Privacy
Privacy Policy
1. Data controller
The controller of personal data collected via Loe.me is LOECSEN, share capital 8 000 €, registered office 19 rue des Trois Bornes, 75011 Paris, France, 451 853 162 R.C.S. Paris, SIRET 451 853 162 00043, VAT FR18451853162.
Contact: contact@loecsen.com. Data-protection requests: dpo@loecsen.com.
2. Scope
This policy applies to the Loe.me website and services (learning-path generation, account, Pro subscription, embed widgets, and related communications). It describes the processing actually performed by our product architecture.
3. Data model (two layers)
- Collective knowledge: pattern caches (qualification verdicts, learned rules) with no user id, device id, or ritual id. These caches improve the service for all users.
- Personal / user-linked data: the ritual is the main anchor between you and your paths; authenticated account, soft-launch email, Stripe subscription, and export/erasure rights attach to that identity.
4. Categories of data
- Learning intent (free text) used to qualify and generate the path.
- Local pseudonymous identifier (loe.user.id), language preferences (UI / native locale), browser preferences.
- Account: email address (magic-link authentication), session (httpOnly cookie).
- Rituals and missions: intent, plan, generated content, cover image, status, technical metadata.
- Learning events: event type, learning object, score, duration, timestamps.
- Soft-launch: email and approval status (access list).
- Pro billing: payment data processed by Stripe (customer email, subscription status); LOECSEN does not store card numbers.
- Generated media: images (CDN storage), synthesized speech audio when applicable.
- Usage metrics, error diagnostics, and session replay via PostHog Cloud (EU region), only after consent (unless a documented forced-enable configuration for internal testing).
- Technical abuse-prevention / rate-limit logs (technical identifiers, hashed IP address or equivalent depending on configuration).
5. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the service (generation, ritual access, account) | Contract performance / pre-contractual steps |
| Pro subscription and billing | Contract performance |
| Security, abuse prevention, safety qualification | Legitimate interests; legal obligation where applicable |
| Pipeline improvement via collective non-identifying caches | Legitimate interests |
| Product analytics / session replay (PostHog) | Consent |
| Respond to authorities / accounting obligations | Legal obligation |
For Brazil (LGPD), equivalent bases include contract performance, consent, legitimate interests, and legal obligation. For Australia (Privacy Act / APPs), data are collected and used for the purposes above, as reasonably expected in providing the service.
6. Processors and recipients
- Vercel — application hosting
- Supabase — authentication and database
- Stripe — payments and billing portal
- PostHog Cloud EU — analytics, errors, session replay (after consent)
- Large-language-model providers — pedagogical content generation
- Cloudflare R2 / CDN — image storage and delivery
- Replicate / Stability — image generation
- Amazon SES / SendGrid — transactional email
- Voicemaker — text-to-speech
- YouTube Data API — video objects when applicable
- Upstash — rate limiting
These recipients act on our instructions (processors) or as independent controllers (e.g. Stripe for payments). An up-to-date list may be requested at dpo@loecsen.com.
7. International transfers
Processing may involve transfers outside the European Economic Area (notably certain LLM or payment providers). Where the GDPR applies, we rely on appropriate safeguards (EU Standard Contractual Clauses and/or provider mechanisms). PostHog is configured for the European region.
8. Retention
- Rituals: while you use them, then up to about 30 days after detach or deletion.
- Learning events: about 24 months.
- Non-identifying collective caches: retained for the useful life of the service.
- Abuse logs: about 90 days.
- Stripe billing data: per Stripe’s policy and applicable accounting obligations.
- Soft-launch / access email: while restricted access remains active, then purged per internal policy.
9. Security
We apply appropriate technical and organisational measures: encryption in transit (TLS), access control, environment separation, rate limiting, incident logging, and export/erasure processes. No system is risk-free; report incidents to contact@loecsen.com.
10. Rights — European Union, EEA and United Kingdom
You have rights including access, rectification, erasure, restriction, objection, portability, and withdrawal of consent (analytics) without affecting prior lawful processing. You may lodge a complaint with the CNIL (France) or your local supervisory authority.
- Export: Account or GET /api/me/export.
- Erasure / detach: Account or DELETE /api/me; Remove a ritual in the library.
- Analytics: Accept/Decline banner or Cookies page.
- Write to: dpo@loecsen.com
11. Rights — Brazil (LGPD)
If you are in Brazil, you have rights including confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about entities with which data are shared, information about refusing consent and consequences, and revocation of consent. Exercise via dpo@loecsen.com. You may contact the Autoridade Nacional de Proteção de Dados (ANPD).
12. Rights — Australia (Privacy Act / APPs)
If you are in Australia, you may request access to your personal information and correction of inaccurate information. Contact dpo@loecsen.com. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
13. Rights — California and United States
We do not sell your personal information and do not “share” it for cross-context behavioural advertising under the CCPA/CPRA. California residents may request to know categories of data collected, request deletion or correction, and exercise other rights under applicable law. Contact: dpo@loecsen.com. We will respond within statutory timelines after reasonable identity verification.
14. Other jurisdictions
In other countries (including Canada — PIPEDA and provincial laws), you may request access and correction, and object to certain processing where the law provides, via dpo@loecsen.com. Where regimes overlap, we apply the more protective standard that is reasonably practicable.
15. Automated processing and artificial intelligence
The service uses language models and automated systems to qualify an intent, generate a path, and produce pedagogical content. These processes are necessary to provide the service. They are not solely automated decisions producing legal effects within the meaning of GDPR Article 22; human-designed controls and safety gates apply. You may contest an outcome or request erasure through the channels above.
16. Minors
See the Minors Policy (/legal/minors). The service is primarily intended for persons aged 16 and over.
18. Changes
We may update this policy to reflect legal or product changes. The date at the top prevails. For material changes, we will publish the updated version on this page.
← Home · Terms · Cookies · Legal notice · Minors · Content rights