· Legal · Nº 01
Privacy policy.
Last updated · September 14, 2026
Nº 1Introduction
Théo Diamant, Entrepreneur Individuel (EI), trading as Cheeppy ("Cheeppy", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered product image generation platform at cheeppy.com (the "Service").
We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
Nº 2Data Controller
The data controller responsible for your personal data is:
Théo Diamant — Entrepreneur Individuel (EI), trading as Cheeppy
SIREN 982 821 183 · 20 rue Garnier, 92200 Neuilly-sur-Seine, France
Email: [email protected]
Website: https://cheeppy.com
Nº 3Information We Collect
3.1 Information You Provide
- Account Information: Name, email address, and password when you create an account
- Profile Information: Profile picture, display name, and bio (optional)
- Payment Information: Billing address and payment details (processed securely by Stripe)
- Uploaded Content: Product images you upload for AI generation
- Creator Payout Information: If you participate in our Creator Program, bank account details and identity verification information required by Stripe Connect for payouts
- Communications: Messages you send to us for support or feedback
3.2 Information Collected Automatically
- Usage Data: Pages visited, features used, generation history, and interaction patterns
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, referring URLs
- Cookies: Session cookies for authentication and preferences (see Section 8)
3.3 Information from Third Parties
- OAuth Providers: If you sign in with Google, we receive your name and email
- E-commerce Platforms: Product data from connected Shopify or WooCommerce stores
- Payment Processor: Transaction status and billing information from Stripe
Nº 4How We Use Your Information
We use your information for the following purposes:
4.1 Service Provision (Contractual Necessity)
- Create and manage your account
- Process your image generations and deliver results
- Process payments and manage subscriptions
- Provide customer support
- Sync with your connected e-commerce stores
4.2 Legitimate Interests
- Improve and optimize our Service
- Analyze usage patterns to enhance user experience
- Detect and prevent fraud or abuse
- Ensure security of our platform
4.3 With Your Consent
- Send marketing communications (you can opt out anytime)
- Use your generated images in our showcase (with explicit permission)
Nº 5AI and Image Processing
When you use our AI image generation features:
- Your uploaded images are processed by our AI systems to generate new images
- We use third-party AI providers (Google, OpenAI), directly and through OpenRouter, to process generations and to check uploaded product photos
- Uploaded images are stored temporarily for processing and then in your account library
- We do not use your images to train our AI models without explicit consent
- Generated images are stored in your account and can be deleted at any time
Nº 6Data Sharing and Disclosure
We may share your information with:
6.1 Service Providers
- Supabase: Database and authentication (EU region)
- Cloudflare R2: Image storage and CDN
- Meta (Facebook, Instagram): Advertising measurement and conversion attribution via the Meta Pixel (browser) and Conversions API (server-side). We share hashed email, hashed user ID, IP address, user-agent, and Meta browser/click identifiers (
_fbp,_fbccookies) so Meta can attribute signups, subscriptions, and purchases to the ads you saw. See Meta's Privacy Policy - Stripe: Payment processing (subscriptions and credit purchases)
- Stripe Connect: Creator payout processing — if you are a creator, your identity, bank account, and earnings data are shared with Stripe to facilitate transfers (see Stripe's Privacy Policy)
- Google Cloud: AI image generation
- OpenRouter: Routes AI image generation and photo-check requests to our model providers
- Google Ads: Advertising measurement via the Google Ads conversion tag and Google Tag (
_gcl_au,_gacookies). We share hashed email and conversion events to attribute signups and purchases to Google ad clicks. See Google's Privacy Policy - Sentry: Error monitoring and debugging
- PostHog: Product analytics and session replay (EU region) — page views, feature usage, and signup funnel events
6.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety, or that of our users or the public.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
Nº 7International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws.
When we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Nº 8Cookies and Tracking
We use the following types of cookies:
| Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security, preferences | Session / 1 year |
| Analytics | Usage statistics, performance monitoring (PostHog) | 1 year |
| Advertising | Meta Pixel (_fbp, _fbc) and Google Ads (_gcl_au, _ga) — measure which ads led to signups and purchases. Combined with our server-side Conversions API (Meta) and conversion tag (Google) to improve attribution accuracy. | 90 days / 1 year |
| Functional | Remember your preferences (theme, language) | 1 year |
Server-side advertising tracking. In addition to browser cookies, we send conversion events (signups, subscriptions, purchases) directly from our server to Meta and Google for attribution. This server-side method (Meta Conversions API, Google Enhanced Conversions) shares the same data the browser tag would send (hashed email, hashed user ID, IP address, user-agent, and Meta/Google identifiers) but is more reliable than browser-only tracking, which can be blocked by ad blockers, privacy browsers, or iOS tracking restrictions. We do not share unhashed personal data.
You can control cookies through your browser settings. Note that disabling essential cookies may affect the functionality of the Service. Server-side conversion tracking is governed by our service providers' own privacy policies (linked in Section 6.1).
Nº 9Data Retention
We retain your data for as long as necessary to provide the Service and fulfill the purposes outlined in this policy. Specifically:
- Account Data: Until you delete your account
- Generated Images: Until you delete them or your account
- Uploaded Images: 30 days after generation, then automatically deleted
- Payment Records: 7 years (legal requirement)
- Creator Earnings and Payout Records: 7 years (legal and tax reporting requirement)
- Usage Logs: 90 days
Nº 10Your Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
Nº 11Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS/HTTPS) and at rest
- Secure authentication with password hashing
- Regular security audits and updates
- Access controls and employee training
- Incident response procedures
While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
Nº 12Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
Nº 13Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will also send an email notification. We encourage you to review this Privacy Policy periodically.
Nº 14Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
Théo Diamant — Entrepreneur Individuel (EI), trading as Cheeppy
SIREN 982 821 183 · 20 rue Garnier, 92200 Neuilly-sur-Seine, France
Email: [email protected]
Website: https://cheeppy.com
You also have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In France, this is the CNIL (Commission Nationale de l'Informatique et des Libertés).