Privacy Policy
Last updated: 4 August 2026
Greenflag is a real-time dating app based on physical co-presence. It is built around a simple principle: the least data, for the least time. This policy explains what data is processed, why, for how long, and what your rights are.
1. Who is the data controller?
The data controller is ELLEM-AI, a simplified joint-stock company (sole shareholder) registered with the Clermont-Ferrand Trade and Companies Register (RCS) under number 101 130 359, whose registered office is at 23 Impasse du Guéry — 63000 Clermont-Ferrand, and whose full contact details appear in the legal notice.
Greenflag has appointed a data protection officer (DPO), responsible for ensuring compliance with the GDPR and for monitoring that compliance. For any question about the protection of your personal data or to exercise your rights (access, rectification, erasure, withdrawal of consent), you can contact the DPO at the dedicated address: dpo@ellem-ai.com.
2. The principle: no account, no permanent profile
Greenflag asks you for no email, no password, no sign-up. Your technical identity is a pseudonymous, persistent cryptographic key generated on your phone. This key allows the app to recognise you from one scan to the next without ever linking you to a civil identity.
3. What data do we process, and for how long?
| Data | Why (purpose) | Retention period |
|---|---|---|
| Pseudonymous device key | Recognising you between two scans without an account | For as long as you use the app, then deleted after 24 months of inactivity |
| GPS location | Making you visible to people present in the same place (radius ~50 m) | Visible for 3 h, deleted after 12 h at the latest. No long-term retention. |
| Wi-Fi network name (transport mode, optional) | Making you visible to people present on the same network — for example on board a train — when GPS does not work | Immediately turned into a non-reversible group identifier; the network name is neither retained nor logged in clear text; the identifier is tied to the ephemeral session and deleted after 12 h at the latest |
| “In-the-moment” photo | Presence signal; visible to people present in the same place | Automatically deleted after 12 h |
| First name / nickname, greenflags, redflags, gender, preferences, temperament slider (introvert–extrovert) | Introducing you briefly and showing you only to people matching your mutual preferences | Tied to the ephemeral session |
| Mutual greenflag and social network registered / unlocked | Keeping proof of a mutual greenflag and allowing you to find each other again after the session via the chosen social network (e.g. Instagram account) | The network you register is kept for 12 h at most; the mutual greenflag and the unlocked access expire at the end of its validity (at the latest 9 h after the end of the later session), then are deleted |
| Reports | Safety and moderation: handling a report, fighting abuse and protecting people | Kept for as long as necessary to handle the report and to ensure the security of the service (up to 12 months), then deleted |
| Blocks | Ensuring that a blocked person can no longer see you or contact you | Kept for up to 24 months, then deleted; erased immediately if you erase your data |
| Payment data | Micro-payments (in-app purchase): €1 to register your social network, €1 to view that of a person you have a mutual greenflag with | Handled by Apple (App Store) or Google (Play); no banking data is processed or stored by Greenflag |
| Purchase: receipt and transaction identifier | Validating the purchase, proving payment and preventing the fraudulent reuse of a receipt | Kept for approximately 24 months (accounting and legal obligation, replay prevention), then deleted |
4. The photo: taken in the moment, moderated, ephemeral
- The photo is taken by the camera only; no import from the gallery is possible.
- It is subject to automated moderation (explicit content filtering) before becoming visible.
- All metadata is removed: the photo is re-encoded before any upload, without any EXIF or GPS data (no place, no device model, no technical timestamp).
- It is visible to people present in the same place during the session.
- It is automatically deleted after 12 h.
Any illegal content detected or reported is removed and, where the law requires it, passed on to the competent authorities. Greenflag is strictly reserved for adults.
Automated moderation (Article 22 GDPR). Photo filtering relies on automated processing: a photo detected as explicit or unlawful is not published. You can contest an automated moderation decision and request a human review by writing to dpo@ellem-ai.com.
4a. The text you enter: moderated too
Your nickname, your greenflags and your redflags are automatically filtered before being made visible, in order to screen out content that breaches the terms of use (sharing contact info, hateful, violent or threatening speech):
- an analysis is carried out on our infrastructure in France (Clever Cloud);
- a toxicity analysis is entrusted to Mistral AI, a French provider: only the text you enter is sent to it, for the duration of the analysis — never your photo or your location — and its processing stays within the European Union.
As for photos, you can contest an automated block and request a human review by writing to dpo@ellem-ai.com.
5. Location: useful in the moment, never kept
Your location is used solely to make you visible to people present in the same place, within a radius of about 50 metres. This location is recorded approximately (rounded, never to the metre). It is visible for 3 hours, then deleted after 12 hours at the latest. The exact distance between you and other people is never displayed, and Greenflag keeps no history of your movements.
At the time of the scan, this approximate location is also used to determine the nearest municipality (commune), in order to feed an aggregated usage counter (see 5b). This calculation is performed on our servers in France, without any third-party service, using a public reference list of French municipalities; the location itself is not retained for this purpose.
5a. Transport mode (Wi-Fi) — optional
On public transport, where GPS is unreliable, you can enable a mode that makes you visible to people present on the same Wi-Fi network (for example on board a train). This mode is disabled by default. Only the network name is sent by the app — never the hardware (MAC) address of your device or of the access point. That name, combined with the technical characteristics of the connection, is used solely, for the duration of the request, to compute a non-reversible group identifier; it is neither retained nor logged in clear text, and disappears with your session. No geographic location is inferred or retained by this mode.
5b. Usage statistics: aggregated and anonymous
To know where the service is used and to guide its development, we keep an aggregated counter: for each day and each municipality, the number of scans carried out. Nothing else.
- No coordinates: only the municipality is kept, never a precise point.
- No identifier and no link to a person, a device or a particular scan: these counters make it impossible to identify you or to reconstruct any journey.
- Scans carried out in transport mode are counted separately, with no municipality.
- These statistics are used solely for our internal product decisions: they are never sold, shared, or used for advertising purposes.
6. Legal basis for processing
- Consent (Article 6(1)(a) GDPR): collected before your first scan for access to the camera and to location, and when transport mode (Wi-Fi) is enabled, where applicable.
- Explicit consent (Article 9(2)(a) GDPR): for sensitive data (data liable to reveal sexual orientation). This is the legal basis specific to special categories of data; withdrawing it stops your visibility.
- Performance of the service (Article 6(1)(b) GDPR): the minimal processing necessary to make you visible and to enable mutual greenflags.
- Legitimate interest (Article 6(1)(f) GDPR): content moderation and the handling of reports, in order to ensure people's safety and prevent abuse; and the production of aggregated, anonymous usage statistics (see 5b), necessary to steer the service. You may object to this processing (Article 21 GDPR).
- Legal obligation (Article 6(1)(c) GDPR): the removal and, where applicable, the reporting to the authorities of manifestly unlawful content.
You can withdraw your consent at any time, without affecting the lawfulness of processing carried out before that withdrawal.
7. Where is your data hosted?
All data is hosted in France:
- Database and application servers: Clever Cloud (Paris region).
- Photo storage: Cellar (sovereign object storage, France).
Your personal data (database, photos) is hosted and stored exclusively in France (Clever Cloud, Cellar): it is never entrusted to a US host such as AWS, Google Cloud or Firebase. Two ancillary technical services, necessary for the app to work, are operated outside the EU: the delivery of push notifications (Apple APNs on iOS, Google FCM on Android) and the delivery of updates to the app (specialist provider). They receive no sensitive data: a notification contains neither your name, nor your photo, nor your location — only enough to wake the app. Payments are processed directly by the Apple and Google app stores (see below).
8. Processors and recipients
- Clever Cloud (hosting, France) — infrastructure and storage.
- Mistral AI (France) — automated toxicity analysis of free text (nickname, greenflags, redflags) for moderation purposes. Only the text entered is sent to it, for the duration of the analysis; its processing stays within the European Union. No photo or location data is disclosed to it.
- Apple (In-App Purchase) and Google (Play Billing) — process micro-payments when you unlock a feature. The processing of banking data falls under their respective terms and conditions; they may transfer certain data outside the EU, framed by the appropriate safeguards provided for in Chapter V of the GDPR (in particular the European Commission's standard contractual clauses). Greenflag neither processes nor stores any bank card data.
- Apple (APNs) and Google (FCM) — technical delivery of push notifications (APNs on iOS, Firebase Cloud Messaging on Android). The message sent contains no identifying or sensitive data (no name, no photo, no location): only a signal to wake the app. Transfers outside the EU are framed by the appropriate safeguards of Chapter V of the GDPR (European Commission's standard contractual clauses).
- Update delivery provider for the app (fixes and improvements) — no personal usage data is sent to it for this purpose.
- Email sending provider (SMTP) — delivery of internal moderation and security emails, for example the snapshot of a report (first name, nickname, greenflags/redflags, reported photo). These emails travel over encrypted transport (TLS) to the mailbox of the moderation and security team.
When a person submits a report, the information necessary to handle it (for example the reported photo and the reason for the report) may be sent by email to Greenflag's moderation and security team, in order to examine and deal with the reported abuse.
No data is sold or transferred for advertising purposes.
9. Your rights
In accordance with the GDPR, you have the following rights at any time:
- Becoming invisible immediately from the app.
- Erasure: most data is erased automatically; see the Data deletion page.
- Access, rectification, objection and restriction of processing.
- Portability: receiving the data you have provided (Article 20 GDPR) — inherently limited in scope, as your data is ephemeral.
- Reporting and blocking another person.
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing.
To exercise your rights: dpo@ellem-ai.com. You can also lodge a complaint with the CNIL (www.cnil.fr).
10. Minors — age limit
Use of Greenflag is strictly reserved for adult natural persons, aged 18 and over. The Publisher knowingly collects no data relating to minors. If you are under 18, you are not allowed to download, to sign up for, or to use the service. On first access, you tick two dedicated boxes: the first is a sworn statement that you are of age, the second collects your explicit consent to the processing of your sensitive data (Article 9(2)(a) GDPR).
11. Security
We implement technical measures designed to protect your data: minimisation, short lifetimes, automatic deletion, encryption at rest and in transit (database and photos encrypted on our infrastructure in France; exchanges over HTTPS/TLS), integrity checking of photos, removal of metadata and access restriction. To protect the photos displayed, screenshots are blocked or detected depending on the platform, throughout the journey. As no system is infallible, we undertake to inform you in the event of a security incident in accordance with the regulations.
12. Cookies and trackers
The appgreenflag.com website places no advertising cookie or third-party tracker. It uses neither Google Analytics nor any external audience measurement tool: no “cookies” consent is therefore required. The only scripts on the site are internal and technical (displaying the current year, browsing comfort): they collect no data and call no third-party service. Likewise, the mobile app does not use cookies and embeds no advertising SDK.
13. Changes
This policy may change. The date of the last update appears at the top of the page. In the event of a substantial change, you will be informed via the app.