Last updated: 19 July 2026

The essentials at a glance

  • we collect the data needed to operate Atypikoo, secure the platform and provide its services to you,
  • some information is required to create an account, while other information is optional and remains under your control,
  • you may manage your profile, withdraw certain consents, request the deletion of your account and exercise your rights at any time.

Contents

1. Purpose of this policy

This privacy policy explains, as clearly as possible, which personal data Atypikoo collects, why we use it and what your rights are.

It applies to use of the Atypikoo website and mobile application (the "Platform"). It has been drafted in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act. For more information, you may consult the CNIL website.

Atypikoo is a space for meeting people, interacting, forums, tests and events. In this context, we process personal data in order to:

  • create and manage accounts,
  • provide dating, forum, messaging, event and test services,
  • provide user support,
  • manage subscriptions and payments,
  • provide moderation and security and prevent abuse,
  • improve the Platform and its features.

2. Data controller and contact details

The data controller is the company that decides why and how your personal data is used:

ATYPIKOO SAS
1 avenue d’Ester, ESTER Technopole, 87280 Limoges, France
905 199 824 RCS

Data Protection Officer (DPO): Delphine Louradour — help02@atypikoo.com

If you have any questions about your data or this policy, you may write to us at: help02@atypikoo.com.

3. Who does this policy apply to?

This policy applies in particular to:

  • users of the support service,
  • members registered on the website or mobile application,
  • subscribers (premium members),
  • test users,
  • purchasers of products from the online shop,
  • event organisers and participants,
  • professionals listed in the directory.

4. Data we process

Depending on how you use Atypikoo, we may process different categories of data. Some are necessary for the service to operate, while others are optional.

4.1 Account and profile data

When you create an account, we collect in particular:

  • Information required for registration: email address, username (pseudonym), password (encrypted), date of birth, sex, country, city, description and preferred type of relationship. Approximate geolocation coordinates (latitude/longitude) are automatically calculated from the city provided to enable proximity-based matching.
  • Optional information: MBTI profile, atypical traits, personality aspects and traits, interests, type of relationship sought, relationship status, sexual orientation, political orientation, children, occupation, website, areas of expertise, education, body type, height, smoking habits, profile photo and test results (including IQ score and MBTI results).

4.2 Browsing and technical data

  • connection logs (dates, times, IP address and technical information),
  • registration IP address and country inferred from that IP address, used to prevent fraud,
  • browser and device data (device type, operating system, language, etc.),
  • technical identifiers relating to the mobile application, including push notification tokens (Firebase Cloud Messaging),
  • data collected using cookies and other trackers (see our Cookie Policy).

4.3 Communications and content data

  • messages sent through private messaging,
  • messages posted on the forums (topics and replies),
  • event-related content (description, comments and exchanges),
  • messages sent to support ("Team Atypikoo"),
  • exchanges with the "Love coach" conversational assistant,
  • reports made (report text and associated content).

4.4 Payment and billing data

  • for the purchase of a subscription or test from the website: email address, billing address, payment amount and date, type of product or service purchased, and Stripe customer identifier associated with your account; bank card data is collected and processed directly by Stripe,
  • for purchases made from the mobile application (iOS/Android): in-app purchase identifier sent by the Apple or Google platform, Adapty customer identifier, type of subscription purchased, and payment date and status,
  • for purchases of products from the online shop (hosted by Shopify): email address, first name, surname, delivery and billing addresses, order amount and details, and payment information processed by Shopify (and Stripe where applicable).

Atypikoo does not collect or store full bank card numbers. Web payments are processed by the Stripe payment platform, and mobile in-app purchases by the Apple App Store and Google Play platforms, whose receipts are processed through Adapty.

4.5 Test and questionnaire data

  • answers to tests and questionnaires,
  • calculated results (profiles, scores and summaries).

This data is used to display your results and, in strictly anonymised or aggregated form (with no possibility of individual identification), to carry out internal statistical analyses and improve the relevance of the tests offered.

4.6 Data that may fall within special categories

Some optional data is more sensitive than other data. It may fall within special categories under the GDPR or indirectly reveal such data. This may concern sexual orientation, political opinions, certain information relating to atypical traits/neurodivergence, and certain test and questionnaire results in particular.

You are not required to provide this information. When you choose to do so, you retain control over how it is used and, where applicable, its visibility through your privacy settings.

5. Legal bases and consent

The GDPR requires us to tell you the basis on which we use your data. Depending on the circumstances, we rely on one or more of the following legal bases:

  • performance of the contract (Terms of Use/Terms of Sale) for the creation of the account, access to dating, forum, messaging, test and event services, and the management of subscriptions,
  • compliance with legal obligations (billing, accounting, retention of certain logs, etc.),
  • Atypikoo's legitimate interest in securing the Platform, combating abuse, assisting with profile validation and moderation, improving its services, and compiling certain internal statistics,
  • your consent, where this basis is required, particularly for sending newsletters or commercial communications by email and for certain processing involving optional data that may fall within special categories.

Where information you choose to provide may fall within Article 9 GDPR or reveal such information (including health, neurodivergence, sex life or sexual orientation), processing is based on your explicit, freely given, specific, informed and traceable consent under Articles 6(1)(a) and 9(2)(a) GDPR. This consent is requested separately from the Terms of Use, without a pre-ticked box, when the profile information is entered or before you answer a test. Refusal does not affect service functions that do not require this data, but may prevent the display or calculation of the sensitive feature concerned.

Where you additionally choose to make information visible to other Members, it may also be regarded as having been manifestly made public by you under Article 9(2)(e) GDPR. That visibility does not authorise us to reuse the information for a purpose unrelated to the one notified to you. In every case, we limit processing to what is necessary for the specific purpose you accepted.

You may withdraw your consent at any time, without retroactive effect on processing lawfully carried out. The control in profile settings deletes sensitive profile data; the dedicated test feature allows the relevant answers and results to be deleted. Withdrawal stops processing based on that consent and results in deletion or anonymisation, except where retention is strictly necessary to comply with a legal obligation or to establish, exercise or defend legal claims. Purging data following a ban is a separate deletion measure and does not, in itself, constitute withdrawal of consent expressed by the Member.

By creating an account or purchasing a subscription or test, you accept the Terms of Use and/or Terms of Sale, which operate in conjunction with this policy.

6. Why we use your data, including AI

6.1 Account management and provision of services

Data is used to:

  • create and manage your account,
  • display your profile in accordance with your privacy settings,
  • enable you to meet and interact with other members,
  • take part in forums, events, tests and the directory,
  • manage your subscriptions and options (e.g. private forum topics).

6.2 Support and communications

We use your data to:

  • respond to your support requests,
  • inform you about changes to the service,
  • send you newsletters or commercial information, where applicable.

6.3 Forums and public visibility of topics

The forums allow discussion topics to be opened between members. By default:

  • the title and content of the first message in a forum topic may be publicly visible and indexed by search engines,
  • replies are accessible only to logged-in members,
  • in the public section, we display neither your first name nor your profile photo, but a pseudonym and possibly a non-photographic avatar.

Premium members may select the "private topic" option: in this case, the topic is not indexed by search engines and remains accessible only to logged-in members.

6.4 Use of artificial intelligence (AI)

We use certain AI services provided by Google (Gemini) and/or Mistral AI for the specific purposes described below. We do not use AI everywhere or for everything, and these uses do not all have the same role or impact.

Atypikoo does not use Members' content to train its service providers' artificial intelligence models: your messages and content are sent solely to generate a response or carry out the analysis described, and are then retained for the periods specified in this policy.

"Team Atypikoo" support

When you use the support assistant, the content of your question may be sent to Google Gemini or Mistral AI to generate a response. We try to minimise the directly identifying data sent to these tools. These exchanges may be retained for support monitoring and quality purposes.

"Love coach" conversational assistant

The "Love coach" is an AI-based conversational assistant. The messages you send to it may be analysed by Google Gemini and/or Mistral AI to generate responses relating to your relationships and emotional life. To make the responses more relevant, certain elements of your profile, such as your pseudonym, interests or declared personality traits, may be sent with your messages. These exchanges may be retained so that you can access the history; they are not used to train AI models.

Validation and analysis of certain profiles

To secure the Platform and assist the validation team, certain profiles may undergo AI-assisted analysis, currently using Google Gemini. The aim is to identify inconsistencies, signs of fraud, content incompatible with the Terms of Use, or matters requiring human verification. The data used may include profile details, freely entered content, certain technical metadata and, where applicable, certain test results associated with the account. This processing provides decision-making support: a final adverse decision is not made solely by AI without human involvement.

Moderation and reports

When content (a profile, private message, forum topic, comment, event, etc.) is reported, it may be analysed by AI tools to identify indicators of harassment, discriminatory statements, scams or other rule violations. These tools are used to prioritise the moderation team's work. No sanction, suspension or other significant adverse decision is made exclusively through automated processing: decisions are always made by human beings.

Notification of reporting persons

When one of your reports is validated by our moderation team, you may receive a thank-you email. This message contains no information about the decision made or the identity of the reported member or content, in accordance with moderation confidentiality rules. You may unsubscribe at any time using the unsubscribe link in the email (RFC 8058) or through your communication preferences.

Analysis of new forum topics

New forum topics may be automatically analysed by Google Gemini before publication. This analysis produces an opinion on compliance with the Forum Charter and the Terms of Use (sensitivity level from 0 to 3, confidence score and suggested category) and may result in immediate publication or the topic being held for human review. Any refusal decision is made by a member of the moderation team; the AI opinion is only a warning signal. The data processed comprises the title and description of the topic; the information returned by the AI (verdict, indicators and short reason for any refusal) is retained for as long as the topic exists to ensure that decisions are traceable.

Like any automated tool, these services may sometimes produce inaccurate, incomplete or inappropriate responses. They:

  • do not constitute a medical or psychological diagnosis,
  • do not replace therapy, medical monitoring, or legal or financial advice.

6.5 Security, prevention of abuse and statistics

Your data may be used to:

  • prevent and detect fraudulent behaviour, abuse, attempts at coercive control or sectarian influence,
  • automatically analyse the registration IP address using the third-party Proxycheck.io service in order to detect the possible use of a VPN, proxy or high-risk IP address and prevent fraudulent or multiple registrations,
  • ensure the security of the Platform and its members,
  • produce internal statistics (number of members, use of features, etc.).

7. Recipients, transfers and service providers

7.1 Who can access your data?

Depending on the processing concerned, your data may be accessible to the following categories. They may access it only where necessary for their role:

  • Site administrators and the development team, for the management and improvement of the Platform,
  • Moderation team, for handling reports and security,
  • Atypikoo support team, for handling your support requests using an internally developed support tool hosted on our own infrastructure,
  • Event Organisers, only for data strictly necessary for organisation: limited recipients for Events organised by non-professional Members, or joint controllers with Atypikoo for Professional Member Events governed by the Professional Terms of Sale,
  • Stripe, for payment for subscriptions and tests purchased from the website,
  • Adapty and the Apple App Store and Google Play mobile distribution platforms, for managing subscriptions purchased from the mobile application,
  • Shopify, the e-commerce platform hosting the online shop, for managing product orders, payments and shipping,
  • AI service providers: Google (Gemini service) and Mistral AI, for the features described above,
  • Firebase Cloud Messaging (Google), for sending push notifications to your mobile application,
  • Proxycheck.io, for VPN/proxy detection during registration,
  • ipStack and Google Maps/Places, for geolocation and place searches,
  • Amazon Web Services (AWS S3), for the secure hosting of uploaded photos and files (European region eu-west-3),
  • SMTP email provider, for delivering notifications, confirmations and newsletters.

For an Official Atypikoo Event, Atypikoo is the sole controller. For an Event organised by a non-professional Member, Atypikoo is the controller for registration on the Platform and the Organiser is a limited recipient with no right of reuse. For a Professional Event, Atypikoo and the Professional Member are joint controllers for registration under the arrangement published in Article 12.1 of the Professional Terms of Sale. The Organiser remains the sole controller of data collected outside the Platform or used for the Organiser's own purposes.

7.2 Transfers outside the European Union

Some of these service providers, including Stripe, Google/Gemini, Firebase, Adapty, Shopify, Proxycheck, ipStack and, depending on the service used, Mistral AI, may process certain data outside the European Union. In contrast, uploaded photos and files are hosted by Amazon Web Services (AWS S3) in a European region (eu-west-3, Paris) and this does not therefore constitute a transfer outside the European Union.

Where this occurs, we ensure that appropriate safeguards are in place, for example the European Commission's standard contractual clauses and supplementary technical and organisational measures.

Mistral AI is a French company. Where its services are used in a business or API context, the processing terms, any data location and applicable safeguards are specified in its relevant contractual and privacy documentation.

Where required by law, Atypikoo may transmit personal data in order to comply with administrative or judicial proceedings. In this context, Atypikoo may have access to all necessary data, including private messages and reported content if required.

7.3 Our service providers' privacy policies

For more information, you may consult our service providers' privacy policies:

8. Retention periods

We do not retain your data indefinitely. The main retention periods or rules applied are as follows:

  • Account and profile: profile data is retained for as long as the account is active. If there has been no login for an extended period (3 years), the account may be deleted automatically. When you delete your account, most profile data is deleted or pseudonymised (see §12).
  • Account blocked or banned at Atypikoo's initiative: upon expiry of a fourteen (14)-day grace period from notification of the ban, account data is deleted by default, with the strictly limited exception of data necessary to prevent repeat offending (pseudonym, non-reversible HMAC-SHA256 cryptographic hash of the email address, registration IP address) and to retain proof of the reasoned decision. The pseudonym, email hash and decision are retained for a maximum of five (5) years; the IP address for a maximum of twelve (12) months. Details are provided in section 12.6.
  • Purchase via Stripe: Stripe generally retains payment data for 5 years after use of its services, in accordance with its own legal obligations.
  • Lifetime subscription: subscription records (date, price paid, transaction identifier and plan) are retained by Atypikoo for as long as the Lifetime Subscription remains active, then for five (5) years after the Subscription ends (account deletion, ban or discontinuation of the service), in order to respond to any dispute (Article 2224 of the French Civil Code).
  • Mobile in-app purchases: data relating to in-app purchases is retained by Apple, Google and Adapty in accordance with their own retention policies.
  • Purchases from the online shop (Shopify): orders, delivery details and billing information are retained by Shopify in accordance with applicable tax and legal periods (generally 10 years for accounting records).
  • Test results: test data linked to an account is deleted or dissociated from the account when the account is deleted, unless retention is necessary to provide access to a purchased result, handle a complaint or comply with a legal obligation. Where a test is purchased and taken without an account, the results are linked to the email address provided at the time of purchase; they may be erased upon request to our contact point (see section 13). Internal statistics are produced only in anonymised or aggregated form.
  • Artificial-intelligence profile analysis and validation: analysis results (profile verification score and verdict) are retained for up to twelve (12) months; the most sensitive detailed outputs for up to six (6) months; technical logs of AI calls for up to twelve (12) months.
  • Action logs (security audit): twelve (12) months. Email events (email opens and clicks): one hundred and eighty (180) days.
  • Newsletter: your email address is retained until you unsubscribe or until a reasonable period of inactivity has elapsed.
  • Connection logs: connection logs are retained for 1 year, particularly so that we can respond to official judicial requests.
  • Session and authentication tokens: mobile application refresh tokens are valid for 30 days; email login links (magic links) expire after 15 minutes.
  • Push notification tokens (Firebase): retained for as long as they are needed for notifications to operate in the mobile application; they may be deactivated when you turn off notifications, deleted when you log out or delete your account, and renewed as the application or device is technically updated.
  • Support: support messages may be retained for up to 1 year (or an appropriate period) for follow-up, service improvement and evidence in the event of a dispute.
  • Deletion period: when a request to delete an account is made, it is carried out after a 24-hour period during which the operation may be cancelled.

9. Content embedded from other websites

Some content published on Atypikoo may incorporate material from other websites, such as videos, images or articles. In this case, those third-party websites may collect data, use cookies or track your interactions with that content, particularly if you already have an account with them. Their own privacy policies then apply.

10. Secure payment

Atypikoo does not collect or store the bank details used to pay for subscriptions and tests.

Payments made from the website are processed by the Stripe platform, which protects user data (3D Secure authentication and security measures compliant with current standards). In-app purchases made from the mobile application are processed by the Apple App Store and Google Play platforms, with receipt management through Adapty.

11. Protection and security of your data

We implement technical and organisational measures to protect your personal data as effectively as possible:

  • passwords stored in encrypted form using the bcrypt algorithm (one-way hash function),
  • encryption of communications using HTTPS/TLS,
  • storage of user sessions in a secure Redis database that is not publicly exposed,
  • hosting of uploaded photos and files on Amazon S3 (European region eu-west-3) with access control,
  • segregation of roles and management of administrator access,
  • regular database backups,
  • logging of security events and detection of abnormal behaviour.

No method of electronic storage or transmission is completely infallible. We therefore cannot guarantee absolute security, but we do our utmost to limit risks and protect your data.

12. Deletion of your account and data

12.1 Requesting deletion of your account

To delete your account and personal data, go to: https://www.atypikoo.com/settings/account

Click "delete account". Deletion takes effect after 24 hours. During this period, you may still change your mind and cancel the operation by logging in again.

12.2 What is deleted

At the end of this period, the following are permanently deleted:

  • your photos (profile and gallery),
  • your extended profile characteristics (atypical traits, MBTI, aspects, interests, orientation, etc.),
  • blocking and hiding relationships,
  • historical notifications and activities,
  • push notification tokens and the main technical tokens associated with the account,
  • AI-generated profile-validation analyses and scores, and test data linked to the account,
  • profile data directly linked to the user account.

12.3 What may be retained in pseudonymised form

For technical, security, evidential and public-discussion consistency purposes, certain data may be retained in pseudonymised form. This means it is no longer displayed under your usual identity. This applies in particular to:

  • your truncated email address (only the first 4 characters remain visible; the rest is hidden by asterisks),
  • messages posted on the forum, attributed to an anonymous pseudonym,
  • messages sent through private messaging, which remain visible to the people you corresponded with,
  • an internal technical identifier used to ensure the integrity of retained data.

If you wish to erase certain content before closing your account, you may delete your messages individually, insofar as this does not impair the understanding of a public thread or the evidence of an ongoing incident.

12.4 Special case of tests and questionnaires

Test data linked to an account is deleted or dissociated from the account when it is deleted, unless its retention is necessary to provide access to a purchased result, handle a complaint or comply with a legal obligation. Internal statistics are produced only in anonymised or aggregated form.

A test may be purchased and taken without creating an account. In this case, the results are identified by the email address used for the purchase rather than by an account. You may request their erasure at any time by writing to our contact point (see section 13); these results may also be deleted after an extended period of inactivity.

12.5 Automatic deletion of inactive accounts

Automatic deletion: if there has been no login for an extended period (3 years), your account may be automatically deleted under the same rules.

12.6 Special case of blocked or banned accounts

Where your account is banned by Atypikoo (for failure to comply with the Terms of Use or Charters), the rules described in sections 12.1 to 12.5 — which concern deletion at your initiative — do not apply in the same way. The specific arrangements are as follows.

Fourteen (14)-day grace period. Your data remains fully retained for fourteen days following notification of the ban, to allow you to make an appeal and to enable the decision to be fully reversed where applicable.

At the end of the fourteen days, unless the decision has been reversed, the following are permanently deleted:

  • your photos (profile and gallery), including from external storage;
  • your profile description and sensitive characteristics (sex, date of birth, city and geolocation);
  • extended characteristics (orientation, personality type, interests, neurodivergence-related traits and any other special category within the meaning of Article 9 GDPR, freely provided by you and, when displayed on your profile, processed as data you manifestly make public — Article 9(2)(e) GDPR);
  • your favourites, hiding lists, visits, votes, received notifications and activity history.

If the purge has not yet been technically carried out when the decision is reversed (internally or by an authority), your data is fully restored. If the purge has already been carried out, it is technically impossible to restore the erased data; however, you retain the right to have your account reactivated and to retain your forum and private messages that have not been purged.

The following are hidden as soon as the ban is imposed:

  • your public messages (forums, topics and comments);
  • your private messages (on recipients' side).

This content is no longer accessible through the interface or in other Members' personal areas. This measure protects the community against the post-ban exploitation of information that may have appeared there (contact details, external references, etc.) and forms part of the processing-security obligation laid down in Article 32 GDPR.

The content remains stored in the database in an inaccessible form for evidential purposes, technical integrity and responses to any judicial requests. An internal technical identifier needed to ensure the integrity of the retained data is also maintained. If the ban is reversed, access to the content is restored.

The following are retained in an anti-reoffending blocklist:

  • your pseudonym, which cannot be reused to create a new account, and a cryptographic hash of your email calculated using HMAC-SHA256 (non-reversible: the email address in plain text cannot be reconstructed) — for a maximum of five (5) years from the ban;
  • the IP address recorded when you initially registered — for a maximum of twelve (12) months, after which its predictive usefulness becomes marginal.

The retention of these hashes is based on Atypikoo's legitimate interest (Article 6(1)(f) GDPR) in protecting the security and integrity of its community, after balancing this interest against your rights and freedoms (this balancing exercise is subject to a documented internal assessment). You may object to this processing by writing to help02@atypikoo.com: your request will be considered on a case-by-case basis. All these hashes are deleted immediately if the banning decision is reversed.

The reasoned decision (reason, cited extracts, rules relied upon and date) is also retained for five (5) years for evidential purposes, to respond to any appeal and for the defence of legal claims.

Your GDPR rights remain fully exercisable after a ban:

  • right of access to the data still retained and to the reasoned moderation decision (Article 15);
  • right to portability of the data generated before the measure (Article 20);
  • right to erasure, subject to Article 17(3) (the legitimate interest in preventing repeat offending and the establishment, exercise or defence of legal claims are exceptions);
  • right to object to processing based on legitimate interest (Article 21), considered on a case-by-case basis;
  • right not to be subject to a decision based solely on automated processing (Article 22): Atypikoo confirms that every banning decision is made by a human administrator.

These requests should be sent to help02@atypikoo.com, the contact point for data-protection matters. You also have the right to lodge a complaint with the CNIL (see section 15).

13. Your rights

You retain rights over your data. In particular, you may:

  • access the data we hold about you,
  • correct inaccurate or incomplete data,
  • request the erasure of certain data or the restriction of certain processing,
  • object to certain processing based on legitimate interest, for example direct marketing,
  • withdraw your consent at any time where processing is based on consent, without retroactive effect,
  • receive certain data in a structured format (right to data portability).

You may also give instructions about what should happen to your data after your death, in accordance with French law.

14. How can you exercise your rights?

The easiest way to exercise your rights is to contact us at:

Email: help02@atypikoo.com

If you request access to or a copy of your data, we may ask you for proof of identity to protect your account. We will respond within a maximum of one month from receipt of your request.

15. Complaint to the CNIL

If, after contacting us, you believe that your rights have not been respected, you may lodge a complaint with the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés — CNIL).

Contact details and information: https://www.cnil.fr