← Back to home

Privacy Policy

Courtesy translation. This English version is provided for convenience only. The French version is the legally binding text.

Last updated: 4 August 2026

Greenflag is a real-time dating app based on physical co-presence. It is built around a simple principle: the least data, for the least time. This policy explains what data is processed, why, for how long, and what your rights are.

1. Who is the data controller?

The data controller is ELLEM-AI, a simplified joint-stock company (sole shareholder) registered with the Clermont-Ferrand Trade and Companies Register (RCS) under number 101 130 359, whose registered office is at 23 Impasse du Guéry — 63000 Clermont-Ferrand, and whose full contact details appear in the legal notice.

Greenflag has appointed a data protection officer (DPO), responsible for ensuring compliance with the GDPR and for monitoring that compliance. For any question about the protection of your personal data or to exercise your rights (access, rectification, erasure, withdrawal of consent), you can contact the DPO at the dedicated address: dpo@ellem-ai.com.

2. The principle: no account, no permanent profile

Greenflag asks you for no email, no password, no sign-up. Your technical identity is a pseudonymous, persistent cryptographic key generated on your phone. This key allows the app to recognise you from one scan to the next without ever linking you to a civil identity.

3. What data do we process, and for how long?

Data Why (purpose) Retention period
Pseudonymous device key Recognising you between two scans without an account For as long as you use the app, then deleted after 24 months of inactivity
GPS location Making you visible to people present in the same place (radius ~50 m) Visible for 3 h, deleted after 12 h at the latest. No long-term retention.
Wi-Fi network name (transport mode, optional) Making you visible to people present on the same network — for example on board a train — when GPS does not work Immediately turned into a non-reversible group identifier; the network name is neither retained nor logged in clear text; the identifier is tied to the ephemeral session and deleted after 12 h at the latest
“In-the-moment” photo Presence signal; visible to people present in the same place Automatically deleted after 12 h
First name / nickname, greenflags, redflags, gender, preferences, temperament slider (introvert–extrovert) Introducing you briefly and showing you only to people matching your mutual preferences Tied to the ephemeral session
Mutual greenflag and social network registered / unlocked Keeping proof of a mutual greenflag and allowing you to find each other again after the session via the chosen social network (e.g. Instagram account) The network you register is kept for 12 h at most; the mutual greenflag and the unlocked access expire at the end of its validity (at the latest 9 h after the end of the later session), then are deleted
Reports Safety and moderation: handling a report, fighting abuse and protecting people Kept for as long as necessary to handle the report and to ensure the security of the service (up to 12 months), then deleted
Blocks Ensuring that a blocked person can no longer see you or contact you Kept for up to 24 months, then deleted; erased immediately if you erase your data
Payment data Micro-payments (in-app purchase): €1 to register your social network, €1 to view that of a person you have a mutual greenflag with Handled by Apple (App Store) or Google (Play); no banking data is processed or stored by Greenflag
Purchase: receipt and transaction identifier Validating the purchase, proving payment and preventing the fraudulent reuse of a receipt Kept for approximately 24 months (accounting and legal obligation, replay prevention), then deleted
Sensitive data (special categories of personal data — Article 9 GDPR). Given its purpose of connecting people, Greenflag processes data liable to reveal your sexual orientation (your connection preferences). This data is processed solely on the basis of your explicit consent (Article 9(2)(a) GDPR), collected before the first scan and revocable at any time. Your photograph, while not a special category within the meaning of Article 9 (no facial recognition, no biometric processing), benefits from the same reinforced measures: minimisation, very short lifetimes (3 h / 12 h), automatic deletion and the complete absence of advertising profiling.

4. The photo: taken in the moment, moderated, ephemeral

Any illegal content detected or reported is removed and, where the law requires it, passed on to the competent authorities. Greenflag is strictly reserved for adults.

Automated moderation (Article 22 GDPR). Photo filtering relies on automated processing: a photo detected as explicit or unlawful is not published. You can contest an automated moderation decision and request a human review by writing to dpo@ellem-ai.com.

4a. The text you enter: moderated too

Your nickname, your greenflags and your redflags are automatically filtered before being made visible, in order to screen out content that breaches the terms of use (sharing contact info, hateful, violent or threatening speech):

As for photos, you can contest an automated block and request a human review by writing to dpo@ellem-ai.com.

5. Location: useful in the moment, never kept

Your location is used solely to make you visible to people present in the same place, within a radius of about 50 metres. This location is recorded approximately (rounded, never to the metre). It is visible for 3 hours, then deleted after 12 hours at the latest. The exact distance between you and other people is never displayed, and Greenflag keeps no history of your movements.

At the time of the scan, this approximate location is also used to determine the nearest municipality (commune), in order to feed an aggregated usage counter (see 5b). This calculation is performed on our servers in France, without any third-party service, using a public reference list of French municipalities; the location itself is not retained for this purpose.

5a. Transport mode (Wi-Fi) — optional

On public transport, where GPS is unreliable, you can enable a mode that makes you visible to people present on the same Wi-Fi network (for example on board a train). This mode is disabled by default. Only the network name is sent by the app — never the hardware (MAC) address of your device or of the access point. That name, combined with the technical characteristics of the connection, is used solely, for the duration of the request, to compute a non-reversible group identifier; it is neither retained nor logged in clear text, and disappears with your session. No geographic location is inferred or retained by this mode.

5b. Usage statistics: aggregated and anonymous

To know where the service is used and to guide its development, we keep an aggregated counter: for each day and each municipality, the number of scans carried out. Nothing else.

6. Legal basis for processing

You can withdraw your consent at any time, without affecting the lawfulness of processing carried out before that withdrawal.

7. Where is your data hosted?

All data is hosted in France:

Your personal data (database, photos) is hosted and stored exclusively in France (Clever Cloud, Cellar): it is never entrusted to a US host such as AWS, Google Cloud or Firebase. Two ancillary technical services, necessary for the app to work, are operated outside the EU: the delivery of push notifications (Apple APNs on iOS, Google FCM on Android) and the delivery of updates to the app (specialist provider). They receive no sensitive data: a notification contains neither your name, nor your photo, nor your location — only enough to wake the app. Payments are processed directly by the Apple and Google app stores (see below).

8. Processors and recipients

When a person submits a report, the information necessary to handle it (for example the reported photo and the reason for the report) may be sent by email to Greenflag's moderation and security team, in order to examine and deal with the reported abuse.

No data is sold or transferred for advertising purposes.

9. Your rights

In accordance with the GDPR, you have the following rights at any time:

To exercise your rights: dpo@ellem-ai.com. You can also lodge a complaint with the CNIL (www.cnil.fr).

10. Minors — age limit

Use of Greenflag is strictly reserved for adult natural persons, aged 18 and over. The Publisher knowingly collects no data relating to minors. If you are under 18, you are not allowed to download, to sign up for, or to use the service. On first access, you tick two dedicated boxes: the first is a sworn statement that you are of age, the second collects your explicit consent to the processing of your sensitive data (Article 9(2)(a) GDPR).

11. Security

We implement technical measures designed to protect your data: minimisation, short lifetimes, automatic deletion, encryption at rest and in transit (database and photos encrypted on our infrastructure in France; exchanges over HTTPS/TLS), integrity checking of photos, removal of metadata and access restriction. To protect the photos displayed, screenshots are blocked or detected depending on the platform, throughout the journey. As no system is infallible, we undertake to inform you in the event of a security incident in accordance with the regulations.

12. Cookies and trackers

The appgreenflag.com website places no advertising cookie or third-party tracker. It uses neither Google Analytics nor any external audience measurement tool: no “cookies” consent is therefore required. The only scripts on the site are internal and technical (displaying the current year, browsing comfort): they collect no data and call no third-party service. Likewise, the mobile app does not use cookies and embeds no advertising SDK.

13. Changes

This policy may change. The date of the last update appears at the top of the page. In the event of a substantial change, you will be informed via the app.

A question about your data? Write to us: dpo@ellem-ai.com.