Legal

Privacy Policy

Last updated: May 15, 2026

This is an English translation provided for convenience. In the event of any discrepancy, the French version available at cortifit.app/privacy/ shall prevail.

1. Introduction

This Privacy Policy describes how AMBAVILLE (hereinafter "we", "our" or "the Publisher") collects, uses, stores and protects the personal data of users of the Cortifit mobile application.

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the French Data Protection Act (loi Informatique et Libertés) of January 6, 1978, as amended, and any applicable regulations.

2. Data controller

The controller of the data processing is AMBAVILLE.

3. Data collected

Account data: email address, password (encrypted), display name. If you use Apple or Google authentication, we receive a unique identifier and, where applicable, the name associated with your account.

Profile data: cortisol profile, well-being goals, priorities, caffeine level, time zone.

Well-being data: daily mood and energy (0-100), stress and triggers, emotions, symptoms, personal notes.

Self-reported sleep data: bedtime and wake-up time, night-time awakenings, perceived quality (1-10), positive and negative factors.

Nutrition data: anti-inflammatory and pro-inflammatory foods, hydration, meal times.

Activity data: completed routines, breathing exercises, vagal stimulation, grounding, protocol progress, articles read.

3a. Usage data and anonymous statistics (Mixpanel)

Data collected. To understand how the Application is used and to improve it, we measure a limited number of actions performed (onboarding started and completed, protocol mission completed, paywall displayed, free trial started, purchase completed, app opened). For each action, profile attributes are also transmitted, in categorical form only (age range, gender, perceived stress level, sleep quality, diet type, main goal), together with your Cortifit user identifier and your email address.

What is never transmitted to Mixpanel. No free text is sent to Mixpanel: not your first name, not the content of your writing journal (Ruminations, Achievement, Beck Columns), not your routine notes, not your detailed sleep logs, not your HealthKit data, not your photos. Only the actions and the categorical attributes listed above.

European hosting. Your usage data is stored in Mixpanel's European data center (Frankfurt, Germany) — it is not transferred to the United States. Retention is 90 days on the free plan in use.

Purposes. Identifying friction points in the onboarding journey, measuring the conversion rate to the Premium subscription, understanding week-by-week retention, prioritizing improvements to the Application. No advertising use, no sharing with commercial third parties.

Legal basis. Legitimate interest within the meaning of Article 6(1)(f) GDPR: improvement of the product and of the user experience. You may object to this collection at any time via Settings > Privacy > Anonymous statistics (opt-out toggle), without any degradation of the service.

Processor. Mixpanel Inc. — see section 5 for details.

3b. Health data (Apple HealthKit)

Data collected. When you connect Cortifit to Apple Health and enable personalized analysis, we may access the following types of data, subject to your explicit authorization: daily step count and distance covered, active calories burned, resting heart rate, heart rate variability (HRV), respiratory rate, oxygen saturation (SpO2), sleep data (duration and stages), mindfulness sessions, nutritional intake (calories, caffeine, hydration).

Purpose of the processing. Your health data is used exclusively for: generating your personalized well-being report by artificial intelligence, tracking your health trends over time (streaks, averages, changes), and personalized recommendations regarding stress management, physical activity, sleep and nutrition.

Storage and security. Your health data is transferred to our secure servers (hosted by Supabase) only after your explicit consent, which is separate from the HealthKit authorization. The data is encrypted in transit (TLS) and at rest. Access is restricted to your user account only (Row Level Security). Your health data is never stored in iCloud.

What we do NOT do. In accordance with Apple's guidelines, your HealthKit data is never used for advertising or marketing purposes, never sold, rented or shared with third parties, never used for data mining or commercial profiling, and never stored in iCloud.

Your rights. You may revoke Cortifit's access to your HealthKit data at any time in the iOS settings (Settings > Health > Data Access > Cortifit). You may also disable server synchronization in the app settings, without losing access to your history. To request the deletion of the health data stored on our servers, contact us at privacy@cortifit.app.

Legal basis. The processing of your health data is based on your explicit consent (Article 9(2)(a) GDPR). This consent is obtained separately from the HealthKit authorization, through a dedicated screen in the application.

3c. Website audience measurement and advertising (Umami, Google Analytics, Microsoft Clarity, Meta Pixel)

Context. The cortifit.app website uses several audience measurement and advertising effectiveness measurement tools to understand how visitors discover and use our pages.

Umami. Cookie-free analytics tool hosted in Europe (Scitylana GmbH, Germany). It collects entirely anonymous data (page views, traffic source, browser type) without tracking any individual identifier. No consent banner is required — Umami is compliant by default with the GDPR and with the recommendations of the CNIL (the French data protection authority). No cookie is placed. Data retained for 12 months.

Google Analytics 4. Audience measurement tool from Google (Google Ireland Limited, Ireland). Loaded only after your explicit consent via the Axeptio banner. Data collected: pages visited, session duration, traffic source, device and browser type, country (anonymized IP address). Cookie lifetime: 13 months. Transfers outside the EU are governed by the European Commission's standard contractual clauses.

Microsoft Clarity. Behavioral analytics tool (heatmaps, anonymized session recordings) from Microsoft (Microsoft Ireland Operations Limited, Ireland). Loaded only after your explicit consent via the Axeptio banner. Data entered in forms is not recorded. Cookie lifetime: 1 year. Transfers outside the EU are governed by the standard contractual clauses.

Meta Pixel (Facebook & Instagram). Advertising effectiveness measurement tool from Meta (Meta Platforms Ireland Limited, Ireland). Loaded only after your explicit consent via the Axeptio banner. The Pixel allows Cortifit to measure the success of its advertising campaigns on Facebook and Instagram (impressions, clicks, conversions) and to offer personalized advertising content. The data is also transmitted to Meta through a server-to-server Conversions API (with deduplication by event identifier) in order to recover the signal limited by iOS 14+ restrictions and by certain browser blockers. Data collected: pages visited, clicks on the application download buttons, IP address, user agent. No directly identifying personal data (email, telephone) is transmitted without SHA-256 hashing. Cookie lifetime: 90 days (_fbp), 30 days (_fbc). Transfers outside the EU are governed by the European Commission's standard contractual clauses.

Axeptio. Consent manager (cookie banner) developed by Inmotion SAS (France). Collects and stores your consent preferences. Hosted in France. Retention period of the preference cookie: 6 months.

Legal basis. Umami: legitimate interest (Art. 6(1)(f) GDPR) — no individual identifier collected. Google Analytics 4, Microsoft Clarity, Meta Pixel and Axeptio: consent (Art. 6(1)(a) GDPR), obtained through the consent banner displayed on your first visit. You may withdraw or change your consent at any time via the cookie management icon at the bottom left of the page.

4. Purposes of the processing

Creation and management of your account (performance of the contract). Personalization of recommendations (performance of the contract). Calculation of scores and visualizations (performance of the contract). Synchronization of your data across devices (performance of the contract). Management of the Premium subscription (performance of the contract). Generation of personalized insights (consent). Improvement of the Application (legitimate interest, anonymized data).

Certain data (mood, stress, sleep, nutrition, symptoms) may be considered health data within the meaning of Article 9 GDPR. Its processing is based on your explicit consent, which you express by entering the data voluntarily.

5. Processors

Supabase Inc. (United States): database hosting, authentication and server functions. Data stored in Europe (Frankfurt, Germany). SOC 2 Type II compliant.

RevenueCat Inc. (United States): subscription management. Only your user identifier is shared.

Mixpanel Inc. (United States, EU infrastructure): anonymized product analytics. Data stored in the European data center (Frankfurt, Germany). GDPR compliant, SOC 2 Type II and ISO 27001 certified. See section 3a for details of the data transmitted.

Apple Inc. / Google LLC: payment processing through the App Store and the Google Play Store.

Umami Cloud (Scitylana GmbH) (Germany): cookie-free audience measurement for the cortifit.app website. Anonymous data only. GDPR compliant by default.

Google Ireland Limited (Ireland): Google Analytics 4, audience measurement for the website (subject to consent). Anonymized IP address. Transfers outside the EU governed by the standard contractual clauses.

Microsoft Ireland Operations Limited (Ireland): Microsoft Clarity, heatmaps and anonymized sessions on the website (subject to consent). Transfers outside the EU governed by the standard contractual clauses.

Inmotion SAS — Axeptio (France): consent manager (cookie banner) on cortifit.app. Processing of consent preferences only. Hosted in France.

Meta Platforms Ireland Limited (Ireland): Meta Pixel and Conversions API, advertising effectiveness measurement and personalization of Facebook and Instagram advertising content (subject to consent). For user data transmitted through the Conversions API, systematic SHA-256 hashing on the server side before sending. Transfers outside the EU governed by the European Commission's standard contractual clauses and by the EU-US Data Privacy Framework.

We do not sell, rent or share your data with third parties for commercial or advertising purposes other than the advertising effectiveness measurement tools listed above, on the basis of your consent.

6. International transfers

Some processors are based in the United States. These transfers are governed by the European Commission's standard contractual clauses and by the EU-US Data Privacy Framework.

7. Retention period

Your data is retained for as long as your account is active. If you delete your account, your personal data is deleted within 30 days, with the exception of billing data (10 years, French Commercial Code).

HealthKit data synchronized to our servers (with your consent) is retained for as long as your account is active. If you disable server synchronization, the data already synchronized is retained for your past reports. If you delete your account, all health data is deleted along with the rest of your personal data.

8. Security

All communications are encrypted via HTTPS/TLS. Authentication uses JWT tokens with expiry. Passwords are hashed (bcrypt via Supabase Auth). Access to data is restricted by Row Level Security. The Application has a local synchronization queue so that it works offline.

In the event of a data breach, we will inform you in accordance with the GDPR (72 hours to the CNIL, the French data protection authority).

9. Your rights

Right of access (art. 15): obtain a copy of your data. Right to rectification (art. 16): correct inaccurate data. Right to erasure (art. 17): delete your data from the app settings. Right to restriction (art. 18): restrict the processing in certain cases. Right to data portability (art. 20): receive your data in a readable format. Right to object (art. 21): object to processing based on legitimate interest. Right to withdraw consent: at any time.

Contact: privacy@cortifit.app

You may also refer the matter to the CNIL, the French data protection authority: www.cnil.fr.

10. Minors

The Application is not intended for children under the age of 16. We do not knowingly collect data from minors.

11. Changes

We may update this Policy. In the event of a substantial change, you will be informed by a notification in the Application.

12. Contact

For any question relating to your personal data: privacy@cortifit.app