Privacy Policy & Data Protection
Kiplik is dedicated to safeguarding your privacy, personal memoirs, and family photographs. This policy explains how your information is collected, processed, and secured in compliance with the General Data Protection Regulation (GDPR) and global privacy standards.
1. Data Controller & Contact
The data controller responsible for the processing of personal data collected through the Kiplik service is Kiplik. For any questions, inquiries, or to exercise your privacy rights, please contact our Data Protection Officer at: privacy@kiplik.com.
2. Personal Data We Collect
When using Kiplik, we collect the following categories of personal data:
- Account & Identity Data: Full name, email address, unique user identifier (Firebase UID), and profile picture (if provided).
- User Content & Memoirs: Written stories, chapter drafts, uploaded audio notes/transcripts, uploaded photographs, and associated EXIF metadata.
- AI Assistant Interactions: Prompts, writing instructions, questions submitted to the creative assistant, and generated suggestions.
- Payment & Shipping Data: Transaction references, tokenized payment methods (handled directly by Stripe), physical delivery addresses, and recipient contact info for printed book orders.
- Technical & Usage Data: IP address, access logs, browser type, operating system, and session tokens.
3. Purposes & Legal Bases for Processing
Your data is processed for explicit purposes, each anchored on a valid legal basis:
Performance of Contract (Art. 6.1.b GDPR)
Providing the writing studio, securely storing your stories and photos, generating layout previews, producing print files (PDF/EPUB), and printing/shipping your hardcover books.
User Consent (Art. 6.1.a GDPR)
Accessing your device microphone for audio recording and transcription, as well as invoking AI writing tools (Google Gemini).
Legitimate Interests (Art. 6.1.f GDPR)
Preventing fraud, safeguarding platform infrastructure, optimizing service performance, and maintaining security.
Legal Compliance (Art. 6.1.c GDPR)
Retaining accounting records, proof of transactions, and tax invoices as mandated by applicable statutory laws.
4. Data Retention Period
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account Data & Projects: Retained while your account remains active. Upon account deletion, all your projects, texts, and photos are permanently erased from our servers within 30 days.
- Temporary Audio Recordings: Processed immediately for transcription and then deleted or saved to your chapter based on your choice.
- Transaction & Invoicing Data: Kept for 10 years to comply with statutory fiscal and commercial recordkeeping obligations.
- Security & Technical Logs: Retained for up to 12 months before automatic deletion.
5. Your Rights & How to Exercise Them
Under GDPR and applicable privacy legislation, you hold the following rights regarding your personal data:
- Right of Access: Request confirmation of data processing and receive a copy of your personal data.
- Right to Rectification: Correct inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data.
- Right to Data Portability: Export your stories, drafts, and photos in a structured, machine-readable format.
- Right to Restrict or Object: Limit or object to specific processing operations for legitimate grounds.
- Right to Withdraw Consent: Revoke consent at any time for consent-based features.
Exercising Your Rights
You can exercise your rights at any time by emailing privacy@kiplik.com or directly via your Account settings (data export and account deletion). Proof of identity may be requested for verification.
Lodging a Complaint
If you believe our data processing violates your rights, you have the right to lodge a complaint with your national data protection supervisory authority (such as the CNIL in France, ICO in the UK, or CPPA in Canada).
6. Data Security & Encryption
Kiplik enforces rigorous technical and organizational security measures to protect your content from unauthorized access, loss, or alteration:
- Encryption in transit using modern HTTPS / TLS 1.3 encryption.
- Encryption at rest for databases and file storage (AES-256).
- Strict user isolation enforced by granular Firebase Security Rules.
- Server-side validation for media uploads (MIME type restrictions and file size caps).
- Role-based access control based on the principle of least privilege.
Subprocessors & Service Providers
We work with trusted service providers for cloud hosting, AI processing, payment handling, and book printing.
Google Cloud & Firebase
Application hosting, secure user authentication, Firestore database, and Cloud Storage for media assets.
Google Gemini API
AI language models powering creative assistance, interview questions, and chapter drafting.
Stripe Inc.
Secure payment gateway for credit packs and physical book orders. Certified PCI-DSS Level 1.
Lulu Press, Inc.
On-demand printing, hardcover binding, and global shipping of ordered physical memoirs and photobooks.
Exercer vos droits RGPD
Une question sur vos données ou une demande d’exportation / suppression ? Écrivez-nous directement.