Privacy Policy
Last updated: March 2026 — English translation provided for convenience; the French version prevails in case of discrepancy.
CertiPix is committed to protecting the privacy of its users in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
1. Data controller
The data controller is:
Valentin Audebert
Sole trader (auto-entrepreneur)
Email: contact@certipix.co
2. Data collected
2.1 Mobile app (without an account)
When using the app without an account, we process:
- Digital fingerprint (hash) of the photo: a unique identifier derived from the image, from which the photo cannot be reconstructed.
- Timestamp: date and time of capture.
- Device identifier: an anonymous technical identifier.
Important: without an account, we do NOT store your photos on our servers. Only the digital fingerprint (hash) is transmitted and kept.
2.2 User account and subscriptions
If you have a CertiPix account, we additionally process:
- Email address: used for authentication.
- Password: stored as a bcrypt hash (never in plaintext).
- Certified photos: for subscribers, photos are saved on our servers for viewing in the app.
- Request links: the links generated and the photos received via those links are associated with your account.
- Subscription type: to manage the features available.
Login credentials are stored encrypted on your device (Keychain on iOS, EncryptedSharedPreferences on Android).
2.3 Partner API
For partners using the API, we process:
- API key (stored in encrypted form).
- Usage logs (number of requests, timestamp).
- Photos submitted as part of external requests (kept temporarily).
- Contact information (name, email).
2.4 Website
The contact form collects: name, email, message. This data is used solely to respond to your request.
3. Purposes of processing
- Provide the photo-certification service.
- Enable authenticity verification of certified photos.
- Manage API subscriptions and track usage.
- Respond to contact requests.
- Improve the Service.
4. Legal basis
- Performance of the contract: processing necessary to provide the certification service.
- Legitimate interest: improving the service, security.
- Consent: contact form.
5. Retention period
- Photo fingerprints: kept as long as the certificate is active.
- Photos from external requests: 30 days after the request is completed.
- API usage logs: 12 months.
- Contact data: 3 years after the last contact.
6. Data recipients
Your data is not sold or transferred to third parties. It may be shared with:
- The server host (as part of hosting).
- The competent authorities if required by law.
7. Security
We implement technical and organizational measures to protect your data:
- Encryption of communications (HTTPS/TLS).
- API keys stored as a hash (never in plaintext).
- Restricted access to data.
- Access logging.
8. Your rights (GDPR)
In accordance with the GDPR, you have the following rights:
- Right of access: obtain a copy of your data.
- Right to rectification: correct inaccurate data.
- Right to erasure: request deletion of your data.
- Right to portability: receive your data in a structured format.
- Right to object: object to the processing of your data.
- Right to restriction: restrict the processing of your data.
To exercise these rights, contact us at: contact@certipix.co
You may also lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).
9. Cookies
The CertiPix website does not use tracking cookies or third-party cookies. Only technical cookies strictly necessary for operation may be used.
10. Transfers outside the EU
Your data is hosted within the European Union. In the event of a transfer outside the EU, appropriate safeguards will be put in place (standard contractual clauses).
11. Changes
This policy may be updated. The date of last modification is shown at the top of the document.
12. Contact
For any question: contact@certipix.co