Privacy Policy

Last updated: 15 June 2026

This Privacy Policy explains how Depipol processes your personal data when you use the Depipol mobile application and the website https://www.depipol.com (the "Service"). Depipol is a private application that lets you create groups and share photos and videos only with the people you choose.

We process your data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

In short

  • Your photos and videos are yours.
  • We don't sell your data and there are no ads.
  • We don't use facial recognition or store your photos' location.
  • We only use your data to make the app work and to show your content to your group.

And now exactly the same, but in legal language (because we're required to) 👇

1. Data controller

2. Data we process

Data you provide

Data from your device (with your permission)

Data generated through use

What we do NOT process

3. Why we use your data and on what legal basis

PurposeLegal basis (GDPR)
Create your account, authenticate you by phone and provide the Service (groups, albums, photo and video uploads). Performance of a contract (Art. 6(1)(b)).
Send you push notifications about your groups and your uploads. Performance of a contract and/or your consent (Art. 6(1)(a)/(b)).
Check which contacts in your address book use Depipol. Your consent when granting the permission (Art. 6(1)(a)).
Analyse content to organise it and enable searches. Performance of a contract / legitimate interest (Art. 6(1)(b)/(f)).
Security, abuse prevention and troubleshooting. Legitimate interest (Art. 6(1)(f)).
Comply with legal obligations and respond to requests from authorities. Legal obligation (Art. 6(1)(c)).

4. Processors and providers acting on our behalf

To provide the Service we rely on the following providers, which act as data processors under contract:

ProviderPurposeData
Amazon Web Services (AWS) Storage of photos and videos (S3) and video transcoding (MediaConvert). Photos, videos and their technical metadata.
Google Cloud / Firebase Phone authentication (Firebase Auth); image analysis (Cloud Vision) and video analysis (Video Intelligence); temporary video storage for analysis. Phone number, photos and videos.
OneSignal Sending push notifications. User identifier, language and device token.

We do not share your data with third parties for commercial purposes. We only disclose it where legally required or necessary to protect rights, safety or against legal liability.

We do not sell or "share" your personal information (including in the sense of U.S. privacy laws such as California's CCPA/CPRA). If you reside in the United States, you may exercise the same access and deletion rights described below, without being discriminated against for doing so.

5. International transfers

Some of the providers above (AWS, Google and OneSignal) may process data on servers located outside the European Economic Area, including the United States. In those cases the transfer relies on the European Commission's Standard Contractual Clauses or on an adequacy decision, with appropriate safeguards for your data.

The Service is operated from Spain and is available internationally. If you access it from outside the European Union, in addition to the GDPR the data protection laws of your country of residence may also apply.

6. Retention periods

You can delete your account from within the app or by following the account deletion request procedure.

7. Your rights

At any time you may exercise your rights of access, rectification, erasure, restriction, portability and objection, and withdraw any consent given, by writing to admin@depipol.com and stating the phone number linked to your account.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the data protection supervisory authority of your country of residence.

8. Minors

The Service is not directed to children under 14 years of age. We do not knowingly collect data from anyone under that age. If we become aware that we have processed data of a child under 14 without the consent of the holder of parental authority or guardianship, we will delete it.

9. Security

We apply reasonable technical and organisational measures to protect your data (on-device credential encryption, secure connections and access control). No system is 100% secure, but we work to minimise risks.

10. Changes to this policy

We may update this Privacy Policy. We will post the current version on this page and, if the changes are significant, we will notify you through a prominent notice in the Service, updating the date in the header.

11. Contact

For any question about this policy or your data: admin@depipol.com.