Legal · GDPR · English translation

Privacy Policy

Version 1.0.16 · Effective 28 April 2026 · Last updated 2 October 2026
Data controller: SentinElles Association (a registered non-profit under French law of 1901, RNA W751284130), WILLA, 6 rue du Sentier, 75002 Paris.
This is a translation. The French version prevails in case of conflict.

1. Data controller

The controller for the processing of your personal data is:

Hosts. Data and services are hosted in the European Union on Google Cloud Platform (region europe-west1, Belgium), operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (+353 1 436 1000). The mobile app updates its content (OTA) via Expo, Inc. (Expo Application Services), 650 Castro Street, Suite 400, Mountain View, CA 94041, USA, and is distributed via the App Store (Apple Distribution International Ltd, Hollyhill Industrial Estate, Cork, Ireland) and Google Play (Google Ireland Limited).

This policy applies to the SentinElles mobile app, the website sentinellesapp.fr and all related services.

2. Data we collect

2.1 Data you provide

CategoryExamples
AccountPhone number — the only account identifier: no email is requested from app users. It is stored in two forms, never in clear: (1) a SHA-256 fingerprint (lookup, dedup, erasure) and (2) a reversible ciphertext protected by a Google Cloud KMS key that the API is not allowed to decrypt (decryption isolated in a dedicated function). The number in clear is only looked up in three cases: a judicial requisition (LCEN Art. 6-II); a look-up by an authorized team member, with a mandatory reason, in case of serious abuse or for a user's safety — last 4 digits by default, every access logged in a tamper-evident way; and, if you ask to join an « On y va ? » company space, that site's referent, to recognize you before accepting your request.
Self-declarationDeclared belonging to women / gender minorities (a value from a closed list, never free text), gating access to the non-mixed space. The gender shown on the ID document is not checked. This declaration and the optional « I am a trans woman » box are treated as sensitive data (GDPR art. 9): they are recorded only after your explicit consent, of which we keep the proof (text version, hash, timestamp); they are visible to the team only, when reviewing a signup, to understand an expected discrepancy between an identity document and an appearance — such a discrepancy is never a ground for refusal. They are shown neither to your marraine nor to other users, and are never exported for analytics. You can withdraw this consent at any time from the app: the declaration and its proof are then erased.
How you heard about SentinElles (optional)Your answer to « How did you hear about SentinElles? », asked once after your signup is approved: a value from a closed list (a friend / a code, a flyer, Instagram, LinkedIn, an event, word of mouth, an article or the website, other), never free text. You can skip the question; it is then not asked again. Erased with your account.
Matrimoine places you suggest (optional)If you suggest a place named after a woman: the place name, the woman's name, the category, where you dropped the pin and an optional note (no e-mail address or phone number). The team reviews each suggestion without seeing who made it; a place that is accepted joins the map with no link to you. You can see the status of your suggestions in the app and withdraw the pending ones. « I've been there » is confirmed on the path of your session (during the session or within the 30 minutes after it): our server checks that the place is near your path, without recording anything more. Your list of places stays on your phone. We only keep an anonymous count of visits per place and per month (see § 3). If you report a mistake about a place (it no longer exists, it is not the right person, it is listed twice or misplaced), we record the place and the reason, without your identifier: a non-reversible technical fingerprint prevents duplicates and caps reports per day, and is erased as soon as the team has decided. « It no longer exists » is checked, like « I've been there », on the path of your session.
SponsorshipSingle-use invitation code consumed at signup and the "invited by" link (chain of trust).
Identity verificationVerification outcome (verified / not) and Didit session id — see §9 bis. SentinElles neither downloads nor stores any image or biometric template: this data is processed and retained by our processor Didit under its own policy (see §9 bis).
Posted contentReports (category, description, zone), zone chat messages (ephemeral), direct messages between visible users (ephemeral), optional end-of-session mood note.
« On y va ? » spaces (workplace or event, optional)If you enter a space's code: your membership (space, a pseudonym specific to that space, avatar, dates), the journeys you propose or join — direction, mode, time slot and two landmarks chosen from lists (meeting point, town or arrondissement), never a position or an address —, the messages of their threads and your notification settings per conversation. In a workplace space, your number is shown to the site's référente so she can recognise you (see "Account"); in an event space, the code published by the organiser is enough: your number is shown to no one. The organiser or the employer receives no data about you: at most an aggregated count, and only from 5 people.
Waitlist (website)Email, first name, profile type (user / partner / press / etc.) — collected on the website only, separate from the app account.

The pseudonym shown in community spaces is deterministically derived from the device's technical identifier; it is validated to never contain an email, phone number or full name.

2.2 Data collected automatically

CategoryDescription
Approximate locationProcessed only during an active session you start. Before any storage, the position is degraded to a geographic cell (~150 m, never raw GPS). It powers zones, proximity alerts and, if you enable them, "I'm here" presence and route, and to check that a matrimoine place is on your path when you confirm « I've been there » — shared only with the network you chose, never for advertising. Route geometry is never transmitted to another user.
Technical dataDevice type, OS version, app version, system language, anonymized error logs
IP fingerprintSHA-256 hash of the IP with private salt. Used for anti-spam. Raw IP is never stored.

2.3 Data we never collect

3. Purposes & legal basis (GDPR Art. 6)

PurposeLegal basis
Account creation and managementPerformance of contract (Terms)
Display and alerts based on reported zonesPerformance of contract
Content moderation, fraud and abuse preventionLegitimate interest of SentinElles and other users
Production and valorization of aggregated, irreversibly anonymized statistics (mappings, research, institutional or private public-interest partnerships)Legitimate interest + irreversible anonymization
Measuring our communication channels (where users discover SentinElles), from the optional answer to « How did you hear about SentinElles? » — internal statistics on pseudonymised dataLegitimate interest; optional answer, the question can be skipped
Growing the matrimoine map from the places you suggestPerformance of contract; suggesting is optional
Counting visits to matrimoine places: one counter per place and per month, with no identifier, shared with cities or cultural partners only from 5 visits up. To count each person once a month, a non-reversible technical fingerprint is kept until the end of the month, then deleted. If you objected to analytics (§ 7), your visits are not countedLegitimate interest; right to object (§ 7)
« On y va ? » spaces: letting you, if you choose to, arrange journeys with colleagues (workplace space) or with other participants of an event (event space), under a pseudonym; giving the employer or the organiser an aggregated count only from 5 peopleConsent (Art. 6.1.a): joined with a code, left in one gesture, never on the instruction of an employer or an organiser
Transactional emails (signup confirmation, major updates)Performance of contract
Notifications about your account and your use of the app (signup approval, a reminder if your signup is not finished — at most two, one day then three days after you started —, messages and requests addressed to you) — delivered to your device if you allowed notificationsPerformance of contract
"SentinElles news" notifications (off by default, can be turned on in Settings)Consent, withdrawable at any time in Settings
Trusted contacts and alert (see §9 ter): letting the people you chose know, and showing them your position during an alert you triggerPerformance of contract, for the feature you turn on; your position is only disclosed on your explicit gesture of triggering an alert. For your contacts' data: their acceptance, withdrawable at any time (Art. 6.1.a)
Biometric identity verification (see §9 bis)Explicit consent (Art. 9.2.a)
Blocking re-registration of a person excluded for abuse (face blocklist, see §9 bis)Legitimate interest: protecting users and preventing fraud (Art. 6.1.f)
Marketing emails / newslettersConsent (dedicated, never pre-checked opt-in)
Sign-up to « Running crew » outings on the website (first name, e-mail, optional level): organising the outing, sending the confirmation and the meeting pointSteps taken at your request (art. 6.1.b). Appearing on the outing's photos and receiving the newsletter: two separate consents, optional, never pre-checked (art. 6.1.a), withdrawable at any time
Prospecting companies and institutions: presenting our offers to professionals, at their work address (see §9 quater)Legitimate interest (art. 6.1.f); one-click objection at any time
Legal obligations (judicial requests, unlawful content)Legal obligation (LCEN, Code of Criminal Procedure)

4. Retention periods

DataPeriod
Active accountAs long as you use the app
Deleted account (your initiative)Erased within 30 days, except legal-obligation data (connection logs: 1 year, LCEN Art. 6-II)
Positions (degraded cells)7 days
Session events30 days
Reports365 days (then anonymized / aggregated)
Zone chat and direct messages48 hours then automatic deletion
« On y va ? » spaces: journeys and their messagesA journey is erased 30 minutes after its time slot, with the messages of its thread. Messages of the space's own thread: 48 hours. In an event space, a journey's messages stay until the journey is erased (people sometimes organise several days ahead)
Membership of a « On y va ? » spaceUntil you leave, are removed, or the space ends; an event space closes by itself 7 days after the event (journeys and messages erased). A number shown to a référente is erased as soon as she decides and when the membership ends. A request the référente never decides expires after 30 days, with the number. An ended membership (pseudonym, avatar, dates) is erased 30 days after the exit
"I'm here" presenceHidden after 3 min of silence, deactivated after 10 min, deleted after 24 h
Routes / route events7 days / 30 days
Matrimoine place suggestionsAs long as your account exists; deleted with it (a place already added to the map stays there, with no link to you)
Anti-duplicate fingerprint of visits to a matrimoine placeUntil the end of the current month (only anonymous counts remain afterwards)
Fingerprint of a report about a matrimoine placeUntil the team's decision; the report then keeps no link to you
Mood note (free text)Erased after 30 days (the mood record, without the text, is kept)
Trusted contacts (see §9 ter)Precise position during an alert: erased as soon as the alert ends, 2 hours at most. Alert log, without position: 1 year. A contact's number: erased as soon as you remove them, they refuse, you turn the feature off or you delete your account
Biometric / verification dataSee §9 bis (SentinElles never keeps an image; at Didit: erased on account deletion, purged after 12 months of inactivity, and in every case no later than 1 year after verification)
Signup never completed (identity verification not finished)Deleted after 30 days, including the verification session at Didit
Reports (after account deletion)Anonymized and retained as aggregated data indefinitely
Technical logs (errors, anti-spam)30 days
Internal analytics warehouse ("bronze" and "silver" tables): your identifiers there are pseudonymized (a per-account salted HMAC) — still personal data, not anonymous. Deleting your account destroys that salt and makes your rows unrecoverable (a cryptographic break of the link, not a row-by-row purge). You can object to this processing (§7, Art. 21).730 days (2 years)
Account-deletion anti-abuse marker (irreversible fingerprint of the hashed number, no recoverable personal data — legitimate interest, Art. 6(1)(f), preventing abusive delete/re-signup cycles)12 months
Sign-up to a « Running crew » outing (first name, e-mail, level, photo and newsletter choices)Erased 6 months after the outing, or earlier on request. If you ticked the newsletter, your e-mail joins the newsletter list and follows the next row
Website waitlist and contact form (e-mail, name, message)3 years after our last exchange. One month before, a single e-mail lets you keep your details or erase them right away; without an answer they are erased, including in our tracking sheet and at our e-mail provider
Account deletion log (irreversible fingerprint of the identifier, number of rows erased, erasure dates)3 years, to prove the erasure if a complaint is made
Professional prospecting contacts (see §9 quater)3 years after our last exchange, then erased, including at our e-mail provider. If you object: erased the next day; only an irreversible fingerprint of the address is kept so we never contact you again
Encrypted backupsManaged automatically by the host (Google Cloud SQL), encrypted, then purged per its retention cycle

5. Recipients

Your data is accessed by:

CategoryRolePrimary location
Cloud hostingHosting, database, storageEuropean Union
SMS providerOTP verification (number hashed server-side) and, if you turn on trusted contacts, sending SMS to the people you chose (neither the SMS text nor the full number is kept by this provider)EU / outside EU (DPF then SCCs/BCR)
Email providerTransactional email (waitlist, notifications) and sending our prospecting messages to professionals (§9 quater)EU / outside EU (SCCs)
Error trackingAnonymized error logsEuropean Union
Identity verificationID document reading, video selfie and liveness detection, apparent-age estimate (a human-review signal), duplicate-account check (see §9 bis)European Union
Notification deliveryDelivery of notifications to your device by a delivery provider, then by Apple's and Google's notification services (device notification token, notification text — never your location, your reports or your identity)EU / outside EU (SCCs)
Address geocodingAddress suggestions (routing, zone check) via the French public service IGN Géoplateforme / Base Adresse Nationale. Queries are relayed by our server without any user identifier and the searched text is never logged. So that nearby places come first rather than a namesake 400 km away, your position is sent rounded to about a kilometre — never your exact position, and never logged either. Suggested transit stops come from our own referential, with no external call.France
Map tilesMap display inside the app: Apple Maps on iOS, Google Maps on Android (SDKs embedded in the app). Only tile requests for the displayed area (and the device's IP address) reach them; neither your account, nor your reports, nor your route are transmitted. Commercial points of interest are hidden (ADR 0137).EU / outside EU (SCCs)

The detailed list of processors (legal name, DPA) is kept up to date and available on request at privacy@sentinellesapp.fr.

In line with our policy of minimizing our exposure surface, we publish the categories of processors above rather than the full named list. The up-to-date detailed list (legal name, service, location, DPA and transfer safeguards for each processor) is maintained under GDPR Article 30 and provided on request at privacy@sentinellesapp.fr.

Your data is never sold in personally-identifying form. However, aggregated and irreversibly anonymized data may be shared or commercially valorized with institutional or private partners (local authorities, law enforcement under formal agreements, research, urban planning, prevention) — exclusively as statistics or heat maps, never personally identifying, never at the level of an individual trajectory.

6. Transfers outside the European Union

Some processors (notably the SMS provider and certain verification or notification providers) may handle data outside the European Union. In such cases, the transfer is governed by the European Commission's Standard Contractual Clauses (SCCs) (Decision 2021/914) and, where applicable, supplementary measures (encryption, pseudonymization, hashing). The detailed mapping of transfers outside the EU and the safeguards applicable to each processor is available on request at privacy@sentinellesapp.fr.

7. Your GDPR rights

You have the following rights regarding your personal data:

How to exercise your rights: in-app: Settings → Privacy → "My Data". Or email privacy@sentinellesapp.fr. We respond within 30 days at most (GDPR Art. 12.3).

8. Security

We implement appropriate technical and organizational measures (GDPR Art. 32):

9. Cookies & trackers

The website sentinellesapp.fr uses only strictly necessary cookies (language preference, anti-CSRF token). No advertising cookies, no third-party analytics cookies.

The mobile app uses no cookies, but stores your session token in the system's secure enclave (iOS Keychain / Android Keystore, hardware-encrypted; deleted on account deletion or session expiry) — it is excluded from device backups and your language preference.

The website loads no resources from third-party servers: fonts are self-hosted (no requests to Google Fonts or any other CDN — your IP address is never transmitted to a third party while browsing). Since there are no trackers requiring consent, no cookie banner is needed or shown (CNIL "cookies and other trackers" guidelines).

9 bis. Biometric identity verification (sponsorship)

Access to the app requires an identity verification operated by our processor Didit (processed within the EU): ID document reading and a video selfie (liveness detection). This is biometric data (special category, GDPR Art. 9).

9 ter. Trusted contacts and alert (optional)

If you turn on trusted contacts in the app, you choose up to 3 people (a French or other European Union mobile number; they do not need the app). Each one receives an SMS to accept or refuse. During a session, you can then trigger an alert: the people who accepted receive an SMS with a link to a page showing your position, for the duration of the alert. Nothing is collected until you turn the feature on.

9 quater. Prospecting professionals

This section is about people who do not necessarily use the app: the professionals (companies, local authorities, event organisers) to whom we present our offers, such as the « On y va ? » company space.

10. Minors

SentinElles is restricted to adults (18 or older). If we find that an account was created by a minor, the account is deleted without notice and the data erased.

If you believe a minor has created an account, please report to moderation@sentinellesapp.fr.

11. Complaint to the CNIL

If you believe your rights are not respected, you can file a complaint with the French data protection authority, the CNIL:

We encourage you to contact us first at privacy@sentinellesapp.fr before filing — we'll do our best to respond promptly.

12. Policy changes

We may update this policy to reflect changes in our practices or regulation. Substantial changes are notified:

The current version is always available at this URL, dated at the top.