Privacy policy
Find information about the data collected, how it is used and retained, and how to contact Sinco.
This policy describes the categories of data processed by Sinco, the purposes and main legal bases for processing, the technical service providers involved, retention principles and the ways to exercise your rights.
1. Data controller and contacts
The data controller is Houlmann Yohann — sole trader (Entrepreneur individuel, EI), trading as CBY, SIREN 924 394 190, 20 rue des Tanneurs, 68800 Thann, France.
Privacy and general support contact: contact@sinco.fr — +33 7 67 28 94 03.
Safety, moderation and child-safety contact: moderation@sinco.fr.
2. Age requirement
Sinco is reserved for people aged 18 or older. During the eligibility check, the date of birth is used transiently to calculate whether the age threshold is met. Sinco does not store this date of birth in the profile or database; it stores only the confirmed minimum-age policy version, the applicable threshold and the confirmation timestamp.
3. Account and profile data
- email address and information required for authentication; passwords are managed by Firebase Authentication and are not stored in plain text by Sinco;
- account identifier, sign-in providers and account-verification status;
- username, display name, biography, profile picture, profile preferences and equipped cosmetics;
- versioned acceptance of the Community Guidelines when required.
4. Content, communications and social activity
- Projects, Steps, Artworks, media, descriptions, hashtags and location information a member chooses to associate with content;
- comments, replies, Supports, Traces, reactions, follows and other social interactions;
- private messages, message requests and information required for delivery and read status;
- reports, blocks and information required for moderation and safety handling.
5. Technical, security and notification data
- installation identifier, IP address and user-agent information where needed for account security, abuse prevention and rate limiting;
- Firebase Cloud Messaging tokens and notification preferences used to deliver requested notifications;
- Firebase App Check / Play Integrity and reCAPTCHA Enterprise signals used to protect certain actions against automated abuse;
- technical data, logs and states needed for diagnostics, reliability, fraud prevention and service security.
6. Google Play purchases, Stripe contributions and advertising
For digital purchases and subscriptions, Sinco processes the information needed to verify the product, purchase status, Premium or cosmetic entitlement and transaction tokens supplied by Google Play. Sinco does not directly process card details for these purchases.
Sinco also allows voluntary contributions through Stripe. They are separate from Premium, cosmetics and other digital purchases and provide no digital benefit or additional entitlement in the app. For this flow, Sinco sends Stripe the information required to create and verify the payment session, including a Sinco account identifier, contribution tier, quantity, amount and technical reconciliation metadata. Stripe processes payment information under its own terms and policies. Sinco retains transaction references and states needed for reconciliation, security, fraud prevention and applicable accounting or legal obligations.
When advertising is enabled for an eligible account, Sinco uses Google Mobile Ads (AdMob). The app first checks consent information through Google’s UMP platform and does not request an ad until the SDK indicates that requesting ads is allowed. Depending on the user’s choices and the applicable Google configuration, the advertising SDK may process advertising identifiers and technical data. Where required by Google, the app provides access to advertising privacy options.
7. Main purposes and legal bases
- Performance of the service and contract: creating and managing accounts, publishing and distributing content chosen by members, messaging, social interactions, purchases, subscriptions and delivery of requested features.
- Legitimate interests: service security, abuse and fraud prevention, rate limiting, diagnostics, reliability and moderation needed to protect the community, subject to the rights and interests of affected individuals.
- Consent where required: in particular for certain advertising or tracking activities that require consent. Consent can be withdrawn for the future through the available options where processing relies on this basis.
- Legal obligations: retaining or disclosing certain information where applicable law requires it, including accounting, tax, safety obligations or valid requests from competent authorities.
8. Service providers and recipients
Sinco relies in particular on Google Firebase and Google Cloud for authentication, databases, storage, server functions, notifications, security and certain moderation checks. Some media may be analysed by Google Cloud Vision as part of Sinco’s automated checks.
Brevo is used to send certain verification or security emails. Google Play is used for billing and purchase validation. Google Mobile Ads is involved when advertising is enabled. Stripe is used for voluntary contributions.
Data is accessible only to recipients and service providers that need it for the purposes described, and to competent authorities or organisations where disclosure is required by law.
9. Transfers outside the European Economic Area
Some international providers may process data from countries outside the European Economic Area. Where the GDPR requires it, such transfers must rely on a mechanism recognised by applicable law, such as an adequacy decision or appropriate contractual safeguards implemented by the provider concerned.
10. Retention and deletion
Account, profile and content data is retained for as long as necessary to operate the account and service and is then deleted or anonymised when it is no longer needed, subject to applicable legal and security obligations.
Direct messages are designed with a technical lifetime of 48 hours. Certain metadata or references needed for operation, safety or report handling may follow a different retention period while they remain necessary.
Closed reports are purged according to the service’s technical policy. Data required for safety, evidence of abuse or compliance with a legal obligation may be retained for longer where justified.
When a member requests deletion of their own account from the app, access to the account is disabled and deletion processing starts without delay. The purge is automated and progressive so the account and associated data can be removed from Firestore, Storage and Firebase Authentication. Several technical passes may be required. Information that must be kept for longer to comply with a legal, accounting, tax or safety obligation is isolated from ordinary use and retained only for as long as necessary.
Account deletion can be requested from account settings in the app or through the public Account deletion page.
11. Data stored locally
The app may keep technical preferences and caches on the device, such as language, interface preferences, tutorial states or previews used to improve responsiveness. Local app data can be cleared through the device or by uninstalling the app.
The sinco.fr website uses browser local storage to remember the selected language. No analytics tool or advertising pixel is integrated into the public website in the version described by this policy.
12. Your rights
Depending on the situation and legal basis, you may request access to your data, correction, erasure, restriction of processing, object to certain processing and request data portability where applicable. Where processing is based on consent, you can withdraw that consent at any time for the future.
To exercise your rights or ask a question about the processing of your data, email contact@sinco.fr. Sinco may request only the information necessary to verify your identity where this is needed to protect your account.
You may also lodge a complaint with the French data-protection authority, the CNIL.
13. Automated moderation and review
Sinco uses automated checks to help identify certain content or behaviour that may violate its rules. These checks assist moderation and safety mechanisms. To request a review of a moderation decision or report an error, email moderation@sinco.fr.