01 Who we are
Popsillage is a 13+, iOS-first app for collecting, discovering, layering, and sharing finished fragrances. There are no under-13 accounts. This policy covers the iOS app and popsillage.com.
We designed Popsillage to treat the US state Age-Appropriate Design Codes and the UK AADC as the floor, not the ceiling — privacy-protective defaults for everyone, and extra care for teens.
02 What we collect
- Account — you sign in with Apple. We receive an Apple identifier and, if you allow it, a relay email. We don't get your Apple password.
- Age band — we ask your date of birth once to confirm you're 13+, compute an age band (13–17 or 18+), and discard the date. See §04.
- Profile — your handle and a curated avatar you pick (no photo uploads in v1).
- Your stuff — the scents on your shelf, recipes you craft, wishlist, reactions and comments you post, and follows.
- Usage — privacy-safe, aggregate product analytics (e.g., "an onboarding step was completed") with no behavioral profiling of minors.
- Technical — device type, app version, and crash diagnostics to keep the app working.
03 What we never do
- No behavioral ad targeting of minors. Sponsored placements are contextual only (by accord, season, occasion) — never built from a behavioral profile.
- No selling your personal data. Our trend product is aggregate and de-identified (§06).
- No DMs / private messaging — there is no inbox, by design.
- No facial recognition or biometrics, ever.
- No storing your raw date of birth after we compute your age band.
- No third-party ad-tracking SDKs following you across apps; no IDFA fingerprinting.
04 Age band, not your birthday
At sign-up we show a neutral date-of-birth screen (we ask the date — never "are you 13?"). The app computes whether you fall in the 13–17 or 18+ band and then throws the date away. We store only the band, and we never use it to target ads.
05 Affiliate links
When you tap "Shop" on a fragrance, you go to a retailer and we may earn a commission — at no extra cost to you. Every one of those links is labeled #ad right next to it; the disclosure is built into the component, never an afterthought. We use standard affiliate networks (e.g., Awin, CJ, fragrance specialists); they process the click to attribute a possible sale.
06 Aggregate trend data ("Signal")
We disclose this from day one (not retroactively). The de-identification methodology is reviewed by a licensed attorney before any subscriber accesses it.
07 Images & AI art
Real bottle photos come from licensed retailer/brand feeds and only appear next to a disclosed buy link. Atmospheric/background art is originally generated and never depicts real branded products, logos, or real people. We don't scrape images, and we don't claim a fragrance is a "dupe" of another — similarity is expressed only through accord-profile language.
08 Safety & moderation
- User content (handles, comments, recipe names) is moderated before it's public.
- Report and Block are available on every piece of user content; blocking is mutual and enforced server-side.
- If we ever enable photo uploads, industry-standard CSAM detection and NCMEC reporting are in place first — a legal floor we don't cross.
- We don't give minors instructions for mixing raw materials — Popsillage is about wearing and layering finished fragrances.
09 Who we share with
- Service providers — hosting, content moderation, crash/error monitoring, and affiliate networks — under contracts limiting their use of data.
- Aggregate, de-identified trends — as described in §06 (never your personal data).
- Legal — when required by law, or to protect safety (including the CSAM reporting obligations above).
- We do not share data with data brokers or ad networks for cross-app tracking.
10 Your rights & choices
- Delete your account — real deletion (not a hidden deactivation): a 30-day cancellable window, then your profile, shelf, recipes, social data, and media are erased. Settings → Delete account.
- Private by default — your shelf is private until you choose to make it public.
- Access & correction — request a copy of your data or fix it ([email protected]).
- Notifications are event-based and preference-controlled — no streak-nagging.
- Sound is off by default and respects Silent mode.
- Depending on where you live (e.g., California/CCPA, EEA/UK GDPR), you may have additional rights to access, delete, or object.
11 Children & teens
Popsillage is for ages 13 and up. We don't knowingly collect data from anyone under 13. For teens (13–17), we apply Age-Appropriate Design Code protections by default: private shelf, no behavioral ad targeting, no DMs, no engagement-baiting dark patterns.
12 Security & retention
We use encryption in transit, scoped access controls, and audit logging for staff access to user data. We keep your data while your account is active and delete it on the schedule in §10. Some records may be retained longer where law requires (for example, a safety report on file).
13 Changes & contact
If we change our data practices, we'll update this page and, for material changes, notify you in the app. Questions? [email protected].
This draft will carry a finalized effective date and full contact/entity details once reviewed by counsel.