Privacy Policy

TextCalm AI — last updated: September 24, 2026

This policy explains how Thibault Demars ("we") processes personal data in connection with the TextCalm AI application, including under the EU General Data Protection Regulation (GDPR).

Summary

1. Data controller

Thibault Demars, French sole trader (SIRET 840 556 914 00025) — 59 rue de Ponthieu, Bureau 326, 75008 Paris, France.
Privacy contact: support@textcalm.app

2. Data, purposes and legal bases

DataPurposeLegal basis
Messages and screenshots submitted for analysis, which may contain data about the user or other peopleTranscribe screenshots and generate the requested AI analysisPerformance of the requested service; explicit consent where submitted content reveals sensitive data
Local preferences, such as display name, intention and empathy settingPersonalise the application and its analysesPerformance of the service
Journal and reflection history stored on the deviceDisplay the user's history and trendsPerformance of the service
Pseudonymous app usage data, including viewed screens, technical actions, app/device version and a pseudonymous identifierMeasure usage and improve the product. Messages, onboarding answers, intentions, moods and reflections are excluded.Optional consent, withdrawable at any time
Subscription status and purchase identifierProvide and restore Premium accessPerformance of the subscription contract
Installation-integrity identifier, public key and signature counterPrevent abuse and verify that requests originate from the official applicationLegitimate interest in securing the service

3. What we do not do

4. Service providers

Providers are grouped by purpose. Each one processes only the data listed for it.

AI analysis

Microsoft Azure (Azure AI Foundry)
RoleTranscribes submitted screenshots and generates the requested analysis; applies Microsoft's safety and abuse-prevention controls. The models run on Microsoft infrastructure: submitted content is not shared with the model publishers and is not used to train models.
DataSubmitted message text and screenshots
LocationEuropean Union (Azure EU Data Zone; resource located in Sweden Central)
PrivacyData, privacy and security · Microsoft Privacy Statement

Usage measurement (only with consent)

PostHog
RolePseudonymous usage analytics
DataViewed screens, technical actions, app, device and OS version, language, time zone, pseudonymous identifier. No IP-based location, no user profile.
LocationEuropean Union
PrivacyPostHog Privacy Policy

Subscriptions and payments

RevenueCat
RoleSubscription and entitlement management
DataPseudonymous app user identifier, purchase and subscription status, store receipts
LocationUnited States
PrivacyRevenueCat Privacy Policy
Apple / Google
RoleStore payment and purchase processing, as independent controllers
DataStore account and payment data, handled by the store; we do not receive your payment details
LocationAccording to the user's store region and the provider's terms
PrivacyApple Privacy Policy · Google Privacy Policy

Infrastructure and security

Expo / EAS
RoleHosting and operation of the application's API; submitted content passes through it in transit to Microsoft Azure and is not stored
DataRequests to the analysis service, technical request metadata
LocationAccording to the configured service region and contract
PrivacyExpo Privacy Policy
Upstash
RoleStorage required for application attestation
DataInstallation-integrity identifier, public key and signature counter
LocationAccording to the configured region
PrivacyUpstash Privacy Policy

Where a provider processes personal data outside the European Economic Area, the transfer relies, depending on the provider and destination, on an adequacy decision or the European Commission's Standard Contractual Clauses. You may request information about the applicable safeguards using the privacy contact above.

5. Retention

6. Your rights

Subject to applicable law, you may have rights of access, correction, deletion, restriction, objection and data portability, as well as the right to withdraw consent without affecting prior lawful processing.

Most journal, preference and onboarding data remains on the device. It can be erased through Help & Safety → Delete my data or by uninstalling the application.

PostHog and RevenueCat data is associated with pseudonymous technical identifiers. The in-app deletion control erases local data and resets the PostHog identifier on the device. To request deletion of data already received by a provider, contact support@textcalm.app and include the relevant identifier or store receipt if available.

Requests are free of charge. We answer as soon as possible and within one month of receipt; this period may be extended by two further months for complex requests, in which case we will tell you within the first month. We may ask for information needed to identify the data concerned.

You may also lodge a complaint with the French data-protection authority, the CNIL, or with the competent supervisory authority in your country.

7. Security

Communications with the analysis service are encrypted in transit using TLS. Access to systems is restricted to authorised persons and providers requiring access for their role.

8. Children

TextCalm AI is not intended for children under 16. If you are a parent or guardian and believe a child has submitted personal data without the required authorisation, contact us to request deletion.

9. Changes

We may update this policy. The date above identifies the latest revision, and material changes will be communicated in the application where required.

Version française