GDPR
Privacy policy
This page explains what data Enveline processes, why, where it is hosted, and the rights you have.
Data controller
The data controller is Axell Bordelais, Sole trader (micro-entreprise, France), 97180 Sainte-Anne, Guadeloupe, France. For any question about your data, you can write to contact@enveline.com.
Data processed and legal bases
We only process the data needed to run the service. For each category, here is the legal basis and the retention period.
- Email address and authentication methodPerformance of the contract. Kept for the lifetime of the account.
- Public pseudonymPerformance of the contract. It is the only identifier visible to other members.
- Letters, replies and messagesPerformance of the contract, then anonymisation. They make the exchange at the heart of the service possible.
- Private journal and moodsPerformance of the contract. Visible to you only, and deleted when the account is deleted.
- AI memoriesConsent. Kept until you withdraw your consent, which you can do at any time.
- Moderation scoresLegitimate interest (community safety). Kept for 12 months.
- Notification tokensConsent. Used only to send you the notifications you have accepted.
Hosting in the European Union
The database is hosted in the European Union, with Supabase, region eu-west-3. This choice keeps your data within the EU and under the protection of the GDPR.
Processors
To operate, Enveline relies on a limited number of providers, each for a specific purpose:
- Supabase — database, authentication and hosting (European Union).
- OpenAI — moderation and automated AI replies.
- RevenueCat — subscription management.
- Apple / APNs — delivering notifications.
- AppsFlyer — install attribution.
- Sentry — technical error detection.
The content of letters, the journal and AI memories never flows to a third-party analytics tool.
Sensitive data
The content of letters and the journal may reveal elements relating to your mental health, considered sensitive data under Article 9 of the GDPR. That is why we host it in the European Union and surround its processing with particular safeguards.
Artificial intelligence processing
Enveline uses AI in three ways: automated replies signed “Enveline” to letters, a “Parler” chatbot, and content moderation. Whenever you interact with an AI, this is clearly disclosed to you, in line with Article 50 of the EU AI Act and California’s SB 243.
No sensitive data is memorised by the AI: a server-side filter prevents this kind of information from being kept in the AI’s memories.
Your rights
Under the GDPR, you have the following rights:
- Right of access to your data.
- Right to portability — you can export your data as JSON from the app.
- Right to erasure.
- Right to rectification.
- Right to object.
- Right to withdraw your consent at any time.
Account deletion is done directly in the app. It deletes your journal, your moods and your account data, and anonymises the letters and replies you have exchanged with the community.
You may also lodge a complaint with the CNIL (the French data protection authority).
Privacy contact
To exercise your rights or ask a question about this processing, write to contact@enveline.com.