← Back to Fragments

Privacy Policy

Last Updated: June 30, 2026

This Privacy Policy describes how users' personal data is collected, used, stored, and protected during the use of our mobile application (the "Application"). Data processing is carried out in full compliance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679).

1. Data Controller

The Data Controller is the developer and administrator of the Application. For any questions, requests, or to exercise your privacy rights under the GDPR, you can contact the Data Controller directly at the following email address: support.appfragments@gmail.com.

2. Personal Data Collected

The Application collects only the data strictly necessary for the operation of the service and the provision of its features:

  • Registration Data: Email address, encrypted password, and username.
  • User-Generated Content (UGC): The data entered into the "Fragment" (the selection of 1 song, 1 book, and 1 movie).
  • Interaction Data: Preferences expressed on other users' Fragments ("Resonates" or "Pass"), the list of Matches, the history of blocks (Chat Block / User Block), and reports sent to moderation.
  • Communications: Text messages exchanged within the private chat that activates following a mutual Match.

3. Purposes of Processing and Legal Basis

Personal data is processed for the following purposes:

  1. Performance of a contract (Art. 6(1)(b) GDPR): To allow account creation, Fragment publication, matchmaking, and the use of the private chat.
  2. Legitimate interest of the Controller (Art. 6(1)(f) GDPR): To ensure platform security, manage reports (Reports) of offensive content through the moderation queue, and implement blocking features to protect the community.

4. Data Storage and Infrastructure (Lovable Cloud / Supabase)

The Application is developed using the Lovable platform. Consequently, all databases, authentication systems, logs, and storage data of the Application are hosted and protected via the Lovable Cloud infrastructure (technologically based on PostgreSQL databases managed in partnership with Supabase).

Data is stored and hosted on secure servers located within the region chosen during configuration (prioritizing servers within the European Union for European users). Both Lovable and Supabase adopt enterprise-level security measures, including data encryption at rest and in transit, periodic backups, and compliance with international security standards (e.g., SOC 2).

5. Local Technical Identifiers & Cookies

The Application does not use profiling or tracking cookies for advertising purposes. For web users, we use strictly necessary cookies. For mobile app users, we use secure local storage like Keychain on iOS and Keystore on Android. In both cases, the purpose is strictly necessary and solely intended to maintain your active login session, preventing you from re-entered credentials at each access. For more details see our Cookie Policy.

6. Data Retention Period

Data is retained for different timeframes depending on its nature:

  • Profile and Fragment Data: Retained as long as the account remains active. Upon account deletion, the profile and Fragment are immediately removed from the feed.
  • Chat Messages: Retained on the database to ensure conversation continuity between users. They are permanently deleted if the account is deleted.
  • Moderation Data (Reports): Reports and the history of actions taken by the moderator (e.g., removed Fragments or Bans) may be retained for a maximum period of 12 months from report resolution, in order to prevent abuse and handle potential disputes.

7. Data Sharing and International Transfers

Users' personal data is not sold, traded, or transferred to third parties for commercial purposes. Data is transmitted exclusively to cloud service providers appointed as Data Processors (Lovable / Supabase) solely for the provision of the app's technological infrastructure. If the infrastructure of these providers involves transferring data outside the European Economic Area (EEA), this will occur in compliance with the Standard Contractual Clauses (SCC) approved by the European Commission.

8. User Rights (GDPR)

In accordance with the GDPR, users can exercise their rights at any time by contacting the Controller at support.appfragments@gmail.com:

  • Right of Access and Rectification: To verify what data is processed and request corrections.
  • Right to Erasure ("Right to be Forgotten"): To request the deletion of their data. Users can exercise this right independently using the "Delete Account" button within the app.
  • Right to Restriction and Objection: To object to processing for legitimate reasons or request the restriction of processing.
  • Right to Data Portability: To request a copy of their data in a structured, machine-readable format.
  • Right to Lodge a Complaint: To submit a complaint to the competent Data Protection Authority.

9. Data Security

The Data Controller and the connected hosting platforms adopt appropriate technical and organizational security measures to protect data from unauthorized access, alteration, disclosure, or accidental destruction. However, no internet transmission or cloud storage can be guaranteed 100% secure; users are urged to guard their login credentials responsibly.

See also our Terms and Conditions.