Privacy Policy
Summary
This summary is provided for convenience only. It is not part of this policy, and it neither qualifies nor expands the numbered sections below, which govern.
- Your photograph. Used to produce your sticker: screened by automated safety services, transmitted to the AI service that generates your clip, from where it may reach the company that developed the model you select, and deleted from our storage on delivery of that clip (section 2).
- Model training. Dappi does not use your content to train AI models and trains no models of its own. The AI companies that generate your sticker receive your content under their own terms; section 2.6 sets out our position regarding them.
- Face data. We do not use your photograph to identify you or any other person. We operate no facial recognition and build no face databases (section 2.6). We do not create face geometry or facial landmark data from your photograph.
- Your stickers. Private to your account. The Service has no feed and no sharing surface.
- Advertising. The application and the website carry no advertising, no ad networks, no tracking software and no third-party analytics, and we do not sell personal data (section 4).
- Deletion. You can delete your account in the application. A limited set of records survives, and section 8.2 identifies every one.
- Contact. support@dappistickers.com.
1. Controller, scope and legal basis
1.1 Controller. Dappi is operated by Eilon Aharoni, an independent developer. He is the data controller, meaning the person responsible for how your data is handled. Contact: support@dappistickers.com.
1.2 Scope. This policy covers the Dappi application and the dappistickers.com website (together, the "Service"). In this policy, a sticker is the short looping video the Service generates from your photograph, together with the preview images the application derives from it.
1.3 Voluntary provision. You are under no legal obligation to provide information to us, and provision is voluntary in each case. Where information is necessary to deliver a function of the Service, that function is unavailable without it. An email address is required in order to create an account. A photograph and a prompt are required in order to generate a sticker.
1.4 Legal basis. We process your data on the basis of your consent: the agreement you give at sign-up, and the separate consent you give before your first AI generation. You may withdraw consent at any time by deleting your account.
2. How your photograph is processed
2.1 On your device. Selection and cropping take place on your device. A photograph is uploaded only when you tap Generate.
2.2 Safety screening. When you tap Generate, the photograph and your prompt are uploaded to our storage and screened by an automated safety service:
- OpenAI (United States) receives the photograph and the prompt for a safety check. Per its published documentation, it does not train on this data and retains nothing after the check. Images flagged as child sexual abuse material may be retained longer by OpenAI for review and reported to the authorities.
2.3 Generation. If the screening passes, your photograph and your prompt are transmitted to our video provider, through a private, time-limited link or directly, and a video model produces your clip. The application offers a small menu of video models, and you choose the model for each sticker. Our video provider is fal, a United States company, and it receives your photograph and your prompt. We may change providers, and section 5 identifies the provider in use. The model you select was developed by another company, and that developer may receive your photograph and your prompt. Per fal's published terms, fal does not use customer content to develop its own products or services, and it applies that restriction, its data processing agreement and its information security obligations to models reached through another company's interface, except for models fal marks Pending Enterprise Ready or otherwise designates to us in advance. Section 5 identifies each developer, and where it may process your content. We have no control over the developers and make no representation or warranty as to their data practices, which are governed by their own terms and may change without notice to us. We set a one-hour expiry on the files fal holds for your generation, and we ask fal to store no copy of the request itself. Those settings apply to fal and do not bind a model developer that receives your content.
2.4 Deletion of the source photograph. On delivery of your clip, our storage deletes the source photograph. Where a generation never completes, the photograph is removed within about two days. Where a generation is blocked by our safety check, we retain a copy of the photograph for up to 30 days for abuse review, after which it is deleted.
2.5 Storage of clips and stickers. Under a paid subscription, your clips and finished stickers are stored in the cloud until you delete them or your account. Stickers finished on the free tier reside on your device and not in the cloud, and the cloud copy of a clip made on the free tier is removed once the sticker is finished. On upgrade, the stickers on your device are uploaded for you.
2.6 Face data, and limits on our use of your content.
- We do not use your photograph, or data derived from it, to identify you or any other person. We operate no facial recognition and build no face templates or face databases. We do not collect or create face mesh, facial map, face modeling, facial coordinate or facial landmark data from your photograph.
- We do not sell or trade your photograph.
- We use your photograph only to produce the sticker you asked for, including the safety screening and the abuse review described in this section. We do not use it for advertising, marketing or authentication, and we do not use it to build a profile of you.
- Dappi does not use your photographs, prompts or stickers to train or fine-tune AI models, and we develop and train no models of our own. The AI providers named in section 5 receive your content to perform their function. We have no control over those providers and make no representation or warranty as to their data practices, which are governed by their own terms and may change without notice to us.
- The background cut-out feature runs on your device, and no image data is sent to anyone in order to perform it. Where you choose a background, the picture the cut-out produces is composited on your device and becomes either the photograph that is uploaded when you tap Generate or your finished sticker, each handled as sections 2.3 and 2.5 describe.
2.7 Laws treating face data as biometric. Some laws treat data derived from images of faces as biometric information. We do not use your photograph to identify anyone, but where such laws require consent, we process your photograph only with yours. Accordingly, the Service requires your explicit consent before your first generation.
3. Categories of data we collect
Account. Your email address and a password stored only in a scrambled one-way form (a hash), or your Apple or Google sign-in. With Apple sign-in we receive an identifier specific to Dappi and your email address, or Apple's private relay address if you chose to hide your email. With Google sign-in we receive your name, your email address and a web address for your Google profile picture, which we keep in your sign-in record for as long as your account exists and which the application does not display. An optional display name and your subscription tier are stored in your profile.
Content. Your photographs (briefly, as described in section 2), prompts, clips, stickers, videos, editor text and emoji, pack names, and saved presets. Section 7 states how long each of these is kept, and section 8 what happens to them when you delete.
Purchases. If you buy a subscription, Apple processes the payment. We receive subscription status and purchase history through RevenueCat, our subscription processor. Neither we nor RevenueCat receives your card or bank details.
Store country. We record the country of your App Store account, once, as a two-letter code. The App Store supplies it to the application on your device. We use it only to determine whether an account is eligible for the credits granted on sign-up, which we may offer in some countries and not in others. This is an attribute of your App Store account and not a location. We do not collect location data, and we do not derive this code from a postal address or an IP address.
Consent records. Each time you accept the Terms or this policy, and when you give generation consent, we record which document version you accepted, when, in which screen, the email address on the account, the application version, and, where the request carries one, the device user agent that made the request. We do not record your IP address with your consent.
Moderation records. When a generation is blocked, we record the prompt, the reason, your account, and the email address on it. Where a generation is blocked, a copy of the photograph is retained briefly (section 2.4). These records exist to prevent abuse.
Support and reports. Messages you send through the feedback form or by email. Every message you send from inside the application also carries a short line of technical detail about the application and the device at the moment you sent it, together with a random session code created when the application started, which connects your message to that session's technical measurements. Where you are reporting an error, the message also carries the screen you were on and the text of the error, both as it was shown to you and in its raw technical form.
Technical measurements. The application records usage events and performance measurements, for example timings, sizes, device state such as low memory, and which features and screens you use, including the subscription screens, in order to keep the Service reliable and to decide what to improve. These are recorded without your account attached and do not include prompts, photographs or email addresses. They remain unconnected to you unless you send a report, as described above.
Notifications. If you allow notifications, we store a device push token. Notifications tell you about your own activity in the application. They never contain your photograph, your prompt or your sticker.
Server logs. Our infrastructure provider keeps short-lived technical logs, comprising IP address, approximate location derived from it, and request metadata, for security purposes, for a short period set by our hosting plan, which does not exceed 30 days. Request bodies, including your photographs and prompts, are not written to those logs.
On your device. Your sign-in session is kept in the device keychain. A copy of the photograph each sticker was made from, your stickers, videos and caches are stored in the application's own storage. Deleting a sticker removes its copy of the photograph, and deleting the application removes all of them. iOS may retain the keychain entry after the application is deleted. Signing out before you delete the application clears it.
4. Limits on our use of your data
4.1 No sale of personal data. We do not sell or rent personal data, and we have not done so.
4.2 No advertising or tracking. The application and the website carry no advertising, no ad networks, no tracking software development kits and no third-party analytics. The website sets no cookies and contains no forms. Our emails contain no tracking pixels and no rewritten tracking links.
5. Recipients
We use a small set of companies to operate the Service. We send each of them only what its function requires, and beyond performing that function we grant none of them any use of your content. Each of these companies is engaged on its published terms, which carry its published data protection commitments, and per fal's published terms its data processing addendum is incorporated into those terms to the extent applicable. Our arrangements with these companies extend no further. Each of these companies also operates under its own terms, which reserve rights we cannot remove: several of them, including fal, Supabase and RevenueCat, reserve the right to use anonymized or aggregated data derived from customer content for their own purposes, and Cloudflare uses the bot check signals described below to improve its own detection. A model's developer may receive your content under an arrangement between that developer and fal, to which we are not a party, and the entry for model developers below states what each receives. We have no control over these companies and make no representation or warranty as to their data practices, which are governed by their own terms and may change without notice to us.
- Supabase operates our database, sign-in and file storage. Everything identified in section 3 that we store is stored with Supabase. Primary storage is in Singapore, with limited support access from the United States, and some processing may run in other locations, as section 6 describes.
- fal (United States) is our video provider. It receives your photograph and your prompt in order to generate your clip, as described in section 2.3. We set a one-hour expiry on the files fal holds for your generation, and we ask fal to store no copy of the request itself.
- Model developers. The video models on the menu were developed by ByteDance and by MiniMax, and each of those companies may receive your photograph and your prompt. ByteDance's international arm, BytePlus, is based in Singapore and states that it processes data in Malaysia, Indonesia and the European Economic Area, and that content flagged by its safety filter is retained for 180 days. MiniMax is a group headquartered in Shanghai, China and listed in Hong Kong. Per its published privacy policy, its developer platform is operated by Nanonoble Pte. Ltd., a company registered in Singapore, which states that personal data is stored in a data center in the United States, sets no retention period, and gives no undertaking as to training. That policy covers MiniMax's own platform, and MiniMax publishes nothing about content that reaches it through another company. Per fal's published terms, fal identifies on its platform which models it reaches through another company's own service, and content for those models is transferred to that company. fal does not currently identify the MiniMax model we use in that way, and describes it as running on fal's own systems. fal may change that at any time. We have no control over these developers and make no representation or warranty as to their data practices.
- OpenAI (United States) receives your photograph and prompt for the pre-generation safety check. Per its published documentation, it retains nothing after the check (section 2.2).
- Resend (United States) delivers our emails: sign-up confirmations, password resets and account notices. Per Resend, it retains sent email content for about 30 days.
- Cloudflare provides the bot check (called Turnstile) on the sign-up, sign-in, password-reset and change-password screens, hosts the website, and routes email to our inbox. During the bot check your device sends Cloudflare its IP address, a technical fingerprint of the connection, and browser information. Cloudflare also uses these signals to improve its bot detection. See Cloudflare's Turnstile Privacy Addendum at cloudflare.com/turnstile-privacy-policy for details. Cloudflare does not store our support email; it passes it on.
- Apple handles Apple sign-in, delivers notifications, and processes all payments. Apple may hold an undelivered notification for up to 30 days. We do not receive your payment details.
- Expo (United States) relays our notifications to Apple, and issues and holds the push token for your device. Per Expo, notification contents are held only in memory and in its message queues, not in databases, and delivery receipts are cleared after 24 hours.
- Google Sign-In, if you use it, shares your name, email address and profile picture with us, and keeps its own record that your Google account is linked to Dappi.
- RevenueCat (United States) is our subscription processor. Its software runs inside the application from the moment you open it, so it receives, with each request it makes, technical information about your device and your request, including the network address your device connects from, the account identifier, an identifier Apple assigns to our applications for your device, your device model and operating system version, your device language preferences, and the country of your App Store account. If you buy a subscription it also receives the Apple receipt and your purchase history. It does not receive payment details. We do not enable its attribution features, and it does not receive the Apple advertising identifier.
- Gmail. Emails you send to support@dappistickers.com are received and stored in a Google mailbox.
Other disclosures. We disclose data where a law, a court order or a competent authority validly requires it, including the reporting of content that sexually exploits children, as section 6 of the Terms provides. If the Service is transferred to a company formed to operate it, your data transfers with it under this policy.
Limits on sharing. Other than as described in this section, we do not share personal data with third parties for their own marketing or advertising purposes. We may engage further service providers in order to operate the Service, and will update this section when we do.
6. International processing
We operate from Israel. Your data is stored and processed in the United States, in Singapore, in Malaysia, in Indonesia, in the European Economic Area, and in other locations in which the companies identified in section 5 operate, and those locations may change. One of the companies identified in section 5 is part of a group headquartered in China. Its published privacy policy names the United States as the place it stores personal data and does not name China. By using the Service you agree that your data is stored and processed outside Israel.
7. Retention
- Source photograph: deleted on delivery of your clip. At most about two days where a generation never completes.
- Copy of the photograph from a blocked generation: up to 30 days.
- Clips, stickers, videos: under a paid subscription, retained in the cloud until you delete the sticker or your account. Stickers finished on the free tier reside on your device, and the cloud copy of a free account's clip is removed once the sticker is finished. Section 10.2 of the Terms also reserves a right to remove cloud copies of accounts that have been without an active subscription for 30 days. Stickers on your device are not affected.
- Prompts: retained with your sticker until you delete it, and in presets you save until you delete them. Every prompt is also written, with nothing connecting it to you or your sticker, into a safety archive, and the text is removed from that archive after 365 days. Where a prompt is blocked, the blocked-attempt record is retained for 90 days. Technical error records, which can quote a prompt, are retained for 30 days.
- Store country: for as long as your account exists, and deleted with it.
- Consent records: for as long as your account exists, and for 7 years after deletion, as evidence of consent.
- Moderation records: blocked-attempt records for 90 days. Records of account closures for breach are retained for as long as necessary to keep those closures effective.
- Feedback: for as long as your account exists, and deleted with it. Emails you send us remain in our support mailbox.
- Technical measurements: usage events for 90 days and performance measurements for 180 days. Daily totals of usage events remain, with nothing connecting them to you.
- Sent emails at Resend: about 30 days.
- Server logs: a short period set by our hosting plan, which does not exceed 30 days.
8. Deletion, and what survives it
8.1 Deleting your account. You may delete your account at any time in the application, at Profile, then Delete account. This permanently deletes your photographs, clips, stickers and videos from our storage, and your profile, packs, presets, credit history, feedback, notification tokens and sign-in records. If you signed in with Apple, we also instruct Apple to disconnect Dappi from your Apple ID. We also instruct RevenueCat, our subscription processor, to delete its record of your account. The push token for your device is deleted from our storage, and Expo's own record of that token is governed by its terms, as section 5 describes.
8.2 What survives. A limited set of records survives deletion, by design:
- consent records, including the email address on them: kept 7 years as proof of consent;
- blocked-attempt records, including the email address on them: up to 90 days, and any copy of the photograph from a blocked generation up to 30 days, for abuse prevention;
- ban records: kept as evidence that an enforcement decision was made, with nothing on them naming you once your account is deleted;
- purchase records, including the email address on them: kept 24 months for refunds and payment disputes;
- technical error records: up to 30 days;
- technical measurements that were never connected to your account;
- prompts in the anonymous safety archive described in section 7, which carry nothing connecting them to you: up to 365 days;
- a deletion marker with no name and no email: 7 years.
8.3 Subscriptions. Deleting your account does not cancel an Apple subscription. Cancel it in your Apple ID settings.
8.4 Deleting the application. Deleting the application from your device removes the photograph copies, stickers, videos and caches stored there. Your sign-in session resides in the device keychain, and iOS may retain it after the application is deleted. Signing out before you delete the application clears it.
9. Your rights
9.1 Requests. You may request access to the personal data we hold about you, its correction, a copy of it, or its deletion. Deletion is available in the application (section 8). For any other request, email support@dappistickers.com from the address on your account. We respond within 30 days and make no charge, and where we refuse a request we tell you within 21 days. We may require verification of your identity before acting on a request. Where a request is complex, or where you have made a number of requests, we may extend the 30 day period and will tell you if we do. We may decline requests that are manifestly unfounded or excessive.
9.2 Local rights. If you are in Israel, these include your inspection and correction rights under the Privacy Protection Law, and you may complain to the Privacy Protection Authority, Israel's privacy regulator. Where the law of the place you live confers further rights that apply to us, we honor those.
10. Children
The Service is not intended for children under 13. We do not knowingly collect data from children under 13. If we become aware that an account belongs to a child under 13, we will close it and delete its data. Parents and guardians may contact us at support@dappistickers.com.
11. Security
11.1 Measures. Per our providers' published documentation, data is encrypted in transit and at rest. Access to your data is restricted to your signed-in account by database and storage access controls, and the AI services are called from our servers, using credentials that are not distributed with the application.
11.2 No guarantee of security, and no backups. No service is perfectly secure, and we do not warrant that the Service or its infrastructure will be free from unauthorized access. We do not provide backups. Your stickers reside on your device, and retaining copies of what you need is your responsibility (Terms, section 10).
11.3 Incidents. If a security incident places your data at risk, we will give notice to the competent authority and to affected users where and as the law requires, using the email address on your account.
12. Use without an account
You may browse the Service and compose a sticker without an account. No account data exists for guests. The application records usage events with no identity attached, including which features and screens you use, as section 3 describes. The bot check runs on the sign-up, sign-in and password-reset screens.
13. The website
dappistickers.com sets no cookies, contains no forms, and runs no analytics. It is hosted by Cloudflare, and its lettering is served from the site itself.
14. Territory
The Service is not directed to, or offered in, the European Union or the United Kingdom.
15. Changes to this policy
When we publish a new version, the application presents it to you and asks you to accept before you continue using the Service. The version number at the head of this policy identifies the version you are reading.
16. Contact
Eilon Aharoni · support@dappistickers.com