Last updated: 19 July 2026
The essentials at a glance
Contents
This privacy policy explains, as clearly as possible, which personal data Atypikoo collects, why we use it and what your rights are.
It applies to use of the Atypikoo website and mobile application (the "Platform"). It has been drafted in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act. For more information, you may consult the CNIL website.
Atypikoo is a space for meeting people, interacting, forums, tests and events. In this context, we process personal data in order to:
The data controller is the company that decides why and how your personal data is used:
ATYPIKOO SAS
1 avenue d’Ester, ESTER Technopole, 87280 Limoges, France
905 199 824 RCS
Data Protection Officer (DPO): Delphine Louradour — help02@atypikoo.com
If you have any questions about your data or this policy, you may write to us at: help02@atypikoo.com.
This policy applies in particular to:
Depending on how you use Atypikoo, we may process different categories of data. Some are necessary for the service to operate, while others are optional.
When you create an account, we collect in particular:
Atypikoo does not collect or store full bank card numbers. Web payments are processed by the Stripe payment platform, and mobile in-app purchases by the Apple App Store and Google Play platforms, whose receipts are processed through Adapty.
This data is used to display your results and, in strictly anonymised or aggregated form (with no possibility of individual identification), to carry out internal statistical analyses and improve the relevance of the tests offered.
Some optional data is more sensitive than other data. It may fall within special categories under the GDPR or indirectly reveal such data. This may concern sexual orientation, political opinions, certain information relating to atypical traits/neurodivergence, and certain test and questionnaire results in particular.
You are not required to provide this information. When you choose to do so, you retain control over how it is used and, where applicable, its visibility through your privacy settings.
The GDPR requires us to tell you the basis on which we use your data. Depending on the circumstances, we rely on one or more of the following legal bases:
Where information you choose to provide may fall within Article 9 GDPR or reveal such information (including health, neurodivergence, sex life or sexual orientation), processing is based on your explicit, freely given, specific, informed and traceable consent under Articles 6(1)(a) and 9(2)(a) GDPR. This consent is requested separately from the Terms of Use, without a pre-ticked box, when the profile information is entered or before you answer a test. Refusal does not affect service functions that do not require this data, but may prevent the display or calculation of the sensitive feature concerned.
Where you additionally choose to make information visible to other Members, it may also be regarded as having been manifestly made public by you under Article 9(2)(e) GDPR. That visibility does not authorise us to reuse the information for a purpose unrelated to the one notified to you. In every case, we limit processing to what is necessary for the specific purpose you accepted.
You may withdraw your consent at any time, without retroactive effect on processing lawfully carried out. The control in profile settings deletes sensitive profile data; the dedicated test feature allows the relevant answers and results to be deleted. Withdrawal stops processing based on that consent and results in deletion or anonymisation, except where retention is strictly necessary to comply with a legal obligation or to establish, exercise or defend legal claims. Purging data following a ban is a separate deletion measure and does not, in itself, constitute withdrawal of consent expressed by the Member.
By creating an account or purchasing a subscription or test, you accept the Terms of Use and/or Terms of Sale, which operate in conjunction with this policy.
Data is used to:
We use your data to:
The forums allow discussion topics to be opened between members. By default:
Premium members may select the "private topic" option: in this case, the topic is not indexed by search engines and remains accessible only to logged-in members.
We use certain AI services provided by Google (Gemini) and/or Mistral AI for the specific purposes described below. We do not use AI everywhere or for everything, and these uses do not all have the same role or impact.
Atypikoo does not use Members' content to train its service providers' artificial intelligence models: your messages and content are sent solely to generate a response or carry out the analysis described, and are then retained for the periods specified in this policy.
"Team Atypikoo" support
When you use the support assistant, the content of your question may be sent to Google Gemini or Mistral AI to generate a response. We try to minimise the directly identifying data sent to these tools. These exchanges may be retained for support monitoring and quality purposes.
"Love coach" conversational assistant
The "Love coach" is an AI-based conversational assistant. The messages you send to it may be analysed by Google Gemini and/or Mistral AI to generate responses relating to your relationships and emotional life. To make the responses more relevant, certain elements of your profile, such as your pseudonym, interests or declared personality traits, may be sent with your messages. These exchanges may be retained so that you can access the history; they are not used to train AI models.
Validation and analysis of certain profiles
To secure the Platform and assist the validation team, certain profiles may undergo AI-assisted analysis, currently using Google Gemini. The aim is to identify inconsistencies, signs of fraud, content incompatible with the Terms of Use, or matters requiring human verification. The data used may include profile details, freely entered content, certain technical metadata and, where applicable, certain test results associated with the account. This processing provides decision-making support: a final adverse decision is not made solely by AI without human involvement.
Moderation and reports
When content (a profile, private message, forum topic, comment, event, etc.) is reported, it may be analysed by AI tools to identify indicators of harassment, discriminatory statements, scams or other rule violations. These tools are used to prioritise the moderation team's work. No sanction, suspension or other significant adverse decision is made exclusively through automated processing: decisions are always made by human beings.
Notification of reporting persons
When one of your reports is validated by our moderation team, you may receive a thank-you email. This message contains no information about the decision made or the identity of the reported member or content, in accordance with moderation confidentiality rules. You may unsubscribe at any time using the unsubscribe link in the email (RFC 8058) or through your communication preferences.
Analysis of new forum topics
New forum topics may be automatically analysed by Google Gemini before publication. This analysis produces an opinion on compliance with the Forum Charter and the Terms of Use (sensitivity level from 0 to 3, confidence score and suggested category) and may result in immediate publication or the topic being held for human review. Any refusal decision is made by a member of the moderation team; the AI opinion is only a warning signal. The data processed comprises the title and description of the topic; the information returned by the AI (verdict, indicators and short reason for any refusal) is retained for as long as the topic exists to ensure that decisions are traceable.
Like any automated tool, these services may sometimes produce inaccurate, incomplete or inappropriate responses. They:
Your data may be used to:
Depending on the processing concerned, your data may be accessible to the following categories. They may access it only where necessary for their role:
For an Official Atypikoo Event, Atypikoo is the sole controller. For an Event organised by a non-professional Member, Atypikoo is the controller for registration on the Platform and the Organiser is a limited recipient with no right of reuse. For a Professional Event, Atypikoo and the Professional Member are joint controllers for registration under the arrangement published in Article 12.1 of the Professional Terms of Sale. The Organiser remains the sole controller of data collected outside the Platform or used for the Organiser's own purposes.
Some of these service providers, including Stripe, Google/Gemini, Firebase, Adapty, Shopify, Proxycheck, ipStack and, depending on the service used, Mistral AI, may process certain data outside the European Union. In contrast, uploaded photos and files are hosted by Amazon Web Services (AWS S3) in a European region (eu-west-3, Paris) and this does not therefore constitute a transfer outside the European Union.
Where this occurs, we ensure that appropriate safeguards are in place, for example the European Commission's standard contractual clauses and supplementary technical and organisational measures.
Mistral AI is a French company. Where its services are used in a business or API context, the processing terms, any data location and applicable safeguards are specified in its relevant contractual and privacy documentation.
Where required by law, Atypikoo may transmit personal data in order to comply with administrative or judicial proceedings. In this context, Atypikoo may have access to all necessary data, including private messages and reported content if required.
For more information, you may consult our service providers' privacy policies:
We do not retain your data indefinitely. The main retention periods or rules applied are as follows:
Some content published on Atypikoo may incorporate material from other websites, such as videos, images or articles. In this case, those third-party websites may collect data, use cookies or track your interactions with that content, particularly if you already have an account with them. Their own privacy policies then apply.
Atypikoo does not collect or store the bank details used to pay for subscriptions and tests.
Payments made from the website are processed by the Stripe platform, which protects user data (3D Secure authentication and security measures compliant with current standards). In-app purchases made from the mobile application are processed by the Apple App Store and Google Play platforms, with receipt management through Adapty.
We implement technical and organisational measures to protect your personal data as effectively as possible:
No method of electronic storage or transmission is completely infallible. We therefore cannot guarantee absolute security, but we do our utmost to limit risks and protect your data.
To delete your account and personal data, go to: https://www.atypikoo.com/settings/account
Click "delete account". Deletion takes effect after 24 hours. During this period, you may still change your mind and cancel the operation by logging in again.
At the end of this period, the following are permanently deleted:
For technical, security, evidential and public-discussion consistency purposes, certain data may be retained in pseudonymised form. This means it is no longer displayed under your usual identity. This applies in particular to:
If you wish to erase certain content before closing your account, you may delete your messages individually, insofar as this does not impair the understanding of a public thread or the evidence of an ongoing incident.
Test data linked to an account is deleted or dissociated from the account when it is deleted, unless its retention is necessary to provide access to a purchased result, handle a complaint or comply with a legal obligation. Internal statistics are produced only in anonymised or aggregated form.
A test may be purchased and taken without creating an account. In this case, the results are identified by the email address used for the purchase rather than by an account. You may request their erasure at any time by writing to our contact point (see section 13); these results may also be deleted after an extended period of inactivity.
Automatic deletion: if there has been no login for an extended period (3 years), your account may be automatically deleted under the same rules.
Where your account is banned by Atypikoo (for failure to comply with the Terms of Use or Charters), the rules described in sections 12.1 to 12.5 — which concern deletion at your initiative — do not apply in the same way. The specific arrangements are as follows.
Fourteen (14)-day grace period. Your data remains fully retained for fourteen days following notification of the ban, to allow you to make an appeal and to enable the decision to be fully reversed where applicable.
At the end of the fourteen days, unless the decision has been reversed, the following are permanently deleted:
If the purge has not yet been technically carried out when the decision is reversed (internally or by an authority), your data is fully restored. If the purge has already been carried out, it is technically impossible to restore the erased data; however, you retain the right to have your account reactivated and to retain your forum and private messages that have not been purged.
The following are hidden as soon as the ban is imposed:
This content is no longer accessible through the interface or in other Members' personal areas. This measure protects the community against the post-ban exploitation of information that may have appeared there (contact details, external references, etc.) and forms part of the processing-security obligation laid down in Article 32 GDPR.
The content remains stored in the database in an inaccessible form for evidential purposes, technical integrity and responses to any judicial requests. An internal technical identifier needed to ensure the integrity of the retained data is also maintained. If the ban is reversed, access to the content is restored.
The following are retained in an anti-reoffending blocklist:
The retention of these hashes is based on Atypikoo's legitimate interest (Article 6(1)(f) GDPR) in protecting the security and integrity of its community, after balancing this interest against your rights and freedoms (this balancing exercise is subject to a documented internal assessment). You may object to this processing by writing to help02@atypikoo.com: your request will be considered on a case-by-case basis. All these hashes are deleted immediately if the banning decision is reversed.
The reasoned decision (reason, cited extracts, rules relied upon and date) is also retained for five (5) years for evidential purposes, to respond to any appeal and for the defence of legal claims.
Your GDPR rights remain fully exercisable after a ban:
These requests should be sent to help02@atypikoo.com, the contact point for data-protection matters. You also have the right to lodge a complaint with the CNIL (see section 15).
You retain rights over your data. In particular, you may:
You may also give instructions about what should happen to your data after your death, in accordance with French law.
The easiest way to exercise your rights is to contact us at:
Email: help02@atypikoo.com
If you request access to or a copy of your data, we may ask you for proof of identity to protect your account. We will respond within a maximum of one month from receipt of your request.
If, after contacting us, you believe that your rights have not been respected, you may lodge a complaint with the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés — CNIL).
Contact details and information: https://www.cnil.fr