Privacy policy
Last updated: 15 July 2026
Philoscopia (www.philoscopia.com) is built on a local-first principle: privacy is a design choice here, not mere compliance. This policy describes what data is processed, why, how long it is kept, and how to exercise your rights. It applies to the site, the app (web and mobile) and the associated services.
Your philosophical profile never leaves our servers, because it never reaches them: it is stored on your device. If you create an account, the only data the server holds about you is a credit balance. The server knows your balance, never your profile.
1. Data controller
The data controller is the publisher of Philoscopia, whose details appear in the legal notice.
For any question about your personal data: contact@philoscopia.com.
2. Data processed and purposes
2.1 Public site and encyclopedia
Browsing the public site requires no account. No personal data is collected for mere navigation, except anonymous audience statistics via Vercel Analytics: this tool sets no cookies, collects neither a clear-text IP address nor a persistent identifier, and aggregates only anonymised measurements.
Alongside these, anonymous usage counters serve one purpose only: telling whether the app's features are used at all — a visit, a questionnaire opened, a journey finished, an entry added to the notebook. The server records nothing but a daily total per kind of gesture. It receives no retained IP address, no session or device identifier and no page address, and it never learns which axis, which figure or which journey was involved. These totals cannot be traced back to a person or to a profile, and so are not personal data. Your answers and your profile, for their part, are never transmitted. You can switch these counters off in the advanced settings of your personal area.
Your preferences (theme, language) and your discovery profile are stored locally in your browser (IndexedDB, localStorage) and are never transmitted.
2.2 Personal profile (self-profiling)
Your answers to questions, your computed profile, your notebook and your notes are stored on your device (IndexedDB on the web, a local database on mobile). This data is not transmitted to the publisher unless you enable sync (see 2.5).
2.3 AI companion (“Philos”)
The companion runs in one of three regimes that you choose: credits (through our relay), your own key (BYOK, directly with OpenRouter, without going through our servers) or your own server (local inference).
In the credits regime, your messages transit through our relay to reach the model provider (OpenRouter and the underlying providers). Only the strict minimum is sent: what you confirm, never your whole profile. We do not keep the history of your conversations on our servers.
*Legal basis*: performance of the requested service.
2.4 Account (optional)
- Email and passphrase (stored only as a hash, never in clear text).
- Display name (optional).
- Creation date, credit balance and unlocked content.
*Purpose*: authentication, billing of credits, management of unlocked content. *Legal basis*: performance of the contract.
2.5 Sync (optional, zero-knowledge)
If you enable sync, your profile is encrypted on your device with a key derived from your passphrase, then stored on our servers as an encrypted blob we cannot read. We cannot decrypt it. Losing the passphrase makes that content unrecoverable.
2.6 Payments
Payments (credits, unlock, donations) are handled by Stripe. We never store your banking data; we receive only the payment confirmation and the transaction identifier. *Legal basis*: performance of the sales contract.
2.7 Email communications
We send transactional emails via Resend (address verification, passphrase reset, payment confirmation). No marketing email is sent without your explicit consent.
3. Sub-processors and recipients
Your data may be processed by the following sub-processors, all contractually bound to comply with the GDPR:
- Vercel Inc. (USA) — hosting of the site and API, anonymised statistics; transfers governed by the standard contractual clauses.
- Neon Inc. (EU) — database.
- Stripe Inc. (USA / Ireland) — payment processing; transfers governed by standard contractual clauses.
- Resend Inc. (USA) — transactional emails.
- OpenRouter — access to AI models; requests include neither your email nor your identifier.
No data is sold to third parties, nor used for advertising.
4. Retention periods
- Account and associated data: as long as the account is active; deletion on request at any time (see §6) or after 3 years of complete inactivity.
- Encrypted sync blob: as long as the account is active.
- Verification and reset codes: 1 hour maximum.
- Session tokens: renewed on use, 30 days.
- Invoices and payment data: 10 years (French accounting obligation).
- Technical logs and anonymised statistics: 13 months maximum.
- Anonymous usage counters: kept indefinitely, being daily totals that identify no one.
5. Cookies and trackers
The site uses no advertising cookies and no third-party trackers, and no consent banner is required: Vercel Analytics works without cookies or persistent identifiers, and the site stores only your preferences, your profile and the marker described below locally, with no personal data tied to an identifier.
The anonymous usage counters rely on a marker kept in your browser's local storage: a plain date, used to count you at most once a day per device. It is not an identifier — it cannot recognise you, and cannot follow you from one site to another. You can decline it in the advanced settings.
Stripe may set strictly necessary cookies during a payment (anti-fraud, payment session). See the Stripe policy.
6. Your rights
Under the GDPR, you have the following rights:
- Right of access: obtain a copy of the data concerning you.
- Right to rectification: correct inaccurate information.
- Right to erasure: deleting the account erases the associated server-side data (balance, sync blob). Your local data is erased by clearing the app's data on your device.
- Right to portability: receive your data in a structured format.
- Right to object and to restrict processing.
- Right to withdraw your consent at any time.
- Right to set post-mortem directives on the fate of your data.
To exercise any of these rights, write to contact@philoscopia.com. A reply will be provided within 1 month (extendable by 2 months for complex requests).
If, after contacting us, you consider that your rights are not respected, you may lodge a complaint with the French data-protection authority (CNIL): www.cnil.fr/en/plaints.
7. Security
- Passphrase stored as a hash, never in clear text.
- Encrypted HTTPS connections (TLS) across the whole site and API.
- Client-side encryption for sync (zero-knowledge).
- Restricted and logged database access.
As no system is infallible, in the event of a data breach likely to create a risk to your rights, we will inform you within 72 hours in accordance with article 34 of the GDPR.
8. Minors
Philoscopia is aimed at the general public. In accordance with article 8 of the GDPR, if you are under 16, creating an account requires the consent of a holder of parental authority. No minor's data is used for commercial or advertising profiling.
9. Changes to the policy
This policy may change. Any substantial modification will be signalled to you (by email if you have an account, or by a notice on the site). The last-updated date appears at the top of this page.
10. Contact
For any question about this policy or your data: contact@philoscopia.com.