Draft · to be reviewed by a lawyer ("Brouillon à faire valider par un avocat"). Items in brackets must be completed. In case of discrepancy, the French version prevails.
Privacy Policy
Last updated: October 1, 2026
This policy explains what data Maskotto uses, why, for how long, and what your rights are. It applies to the website and to the iOS and Android apps.
1. Data controller
Les Artisans du Digital, 25 rue de Ponthieu, 75008 Paris, France, SIREN 952 778 041.
Data protection contact: bonjour@maskotto.com · Data Protection Officer: not appointed.
2. In short
- Your face photo is used only to create your own character. No facial recognition, no identification.
- We do not sell your data. No targeted advertising.
- We do not train AI models on your photos and videos.
- Your data is hosted in the European Union (Google Cloud, Belgium). Some AI providers are outside the EU: these transfers are safeguarded.
- You can erase everything by deleting your account.
3. Data we process
- Account: email, name or username, login identifier (Google, Apple or email), language, sign-up date.
- Face photos you upload to create your character.
- Motion videos (image, body, and any sound) for motion transfer.
- Text and prompts (character ideas, scene descriptions).
- Generated characters and videos.
- Purchases and credits: offer, amount, date, credit balance and history, transaction ID. We never receive your card number.
- Moderation: check results, refusals, strikes, reports sent or received.
- Technical data: IP address, device type, OS, app version, error logs, notification token.
- Support conversations.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and manage your account, generate characters and videos, store your creations | Performance of contract |
| Process your face photo and motion videos | Performance of contract, and your explicit consent collected before upload (withdrawable at any time by deleting the files) |
| Sell credits and subscriptions, invoice, keep accounts | Performance of contract; legal obligation (accounting, tax) |
| Moderate content, handle reports, prevent abuse and fraud | Legitimate interest (Service safety, protection of people); legal obligations (EU Digital Services Act · DSA) |
| Ensure security and fix bugs (technical logs) | Legitimate interest |
| Aggregated usage statistics to improve the Service | Legitimate interest |
| Service emails (receipts, renewal reminders, price or terms changes) | Performance of contract; legal obligation |
| Newsletters and offers | Consent (one-click unsubscribe) |
| Answer support and data rights requests | Performance of contract; legal obligation |
5. Face photos: our commitments
- We process your photo to produce the image of your character. We do not create a biometric template to identify or authenticate you. We do not perform facial recognition.
- You must only upload photos of yourself. Reference videos (motion transfer) must only show you, or adults who have given their written consent, and you must hold the rights to the video or have its author's consent. Only the moves are transferred to your character: neither the face nor the voice of the people filmed is reproduced.
- Files are sent to the generation provider only to produce the result.
- Source files are deleted automatically after generation (see retention below).
- The reference video (source file) is kept for the period stated below, then deleted; the rights guarantee you tick before uploading is recorded with its date, attached to the generated video, kept with it and deleted with your account.
6. Automated decisions
Before each generation, your request is analysed automatically (keyword filters and an AI model) to block prohibited content. A refusal may therefore be automated. You can ask for a human to review the decision by writing to bonjour@maskotto.com.
7. Retention periods
| Data | Period |
|---|---|
| Uploaded photos and videos (source files) | Kept while the account exists, deleted with it or on request |
| Generated characters and videos | Until you delete them or delete your account |
| Rights guarantees ticked before upload (photos, reference videos, sounds) | Life of the related character or generated video, then deleted with the account |
| Account data | Until account deletion. Inactive account: deleted after 3 years without login, following a notice email |
| Technical logs | 12 months |
| Moderation data (strikes, banned accounts) | Life of the account; for accounts closed for a serious breach: 3 years to prevent re-registration |
| Invoices and accounting records | 10 years (legal obligation). Credit history is anonymised when the account is deleted |
| Support conversations | 3 years after the last exchange |
| Newsletter consent | Until withdrawn, or 3 years without interaction |
Account deletion: from the settings. We delete your photos, videos, characters and generations, then backups within 30 days. Only mandatory accounting records are kept.
8. Who receives your data
Only our authorised staff and our processors, bound by contract (GDPR Article 28):
| Provider | Role | Location |
|---|---|---|
| Google Cloud / Firebase (Google Ireland Ltd) | Hosting, database, storage, authentication, server functions | EU (europe-west1 Belgium, eur3 multi-region) |
| Alibaba Cloud (Model Studio) | Video generation (Wan) from your photos and videos | Singapore |
| Anthropic (Claude) | Writing generation prompts and moderation | United States |
| Stripe | Web payments | Ireland / United States |
| RevenueCat | Mobile in-app purchase management | United States |
| Brevo (Sendinblue SAS) | Sending emails | France (European Union) |
Apple (App Store) and Google (Google Play) process your mobile purchases as independent controllers, under their own policies.
We may disclose data to authorities where required by law.
9. Transfers outside the European Union
Some providers are located outside the European Union: in the United States (Anthropic, RevenueCat and, in part, Stripe) and in Singapore (Alibaba Cloud). These transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, by the provider's certification under the EU-US Data Privacy Framework. We limit the data sent to what is strictly necessary. You can get a copy of the safeguards by writing to bonjour@maskotto.com.
10. Security
Encryption in transit (HTTPS) and at rest, restricted access, security rules on the database and storage, private file links. In the event of a risky data breach, we notify the CNIL and, where required, the people concerned.
11. Minors
Maskotto is for people aged 18 and over. We delete any account or content concerning a minor as soon as we become aware of it.
12. Cookies and trackers
By default, we only use strictly necessary cookies and local storage: login and session, security, language preference, checkout. They do not require your consent.
No advertising cookies. If we ever add audience measurement or advertising tools, we will ask for your consent first, with a "Reject" button as visible as "Accept".
In the mobile app, we request camera and photo access only when you use it, and notifications only with your consent.
13. Your rights
At any time, you can:
- access your data and get a copy;
- have it corrected or erased;
- restrict its use or object to it (in particular to marketing);
- receive it in a reusable format (portability);
- withdraw your consent;
- give instructions on what happens to your data after your death (French law).
Write to bonjour@maskotto.com. We reply within 1 month. We may ask you to prove your identity if we have reasonable doubts.
If you believe your rights are not respected, you can lodge a complaint with the CNIL (www.cnil.fr/fr/plaintes, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France) or with the data protection authority of your EU country.
14. Changes
We may update this policy. For significant changes, we will notify you by email or in the app.