Privacy of the Qulture ambassador programme
This notice explains the data used for Qulture affiliation and your choices. Attribution is optional and separate from enrolment in the ambassador programme.
affiliate-privacy-v1 · 2026-10-09
Controller and scope
Martin Berbesson, France, contact@qulture-app.com, is the controller named in the Qulture policy. This page covers affiliation only. An ambassador erasure request does not delete the shared Google/Apple account, Challenges profile, purchases or Premium rights.
Partner account
Firebase supplies the account identifier, verified email and name. Qulture also records language, the version and hash of accepted terms, partnership status, commission rules and messages with the team. Ambassador enrolment does not create a Challenges profile.
Attribution and purchases
A partner link is associated with a pseudonymous installation, timestamps, statuses and frozen rules. Firebase and RevenueCat identifiers may link that installation to an account; pseudonymous does not mean anonymous. RevenueCat user identifiers, aliases, transactions, products, store, environment, amounts, fees and dates are used to check purchases, refunds and commissions. Quiz content and Challenges answers are not copied into affiliation.
Your choice on Android and iPhone
Before reading Google Play Install Referrer on Android, retaining a received link or creating identifiers for a new attribution, Qulture asks for your optional agreement. Refusing lets you continue using the app without attribution. On iPhone, a one-time reading of a copied link additionally requires specific agreement and an explicit read action. You can withdraw attribution consent from the ambassador screen: new reads and attribution requests stop, and the pending link is removed locally. Withdrawal does not replace your RevenueCat identity, remove Premium or affect recognised financial rights. A separate erasure request addresses data already recorded. The version, choice and date are recorded locally to apply your decision. On the web invitation page, a separate choice precedes creation of the attribution link and its addition to the page address. After agreement, the Google Play button passes the link to the installation and the App Store button copies it. Without agreement, the buttons open the stores without attribution. Withdrawal on that page stops new operations and removes the token from the address; it does not erase data already recorded. This web choice remains in the page’s memory and does not grant consent in the app.
Wise payments
The email-based Wise form stores recipient name, email, country and currency in private collections without application-level encryption of these fields. The separate IBAN interface encrypts the IBAN and holder with AES-256-GCM; country, the final four characters and metadata remain readable to authorised services. Financial exports contain the information needed for payment.
Access, providers and sessions
Clients use an authenticated API; private collections are not intended for direct client access. Server roles separate partners, administration and finance. Firebase/Google provides authentication and server services, Apple provides Apple sign-in, RevenueCat verifies purchases and Wise handles payments. Their privacy information is linked below and describes their processing and transfers. This notice does not presume a shared hosting country for these services. Contact Qulture for the safeguards applicable to your data. Opening the web portal from the app uses a single-use link lasting 60 seconds, followed by a 30-minute session. Raw session secrets are not stored. Sandbox is a read-only, non-payable simulation.
Purposes and legal bases
The partner account, necessary messages and commission administration rely on performance of the requested partnership, limited to data necessary for that service. Retention of legally required accounting records relies on a legal obligation. Security, abuse prevention and conflicting attribution handling rely on the legitimate interest of protecting the service, subject to necessity and proportionality review. Optional attribution and the associated device reads or writes rely on your consent; accepting partnership terms does not give attribution consent. You can refuse or withdraw consent without losing access to other Qulture functions.
Retention and erasure
Once an ambassador erasure request has been fully processed, profile fields, messages, sessions, clicks, operational statistics are removed, and the technical binding between the installation and your Firebase UID is deleted. Processing may require several steps; the receipt remains under review until actual completion. Where a financial file exists, financial records, contract or attribution evidence, minimal contractual data and payment details needed for open rights are retained with categories, reason and criterion stated in the receipt. Payment details are reviewed after open rights are settled, according to what belongs to mandatory records. Accounting documents and supporting records actually covered by article L123-22 of the French Commercial Code are kept for ten years; this period does not apply to all affiliate data. There is no automatic erasure when a balance reaches zero. A pseudonymous receipt remains available to show status and evidence processing while that proof is necessary, with necessity reviewed at shared-account closure or on a new request. Installation and RevenueCat identifiers, mapping keys and secret hashes remain while necessary for the app customer identity and purchase history; partner-file erasure removes the installation’s technical Firebase binding without changing that identity. Identifiers needed for a retained financial file remain according to the receipt’s categories and criteria. Previous exports, backups and provider-held records receive separate review based on settlement, accounting or documented dispute needs. The 30-day attribution windows, session expiry and rate limits govern validity; they do not trigger automatic purging.
Request and processing
From the ambassador screen in the app or this web portal, sign in with the same Google/Apple account, read the scope and confirm your request. Recent authentication may be required. The server stops new attributions, closes affiliation sessions and issues a receipt. Receipt, review and completed erasure are separate stages. Administration performs actual non-financial erasure; where financial records remain, the status and receipt specify retained categories, reason and criterion. Archiving a partner is not erasure.
Your rights
Contact contact@qulture-app.com for access, rectification, erasure, restriction, objection or portability where applicable, and for a request about the whole Qulture account. Responses are normally provided within one month; a justified extension may be communicated under GDPR rules. You may complain to the CNIL. An affiliation-only request preserves the shared account and recognised financial rights.