Privacy policy
Version 2026-09-23.4Controller and scope
The controller is Amélie Denoual, who publishes NALYKO in her own name. For data questions or requests, contact: contact@nalyko.com. This policy covers the NALYKO app and nalyko.com mini-site.
NALYKO is for adults aged 18 or over. Age is self-declared; no routine identity-document check is implemented.
Data and purposes
You provide account and profile information. The application also creates timestamps, relationships, discovery history and technical events. Other users may submit reports concerning you. Contract necessity must be assessed for each field; accepting terms is not blanket privacy consent.
| Data | Purpose | Legal basis | Retention | Recipient |
|---|---|---|---|---|
| Email, user ID, password handled by Supabase Auth, session | Account access, authentication emails and security | Contract; legitimate interest for security | During account life, then deleted through the account-deletion flow; logs and backups have separate periods | Publisher, Supabase; Brevo carries transactional account/service email according to the publisher |
| Nickname, declared age, country, languages, platforms, timezone, voice and game preferences | Profile, adult access and gaming compatibility | Contract where necessary; declared age and country support adult access and matching | Until editing or account deletion | Publisher, Supabase, authenticated users for profile data |
| Games, ranks, roles, precise weekly slots or variable time-of-day tendencies, gameplay preferences | Partner suggestions | Contract for requested matching | Until editing or account deletion | Publisher, Supabase, authenticated users according to profile access |
| Optional avatar and biography | Profile personalisation | Contract for requested publication | Deletion on replacement is attempted for avatars; account deletion; caches to verify | Publisher, Supabase Storage, authenticated users |
| Messages, Mate requests and relationships, teams and invitations | Communication and organising games | Contract | For the beta, account cascades delete sent and received messages, including the other participant’s copy; no separate conversation archive exists | Publisher, Supabase, recipients and authorised members; teams according to access rules |
| Viewed, passed and requested profiles and timestamps | Order discovery and avoid repetition | Contract for the feature; necessity to document | History used to avoid repetition; maximum purge period still to be set | Publisher, Supabase |
| Blocks, hidden conversations, report reasons and details | Safety and handling abuse | Legitimate safety interest; legal obligation for required follow-up | Reports linked to an account currently cascade on deletion. If targeted evidence is separately preserved for safety or a dispute, the beta limit is 12 months after case closure, subject to a justified individual extension | Authorised staff, Supabase; authorities where legally justified |
| Push token, installation ID, preferences, events and receipts | Optional message, Mate and Team notifications | Contract for requested feature; separate system permission | Removal requested at logout, invalidation or account deletion; event and receipt purges depend on necessity | Publisher, Supabase, Expo Push Service, Google FCM |
| Terms/rules version, notice shown, user ID and server acceptance timestamp | Contractual acceptance and information record | Contract and legitimate evidential interest | Until account deletion; legal text archives kept separately without personal data | Publisher, Supabase |
| Support and rights requests, connection metadata and errors | Assistance, rights and security | Contract, legitimate security interest, legal obligation for rights | Ordinary support: 3 months after closure. Ordinary technical logs: 30 days; necessary security traces: up to 90 days. Rights/dispute files and backups have separate criteria | Publisher, Infomaniak mailbox and technical providers as applicable |
Required and optional information
Registration requires email, password, self-declaration of being 18 or over and acceptance of terms and community rules. Current onboarding also requires a nickname, declared age of 18–120, country, languages, platforms, gaming choices, regular or variable availability and game preferences. Identity is not officially verified.
Avatars, biographies, messaging, team creation and notifications are optional. Do not submit sensitive information or identity documents in profiles, messages or reports. The preference questionnaire is about gaming and is not a psychological diagnosis.
Suggestions and visibility
Compatibility compares languages, platforms, games, goals, ranks, schedules, communication and gameplay preferences. You choose whom to connect with. No automated decision with legal or similarly significant effects was identified in this matching.
Profile information is accessible to authenticated users under the database rules. Messages are intended for their participants, with possible technical access by authorised staff. The audited code does not implement end-to-end encryption.
Providers and international transfers
Supabase provides authentication, database, server functions and avatar storage. Expo/EAS builds the app; Expo Push Service relays notifications through Firebase/FCM. Google Play distributes the Android app. The audited push payload does not include private message bodies.
According to the publisher, Infomaniak manages the domain, DNS and contact@nalyko.com mailbox. Brevo carries only transactional account/service email, with no declared marketing campaigns. The mini-site is hosted on Cloudflare Pages. The publisher reports no intentional Google Analytics, Meta Pixel, Hotjar or advertising tracker.
Processing or access outside the EEA remains possible. The regions, contracts and transfer mechanisms actually applicable to NALYKO accounts have not yet been evidenced. No signed agreement or exclusively European hosting is presumed.
Device storage and notifications
Sessions use AsyncStorage on mobile and Supabase local storage in the authenticated web app. Tutorial flags and, on Android, an installation ID and last opened push event are stored. See the Cookies page for the inventory. The static mini-site sets no application trackers.
Android notification permission and per-category settings apply. That system permission is not blanket GDPR consent. The publisher reports no intentional Google Analytics, Meta Pixel, Hotjar or advertising tracker; release SDKs and host-added website trackers still need checking.
Deletion, retention and security
Settings → Delete my account starts deletion; requests may also be sent to contact@nalyko.com. Currently the function removes avatars and the Auth account, and database cascades delete the profile, messages both sent and received, teams created and reports linked to the account. Effects on other participants must be considered before any policy change.
Reports linked to the account currently disappear by cascade; no separate moderation archive is in service. For the beta, targeted evidence may be isolated only where needed for safety, abuse prevention, a dispute or law, with restricted access and a 12-month limit after case closure unless an individual extension is justified.
Beta policy: 30 days for ordinary technical logs, up to 90 days for necessary security or incident traces, and 3 months after closure for ordinary support. Provider and backup settings remain to be verified before opening. Rights requests or disputes may justify a distinct limited file. Sent and received messages are deleted with the account for the beta.
Observed controls include authentication, database access rules and one-hour avatar signed URLs. URL expiry does not delete the image. Encryption, admin access and backups require verification; absolute security is not guaranteed.
Your rights
Contact contact@nalyko.com to request access, rectification, erasure or restriction, or object on grounds relating to your situation to processing based on legitimate interests. Portability covers data you provided where automated processing relies on contract or consent. These rights are subject to their legal conditions and the rights of others.
Where consent is the basis, you may withdraw it as easily as you gave it, without affecting earlier lawful processing. Accepting terms is not blanket consent. You may also give instructions concerning your data after death under applicable French law.
Requests must be answered within one month. A further two months may be justified by complexity or volume, with notice during the first month. Proportionate identity verification may be requested where reasonable doubt exists; identity documents are not systematically required. You can complain to the CNIL at https://www.cnil.fr/fr/plaintes and retain judicial remedies.
Updates
Changes are dated and versioned. New purposes must be explained before implementation. Material changes to terms or community rules require renewed acceptance; updating this notice does not manufacture consent for processing.