1. Data controller
The controller for the processing of your personal data is:
- SentinElles Association, a non-profit governed by the French law of 1 July 1901
- RNA: W751284130 (registered association; SIRET/SIREN being obtained)
- Registered office: WILLA, 6 rue du Sentier, 75002 Paris, France
- Publication director / legal representative: Luiza Drummond
- Personal-data contact: privacy@sentinellesapp.fr
Hosts. Data and services are hosted in the European Union on Google Cloud Platform (region europe-west1, Belgium), operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (+353 1 436 1000). The mobile app updates its content (OTA) via Expo, Inc. (Expo Application Services), 650 Castro Street, Suite 400, Mountain View, CA 94041, USA, and is distributed via the App Store (Apple Distribution International Ltd, Hollyhill Industrial Estate, Cork, Ireland) and Google Play (Google Ireland Limited).
This policy applies to the SentinElles mobile app, the website sentinellesapp.fr and all related services.
2. Data we collect
2.1 Data you provide
| Category | Examples |
|---|---|
| Account | Phone number — the only account identifier: no email is requested from app users. It is stored in two forms, never in clear: (1) a SHA-256 fingerprint (lookup, dedup, erasure) and (2) a reversible ciphertext protected by a Google Cloud KMS key that the API is not allowed to decrypt (isolated decryption, reserved for judicial requisitions — LCEN Art. 6-II). |
| Self-declaration | Declared belonging to women / gender minorities (a value from a closed list, never free text), gating access to the non-mixed space. The gender shown on the ID document is not checked. |
| Sponsorship | Single-use invitation code consumed at signup and the "invited by" link (chain of trust). |
| Identity verification | Verification outcome (verified / not) and Didit session id — see §9 bis. SentinElles neither receives nor stores any image or biometric template: this data is processed and retained by our processor Didit under its own policy (see §9 bis). |
| Posted content | Reports (category, description, zone), zone chat messages (ephemeral), direct messages between visible users (ephemeral), optional end-of-session mood note. |
| Waitlist (website) | Email, first name, profile type (user / partner / press / etc.) — collected on the website only, separate from the app account. |
The pseudonym shown in community spaces is deterministically derived from the device's technical identifier; it is validated to never contain an email, phone number or full name.
2.2 Data collected automatically
| Category | Description |
|---|---|
| Approximate location | Processed only during an active session you start. Before any storage, the position is degraded to a geographic cell (~150 m, never raw GPS). It powers zones, proximity alerts and, if you enable them, "I'm here" presence and route — shared only with the network you chose, never for advertising. Route geometry is never transmitted to another user. |
| Technical data | Device type, OS version, app version, system language, anonymized error logs |
| IP fingerprint | SHA-256 hash of the IP with private salt. Used for anti-spam. Raw IP is never stored. |
2.3 Data we never collect
- Position — your trajectory and presence are stored as degraded ~150 m cells, never as a precise trace; a precise position is only used transiently, in memory, for real-time alerting. Precise coordinates are kept only where the feature requires it — the point you report and, where applicable, the origin/destination of an itinerary — under short retention (see §4);
- Contacts, photos, microphone or sensors beyond what's strictly necessary (only with explicit permission and clear purpose);
- Advertising identifier — SentinElles has no ads, no third-party tracking pixels.
3. Purposes & legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Account creation and management | Performance of contract (Terms) |
| Display and alerts based on reported zones | Performance of contract |
| Content moderation, fraud and abuse prevention | Legitimate interest of SentinElles and other users |
| Production and valorization of aggregated, irreversibly anonymized statistics (mappings, research, institutional or private public-interest partnerships) | Legitimate interest + irreversible anonymization |
| Transactional emails (signup confirmation, major updates) | Performance of contract |
| Marketing emails / newsletters | Consent (dedicated, never pre-checked opt-in) |
| Legal obligations (judicial requests, unlawful content) | Legal obligation (LCEN, Code of Criminal Procedure) |
4. Retention periods
| Data | Period |
|---|---|
| Active account | As long as you use the app |
| Deleted account (your initiative) | Erased within 30 days, except legal-obligation data (connection logs: 1 year, LCEN Art. 6-II) |
| Positions (degraded cells) | 7 days |
| Session events | 30 days |
| Reports | 365 days (then anonymized / aggregated) |
| Zone chat and direct messages | 48 hours then automatic deletion |
| "I'm here" presence | Hidden after 3 min of silence, deactivated after 10 min, deleted after 24 h |
| Routes / route events | 7 days / 30 days |
| Mood note (free text) | Erased after 30 days (the mood record, without the text, is kept) |
| Biometric / verification data | See §9 bis (SentinElles never keeps an image; erased at Didit on account deletion, purged after 12 months of inactivity) |
| Reports (after account deletion) | Anonymized and retained as aggregated data indefinitely |
| Technical logs (errors, anti-spam) | 30 days |
| Account-deletion anti-abuse marker (irreversible fingerprint of the hashed number, no recoverable personal data — legitimate interest, Art. 6(1)(f), preventing abusive delete/re-signup cycles) | 12 months |
| Waitlist (website emails) | Until you unsubscribe, then immediate erasure |
| Encrypted backups | Managed automatically by the host (Google Cloud SQL), encrypted, then purged per its retention cycle |
5. Recipients
Your data is accessed by:
- Authorized SentinElles staff (moderation, support, security), strictly on a need-to-know basis;
- Technical processors under data processing agreements (DPA), in the following categories:
| Category | Role | Primary location |
|---|---|---|
| Cloud hosting | Hosting, database, storage | European Union |
| SMS provider | OTP verification (number hashed server-side) | EU / outside EU (SCCs) |
| Email provider | Transactional email (waitlist, notifications) | EU / outside EU (SCCs) |
| Error tracking | Anonymized error logs | European Union |
| Address geocoding | Address suggestions (routing, zone check) via the French public service IGN Géoplateforme / Base Adresse Nationale. Queries are relayed by our server without any user identifier and the searched text is never logged. Suggested transit stops come from our own referential, with no external call. | France |
The detailed list of processors (legal name, DPA) is kept up to date and available on request at privacy@sentinellesapp.fr.
In line with our policy of minimizing our exposure surface, we publish the categories of processors above rather than the full named list. The up-to-date detailed list (legal name, service, location, DPA and transfer safeguards for each processor) is maintained under GDPR Article 30 and provided on request at privacy@sentinellesapp.fr.
Your data is never sold in personally-identifying form. However, aggregated and irreversibly anonymized data may be shared or commercially valorized with institutional or private partners (local authorities, law enforcement under formal agreements, research, urban planning, prevention) — exclusively as statistics or heat maps, never personally identifying, never at the level of an individual trajectory.
6. Transfers outside the European Union
Some processors (notably the SMS provider and certain verification or notification providers) may handle data outside the European Union. In such cases, the transfer is governed by the European Commission's Standard Contractual Clauses (SCCs) (Decision 2021/914) and, where applicable, supplementary measures (encryption, pseudonymization, hashing). The detailed mapping of transfers outside the EU and the safeguards applicable to each processor is available on request at privacy@sentinellesapp.fr.
7. Your GDPR rights
You have the following rights regarding your personal data:
- Access (Art. 15) — get a copy of your data, directly from the app: Paramètres → "Télécharger mes données" (served by the authenticated
GET /auth/my-dataendpoint), or by email to privacy@sentinellesapp.fr; - Rectification (Art. 16) — correct inaccurate or incomplete data;
- Erasure (Art. 17, "right to be forgotten") — delete your account and all associated data: step-by-step guide at Delete my account (and Delete my data for partial erasure without closing the account);
- Restriction (Art. 18) — temporarily freeze processing;
- Portability (Art. 20) — receive your data in a structured format (JSON): the same export as the app's "Télécharger mes données" button;
- Objection (Art. 21) — object to processing based on legitimate interest;
- Withdrawal of consent (Art. 7.3) — for consent-based processing, at any time.
8. Security
We implement appropriate technical and organizational measures (GDPR Art. 32):
- TLS 1.2+ encryption for all client ↔ server traffic;
- At-rest encryption (AES-256) for the database and backups;
- SHA-256 hashing with private salt for phone numbers and IPs;
- Reversible phone-number encryption via Google Cloud KMS, with strict IAM separation: the application service can encrypt but cannot decrypt; decryption is isolated in a dedicated function, reserved for judicial requisitions (LCEN Art. 6-II);
- Strong authentication (SMS OTP) — no stored passwords;
- Internal access segmentation (least-privilege principle);
- Logging of personal-data access, retained for 1 year;
- Regular security testing and 72-hour breach notification procedure (GDPR Art. 33).
9. Cookies & trackers
The website sentinellesapp.fr uses only strictly necessary cookies (language preference, anti-CSRF token). No advertising cookies, no third-party analytics cookies.
The mobile app uses no cookies, but stores your session token in the system's secure enclave (iOS Keychain / Android Keystore, hardware-encrypted; deleted on account deletion or session expiry) — it is excluded from device backups and your language preference.
The website loads no resources from third-party servers: fonts are self-hosted (no requests to Google Fonts or any other CDN — your IP address is never transmitted to a third party while browsing). Since there are no trackers requiring consent, no cookie banner is needed or shown (CNIL "cookies and other trackers" guidelines).
9 bis. Biometric identity verification (sponsorship)
Access to the app requires an identity verification operated by our processor Didit (processed within the EU): ID document reading and a video selfie (liveness detection). This is biometric data (special category, GDPR Art. 9).
- Purposes: confirm identity, verify you are 18 or older — read from the document, never estimated from your face — and prevent duplicate accounts.
- Legal basis: your explicit consent (Art. 9.2.a), collected through an affirmative control (never a pre-ticked box) before each verification, withdrawable at any time (privacy@sentinellesapp.fr or account deletion).
- What SentinElles keeps: the proof of your consent (text version, hash, timestamp) and the verification outcome (verified / not verified) — never the images nor biometric templates, which stay with Didit under its privacy policy They are erased at Didit when you delete your account, and automatically after 12 months of inactivity (Didit retention ceiling: 1 year).
- Rights: access, withdrawal, erasure — see sections 6-8; the consent proof is exported by "my data" and deleted with the account.
10. Minors
SentinElles is restricted to adults (18 or older). If we find that an account was created by a minor, the account is deleted without notice and the data erased.
If you believe a minor has created an account, please report to moderation@sentinellesapp.fr.
11. Complaint to the CNIL
If you believe your rights are not respected, you can file a complaint with the French data protection authority, the CNIL:
- Website: cnil.fr/en/plaintes
- Address: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Phone: +33 1 53 73 22 22
We encourage you to contact us first at privacy@sentinellesapp.fr before filing — we'll do our best to respond promptly.
12. Policy changes
We may update this policy to reflect changes in our practices or regulation. Substantial changes are notified:
- By an in-app notification at least 15 days before they take effect;
- By email if you've provided one.
The current version is always available at this URL, dated at the top.