Privacy Policy
Summary
This summary is provided for convenience only. It is not part of this policy, and it neither qualifies nor expands the numbered sections below, which govern.
- Your photograph. Used to produce your sticker: screened by automated safety services, transmitted to the AI service that generates your clip, and deleted from our storage on delivery of that clip (section 2).
- Model training. We do not use your content to train AI models, and we train no models of our own. Section 2.6 states what we can and cannot say about the AI providers we use.
- Face data. We do not use your photograph to identify you or any other person. We operate no facial recognition and build no face databases (section 2.6).
- Your stickers. Private to your account. The Service has no feed and no sharing surface.
- Advertising. The application and the website carry no advertising, no ad networks, no tracking software and no third-party analytics, and we do not sell personal data (section 4).
- Deletion. You can delete your account in the application. A limited set of safety records survives, and section 8.2 identifies every one.
- Contact. [email protected].
1. Controller, scope and legal basis
1.1 Controller. Dappi is operated by Eilon Aharoni, an independent developer based in Israel. He is the data controller, meaning the person responsible for how your data is handled. Contact: [email protected].
1.2 Scope. This policy covers the Dappi application and the dappistickers.com website (together, the "Service").
1.3 Voluntary provision. You are under no legal obligation to provide information to us, and provision is voluntary in each case. Where information is necessary to deliver a function of the Service, that function is unavailable without it. An email address is required in order to create an account. A photograph and a prompt are required in order to generate a sticker.
1.4 Legal basis. We process your data on the basis of your consent: the agreement you give at sign-up, and the separate consent you give before your first AI generation. You may withdraw consent at any time by deleting your account.
2. How your photograph is processed
2.1 On your device. Selection and cropping take place on your device. A photograph is uploaded only when you tap Generate.
2.2 Safety screening. When you tap Generate, the photograph and your prompt are uploaded to our storage and screened by an automated safety service:
- OpenAI (United States) receives the photograph and the prompt for a safety check. Per its published documentation, it does not train on this data and retains nothing after the check. Images flagged as child sexual abuse material may be retained longer by OpenAI for review and reported to the authorities.
2.3 Generation. If the screening passes, your photograph and your prompt are transmitted to a video provider, through a private, time-limited link or directly, and a video model produces your clip. The application offers a small menu of video models, and you choose the model for each sticker. Our video providers are Replicate and fal, both United States companies. One of them receives your photograph and prompt, and we may change which one we use. Per fal's published terms, some models on its platform are run by the model's developer rather than by fal, and content sent to such a model is transferred to that developer. fal marks those models on its platform, and states that its restrictions on the use of customer content and its data processing agreement apply to them. Section 5 identifies each developer that receives your data, and where it may process it. We do not control the developers, we cannot verify what they do with content once it reaches them, and we give no warranty in respect of their conduct. Per Replicate's published documentation, it deletes its copy of the inputs and outputs automatically about an hour after the run. For fal, we set a one-hour retention on fal's own copies. That setting applies to fal's copies and does not bind a model developer that receives your content.
2.4 Deletion of the source photograph. On delivery of your clip, our storage deletes the source photograph. Where a generation never completes, the photograph is removed within about two days. Where the photograph itself is flagged by a safety check, we retain a copy for up to 30 days for abuse review, after which it is deleted.
2.5 Storage of clips and stickers. Under a paid subscription, your clips and finished stickers are stored in the cloud until you delete them or your account. Stickers finished on the free tier reside on your device and not in the cloud, and the cloud copy of a clip made on the free tier is removed once the sticker is finished. On upgrade, the stickers on your device are uploaded for you.
2.6 Face data, and limits on our use of your content.
- We do not use your photograph, or data derived from it, to identify you or any other person. We operate no facial recognition and build no face templates or face databases.
- We do not sell or trade your photograph.
- We do not use your photographs, prompts or stickers to train, fine-tune or evaluate AI models, and we develop and train no models of our own. Before we engage an AI provider we assess its published terms and its data processing agreement. We engage only providers whose terms and data processing agreement require them to use customer content solely to provide their service, and permit them to improve their own models only on anonymized or aggregated data. We do not control those providers. We cannot verify what they do with content once it reaches them, their terms may change without notice to us, and we give no warranty in respect of their conduct. We will update this policy if the position we have assessed changes.
- The background cut-out feature runs on your device, and the image data it creates in the process is not uploaded.
2.7 Laws treating face data as biometric. Some laws treat data derived from images of faces as biometric information. We do not use your photograph to identify anyone, but where such laws require consent, we process your photograph only with yours. That is why the Service asks for your explicit agreement before your first generation.
3. Categories of data we collect
Account. Your email address and a password stored only in a scrambled one-way form (a hash), or your Apple or Google sign-in. With Apple sign-in we receive an identifier specific to Dappi and your email address, or Apple's private relay address if you chose to hide your email. With Google sign-in we receive your name, email address and profile picture. An optional display name and your subscription tier are stored in your profile.
Content. Your photographs (briefly, as described in section 2), prompts, clips, stickers, videos, editor text and emoji, pack names, and saved presets. Section 7 states how long each of these is kept, and section 8 what happens to them when you delete.
Purchases. If you buy a subscription, Apple processes the payment. We receive subscription status and purchase history through RevenueCat, our subscription processor. Neither we nor RevenueCat receives your card or bank details.
Store country. We record the country of your App Store account, once, as a two-letter code. The App Store supplies it to the application on your device. We use it only to determine whether an account is eligible for the credits granted on sign-up, which we may offer in some countries and not in others. This is an attribute of your App Store account and not a location. We do not collect location data, and we do not derive this code from a postal address or an IP address.
Consent records. Each time you accept the Terms or this policy, and when you give generation consent, we record which document version you accepted, when, in which screen, the email address on the account, and the application version and device user agent that made the request. We do not record your IP address with your consent.
Moderation records. When a generation is blocked, we record the prompt, the reason, your account, and the email address on it. Where the photograph itself was flagged, a copy is retained briefly (section 2.4). These records exist to prevent abuse.
Support and reports. Messages you send through the feedback form or by email. If you report an error, the report includes the application version, the screen, the error message displayed to you, the raw technical error text, and a random session code created when the application started, which connects your report to that session's technical measurements.
Technical measurements. The application records usage events and performance measurements, for example timings, sizes, and device state such as low memory, in order to keep the Service working well. These are recorded without your account attached and do not include prompts, photographs or email addresses. They remain unconnected to you unless you send a report, as described above.
Notifications. If you allow notifications, we store a device push token. Notifications state only that your sticker is ready.
Server logs. Our infrastructure provider keeps short-lived technical logs, comprising IP address, approximate location derived from it, and request metadata, for security purposes, for about a day. Request bodies, including your photographs and prompts, are not written to those logs.
On your device. Your sign-in session is kept in the device keychain, and stickers, videos and caches are stored in the application's own storage. Deleting the application removes the stickers, videos and caches. iOS may retain the keychain entry after the application is deleted. Signing out before you delete the application clears it.
4. Limits on our use of your data
4.1 No sale of personal data. We do not sell or rent personal data, and we have not done so.
4.2 No advertising or tracking. The application and the website carry no advertising, no ad networks, no tracking software development kits and no third-party analytics. The website sets no cookies and contains no forms. Our emails contain no tracking pixels and no rewritten tracking links.
5. Recipients
We use a small set of companies to operate the Service. Each receives only what its function requires.
- Supabase operates our database, sign-in and file storage. Everything identified in section 3 that we store is stored with Supabase. Primary storage is in Singapore, with limited support access from the United States, and some processing may run in other locations, as section 6 describes.
- Replicate (United States) and fal (United States) are our video providers. One of the two receives your photograph and prompt in order to generate your clip, as described in section 2.3. Per Replicate's documentation, its copies delete automatically after about an hour. For fal, we set that same one-hour period for fal's own copies.
- Model developers. One of the models on the menu is developed by ByteDance. Per fal's published terms, that model runs through ByteDance's own systems, so your photograph and prompt are transferred to ByteDance when you select it. The other model runs on fal's own infrastructure, and its developer receives nothing. Per fal's published terms, fal's restrictions on the use of customer content and its data processing agreement apply to these models. ByteDance's international arm processes data from locations including Singapore, Malaysia and Indonesia. We do not control ByteDance and give no warranty in respect of its conduct.
- OpenAI (United States) receives your photograph and prompt for the pre-generation safety check. Per its published documentation, it retains nothing after the check (section 2.2).
- Resend (United States) delivers our emails: sign-up confirmations, password resets and account notices. Resend retains sent email content for about 30 days.
- Cloudflare provides the bot check on the sign-in screens (called Turnstile), hosts the website, and routes email to our inbox. During the bot check your device sends Cloudflare its IP address, a technical fingerprint of the connection, and browser information. Cloudflare also uses these signals to improve its bot detection. See Cloudflare's Turnstile Privacy Addendum at cloudflare.com/turnstile-privacy-policy for details. Cloudflare does not store our support email; it passes it on.
- Apple handles Apple sign-in, delivers notifications, and processes all payments. Apple may hold an undelivered notification for up to 30 days. We do not receive your payment details.
- Expo (United States) relays our notifications to Apple. Per Expo, notification contents are held only in memory and delivery receipts are cleared within 24 hours.
- Google Sign-In, if you use it, shares your name, email address and profile picture with us, and keeps its own record that your Google account is linked to Dappi.
- RevenueCat (United States) is our subscription processor. Its software runs inside the application from the moment you open it, so it receives, with each request it makes, the account identifier, an identifier Apple assigns to our applications for your device, your device model and operating system version, your device language preferences, and the country of your App Store account. If you buy a subscription it also receives the Apple receipt and your purchase history. It does not receive payment details. We do not enable its attribution features, and it does not receive the Apple advertising identifier.
- Gmail. Emails you send to [email protected] are received and stored in a Google mailbox.
Other disclosures. We disclose data where a law, a court order or a competent authority validly requires it, including the reporting of content that sexually exploits children, as section 6 of the Terms provides. If the Service is transferred to a company formed to operate it, your data transfers with it under this policy.
Limits on sharing. Other than as described in this section, we do not share personal data with third parties for their own marketing or advertising purposes. We may engage further service providers in order to operate the Service, and will update this section when we do. Before adopting a replacement AI model or provider, we will assess it against the protections described in this policy, and will update this policy where the position materially differs.
6. International processing
We operate from Israel. Your data is stored and processed in the United States, in Singapore, and in other locations in which the companies identified in section 5 operate, and those locations may change. By using the Service you agree that your data is stored and processed outside Israel.
7. Retention
- Source photograph: deleted on delivery of your clip. At most about two days where a generation never completes.
- Copy of a safety-flagged photograph: up to 30 days.
- Clips, stickers, videos: under a paid subscription, retained in the cloud until you delete the sticker or your account. Stickers finished on the free tier reside on your device, and the cloud copy of a free account's clip is removed once the sticker is finished. Section 10.2 of the Terms also reserves a right to remove cloud copies of accounts that have been without an active subscription for 30 days. Stickers on your device are not affected.
- Prompts: retained with your sticker until you delete it, and in presets you save until you delete them. Every prompt is also written, with nothing connecting it to you or your sticker, into a safety archive, and the text is removed from that archive after 365 days. Where a prompt is blocked, the blocked-attempt record is retained for 90 days. Technical error records, which can quote a prompt, are retained for 30 days.
- Store country: for as long as your account exists, and deleted with it.
- Consent records: for as long as your account exists, and for 7 years after deletion, as evidence of consent.
- Moderation records: blocked-attempt records for 90 days. Records of account closures for breach are retained for as long as necessary to keep those closures effective.
- Feedback: for as long as your account exists, and deleted with it. Emails you send us remain in our support mailbox.
- Technical measurements: retained without account linkage, with no fixed deletion date.
- Sent emails at Resend: about 30 days.
- Server logs: about a day.
8. Deletion, and what survives it
8.1 Deleting your account. You may delete your account at any time in the application, at Profile, then Delete account. This permanently deletes your photographs, clips, stickers and videos from our storage, and your profile, packs, presets, credit history, feedback, notification tokens and sign-in records. If you signed in with Apple, we also instruct Apple to disconnect Dappi from your Apple ID.
8.2 What survives. A limited set of records survives deletion, by design:
- consent records, including the email address on them: kept 7 years as proof of consent;
- blocked-attempt records, including the email address on them: up to 90 days, and any safety-flagged photo copy up to 30 days, for abuse prevention;
- ban records: kept so that a ban cannot be escaped by deleting the account;
- technical error records: up to 30 days;
- technical measurements that were never connected to your account;
- a deletion marker with no name and no email: 7 years.
8.3 Subscriptions. Deleting your account does not cancel an Apple subscription. Cancel it in your Apple ID settings.
8.4 Deleting the application. Deleting the application from your device removes the stickers, videos and caches stored there. Your sign-in session resides in the device keychain, and iOS may retain it after the application is deleted. Signing out before you delete the application clears it.
9. Your rights
9.1 Requests. You may request access to the personal data we hold about you, its correction, a copy of it, or its deletion. Deletion is available in the application (section 8). For any other request, email [email protected] from the address on your account. We respond within 45 days and make no charge. We may require verification of your identity before acting on a request. Where a request is complex, or where you have made a number of requests, we may extend that period and will tell you if we do. We may decline requests that are manifestly unfounded or excessive.
9.2 Local rights. If you are in Israel, these include your inspection and correction rights under the Privacy Protection Law, and you may complain to the Privacy Protection Authority, Israel's privacy regulator. Where the law of the place you live confers further rights that apply to us, we honor those.
10. Children
The Service is not intended for children under 13. We do not knowingly collect data from children under 13. If we become aware that an account belongs to a child under 13, we will close it and delete its data. Parents and guardians may contact us at [email protected].
11. Security
11.1 Measures. Data is encrypted in transit and at rest by our providers. Access to your data is restricted to your signed-in account by database and storage access controls, and the AI services are called from our servers, using credentials that are not distributed with the application.
11.2 No guarantee of security, and no backups. No service is perfectly secure, and we do not warrant that the Service or its infrastructure will be free from unauthorized access. We do not provide backups. Your stickers reside on your device, and retaining copies of what you need is your responsibility (Terms, section 10).
11.3 Incidents. If a security incident places your data at risk, we will notify you without undue delay at the email address on your account, so far as we are able to identify the users affected.
12. Use without an account
You may browse the Service and compose a sticker without an account. No account data exists for guests. The application records a small number of usage events with no identity attached, for example that a sign-in prompt was shown. The bot check runs on the sign-in screens only.
13. The website
dappistickers.com sets no cookies, contains no forms, and runs no analytics. It is hosted by Cloudflare, and its lettering is served from the site itself.
14. Territory
The Service is not directed to, or offered in, the European Union or the United Kingdom.
15. Changes to this policy
When we publish a new version, the application presents it to you and asks you to accept before you continue using the Service. The version number at the head of this policy identifies the version you are reading.
16. Contact
Eilon Aharoni · [email protected]