Privacy policy
How we handle your data
Last updated: June 25, 2026
This page is maintained by the editor of Que pense Michel. It describes our current commitments — no third-party certification is claimed.
1.Data controller
Que pense Michel is operated by its publisher (the “editor”), reachable at the contact address below. The editor decides why and how your personal data is processed and is the data controller within the meaning of the GDPR.
Until full legal mentions are published, treat the contact email below as the official channel for any data-protection request.
2.What data we process
In plain English: Your WhatsApp export, the names you confirm, your email if you create an account, and a few technical logs.
Data you provide:
- The WhatsApp chat export (.txt or .zip) you upload, including message text, timestamps and sender display names as they appear in the file.
- The participant display names you confirm or edit in the wizard, the group name, and the optional cover image.
- Your email address, used to deliver the report link and, if you sign in, to create your account.
- Billing identifiers returned by Stripe (transaction ID, last 4 digits, country). We never see or store your full card number.
- Basic technical data: IP address (truncated where possible), browser user-agent, request timestamps and error logs, kept for security and debugging.
3.Purposes & legal bases (GDPR art. 6)
In plain English: We use your data to deliver the report you asked for, to bill you, and to keep the service safe.
- Generating and delivering your report, managing your account and reports — performance of the contract (art. 6.1.b).
- Processing your payment and issuing invoices — performance of the contract and legal obligation (art. 6.1.b & 6.1.c).
- Sending transactional emails (report ready, magic link, receipts) — performance of the contract (art. 6.1.b).
- Preventing fraud, abuse and ensuring service security — legitimate interest (art. 6.1.f).
- Anonymous product analytics (page views, conversion) — legitimate interest (art. 6.1.f); no advertising cookies.
4.Retention periods
In plain English: The raw chat is deleted within 24 hours. The report stays as long as your account exists. You can delete everything from the dashboard.
| Data | Retention |
|---|---|
| Raw chat export (uploaded .txt/.zip and parsed messages) | Deleted within 24 hours after the report is generated. |
| Generated report (structured JSON), group name, cover image | Kept as long as your account exists. Deleted immediately on request. |
| Email address and account | Kept until you delete your account. |
| Technical logs (IP, user-agent, errors) | 30 days, then automatically purged. |
| Billing records (invoice, Stripe transaction ID) | 10 years — legal accounting obligation. |
5.AI & automated processing
In plain English: Your messages are read by a third-party AI to write the report — and they are not used to train any model.
To produce the report, we send the parsed chat content to Google's Gemini API. Under Google's API terms for paid Gemini usage, your inputs and outputs are not used to train Google's models.
Once the report is generated, the raw chat content is deleted from our database within the retention window above. The AI provider does not retain inputs for longer than the period required to process the request and run abuse-prevention checks.
The report itself is content authored by an AI based on your chat. It is intended as entertainment and does not produce legal effects about you within the meaning of GDPR art. 22 (no fully automated decision with significant consequences).
6.Sub-processors
In plain English: Four providers help us run the service. Here's who they are and what they do.
| Provider | Role | Region | Safeguards |
|---|---|---|---|
| Lovable Cloud (Supabase) | Hosting, database, authentication, file storage | EU / global | Data Processing Agreement, encryption in transit and at rest. |
| Google (Gemini API) | AI report generation | US (global infra) | Google Cloud DPA, EU Standard Contractual Clauses, no model training on inputs. |
| Stripe | Payment processing | US / IE | PCI-DSS certified, SCCs for EU transfers, DPA. |
| Resend | Transactional emails (report ready, magic link) | US | DPA, SCCs for EU transfers. |
7.International transfers
Some sub-processors above are based outside the European Union. When that is the case, transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), complemented where relevant by additional technical and organisational measures (encryption in transit, access controls, minimisation of the data shared).
8.Security
In plain English: HTTPS everywhere, access is restricted, and the database is locked down per user.
- All traffic between your browser and our servers is encrypted in transit (HTTPS / TLS).
- Data at rest is encrypted by our cloud infrastructure provider.
- Database access is enforced by row-level security: by default a user can only read and modify their own rows.
- Administrative access to production is limited to the editor, protected by strong authentication.
- We do not claim any third-party certification (SOC 2, ISO 27001, HIPAA, etc.) on this page. If we ever obtain one, we will say so here, with evidence.
9.Your rights (GDPR art. 15–22)
In plain English: You can ask for a copy of your data, fix it, or delete everything. Most of it is one click from the dashboard.
- Right of access (art. 15) — get a copy of the personal data we hold about you.
- Right to rectification (art. 16) — correct inaccurate data (e.g. participant names).
- Right to erasure (art. 17) — delete a specific report or your entire account. Self-serve from the dashboard.
- Right to restriction (art. 18) — ask us to freeze processing while a dispute is resolved.
- Right to object (art. 21) — object to processing based on legitimate interest.
- Right to data portability (art. 20) — receive your report and account data in a structured, machine-readable format (JSON).
- Right to withdraw consent at any time, where processing was based on consent.
- Right to lodge a complaint with a supervisory authority (CNIL in France).
11.Minors
Que pense Michel is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor uploaded a chat, contact us and we will remove the report and associated data.
12.Changes to this policy
We may update this policy as the product evolves or as legal requirements change. Material changes will be reflected in the “Last updated” date above. Continued use of the service after a change means you accept the updated policy.
13.Contact
In plain English: One email for legal questions, one button for instant deletion.
Email: privacy@quepensemichel.com
Self-serve: delete your account from the dashboard