Privacy Policy
As of July 2026 · This policy covers the current invitation-only phase of nielou.app. We update it with every significant change in functionality.
1. Who we are
Nielou ("we", "us") is a modeling platform under development. This policy explains how we handle personal data on nielou.app during the pre-launch phase.
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
Nielou — Founder
c/o flexdienst – #21489, Kurt-Schumacher-Straße 76, 67663 Kaiserslautern, Germany
Email: hello@nielou.app
Full provider details: see our Impressum.
2. Scope of this policy
Currently, nielou.app a public website; the member area at app.nielou.app is not public. Members can already build profiles with photos and use a personal profile link. This policy covers both. No agency matching takes place yet; we will update this policy before it starts.
3. What we collect
If you join the waitlist, we collect:
- the email address you provide,
- your name, if you choose to share it,
- the date and time of your sign-up,
- an anti-spam token submitted with the form.
If you create a member account, we collect and store:
- your name, your email address, and your password (stored only as a cryptographic hash, never in plain text),
- your date of birth — used solely for the age check (Nielou is 18+); it never appears publicly on your profile,
- the profile details you enter yourself — for example city, measurements, hair and eye colour, short bio,
- the photos you upload (polas and portfolio),
- your consent settings including their history — so it stays traceable what you allowed or revoked, and when,
- messages you write in the members' room or to support.
Your profile only becomes publicly visible once you publish it yourself and it has been reviewed.
If you only visit the page, our analytics provider (Cloudflare Web Analytics) records:
- the country your visit comes from (not your precise location),
- your browser type and screen size,
- the pages you visit on nielou.app,
- the referring page, if any.
Cloudflare Web Analytics works without cookies and does not track you across other websites. No advertising or fingerprinting profile is created.
If you contact us at hello@nielou.app, we receive your message and your sender email address.
If you send an enquiry through a profile, we store your name, your e-mail address, optionally your company, your message and an encrypted short value (hash) of your IP address that changes every month. We do not store the IP address itself. This protects our members from mass enquiries: without verification you can contact exactly one model, and anyone who contacts more is blocked (legitimate interest, Art. 6(1)(f) GDPR).
4. Why we collect this data — and on what legal basis
We process the data above for the following purposes:
- To inform you of Nielou's launch — based on your consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time.
- To protect the form against spam and abuse — based on our legitimate interest in keeping the service operational (Art. 6(1)(f) GDPR).
- To understand how the site is used and to improve it — based on our legitimate interest, using cookieless, aggregated analytics (Art. 6(1)(f) GDPR).
- To respond to your messages — based on our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR).
5. Where your data is stored and who processes it
We use the following processors:
- Netlify, Inc. (USA) — hosting for the public website nielou.app. Certified under the EU-US Data Privacy Framework.
- Cloudflare, Inc. (USA) — cookieless web analytics and DNS. Certified under the EU-US Data Privacy Framework.
- ImprovMX (USA) — forwards emails sent to hello@nielou.app to our inbox.
- Google LLC (USA) — Gmail mailbox that receives forwarded emails. Certified under the EU-US Data Privacy Framework.
- Supabase (European Union, Frankfurt region) — database, authentication and photo storage for the member area and for waitlist entries. Certified to ISO/IEC 27001:2022. This is where your profile data and your photos are held — inside the EU.
We do not sell personal data and we do not pass it on to advertisers.
6. How long we keep data
- Waitlist entries: until you ask us to delete it, and no longer than three years.
- Analytics: aggregated and held by Cloudflare on a rolling 6-month window. We never see individual visitor data.
- Contact emails: kept as long as needed to respond, then archived for up to 24 months for context.
- Member account and profile: for as long as your account exists. After deletion we remove the profile and photos from the active system within 30 days.
You can request earlier deletion at any time.
7. Your rights under the GDPR
You have the right to
- access the data stored about you,
- have inaccurate data corrected,
- have your data deleted ("right to be forgotten"),
- restrict or object to processing based on legitimate interests,
- withdraw consentat any time, without affecting the lawfulness of processing carried out before the withdrawal,
- receive a copy of your data in a portable, machine-readable format,
- lodge a complaint with a supervisory authority.
To exercise any of these rights, write to us at hello@nielou.app. We respond within one month.
The supervisory authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA) — baylda.de. You may also contact the supervisory authority of your EU member state.
8. Children and minors
The site is not directed at children. Nielou does not allow accounts for anyone under 18, and age is checked at registration. No data from children is intentionally collected.
9. Cookies
We do not use any tracking, advertising, or social cookies on the pre-launch site. Cloudflare Web Analytics is cookieless. Strictly necessary cookies may be set by our hosting provider solely for security and routing. If we introduce non-essential cookies in the future, this policy will be updated and, where required, we will obtain your consent.
10. Security
The site is delivered over HTTPS. Form submissions are encrypted in transit. Access to processor dashboards is restricted to the founder and protected by strong authentication. No system is fully secure; we apply reasonable measures appropriate to the volume of data involved.
11. Changes to this policy
We will revise this policy before the full platform launches — and earlier if our data practices materially change. The "as of" date above indicates the version currently in force.
12. Contact
For any privacy question, request, or correction:
The lotus grows in mud — and blooms most perfectly of all. 🪷