TextCalm AI — last updated: September 24, 2026
This policy explains how Thibault Demars ("we") processes personal data in connection with the TextCalm AI application, including under the EU General Data Protection Regulation (GDPR).
Thibault Demars, French sole trader (SIRET 840 556 914 00025) — 59 rue de Ponthieu, Bureau 326, 75008 Paris, France.
Privacy contact: support@textcalm.app
| Data | Purpose | Legal basis |
|---|---|---|
| Messages and screenshots submitted for analysis, which may contain data about the user or other people | Transcribe screenshots and generate the requested AI analysis | Performance of the requested service; explicit consent where submitted content reveals sensitive data |
| Local preferences, such as display name, intention and empathy setting | Personalise the application and its analyses | Performance of the service |
| Journal and reflection history stored on the device | Display the user's history and trends | Performance of the service |
| Pseudonymous app usage data, including viewed screens, technical actions, app/device version and a pseudonymous identifier | Measure usage and improve the product. Messages, onboarding answers, intentions, moods and reflections are excluded. | Optional consent, withdrawable at any time |
| Subscription status and purchase identifier | Provide and restore Premium access | Performance of the subscription contract |
| Installation-integrity identifier, public key and signature counter | Prevent abuse and verify that requests originate from the official application | Legitimate interest in securing the service |
Providers are grouped by purpose. Each one processes only the data listed for it.
| Microsoft Azure (Azure AI Foundry) | |
|---|---|
| Role | Transcribes submitted screenshots and generates the requested analysis; applies Microsoft's safety and abuse-prevention controls. The models run on Microsoft infrastructure: submitted content is not shared with the model publishers and is not used to train models. |
| Data | Submitted message text and screenshots |
| Location | European Union (Azure EU Data Zone; resource located in Sweden Central) |
| Privacy | Data, privacy and security · Microsoft Privacy Statement |
| PostHog | |
|---|---|
| Role | Pseudonymous usage analytics |
| Data | Viewed screens, technical actions, app, device and OS version, language, time zone, pseudonymous identifier. No IP-based location, no user profile. |
| Location | European Union |
| Privacy | PostHog Privacy Policy |
| RevenueCat | |
|---|---|
| Role | Subscription and entitlement management |
| Data | Pseudonymous app user identifier, purchase and subscription status, store receipts |
| Location | United States |
| Privacy | RevenueCat Privacy Policy |
| Apple / Google | |
|---|---|
| Role | Store payment and purchase processing, as independent controllers |
| Data | Store account and payment data, handled by the store; we do not receive your payment details |
| Location | According to the user's store region and the provider's terms |
| Privacy | Apple Privacy Policy · Google Privacy Policy |
| Expo / EAS | |
|---|---|
| Role | Hosting and operation of the application's API; submitted content passes through it in transit to Microsoft Azure and is not stored |
| Data | Requests to the analysis service, technical request metadata |
| Location | According to the configured service region and contract |
| Privacy | Expo Privacy Policy |
| Upstash | |
|---|---|
| Role | Storage required for application attestation |
| Data | Installation-integrity identifier, public key and signature counter |
| Location | According to the configured region |
| Privacy | Upstash Privacy Policy |
Where a provider processes personal data outside the European Economic Area, the transfer relies, depending on the provider and destination, on an adequacy decision or the European Commission's Standard Contractual Clauses. You may request information about the applicable safeguards using the privacy contact above.
Subject to applicable law, you may have rights of access, correction, deletion, restriction, objection and data portability, as well as the right to withdraw consent without affecting prior lawful processing.
Most journal, preference and onboarding data remains on the device. It can be erased through Help & Safety → Delete my data or by uninstalling the application.
PostHog and RevenueCat data is associated with pseudonymous technical identifiers. The in-app deletion control erases local data and resets the PostHog identifier on the device. To request deletion of data already received by a provider, contact support@textcalm.app and include the relevant identifier or store receipt if available.
Requests are free of charge. We answer as soon as possible and within one month of receipt; this period may be extended by two further months for complex requests, in which case we will tell you within the first month. We may ask for information needed to identify the data concerned.
You may also lodge a complaint with the French data-protection authority, the CNIL, or with the competent supervisory authority in your country.
Communications with the analysis service are encrypted in transit using TLS. Access to systems is restricted to authorised persons and providers requiring access for their role.
TextCalm AI is not intended for children under 16. If you are a parent or guardian and believe a child has submitted personal data without the required authorisation, contact us to request deletion.
We may update this policy. The date above identifies the latest revision, and material changes will be communicated in the application where required.