Privacy Policy
Last updated : 19 May 2026 — Version 1.0
This English translation is provided for convenience. The French version (Politique de confidentialité) is the legally binding text under French law.
1. Introduction
Germe d'histoires attaches particular importance to the protection of personal data, in particular that of children. This policy describes — transparently — the data we collect, why we collect it, how long we retain it and how you can exercise your rights.
It complies with the General Data Protection Regulation (GDPR — EU 2016/679), the French Data Protection Act, the CNIL guidance on minors ("GDPR-K"), and — for US users — the Children's Online Privacy Protection Act (COPPA).
2. Data controller
The data controller is the Platform's publisher, whose details are in our Legal notice.
DPO / Data protection contact: privacy@germedhistoires.fr.
3. Principles
- Minimisation — we only collect what is strictly necessary.
- No behavioural advertising and no data sold.
- No child data used to train third-party AI models.
- Primary hosting in the European Union.
- Encryption of passwords (bcrypt 12 rounds), reset tokens and refresh tokens (SHA-256).
4. Data we collect
4.1 Parent account
- Email, hashed password, first name (optional).
- Notification preferences.
- Purchase history (amount, date, Stripe id — never card number).
4.2 Child profiles
- First name or pseudonym, age or age band, avatar from a catalogue.
- Interests declared by the parent (recommendations and AI personalisation).
- Reading history (books read, favourites).
No biometric data, no address, no phone number and no geolocation is collected for children.
4.3 Partner authors
- Legal name, SIRET, legal form, Stripe Connect account id.
- Strictly necessary data for remuneration and invoicing.
4.4 Technical data
- Connection logs (truncated IP, timestamp) — for security.
- Expo Push tokens — for notifications, deleted on logout.
- Error and crash data (Sentry, anonymised) — opt-in.
5. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Parent account creation and management | Contractual performance (art. 6.1.b GDPR) | Account duration + 30 days |
| Child profile creation and personalisation | Parental consent (art. 8 GDPR; COPPA verifiable parental consent) | Same as Parent account |
| Personalised AI story generation | Contractual performance | Prompt not retained beyond generation time |
| Payment and fraud prevention | Contractual + legal obligation | 10 years (accounting) |
| Push notifications | Consent (art. 6.1.a) | Until revocation or unsubscription |
| Transactional emails (confirmation, reset) | Contractual performance | 3 years after last contact |
| Anonymised audience measurement | Legitimate interest / consent (web) | 13 months max |
| Security (logs) | Legitimate interest | 12 months |
| Partner author accounting | Legal obligation | 10 years |
6. COPPA compliance — US users
For children under 13 residing in the United States:
- No data is collected directly from the child.
- The account is mandatorily created and managed by a parent who provides verifiable parental consent (checkbox + Stripe payer identity verification on purchase or email confirmation).
- The parent can, at any time, view, correct or delete the child's data.
- No child data is shared with third parties for advertising purposes.
7. GDPR-K compliance — CNIL recommendations
In line with the CNIL's 2024 recommendations on minors, we apply:
- A dedicated child interface, without fine-grained behavioural data collection.
- No free chat, social sharing or geolocation features.
- Notices written in clear and accessible language.
- On-demand deletion, with no condition other than parent authentication.
8. Recipients and sub-processors
Your data is accessible to authorised Germe d'histoires teams and, to the strict extent necessary, to the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe Payments Europe Ltd | Payment processing and author Connect | EU (Ireland) |
| Mailjet (Sinch France) | Transactional emails | EU (France) |
| Expo (Push Notifications) | Mobile notifications routing | USA (Standard Contractual Clauses) |
| Cloudflare R2 / Amazon S3 | Media file storage | EU / SCC for USA |
| OpenAI, Mistral AI | AI story generation (no nominative child data) | EU (Mistral), USA (OpenAI — SCC) |
| ElevenLabs | TTS speech synthesis | USA (SCC) |
| Sentry | Error reporting (anonymised) | EU |
| Host (see legal notice) | Application hosting | EU |
Transfers outside the EU are governed by the European Commission's Standard Contractual Clauses (decision 2021/914). For OpenAI, Mistral and ElevenLabs, no nominative child data is transmitted: only the first name (or pseudonym), age band and interests are used for personalisation, without enabling identification.
9. Cookies and trackers (web only)
See our Cookie Policy for details and the management panel.
10. Push notifications (mobile)
On iOS and Android, sending notifications requires your explicit consent via the native system permissions. You can disable them at any time from the app or your device settings.
11. Your rights
Under articles 15 to 22 GDPR, you have the following rights:
- Access — obtain a copy of data concerning you or your children.
- Rectification — correct inaccurate information.
- Erasure — delete your account and all associated data (in-app: Settings → Delete my account).
- Restriction — limit data use in certain cases.
- Portability — receive your data in a structured format (JSON).
- Objection — object to processing based on legitimate interest.
- Consent withdrawal at any time (notifications, audience measurement).
- Post-mortem directives on what happens to your data after death.
To exercise these rights: privacy@germedhistoires.fr. We reply within 1 month maximum.
If, after contacting us, you consider that your rights are not respected, you may lodge a complaint with the CNIL: https://www.cnil.fr/fr/plaintes.
12. Security
We apply appropriate technical and organisational measures: end-to-end TLS encryption, password hashing (bcrypt 12 rounds), token rotation, sensitive access logging, principle of least privilege for teams, encrypted backups. In case of a data breach likely to entail a risk, we notify the CNIL within 72 hours and — if necessary — the persons concerned.
13. Minors — parental access
The parent may, at any time from their account: view each child profile's data, delete a profile, export the data, request full erasure.
14. Changes
Any substantial change to this policy will be notified by email or in-app notification at least 15 days before its effective date.
15. Contact
For any question: privacy@germedhistoires.fr.