Privacy Policy
Last updated: 7 July 2026
This Privacy Policy describes how Cirple collects, uses, and protects your personal data. It applies to all features of the Cirple application. We invite you to read it carefully.
1. Introduction and identity of the data controller
The purpose of this Privacy Policy is to inform users of the Cirple application of the conditions under which their personal data are collected, processed, and protected.
Cirple is a geolocated social application that lets users discover, in real time and in their immediate vicinity, social activities, circles, and local interactions. In this context, certain personal data are required for the service to function.
The data controller is:
- Company name: CIRPLE
- Legal form: Simplified joint-stock company (SAS)
- SIREN: 101 996 924
- SIRET (head office): 101 996 924 00011
- EU VAT number: FR16101996924
- Trade and Companies Register: Paris
- Registered office: 1 rue de Stockholm, 75008 Paris, France
- Incorporation date: 25 February 2026
Cirple undertakes to process personal data in strict compliance with the applicable regulations, in particular Regulation (EU) 2016/679 (GDPR), French Act No. 78-17 of 6 January 1978 as amended (French Data Protection Act), and Regulation (EU) 2022/2065 (DSA).
GDPR contact point
For any question relating to the protection of your personal data:
- Email: privacy@cirple.com
- Post: Cirple — Attn. Data Protection Officer, 1 rue de Stockholm, 75008 Paris, France
2. Data collected
Cirple only collects data strictly necessary for the service to function. These data fall into two categories: data you provide to us directly, and data collected automatically when you use the application.
2.1 Data provided directly by the user
Mandatory data required to create an account:
- Mobile phone number (required for authentication).
- First name (visible to other members).
- Date of birth (private — used to verify legal age).
Optional data to complete the profile:
- Profile picture (visible to other members if added).
- Personal description (visible to other members if provided).
- Interests (visible to other members if provided).
Optional data do not condition access to the service. Their absence does not prevent use of the application but may limit the relevance of the recommendations.
2.2 Data collected automatically
- Location data: collected only when the user activates geolocation or the "Presence" feature. The exact location is never shared with other members.
- Activity data: interactions with the application (logins, circles joined, presences activated, messages sent).
- Technical data: IP address, device identifier, application version, operating system, activity logs.
- Reporting and moderation data: reports made or received, moderation decisions.
- Interaction and session-replay data: recording of user interactions within the application (screens viewed, navigation gestures, actions performed), collected through a third-party SDK to analyse and improve the user experience, detect malfunctions, and prevent abusive use. Text input fields and elements likely to directly identify the user or third parties are masked and not recorded.
3. Purposes of processing and legal bases
In accordance with the GDPR, each data-processing activity is tied to a specific legal basis. Cirple relies on the following legal bases:
- Account creation and management: Performance of the contract (art. 6.1.b GDPR)
- Service delivery (circles, spots, presences): Performance of the contract (art. 6.1.b GDPR)
- Geolocation and Presence activation: Consent (art. 6.1.a GDPR)
- Sending push notifications: Consent (art. 6.1.a GDPR)
- Recommendation of circles and spots: Performance of the contract (art. 6.1.b GDPR)
- Platform security and abuse prevention: Legitimate interest (art. 6.1.f GDPR)
- Moderation of content and behaviour: Legal obligation + legitimate interest (art. 6.1.c and f GDPR)
- Service improvement and statistical analyses: Legitimate interest (art. 6.1.f GDPR)
- Response to rights requests: Legal obligation (art. 6.1.c GDPR)
- Retention of legally required data after account deletion: Legal obligation (art. 6.1.c GDPR + French Digital Economy Trust Act "LCEN")
- Analysis of usage journeys: Legitimate interest (art. 6.1.f GDPR) — service improvement and security
Where processing is based on consent, this consent can be withdrawn at any time from the application settings, without affecting the lawfulness of the processing carried out before withdrawal.
4. Automated decisions and algorithmic recommendations
Cirple uses algorithmic systems to recommend circles, spots, and presences to the user. These recommendations are based on the criteria described in Article 7.3 of the Terms of Service (location, interests, recent activity, circle popularity).
These algorithmic processes have no legal effect on the user and do not constitute automated decisions within the meaning of Article 22 of the GDPR. Their sole purpose is to improve the relevance of the content presented.
Automated tools used for moderation purposes (detection of illegal content or abusive behaviour) are subject to human review in the event of a challenge, in accordance with Article 10 of the Terms of Service.
The user has the right not to be subject to a decision based solely on automated processing producing legal effects concerning them. This right can be exercised in the manner described in Article 9 of this policy.
5. Processing of location data
Location data are at the heart of how Cirple works. Because of their sensitive nature, their processing is subject to specific safeguards.
5.1 Data collected
- The user's approximate location is collected when they activate the "Presence" feature.
- The exact location is never shared with other members. Only an approximate location, within a defined radius, is made visible.
- When the user deactivates their Presence, their location is no longer collected or visible to other members.
5.2 Specific retention periods
- Real-time position data: retained for the duration Presence is active, then deleted.
- Location history (logs): retained for 30 days from collection, then deleted automatically.
Legal basis: Consent — The collection of location data is based on your explicit consent. You can withdraw it at any time by disabling geolocation in your device settings or by deactivating Presence from the application.
6. Data recipients
Users' personal data are accessible only to authorised persons within Cirple, within the scope of their duties.
They may also be transmitted to the following categories of providers, acting as Cirple's processors and bound by contractual confidentiality and security obligations:
- Hosting provider: storage and application infrastructure (Amazon Web Services)
- Analytics and performance tool: audience measurement, error detection
- Push notification service: sending notifications to the user
- Moderation tool: detection of illegal content
Cirple may also transmit data to the competent authorities (judicial, administrative) where required by law or as part of legal proceedings.
In the event of a restructuring, merger, acquisition, or transfer of assets, users' data may be transferred to the acquirer, which will be bound by the same protection obligations. Users will be informed within a reasonable timeframe.
7. Transfers of data outside the European Union
Users' data are hosted, wherever possible, within the European Union.
Some of Cirple's technical providers may be established outside the European Union or may transfer data outside the EU. In such cases, Cirple ensures that these transfers are governed by appropriate safeguards, in particular:
- standard contractual clauses approved by the European Commission (article 46 GDPR); or
- any other transfer mechanism recognised by applicable regulations.
The user may obtain information about the transfers carried out and the safeguards in place by contacting Cirple at privacy@cirple.com.
8. Retention periods
Cirple applies defined retention periods proportionate to the purposes pursued. At the end of these periods, data are deleted or irreversibly anonymised.
- Active account data: duration of registration.
- Data after account deletion by the user: at the user's request, the account is immediately deactivated, then permanently deleted after a period of thirty (30) days, during which the user may reactivate their account. After such permanent deletion, certain data are kept for 13 months in archives (legal obligations under the French Digital Economy Trust Act "LCEN"), then deleted.
- Data after deletion for inactivity: 13 months (LCEN legal obligations), then permanent deletion.
- Real-time location data: duration of active Presence, then immediate deletion.
- Location history (logs): 30 days, then automatic deletion.
- Activity data and technical logs: 12 months.
- Moderation data and reports: 1 year from the report (LCEN).
- Banned-account data: 24 months in the active database to prevent re-registration, then legal archiving.
- Anonymised statistical data: unlimited retention (data are irreversibly anonymised).
- Interaction journeys: 3 months.
Data retained after account deletion are stored in an archive database separate from the production database, accessible only upon judicial requisition.
9. User rights
In accordance with the GDPR and the French Data Protection Act, the user has the following rights over their personal data:
9.1 List of rights
- Right of access (art. 15 GDPR): obtain confirmation that data concerning you are being processed and receive a copy.
- Right of rectification (art. 16 GDPR): have inaccurate or incomplete data corrected. Some data can be modified directly from the profile settings in the application.
- Right to erasure (art. 17 GDPR): request the deletion of your data, subject to legal retention obligations. Account deletion is available directly from the application. It triggers immediate deactivation of the account, followed by permanent deletion after a period of thirty (30) days, during which you can cancel your request by logging back in.
- Right to restriction (art. 18 GDPR): request the temporary freezing of the processing of certain data in the cases provided by regulations.
- Right to portability (art. 20 GDPR): receive the data you have provided in a structured, commonly used, and machine-readable format, and transmit them to another data controller.
- Right to object (art. 21 GDPR): object to the processing of your data based on Cirple's legitimate interest. Cirple may continue the processing if it demonstrates compelling legitimate grounds.
- Right not to be subject to automated decision-making (art. 22 GDPR): not be subject to a decision producing legal effects based solely on automated processing.
- Right to withdraw your consent: where processing is based on your consent, you can withdraw it at any time via the application settings or by contacting Cirple, without affecting the lawfulness of prior processing.
- Right to define post-mortem directives (art. 85 French Data Protection Act): define instructions regarding the retention, deletion, and communication of your data after your death.
9.2 How to exercise your rights
Any request can be addressed to Cirple:
- By email: privacy@cirple.com
- By post at the address given in Article 1.
For security reasons, Cirple may request proof of identity before responding to a request. Cirple undertakes to respond within one (1) month of receipt of the complete request. This period may be extended by a further two months in the event of a complex or multiple request, in which case the user will be informed.
9.3 Right to lodge a complaint with the CNIL
If the user believes that the processing of their personal data does not comply with regulations, they have the right to lodge a complaint with the competent supervisory authority:
French Data Protection Authority (CNIL — Commission Nationale de l'Informatique et des Libertés)
- Website: www.cnil.fr/en
- Address: 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France
10. Data security
Cirple implements appropriate technical and organisational measures to ensure the security, integrity, and confidentiality of personal data, in particular:
- encryption of data in transit (HTTPS/TLS protocol);
- internal access control to data, limited to authorised persons;
- logging of access to sensitive data;
- processes for detecting and managing security incidents.
In the event of a data breach likely to result in a high risk to the rights and freedoms of users, Cirple undertakes to notify the persons concerned as soon as possible, in accordance with Article 34 of the GDPR.
11. Data of minors
The Cirple application is strictly reserved for persons aged 18 and over. Cirple does not knowingly collect personal data concerning minors.
If a user has provided a fraudulent date of birth at registration, or if a parent or legal guardian discovers that a minor has registered on the Platform, they are invited to notify Cirple immediately at privacy@cirple.com. Cirple undertakes to delete all data concerning the minor as soon as possible and to terminate the account concerned.
12. Cookies and trackers
The Cirple application is a native mobile application. It does not use cookies in the traditional sense of the term.
However, third-party SDKs (software development kits) may be integrated into the application to provide certain technical features (analytics, push notifications, error detection). These SDKs may collect technical device identifiers.
Among these SDKs is a session-replay and journey-analysis tool that records interactions within the application in order to improve its ergonomics and stability. This tool is configured to automatically mask input fields and data likely to directly identify the user or third parties.
The user can limit the collection of certain technical identifiers by activating the "Limit ad tracking" feature available in their device settings (iOS: Settings > Privacy > Tracking; Android: Settings > Privacy).
13. Changes to the privacy policy
This Privacy Policy may be amended at any time to reflect changes to the service, processing practices, or applicable regulations.
In the event of a material change, users will be informed by an in-app notification and/or by email, with reasonable prior notice. Continued use of the application after the changes take effect constitutes acceptance of the revised policy.
The version in force is always accessible from the application and from the Cirple website, with the last-updated date indicated at the top of the document.
14. Contact
For any question relating to this Privacy Policy or to exercise your rights over your personal data:
- Email: privacy@cirple.com
- Post: at the address given in Article 1, attention Data Protection Officer
For any moderation- or Terms-related complaint: safety@cirple.com
For any general enquiry: legal@cirple.com