Privacy policy
Last updated: Aug 16, 2026
This document is a complete template. Bracketed entries must be filled in and the text reviewed by legal counsel before publication.
Data controller
[LEGAL ENTITY], [FULL ADDRESS], is the controller of data collected by Elorise. For any question: [DPO OR CONTACT EMAIL].
Data collected
We collect: your email address and first name (account and personalisation); your exercise, game and assessment results (progress); the facts the coach remembers about you (preferences, goals, weak spots, tips given); your conversations with the coach; minimal technical operating data. No banking data is stored by us: payments are handled by Stripe.
Purposes and legal bases
Your data is used solely to provide the service: assess your level, build your plan, personalise coaching, manage your subscription. The legal basis is performance of the contract between us. Usage measurement relies on your consent, collected separately and revocable at any time.
The coach and artificial intelligence
Dialogue with the coach is processed by the OpenAI API. Only the necessary context is transmitted: your first name, your progress profile, the coach memory and the current step. No other user's data is ever transmitted. These contents are not used to train models.
Retention
Your data is kept while your account is active, then [RETENTION PERIOD] after deletion for accounting obligations. Coach memory can be erased at any time from your settings, with no delay.
Recipients
Our processors are: Supabase (data hosting), Vercel (application hosting), OpenAI (coach dialogue), Stripe (payments), [EMAIL PROVIDER] (transactional emails), PostHog (usage measurement, after consent only). No data is sold or transferred.
Your rights
You have rights of access, rectification, erasure, restriction, objection and portability. A full export of your data and deletion of your account are available immediately in your settings. For any other request: [DPO OR CONTACT EMAIL]. You may lodge a complaint with the CNIL.
Security
Data access is partitioned per user at the database level. API keys are server-side only. Exchanges are encrypted in transit.