Privacy policy

Last updated: 26 September 2026.

Controller

Mahé Chadeffaud, entrepreneur individuel, Stonetotem, 7 rue Marie-Thérèse Hermann, 74000, Annecy, France; SIREN 109 270 363. Contact [email protected] or +262 693 65 63 70 for all data protection questions.

Data and purposes

To answer your question and show your history, the service processes what you type, extracted facts, goals, results, conversations and reported outcomes. This processing is necessary to supply the service you request (GDPR article 6(1)(b)). Do not provide personal data about other people.

A random browser identifier connects requests and credits. Account and payment information is processed when those features are used, for the contract and applicable accounting obligations (articles 6(1)(b) and 6(1)(c)). Stripe handles card details. Technical request information, including IP addresses, supports security and abuse prevention (legitimate interests, article 6(1)(f)). Support messages are used to answer your request.

Learning from your experience

With your separate, optional consent (article 6(1)(a)), your facts, results and reported outcomes may contribute to improving shared models. The intended learning process uses pseudonymised records and aggregated data. Pseudonymisation replaces direct identifiers; it is not anonymisation and the records remain personal data. Aggregates are outside GDPR only when re-identification is no longer reasonably possible.

Learning consent must be an active choice at registration or before the first contribution, never inferred from accepting terms or using the service. Refusal must not prevent ordinary use. You can withdraw via [email protected]; withdrawal stops future consent-based use without making earlier lawful processing unlawful. We must explain and assess the consequences for existing datasets and models, rather than promise that every trained model can simply be reversed.

Health and other sensitive data

Health data is a special category under GDPR article 9. When it is needed for your own health-related question, processing requires a separate, explicit consent for that purpose under articles 6(1)(a) and 9(2)(a). Using it for shared learning requires another explicit choice. Neither permission follows from a general checkbox accepting the terms.

Only submit sensitive information through a flow that first explains the purpose and asks for explicit consent. If that flow is unavailable, do not enter it in the general text box. Consent for one purpose does not authorise another. Withdraw via [email protected]; a question that requires health information cannot then use that information. Public profiles and rankings are separate from private learning and require their own lawful basis and clear information.

Recipients and international transfers

The site currently requests Geist from Google Fonts, which exposes technical request information such as your IP address to Google. See Google Fonts privacy information.

Processor contracts and any safeguards for transfers outside the EEA must cover the actual deployed services. Safeguards stated in each provider's data processing terms: Nebius B.V.: EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated through section 6.2 of the Nebius DPA for transfers to countries without an adequacy decision, and its US entities Nebius Inc. and ADC Tech Inc. are covered by its EU-US Data Privacy Framework certification; Resend: EU Standard Contractual Clauses (Module Two) incorporated in the Resend DPA, which also sets out its EU-US Data Privacy Framework commitments; Supabase: EU Standard Contractual Clauses incorporated in the Supabase DPA; Cloudflare: EU-US Data Privacy Framework, and EU Standard Contractual Clauses (Module Two) in the Cloudflare DPA for any transfer it does not cover; Google Workspace only (Google Ireland Limited): under Google's Cloud Data Processing Addendum, transfers to Google LLC in the United States rely on its EU-US Data Privacy Framework certification, and other restricted transfers to its subprocessors on the Standard Contractual Clauses in that Addendum. An unresolved transfer is not authorised merely by describing it here or by obtaining health consent. You can obtain a copy of the applicable transfer safeguards from [email protected]; see also the Nebius, Resend, Supabase, Cloudflare and Google Cloud data processing terms.

Retention and operational verification

Applicable retention periods, including conversations, learning records, consent evidence, logs, account data and backups: Conversations and results: until you delete them or your account; account and profile: until deletion, erased immediately by self-service deletion; visitor cookie: 365 days; sign-in cookies: up to 30 days; AI provider: no retention (Zero Data Retention); provider backups and logs: per each provider's terms, being documented.

Verification of consent, withdrawal, deletion and processor arrangements: 26 September 2026: Nebius Zero Data Retention enabled; processor DPAs accepted through each provider's terms (Nebius, Resend, Supabase, Cloudflare, Google Workspace); self-service account deletion coded and its database migration applied; no consent-based learning active, and no learning-consent or withdrawal flow implemented yet. Publishing this policy alone does not implement those operations.

Your rights

You can request access, correction, erasure, restriction and portability where applicable, object to processing based on legitimate interests, and withdraw consent. Contact [email protected] or write to 7 rue Marie-Thérèse Hermann, 74000. We respond within one month; a justified extension of up to two further months will be explained within the first month. We request identity evidence only when necessary.

You may complain to the CNIL or your local supervisory authority. In Switzerland, see the FDPIC. Mandatory local rights remain available.

Automated estimates and children

AI interprets your text and statistical models generate estimates from the available data. Estimates may be wrong. You decide what to do; the service must not be used to decide another person's access to work, credit, insurance, education or essential services. You may request a human review at [email protected].

The service is for adults aged 18 and over. Contact us if a minor has submitted data so it can be investigated and removed as required.

Security and changes

See the security policy. Where a breach meets the applicable legal thresholds, we notify the supervisory authority and affected people. Changes to purposes or consent-based uses must be communicated before they take effect, with renewed consent where required.

Legal references: GDPR and CNIL guidance on consent.