Privacy Policy
1. Data Controller
The data controller for personal data collected via the TAMSIV application and the tamsiv.com website is:
- Publisher: TAMSIV — Personal project
- Address: [To be completed]
- Email: contact@tamsiv.com
2. Personal Data Collected
2.1 Account Data
During registration and use of the Service:
- Email address (required for account creation)
- First and last name
- Phone number (optional)
- Postal address (optional)
- Profile picture (optional)
2.2 User-Generated Content
- Tasks, memos, and calendar events (title, description, dates, priority)
- Attachments (photos, videos, PDF documents)
- Comments and reactions
- Groups created and participations
2.3 Data Related to the Voice Assistant
- Voice audio: transmitted in real-time for transcription, not stored after processing
- Text transcription: used for conversation with AI
- Chat history: limited to 20 messages, not retained between sessions
2.4 Usage Data
- Activity statistics (gamification: points, levels, badges)
- Notification and navigation preferences
- Subscription type and usage quotas
2.5 Analytical Data (website and app)
- Anonymized usage events (pages visited, main actions)
- Session data (via Google Analytics 4, subject to your consent on the website)
3. Purposes and Legal Basis for Processing
| Purpose | Legal Basis (RGPD) |
|---|---|
| Service Provision (task management, memos, calendar) | Contract performance (Art. 6.1.b) |
| User account creation and management | Contract performance (Art. 6.1.b) |
| Voice assistant and transcription | Contract performance (Art. 6.1.b) |
| AI image generation | Contract performance (Art. 6.1.b) |
| Push notifications | Consent (Art. 6.1.a) |
| Usage analysis and Service improvement | Legitimate interest (Art. 6.1.f) |
| Analytical cookies (website) | Consent (Art. 6.1.a) |
| Paid subscription management | Contract performance (Art. 6.1.b) |
4. Sub-processors and Data Recipients
Your data may be transmitted to the following providers, strictly within the scope of Service operation:
| Provider | Service | Data Concerned | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All account data and content | EU (Paris, France) |
| OpenRouter | AI language model (conversations) | Voice transcription, conversation context | United States |
| Deepgram | Voice transcription (speech-to-text) | Real-time voice audio (not stored) | United States |
| OpenAI | Text-to-speech synthesis | AI response text to be vocalized | United States |
| Google (Gemini) | AI image generation | Text descriptions (prompts) | United States |
| Firebase (Google) | Push notifications, analytics | Device token, usage events | United States |
| Google Play / App Store | Payments and subscriptions | Transactions (managed by the platform) | United States / Ireland |
| Vercel | Website hosting | Website access logs | United States |
Your data is never sold to third parties. It is exclusively used for the operation of the Service.
5. Data transfers outside the European Union
Some of our providers are located in the United States (see table above). These transfers are governed by:
- The EU-US Data Privacy Framework (European Commission adequacy decision of July 10, 2023) for certified providers
- Standard Contractual Clauses (SCCs) adopted by the European Commission for other providers
Your main data (account, content, files) remains hosted in France (Paris) with Supabase. Only data necessary for AI processing and notifications is transferred to the United States.
6. Retention period
| Data type | Retention period |
|---|---|
| Account data (profile) | Until account deletion by the user |
| Content (tasks, memos, events) | Until deletion by the user or account deletion |
| Files (photos, videos, documents) | Until deleted by the user or account |
| Voice audio | Not retained (processed in real-time then deleted) |
| AI conversation history | Session duration only (max. 20 messages) |
| Analytical data | 14 months (Google Analytics) |
| Billing data | Managed by Google Play / App Store according to their policies |
7. Your Rights
In accordance with the RGPD (EU Regulation 2016/679), you have the following rights:
- Right of access (Art. 15): to obtain confirmation that your data is being processed and to receive a copy thereof
- Right to rectification (Art. 16): to correct inaccurate or incomplete data
- Right to erasure (Art. 17): to request the deletion of your data. You can also reset your account directly from the app
- Right to data portability (Art. 20): to receive your data in a structured, machine-readable format
- Right to object (Art. 21): to object to processing based on legitimate interest
- Right to restriction of processing (Art. 18): to request the restriction of processing in certain cases
- Withdrawal of consent: you can withdraw your consent at any time for processing based on it (notifications, analytical cookies)
To exercise your rights, please contact us at: contact@tamsiv.com
We commit to responding within 30 days in accordance with the RGPD.
In case of an unresolved dispute, you can lodge a complaint with the competent supervisory authority:
- France : CNIL — www.cnil.fr
- Germany : BfDI — www.bfdi.bund.de
- Or any other data protection authority in your country of residence within the EU
8. Data Security
We implement the following technical and organizational measures:
- Encrypted connections via HTTPS/TLS
- Secure authentication using JWT (JSON Web Tokens)
- Database-level security policies (Row Level Security)
- Rate limiting to prevent abuse
- No plain-text password storage (management delegated to Supabase Auth)
- No storage of banking data (payments handled by app stores)
9. Protection of Minors
The Service is intended for individuals aged 16 and over. For users under 16, consent from a legal guardian is required in accordance with GDPR.
If we discover that a minor under 16 is using the Service without parental consent, we reserve the right to delete their account.
10. Cookies
For more information on the cookies used on the website, please consult our cookie policy.
11. Changes to this Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. In the event of substantial changes, we will notify you via the app or by email. The date of the last update is indicated below.
Last updated: February 2026