clement@deckart.xyz