Privacy Policy
🇫🇷 FrançaisLast updated: November 16, 2025
1. Introduction
Ça Goutte! ("we", "our") respects your privacy. This policy explains how we collect, use, and protect your personal health data.
2. Data Collected
2.1 Account Data:
- Email address
- Password (encrypted)
- Account creation date
2.2 Health Data:
- Food diary (consumed foods, portions, purines)
- Crisis history (dates, intensities, affected joints)
- Hydration tracking (water intake)
- AI assistant conversations
- Generated statistics and charts
2.3 Technical Data:
- Device type and operating system
- App version
- Error logs (anonymized)
3. Data Usage
We use your data to:
- Provide app features (tracking, AI, statistics)
- Generate your medical CSV exports
- Improve the app (bug fixes, new features)
- Send you important notifications (updates, hydration reminders if enabled)
We NEVER sell your data to third parties.
4. Storage and Security
- Hosting: Supabase (Europe - GDPR compliant)
- Encryption: TLS/SSL for transmissions, encryption at rest
- Access: Limited to authorized developers only
- Retention: As long as your account is active
5. Your Rights (GDPR)
You have the right to:
- Access your data
- Correct your data
- Delete your data (see https://cagoutte.app/delete)
- Export your data (Premium feature)
- Object to processing
- File a complaint with your local data protection authority
6. Data Sharing
We only share your data with:
- Supabase (secure hosting)
- OpenAI (AI assistant - anonymized data)
- Apple/Google (subscription management)
No data is shared for advertising purposes.
7. Cookies and Tracking
The mobile app does NOT use cookies. The cagoutte.app website only uses essential cookies (authentication).
8. Minors
The app is intended for adults (18+). We do not knowingly collect data from minors.
9. Changes
We may update this policy. Significant changes will be notified by email.
10. Contact
For any questions about your data:
Email: support@cagoutte.app
We are committed to responding to all your requests within 30 days in accordance with GDPR.