Privacy Policy
1. Who is responsible for your data?
The data controller is , , SIRET , (“we”), publisher of the Hemera app (the “App”).
For any question about your data or to exercise your rights: .
2. The data we process
We only process the data needed to run the App:
- your account: your email address, an account identifier, the sign-in method you chose (email link, Apple or Google), your first name (required) and your last name (optional). Apple and Google may send us your name and email address when you allow it; Apple may offer you a relay address that hides your real one;
- your preferences: the topics you chose, whether you receive the fact of the day shared by everyone;
- your activity: the facts you open (with the date and where from: personal fact of the day, shared fact of the day, or catalogue browsing), the facts of the day assigned to you, the facts you share (one record per fact, without knowing with whom or by what means you share it), your streaks and your badges;
- the messages you send us from “Help and contact” or “Report a mistake”: your message, its category, the fact concerned if any, your account identifier, the App version and your platform (iOS or Android), without your email address;
- technical data: your sign-in token, kept on your phone, and the connection logs (including your IP address) that our host processes for security and proper operation of the service;
- advertising data: the App shows one banner ad on a fact page, served by Google AdMob. To serve it, Google may process your phone’s advertising identifier, your IP address, information about your device (model, system, language) and your interactions with the ad. We send them neither your account, nor your email address, nor your activity in the App.
On your phone, the App also keeps your appearance choice (light or dark) and, when offline, the list of actions to send once the network is back.
We do not collect your location, contacts, photos, microphone or camera. We use no audience measurement or usage analytics tool. Only advertising (see above) involves an advertising identifier, and only with your agreement where the law or your phone requires it.
3. Why, and on what legal basis
- to provide the App: create and manage your account, choose your fact of the day from your topics, record what you have read, compute your streaks and badges, keep your devices in sync. Basis: performance of the contract formed by the terms of use (article 6(1)(b) GDPR);
- to read your messages, fix the mistakes reported and improve the App. Basis: our legitimate interest in running and improving the service (article 6(1)(f));
- to secure the service and prevent abuse: technical logs, access limits. Basis: our legitimate interest in protecting the App and its users (article 6(1)(f));
- to show advertising, which funds the App. Basis: your consent, asked at first launch in the European Economic Area, the United Kingdom and Switzerland (consent form) and, on iPhone, through Apple’s tracking permission prompt. You can change it at any time (see “Your rights”);
- to meet our legal obligations, for example answering a request from an authority. Basis: article 6(1)(c).
Choosing your fact of the day from your topics is a simple automated selection. It has no legal effect on you and does not significantly affect you.
4. Who receives your data?
We do not sell or rent your data. It is only accessible to the Publisher and to the providers who help us run the App, within what they need:
- Supabase, our database, authentication and server-function provider;
- Supabase, which hosts the servers;
- Apple and Google, when you sign in with their service (Sign in with Apple, Google Sign-In): their own privacy policies apply to that sign-in;
- Google (Google AdMob), which serves the advertising and acts as a controller for its own purposes (targeting, fraud prevention, measurement); its policy is available at policies.google.com/technologies/partner-sites;
- the app stores (App Store, Google Play) for downloading the App and, if any, purchases.
When you share a fact, the text, link and image are passed by your phone’s sharing feature to the app you choose; we have no access to it. The link only contains the fact’s identifier, never personal data.
We may finally disclose data to an authority where the law requires us to.
5. Transfers outside the European Union
Some providers (in particular Apple and Google, including for advertising) may process data outside the European Economic Area, notably in the United States. These transfers rely on a European Commission adequacy decision (including the EU–US Data Privacy Framework) or on the Commission’s standard contractual clauses.
Where our servers are hosted: Supabase ().
6. How long we keep it
- your account data, preferences and activity: as long as your account exists;
- when you delete your account (Profile, Settings, “Delete my account”): it is erased from our database right away; the technical backups that contain it are overwritten within ;
- your messages to the developer: ; they are deleted with your account;
- technical logs: ;
- if the law requires us to keep some information (for example to answer an authority), it is kept for the time required, then deleted.
7. Your rights
You have the following rights over your data:
- access: know whether we process data about you and get a copy;
- rectification: have your information corrected by writing to us;
- erasure: delete your account and data from the App, or by writing to us;
- restriction and objection: ask to restrict a processing or object to it for reasons relating to your situation, when it rests on our legitimate interest;
- portability: receive the data you gave us in a structured, commonly used format;
- post-mortem directives: decide what happens to your data after your death.
To exercise a right, write to . We answer within one month, which can be extended by two months for a complex request. We may ask you to prove your identity if there is doubt.
If you believe your rights are not respected, you may lodge a complaint with the CNIL (Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, cnil.fr) or with the data protection authority of your country of residence.
8. Security
Exchanges between the App and our servers are encrypted. Each account can only reach its own data: the access rules of our database enforce it. We limit access to production data to the people who need it. No system is infallible; in case of a data breach that presents a risk to you, we tell you and inform the CNIL as the law provides.
9. Minors
The App is meant for people aged 15 and over. If you are under 15, you may only use it with the permission of a holder of parental authority. If we learn that an account was created without it, we delete it.
10. Cookies and trackers
The App uses no cookie or audience-measurement tool. Google’s advertising kit may use your phone’s advertising identifier and similar technologies to serve and measure ads, subject to your consent. The App also stores on your phone what it needs to work: your session, your appearance choice, your ad consent choice and the actions waiting to be sent.
11. Changes to this policy
We may update this policy, for example if the App changes. The date of the last update is at the top of the page. When a change is significant, we tell you in the App.
12. Contact
— —