Privacy policy

Version of 2 October 2026 · Translation provided for convenience; the French version prevails.

This policy explains what data Ephemeria processes, why, with whom, for how long, and how to exercise your rights. It describes what the app actually does.

1. Who is responsible

The data controller is EPHEMERIA, 148 rue de la Pompe, 75116 Paris, France (details in the legal notice).

We have not appointed a data protection officer, as this is not required for our activity. privacy@ephemeria.app is our single point of contact for data protection.

2. The short version

3. Data, purposes and legal bases

The legal bases are those of Article 6 GDPR: contract (needed to provide the service you ask for), legal obligation, legitimate interest (balanced against your rights; you can object) and consent (which you can withdraw at any time).

DataWhyLegal basis
Account: university email address, account ID, university (derived from your email domain), account status, sign-up date. An 8-digit sign-in code sent by email, valid for 1 hour.Create your account, sign you in without a password, check you are a student at a covered institution.Contract
Age: date of birth.Check that you are 18 or over. This is a declaration: we do not ask for ID documents.Contract (eligibility condition) and legitimate interest
Profile: first and last name, degree level, programme or specialisation, expected graduation year, interests, career industries, bio, theme and language.Show your profile to students on your campus; suggest communities and events related to your choices.Contract
Acceptance of the terms: version accepted and date (server time).Prove what you agreed to and when.Legal obligation and legitimate interest
Events: events you create (including the map location), public or private “Going” responses, invitations, reminders.Run your campus events.Contract
Attendance: either the scan of your ticket (scanning account, server time) or your self-confirmation (time of your declaration). The source is always kept: a declaration is never recorded as a scan.Create your stars and open access to an event’s memories.Contract
Tickets and payments: order (event, ticket type, price and currency fixed at order time, payment, refund and dispute statuses, Stripe technical identifiers), ticket and its QR code, transfers (from whom, to whom, when), answers requested by the organiser (for example a meal choice) and requested documents. Your card details are entered on Stripe’s payment page: we never receive them.Sell and deliver your ticket on behalf of the association, handle refunds, transfers and disputes, keep accounting records.Contract; legal obligation (accounting)
Photos and memories: photos you send to a Nebula (the photo and the time it was taken), your La Minute photo (taken in the app, with the capture-session time), event recaps, your “this is me, hide it” requests.Build the event’s album, published at 11:00, once the event is over; protect the people photographed.Contract; legal obligation for removal requests
Your Sky, the Class Sky, In common: computed from your confirmed attendance. The copy placed in the Class Sky carries no identity.Show your Sky, your class’s anonymous sky and, on a profile, the number of events you shared.Contract
Messages: private messages (text, images, places you choose to share), event and community chats.Let you talk with other students.Contract
Content: posts, comments, kudos, marketplace listings and their photos, housing listings and attestations, in-person handoffs and disputes, class channels, notes and deadlines, communities, associations (memberships, roles).Run these features.Contract
Passport (trust record): attendance, completed handoffs, disputes and the level of evidence.Let students know whether someone actually turned up or completed an exchange.Legitimate interest
Safety and moderation: reports, blocks, moderation decisions and their reasons, appeals. Text refused by the automatic filter is not stored.Protect the community, handle reports, meet our obligations as a host.Legal obligation (French LCEN, EU Digital Services Act) and legitimate interest
Usage measure: one line per day you open the app while signed in (account ID and date, Europe/Paris time zone). At sign-up, one line “an account was created at this university on this day”, anonymised if you delete your account.Know whether students come back. Nothing else is measured.Legitimate interest
Notifications: your device’s notification token, if you allow notifications.The La Minute signal, the single notification when someone names a constellation containing an event you were at, and event reminders scheduled on your phone.Consent (through your phone, withdrawable in its settings)
App updates: each time it opens, the app asks Expo whether a corrective update exists. This request carries the IP address, platform, app version and a random technical identifier specific to the installation.Deliver security and bug fixes quickly. We do not use this data to measure usage.Legitimate interest
Support: the emails you send us.Answer you and handle your requests.Legitimate interest; legal obligation for GDPR requests
Universities not yet covered: the email domain and the number of attempts. No address, no name.Know where to open next.Legitimate interest (no personal data)
Technical logs: IP address, date and time, request, at our hosting provider.Security, abuse prevention, troubleshooting.Legitimate interest

4. What stays on your phone

5. Who sees what

When you buy a ticket, the organising association is the seller. Through its Stripe account it receives the information needed for the payment and for its accounting obligations, and it is responsible for how it uses it. Stripe processes your payment data under its own privacy policy (stripe.com/privacy).

6. Processors and transfers

We use providers who process data on our behalf, on our instructions and under contract (Article 28 GDPR).

ProviderRoleDataLocation and safeguards
Supabase, Inc.Database, authentication, file storage, server functionsAll service dataData hosted in the European Union (Ireland, Amazon Web Services, eu-west-1 region). US company: any access is covered by the safeguards below.
Resend, Inc.Sending sign-in emailsEmail address, email content (the code)Sent from the European Union (eu-west-1). US company.
Expo (650 Industries, Inc.)Routing notifications; corrective app updatesNotification token, notification content; IP address, platform, app version, installation technical identifierUnited States
Apple (APNs) and Google (Firebase Cloud Messaging)Delivering notifications to your phoneDevice token, notification contentUnder their terms
StripeTicket payments on behalf of the associationData entered on the payment page, amount, email addressStripe Payments Europe (Ireland); independent controller for its own obligations
Google Maps (Android) and Apple Maps (iOS)Displaying mapsIP address, map area displayed; your location if you show it on the mapUnder their terms
Host of the ephemeria.app websiteHosting this websiteTechnical logs (IP address)See the legal notice

Where a provider may access data from outside the European Union, the transfer is covered by the European Commission’s adequacy decision (EU-US Data Privacy Framework) where the provider is certified, and otherwise by the European Commission’s standard contractual clauses. You can get a copy at privacy@ephemeria.app.

7. Photos and image rights

8. Retention

DataPeriod
Account and profileUntil you delete your account. An account inactive for 3 years is deleted, after a warning email.
Date of birthLife of the account
Sign-in code1 hour
Private messagesUntil they or your account are deleted
Event chatsDeleted automatically 24 hours after the event ends
Nebula, La Minute and recap photosAs long as the album exists; your photos are deleted with your account
Listing and post photosUntil your account is deleted, or earlier on request
Class notes removed by moderationAccess ends immediately; files deleted after 30 days (appeal period)
AttendanceLife of the account. After account deletion, the events you attended stay recorded under an anonymous identifier, with your campus and, if one of them was scanned, your class year; they are visible to no one and only feed the Class Sky’s anonymous counts
Orders, payments, refunds10 years (French accounting obligation, Article L123-22 of the Commercial Code). After account deletion they are linked to an anonymous key, no longer to you.
Usage measure (one line per day opened)13 months, then deleted; deleted immediately with your account
Reports and moderation decisionsLife of the account, then kept without your identity
Passport (trust record)Life of the account, then kept without your identity, so the other party’s history is not rewritten
Notification tokensUntil you sign out, delete your account or your phone invalidates them
Support emails3 years after the last exchange
Technical logsAt most 28 days
Domains of universities not yet coveredNo limit: they contain no personal data

9. Account deletion and export

You can delete your account at any time from the app (Settings → Delete my account), or by email if you no longer have the app. The request takes effect immediately (signed out, profile hidden, access revoked) and erasure is completed within 30 days, usually within minutes. All details are on the Delete your account page.

You can also download a copy of your data as a structured file (Settings → Your data → Download my data).

10. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection (in particular to processing based on legitimate interest), the right to withdraw consent at any time, and the right to give instructions about what happens to your data after your death.

To exercise them, email privacy@ephemeria.app from your account’s address. We may ask you to confirm your identity. We answer within one month, which may be extended by two months for a complex request (we would tell you).

You can lodge a complaint with the French data protection authority (CNIL) at any time: www.cnil.fr/fr/plaintes, or 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France; or with the authority of the EU country where you live.

11. Security

If a data breach puts you at risk, we notify the CNIL and, if the risk is high, we tell you.

12. Cookies and trackers

This website uses no cookies and loads no external resources (even the fonts are hosted here). The app uses no advertising ID, no trackers and no analytics SDK. It only keeps on your phone what it needs to work (your session, your preferences). Stripe’s payment page, opened in your browser, may set its own cookies needed for payment security, under Stripe’s policy.

13. Minimum age

Ephemeria is only for people aged 18 and over. Sign-up refuses a date of birth under 18. If we learn that an account belongs to a minor, we delete it. You can tell us at privacy@ephemeria.app.

14. Automated decisions

Ephemeria makes no fully automated decision that produces legal effects or similarly significantly affects you. A filter blocks certain words when you post; if you think it got it wrong, email support@ephemeria.app. No advertising profiling.

15. Changes

If this policy changes significantly, we tell you in the app before the change takes effect. The version date is at the top of this page.