PRIVACY

Privacy Policy

Summary

This summary is provided for convenience only. It is not part of this policy, and it neither qualifies nor expands the numbered sections below, which govern.

1. Controller, scope and legal basis

1.1 Controller. Dappi is operated by Eilon Aharoni, an independent developer based in Israel. He is the data controller, meaning the person responsible for how your data is handled. Contact: [email protected].

1.2 Scope. This policy covers the Dappi application and the dappistickers.com website (together, the "Service").

1.3 Voluntary provision. You are under no legal obligation to provide information to us, and provision is voluntary in each case. Where information is necessary to deliver a function of the Service, that function is unavailable without it. An email address is required in order to create an account. A photograph and a prompt are required in order to generate a sticker.

1.4 Legal basis. We process your data on the basis of your consent: the agreement you give at sign-up, and the separate consent you give before your first AI generation. You may withdraw consent at any time by deleting your account.

2. How your photograph is processed

2.1 On your device. Selection and cropping take place on your device. A photograph is uploaded only when you tap Generate.

2.2 Safety screening. When you tap Generate, the photograph and your prompt are uploaded to our storage and screened by an automated safety service:

2.3 Generation. If the screening passes, your photograph and your prompt are transmitted to a video provider, through a private, time-limited link or directly, and a video model produces your clip. The application offers a small menu of video models, and you choose the model for each sticker. Our video providers are Replicate and fal, both United States companies. One of them receives your photograph and prompt, and we may change which one we use. Per fal's published terms, some models on its platform are run by the model's developer rather than by fal, and content sent to such a model is transferred to that developer. fal marks those models on its platform, and states that its restrictions on the use of customer content and its data processing agreement apply to them. Section 5 identifies each developer that receives your data, and where it may process it. We do not control the developers, we cannot verify what they do with content once it reaches them, and we give no warranty in respect of their conduct. Per Replicate's published documentation, it deletes its copy of the inputs and outputs automatically about an hour after the run. For fal, we set a one-hour retention on fal's own copies. That setting applies to fal's copies and does not bind a model developer that receives your content.

2.4 Deletion of the source photograph. On delivery of your clip, our storage deletes the source photograph. Where a generation never completes, the photograph is removed within about two days. Where the photograph itself is flagged by a safety check, we retain a copy for up to 30 days for abuse review, after which it is deleted.

2.5 Storage of clips and stickers. Under a paid subscription, your clips and finished stickers are stored in the cloud until you delete them or your account. Stickers finished on the free tier reside on your device and not in the cloud, and the cloud copy of a clip made on the free tier is removed once the sticker is finished. On upgrade, the stickers on your device are uploaded for you.

2.6 Face data, and limits on our use of your content.

2.7 Laws treating face data as biometric. Some laws treat data derived from images of faces as biometric information. We do not use your photograph to identify anyone, but where such laws require consent, we process your photograph only with yours. That is why the Service asks for your explicit agreement before your first generation.

3. Categories of data we collect

Account. Your email address and a password stored only in a scrambled one-way form (a hash), or your Apple or Google sign-in. With Apple sign-in we receive an identifier specific to Dappi and your email address, or Apple's private relay address if you chose to hide your email. With Google sign-in we receive your name, email address and profile picture. An optional display name and your subscription tier are stored in your profile.

Content. Your photographs (briefly, as described in section 2), prompts, clips, stickers, videos, editor text and emoji, pack names, and saved presets. Section 7 states how long each of these is kept, and section 8 what happens to them when you delete.

Purchases. If you buy a subscription, Apple processes the payment. We receive subscription status and purchase history through RevenueCat, our subscription processor. Neither we nor RevenueCat receives your card or bank details.

Store country. We record the country of your App Store account, once, as a two-letter code. The App Store supplies it to the application on your device. We use it only to determine whether an account is eligible for the credits granted on sign-up, which we may offer in some countries and not in others. This is an attribute of your App Store account and not a location. We do not collect location data, and we do not derive this code from a postal address or an IP address.

Consent records. Each time you accept the Terms or this policy, and when you give generation consent, we record which document version you accepted, when, in which screen, the email address on the account, and the application version and device user agent that made the request. We do not record your IP address with your consent.

Moderation records. When a generation is blocked, we record the prompt, the reason, your account, and the email address on it. Where the photograph itself was flagged, a copy is retained briefly (section 2.4). These records exist to prevent abuse.

Support and reports. Messages you send through the feedback form or by email. If you report an error, the report includes the application version, the screen, the error message displayed to you, the raw technical error text, and a random session code created when the application started, which connects your report to that session's technical measurements.

Technical measurements. The application records usage events and performance measurements, for example timings, sizes, and device state such as low memory, in order to keep the Service working well. These are recorded without your account attached and do not include prompts, photographs or email addresses. They remain unconnected to you unless you send a report, as described above.

Notifications. If you allow notifications, we store a device push token. Notifications state only that your sticker is ready.

Server logs. Our infrastructure provider keeps short-lived technical logs, comprising IP address, approximate location derived from it, and request metadata, for security purposes, for about a day. Request bodies, including your photographs and prompts, are not written to those logs.

On your device. Your sign-in session is kept in the device keychain, and stickers, videos and caches are stored in the application's own storage. Deleting the application removes the stickers, videos and caches. iOS may retain the keychain entry after the application is deleted. Signing out before you delete the application clears it.

4. Limits on our use of your data

4.1 No sale of personal data. We do not sell or rent personal data, and we have not done so.

4.2 No advertising or tracking. The application and the website carry no advertising, no ad networks, no tracking software development kits and no third-party analytics. The website sets no cookies and contains no forms. Our emails contain no tracking pixels and no rewritten tracking links.

5. Recipients

We use a small set of companies to operate the Service. Each receives only what its function requires.

Other disclosures. We disclose data where a law, a court order or a competent authority validly requires it, including the reporting of content that sexually exploits children, as section 6 of the Terms provides. If the Service is transferred to a company formed to operate it, your data transfers with it under this policy.

Limits on sharing. Other than as described in this section, we do not share personal data with third parties for their own marketing or advertising purposes. We may engage further service providers in order to operate the Service, and will update this section when we do. Before adopting a replacement AI model or provider, we will assess it against the protections described in this policy, and will update this policy where the position materially differs.

6. International processing

We operate from Israel. Your data is stored and processed in the United States, in Singapore, and in other locations in which the companies identified in section 5 operate, and those locations may change. By using the Service you agree that your data is stored and processed outside Israel.

7. Retention

8. Deletion, and what survives it

8.1 Deleting your account. You may delete your account at any time in the application, at Profile, then Delete account. This permanently deletes your photographs, clips, stickers and videos from our storage, and your profile, packs, presets, credit history, feedback, notification tokens and sign-in records. If you signed in with Apple, we also instruct Apple to disconnect Dappi from your Apple ID.

8.2 What survives. A limited set of records survives deletion, by design:

8.3 Subscriptions. Deleting your account does not cancel an Apple subscription. Cancel it in your Apple ID settings.

8.4 Deleting the application. Deleting the application from your device removes the stickers, videos and caches stored there. Your sign-in session resides in the device keychain, and iOS may retain it after the application is deleted. Signing out before you delete the application clears it.

9. Your rights

9.1 Requests. You may request access to the personal data we hold about you, its correction, a copy of it, or its deletion. Deletion is available in the application (section 8). For any other request, email [email protected] from the address on your account. We respond within 45 days and make no charge. We may require verification of your identity before acting on a request. Where a request is complex, or where you have made a number of requests, we may extend that period and will tell you if we do. We may decline requests that are manifestly unfounded or excessive.

9.2 Local rights. If you are in Israel, these include your inspection and correction rights under the Privacy Protection Law, and you may complain to the Privacy Protection Authority, Israel's privacy regulator. Where the law of the place you live confers further rights that apply to us, we honor those.

10. Children

The Service is not intended for children under 13. We do not knowingly collect data from children under 13. If we become aware that an account belongs to a child under 13, we will close it and delete its data. Parents and guardians may contact us at [email protected].

11. Security

11.1 Measures. Data is encrypted in transit and at rest by our providers. Access to your data is restricted to your signed-in account by database and storage access controls, and the AI services are called from our servers, using credentials that are not distributed with the application.

11.2 No guarantee of security, and no backups. No service is perfectly secure, and we do not warrant that the Service or its infrastructure will be free from unauthorized access. We do not provide backups. Your stickers reside on your device, and retaining copies of what you need is your responsibility (Terms, section 10).

11.3 Incidents. If a security incident places your data at risk, we will notify you without undue delay at the email address on your account, so far as we are able to identify the users affected.

12. Use without an account

You may browse the Service and compose a sticker without an account. No account data exists for guests. The application records a small number of usage events with no identity attached, for example that a sign-in prompt was shown. The bot check runs on the sign-in screens only.

13. The website

dappistickers.com sets no cookies, contains no forms, and runs no analytics. It is hosted by Cloudflare, and its lettering is served from the site itself.

14. Territory

The Service is not directed to, or offered in, the European Union or the United Kingdom.

15. Changes to this policy

When we publish a new version, the application presents it to you and asks you to accept before you continue using the Service. The version number at the head of this policy identifies the version you are reading.

16. Contact

Eilon Aharoni · [email protected]