Legal
Privacy policy
Last updated: October 4, 2026
We collect the minimum needed to run your account, your keys and your payments. We never sell personal data and never use it for advertising.
Data controller
Adrien Insights, 164 Rue des Mimosas, 83220 Le Pradet, France, is the controller of the processing described here. For any question or to exercise your rights: [email protected].
Data processed and purposes
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, account ID, language, sign-in links and sessions | Create the account, sign you in, write to you about the Service | Performance of the contract |
| API keys (only a fingerprint is kept, never the key), their name, rights, allowed IP addresses, creation, last use and revocation dates | Authenticate access to the API and the stream | Performance of the contract |
| Usage: open connections and subscriptions, request counts, compute and export volume | Enforce the limits of the plan, show your usage | Performance of the contract |
| Billing country, customer and subscription IDs at the payment provider, status of subscriptions and purchases | Sell the plans and grant the matching rights | Performance of the contract; accounting and tax obligations |
| Proof of the waiver of the right of withdrawal: account, email, plan, version and language of the text, date, IP address, browser (user agent) | Prove your request for immediate access | Legal obligation; legitimate interest (evidence) |
| Log of account operations (keys, plans) | Security, abuse prevention, handling your requests | Legitimate interest |
| Account events (sign-up, sign-in, key creation, payments, cancellation, first use of a key) linked to the account ID | Understand and improve the experience | Legitimate interest |
| Website analytics (next section) | Improve the website and account pages | Legitimate interest without cookie; consent with cookie |
We do not process your card details: you enter them directly with Stripe or Creem. We make no automated decision producing legal effects concerning you.
Analytics
We measure how the website and account pages are used: pages viewed, steps completed, errors encountered. Measurement uses PostHog, hosted in the European Union; data goes through this website before being sent to PostHog.
- Without your consent, measurement is anonymous and cookie-free: no identifier is stored in your browser, only your choice. Your visits are not linked to each other from one day to the next, nor to your account.
- With your consent, a first-party cookie, valid for at most 13 months, links your visits and, when you are signed in, your account (by its ID, never by your email address).
In both cases, no session is recorded and what you type in form fields is never collected. Your API keys are never sent.
Change your choice
Retention periods
| Data | Period |
|---|---|
| Account, keys, usage, log of operations | As long as the account exists; deleted within 30 days of its closure. An account with no sign-in and no key use for 3 years is closed after a warning email |
| Sign-in links and sessions | Until they expire; an expired link is deleted one day later |
| Payments, subscriptions, purchases | 10 years from the end of the financial year (accounting obligation) |
| Proof of the waiver of the right of withdrawal | Duration of the contract, then 5 years (limitation period) |
| Analytics | At most 25 months; cookie: at most 13 months |
Recipients
Your data is only accessible to the people at Adrien Insights who need it, and to our service providers, within the limits of their task:
| Provider | Role | Location |
|---|---|---|
| Railway Corporation | Hosting of the website, the API and the database | United States |
| Cloudflare, Inc. | Content delivery network and protection of the website | Worldwide |
| Brevo SAS | Sending emails (sign-in links, service messages) | European Union |
| PostHog, Inc. | Analytics and account events | European Union |
| Stripe Payments Europe, Limited | Payments from France | European Union |
| Creem (Armitage Labs OÜ) | Reseller and payments outside France | European Union |
Stripe and Creem also process payment data on their own behalf (fraud prevention, legal obligations), under their own privacy policies. Creem, as reseller of the plan outside France, is the controller of the processing related to that sale.
We may disclose data when the law or an authority requires it.
Transfers outside the European Union
Railway and Cloudflare process data in the United States. These transfers are covered by the standard contractual clauses of the European Commission and, for certified companies, by the EU–US Data Privacy Framework. You can get a copy by writing to us.
Security
Traffic is encrypted (HTTPS, WSS). API keys and sign-in links are only stored as fingerprints. The computing services and the database are not exposed to the Internet. Access to data is limited to the people who need it.
Your rights
You have the right to access, rectify and erase your data, to restrict its processing, to data portability, and to object to processing based on our legitimate interest. When processing relies on your consent, you may withdraw it at any time, without affecting the lawfulness of prior processing. You may also set instructions on what happens to your data after your death.
To exercise these rights, write to [email protected] from the address of your account. We answer within one month.
If you believe your rights are not respected, you may lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with the data protection authority of your country.
Minors
The Service is reserved for adults. We do not knowingly collect data about minors.
Changes
We may change this policy. The date of the current version is shown at the top of the page; a substantial change is notified to you by email.