Privacy Policy
Last update: January 2025
The protection of your personal data is a priority for Ask Leon. This privacy policy informs you about how we collect, use and protect your information in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act.
1. Data Controller
The data controller is:
- Company: Pierre HERAUD EI
- Email: contact@demandealeon.fr
2. Data Collected
We collect the following data:
2.1 Identification data
- Email address
- First name (optional)
- Password (stored encrypted)
2.2 Professional data
- Industry (Construction, Beauty, Restaurants, Healthcare, Real Estate, Retail, etc.)
- Specific profession (e.g., Mason, Hairdresser, Chef)
- Tone preference for publications
2.3 User content
- Photos uploaded for text generation
- Additional context provided for generations
- Generated texts and publication history
- Instagram profile screenshot (Agency plan only, with explicit consent)
2.4 Technical data
- Unique device identifier
- Push notification token (for notifications)
- RevenueCat identifier (subscription management)
- Connection and usage logs
3. Processing Purposes
Your data is used for:
- Service provision: Generating personalized texts according to your profile and industry
- Authentication: Creating and managing your user account
- Personalization: Adapting generated content to your profession and style
- Subscription management: Billing and quota tracking
- Communication: Transactional emails (account validation, password reset) and notifications
- Service improvement: Anonymized analysis to improve generation quality
- Customer support: Responding to your support requests
4. Legal Basis for Processing
The processing of your data is based on:
- Contract performance: To provide the service you subscribed to
- Your consent: For marketing notifications and the Style Clone feature
- Legitimate interest: For service security and fraud prevention
- Legal obligation: For retention of billing data
5. Data Hosting and Storage
All your data is hosted in France and the European Union, ensuring GDPR compliance.
5.1 Servers and database
- Host: OVH SAS
- Location: France
- Address: 2 rue Kellermann, 59100 Roubaix, France
The PostgreSQL database containing your account information is hosted on secure OVH servers with encryption at rest.
5.2 Image storage
- Host: Scaleway (Groupe Iliad)
- Service: Object Storage (S3)
- Location: Paris, France
- Address: 8 rue de la Ville l'Évêque, 75008 Paris
Your photos are stored encrypted and are only accessible by you and our generation system. They are never shared with third parties or used for advertising purposes.
5.3 Backups
Automatic daily backups are made and kept for 30 days on Scaleway servers in France.
6. Subcontractors and Third-party Services
We use the following subcontractors, all GDPR compliant:
| Service | Provider | Purpose | Location |
|---|---|---|---|
| Server hosting | OVH | Infrastructure | France |
| Image storage | Scaleway | Object Storage | France |
| Artificial intelligence | Anthropic | Text generation | USA* |
| Transactional emails | Brevo | Email sending | France |
| Payments | RevenueCat | Subscription management | USA* |
* These American providers comply with the EU-US Data Privacy Framework and/or have standard contractual clauses approved by the European Commission.
7. AI Processing
Your photos are analyzed by Anthropic's Claude API to generate texts. Regarding this processing:
- Images are transmitted encrypted (HTTPS/TLS)
- Anthropic does not retain images after processing
- Images are not used to train AI models
- No personally identifiable information is transmitted with the images
For the "Style Clone" feature (Agency plan), your Instagram profile screenshot is analyzed once to extract your writing style. The resulting text analysis is stored, but the original image is not retained.
8. Data Retention Period
| Data type | Retention period |
|---|---|
| Account data | Until account deletion + 30 days |
| Uploaded photos | 90 days after generation |
| Text history (START) | 7 days |
| Text history (PRO/AGENCY) | Subscription duration + 30 days |
| Billing data | 10 years (legal requirement) |
| Technical logs | 12 months |
9. Your Rights
In accordance with GDPR, you have the following rights:
- Right of access: Obtain a copy of your personal data
- Right of rectification: Correct inaccurate or incomplete data
- Right to erasure: Request deletion of your data (directly in the app: Settings > Delete my account)
- Right to portability: Receive your data in a structured format
- Right to object: Object to the processing of your data
- Right to restriction: Request suspension of processing
- Withdrawal of consent: Withdraw your consent at any time
To exercise these rights, contact us at: contact@demandealeon.fr
You can also file a complaint with the CNIL (French Data Protection Authority): www.cnil.fr
10. Data Security
We implement the following security measures:
- Encryption of data in transit (TLS 1.3) and at rest
- Passwords hashed with bcrypt algorithm
- JWT authentication with token rotation
- Protection against attacks (rate limiting, CORS, secure headers)
- Validation and sanitization of all user inputs
- Encrypted daily backups
- Error monitoring and security alerts (Sentry)
- Restricted access to production data
11. Cookies
The mobile application does not use cookies. The website uses only cookies strictly necessary for operation:
- Session cookie: Maintaining your login
- Preferences cookie: Remembering your choices
No advertising or third-party tracking cookies are used.
12. Minors
The Ask Leon service is intended for professionals and is not designed for minors under 16 years of age. We do not knowingly collect personal data from minors.
13. Changes to this Policy
This privacy policy may be updated. In case of substantial changes, you will be notified by email or by notification in the application.
The date of last update is indicated at the top of this document.
14. Contact
For any questions regarding this privacy policy or your personal data:
- Data Protection Officer: contact@demandealeon.fr
- General support: contact@demandealeon.fr