What we do with your data
A page written from the code, not from a promise. Every claim below matches a mechanism that exists — and we also say what does not.
Messages encrypted at rest
Conversation content is encrypted in the database, envelope-style: a separate key per conversation, sealed by a master key. A copy of the database, a backup or direct access to storage return ciphertext and nothing else.
A European AI
Matching and the coach run on Mistral, a French model — that is the project's default choice. Skill vectors are computed there in every case.
The European ESCO framework
Skills are tied to ESCO, the European Commission's public taxonomy — around 13,500 entries, re-imported with every release. Not a home-grown keyword cloud.
Bounded retention
Usage events are purged automatically beyond 13 months, every day. That is the cap the French DPA recommends for trackers, enforced by code rather than by a promise.
Your conversations
Every conversation carries its own key, and every encrypted value is bound to its place — its conversation, its message, its column. Moving a row from one conversation to another does not make it readable: verification fails.
- What this protects
- A copy of the database, a backup, direct administrative access to storage, a duplicated bucket. That is the most common leak scenario, and it is covered.
- What this does not protect
- This is not end-to-end encryption. The server holds the master key — that is what makes read-time translation, notification previews and moderation possible. A compromised server would expose the plaintext.
- What moderation sees
- Nothing, as long as nobody reports. A report opens a window of eleven messages around the one flagged — that message, and five on either side. No screen browses a conversation.
What stays in your hands
Delete your account for good
From your settings. The profile and all its content go in the same transaction — this is not a deactivation, and nothing is kept "just in case".
Turn down audience measurement
Usage statistics are first-party and sit behind explicit consent, revocable at any time. Withdrawing it clears what had been placed on the browser.
A guardian's consent, for minors
A minor's profile names their guardian, who confirms through a link — with no account to create. Without that consent, applying stays closed, and no tracker starts on the session.
Browsing without leaving a trace
Ghost mode is reciprocal, on purpose: you stop reporting your visits, and you give up seeing your own. No one-way mirror.
What this is not
Three limits we would rather write ourselves. They are verifiable in the code, so keeping quiet about them would protect us from nothing.
The encryption is not end-to-end
The server can read your messages. We write it here rather than let the word "encrypted" suggest otherwise: this encryption protects storage, not against the operator.
Protection for minors only covers declared birth dates
Date of birth is not asked anywhere at sign-up. Without it, neither the guardian's consent nor the tracker block is triggered. That is a known limit, not a guarantee.
There is no automated export yet
Deletion exists, exporting your data in one click does not. In the meantime, write to us: your access request will be handled.
A precise question about your data?
School, company or individual: we answer about the mechanism, not with a pointer to twenty pages of terms.