Privacy
Policy
In accordance with the General Data Protection Regulation (GDPR) and applicable French data protection law.
Introduction
Protecting your privacy is an absolute priority for Nolan Essertaize EI. This Privacy Policy aims to inform you clearly, transparently and comprehensively about how we collect, use, share and protect your personal data when you use the KnowIt mobile application, in compliance with the GDPR and the French Loi Informatique et Libertés.
1. Identity of the Data Controller
The controller of personal data collected through the Application is Nolan Essertaize, operating as a sole trader (Entrepreneur Individuel — EI).
Registered address
72 Rue Marc Chagall, 26500 Bourg-lès-Valence, France
Contact
[email protected]SIRET (French business ID)
97823214800020
EU VAT number
FR62978232148
2. Categories of Data Collected and Purposes
Account Data
Data: First name, last name, email address, password (hashed and secured).
Purpose: Account creation, secure authentication, user relationship management, cross-device sync.
Legal basis: Performance of contract (accepted Terms of Use).
Learning Data (User-generated Content)
Data: Texts and topics entered to generate flashcards, revision statistics, success scores, usage frequency.
Purpose: Delivering the core educational service, spaced repetition algorithms, personalised learning experience.
Legal basis: Performance of contract.
Technical & Navigation Data
Data: IP address, device model, OS version, connection logs, crash reports.
Purpose: Backend infrastructure security, fraud prevention, technical diagnostics, performance optimisation.
Legal basis: Legitimate interest in ensuring the security and proper functioning of the service.
Audio Data (Voice Recordings)
Data: Audio recordings captured via your device's microphone when you use the voice analysis feature of the Application.
Purpose: Transmitting your recording to OpenAI Whisper to automatically generate a transcription and a personalised AI analysis in the form of flashcards.
Legal basis: Your explicit consent, collected before any microphone activation.
Retention: Raw audio is not stored after processing. Only the generated analysis is retained.
3. Data Retention Periods
Account & Learning Data
Retained for the entire duration your account is active. After 2 years of continuous inactivity, a warning will be sent. Without a response, the account will be deleted.
Technical Data & Logs
Retained for a maximum of 12 months, in accordance with CNIL recommendations and applicable security traceability obligations.
Audio Data
Audio recordings are deleted immediately after processing by OpenAI Whisper. Only the generated analysis is retained, subject to the same rules as Learning Data.
4. Data Sharing and Recipients
We formally commit to never selling, renting or commercialising your personal data to third parties for advertising purposes. Access to your data is strictly limited to:
The data controller (the Publisher).
Our technical sub-processor OVHcloud (backend hosting provider, 2 rue Kellermann, 59100 Roubaix, France), bound by strict confidentiality and security obligations.
OpenAI, L.L.C. (3180 18th Street, San Francisco, CA 94110, USA) for processing audio recordings via its Whisper service. OpenAI processes this data in accordance with its own privacy policy and is subject to Standard Contractual Clauses (SCCs) ensuring an adequate level of protection for transfers outside the European Union.
Your data is hosted on servers located in France / the European Union.
5. Security of Your Personal Data
We implement state-of-the-art technical and organisational measures to protect your data against alteration, accidental loss, or unauthorised access.
TLS
HTTPS / TLS
Encrypted communications
SHA
Cryptographic hashing
Secured passwords
IAM
Access control
Strict policies
6. Your Rights under GDPR
In accordance with applicable regulations, you have full control over your data. You may exercise the following rights at any time:
Access & Rectification
View and edit your information directly from your account settings in the Application.
Erasure (Right to be forgotten)
An account deletion button is available directly in the Application. Activating it results in the irreversible deletion of your personal data.
Restriction & Objection
You may object to certain processing based on our legitimate interest.
Portability
Retrieve your learning data in a structured, machine-readable format via the export feature in settings.
To exercise these rights or for any question relating to this policy:
[email protected]We commit to responding within one month. If you believe, after contacting us, that your rights are not being respected, you may lodge an official complaint with the CNIL (French data protection authority).