Home›Privacy policy
Legal
Privacy policy
1. Who is responsible
Odette is published by Swapp SARL, 64 route de Versailles, 78430 Louveciennes, France, registered under SIREN 904 693 264, RCS Versailles (SIRET 904 693 264 00023, VAT FR16904693264) (“we”, “us”). We are the data controller for the personal data described here.
Questions about this policy, or about your data: hello@odetteapp.com. No data-protection officer is appointed; that address is the contact.
2. Who this is for, and the age limit
Odette is for adults. When you create an account we ask for your date of birth and check it in your browser. If it shows you are under 18, the date is never sent to us and no account is created. Modelling under 18 runs through agencies and legal guardians, and we do not want minors' career data on our servers.
3. What we hold, and why
Almost everything in Odette is data you enter or forward. We group it as follows.
- Your account — email address, and the date of birth used for the age check. Your email is how you sign in; there is no password unless you set one, and if you do, it is stored hashed by our authentication provider, never by us in clear text.
- Your profile — the name you give, your home city, your currency, your working status, and (if you fill them in) measurements and polas. These are the fields a comp card is built from.
- Your career — bookings, castings, auditions, pitches, options, clients, agencies and their contract terms, rates, commissions, invoices, statements, expenses, trips, documents, to-dos, calendar entries and notes.
- Correspondence you forward — when you use the forwarding address, we read the message and its attachments to draft an entry for your Inbox. We keep the parsed result and enough of the original to show you where a value came from.
- Photographs — two different things. Images you upload go to our storage. Images the optional photo watch finds on your clients' sites are not copied: we keep the address of the page and of the image, and what we concluded about it.
- Face data, only if you turn it on — see section 5.
- Notifications — if you allow them, the technical subscription your browser issues, so we can send a push to that device.
We do not run analytics, advertising or third-party trackers on the app or on this site. There is no cookie banner because there are no such cookies. The app uses your browser’s local storage to keep you signed in and to remember small preferences such as your language.
4. What we never do
- We have no connection to your bank. Odette never sees a bank account and never claims a payment arrived — it asks you.
- We do not send email on your behalf. Reminders and takedown requests are drafted and wait for you to send them.
- We do not sell personal data, and we do not share it for advertising.
5. Photo watch and face recognition
Both are off by default and each is a separate switch.
Photo watch checks the websites and social profiles of the clients and agencies in your own account, about once a week. It does not search the open internet. It stores the address of a page and of an image, and its verdict.
Face recognition, if you enable it, is how Odette tells your photos from someone else’s. Reference photographs you provide are stored in a private folder for your account. From each one we compute a mathematical descriptor — a list of numbers — and it is that descriptor, not the photograph, that is compared. Faces found on a client’s page are measured and the measurement is discarded. Turning the switch off deletes the reference photographs and the descriptors.
A facial descriptor is biometric data. We process it only on the basis of your explicit consent, only to answer “is this you?”, and you can withdraw that consent at any time in Settings.
6. Automated reading, and what it decides
To read a forwarded email or a contract, we send its text — and, for a contract, the file — to Anthropic, which runs the Claude models on our behalf as a processor. The result is a draft in your Inbox with a plain word for how sure it is. Nothing becomes a job, an invoice or a calendar entry until you confirm it. No decision with a legal or similarly significant effect is taken automatically.
7. Legal bases
- Performance of a contract — running the account and the features you use (Article 6(1)(b) GDPR).
- Consent — photo watch, face recognition, push notifications, and any sharing you set up (Articles 6(1)(a) and 9(2)(a)).
- Legitimate interests — keeping the service secure and working, and preventing abuse (Article 6(1)(f)).
- Legal obligation — accounting records, if and when we invoice you (Article 6(1)(c)).
8. Who else sees it
We use a small number of processors, each under contract and each limited to what its job requires:
- Supabase — database, authentication and file storage. Hosting region: the European Union (Paris, France).
- Resend — sends the sign-in codes, and one mail three days before a free trial ends. It sees your email address and the message, nothing else.
- Vercel — serves this website and the application.
- Anthropic — reads forwarded mail and contracts, as described above.
- Google (Gmail) — receives the messages you forward.
- Your browser vendor’s push service, if you turn notifications on.
And the people you invite. If you share your account — with an agent, a manager or an accountant — they see what the scope you chose allows: full access, read-only, or money only, which reaches jobs, clients, agencies, expenses and the ledger and never your photographs, your calendar or your correspondence. You can withdraw a share at any time.
Where a processor is outside the European Economic Area, the transfer is covered by the European Commission’s standard contractual clauses.
9. How long we keep it
- Your career data stays for as long as your account exists — it is a record you will want years later, when an agency disputes a fee.
- Face reference photographs and descriptors are deleted as soon as you turn the switch off.
- When you delete your account, we delete your data within 30 days, except what accounting law requires us to keep (invoices, for the statutory period).
- A date of birth that showed you were under 18 is never stored at all.
10. Security
Every table is protected by row-level security: a query can only return rows belonging to the signed-in account, or to an account that has explicitly shared with it. Access is enforced by the database, not only by the interface. Files live in private buckets and are reached through short-lived signed links.
11. Your rights
You have the right of access, rectification, erasure, restriction, portability, and the right to object. You can withdraw consent at any time without affecting what was done before. Write to hello@odetteapp.com and we will answer within one month.
If you are not satisfied, you can complain to the French supervisory authority, the CNIL, or to the authority where you live.
12. Changes
If we change this policy in a way that matters, we will say so in the application before the change takes effect.