Privacy Policy
Last updated: March 2026
1. Data Controller
The data controller for GoPrivox is:
Insightrix SASU
60 RUE FRANCOIS IER, 75008 PARIS, France
SIRET: 98923685600013
Contact: privacy@goprivox.com
2. Data We Collect
We collect the minimum data necessary to provide the service:
- Email address — used for authentication and account recovery.
- Hashed password — stored using bcrypt with 12 rounds. We never store your plaintext password.
- Encryption salt — a cryptographically random value used for key derivation on your device.
- Usage statistics — daily message counts and token usage for rate limiting and billing.
- Encrypted conversation blobs — your conversations are encrypted with AES-256-GCM on your device before reaching our servers. We store only the ciphertext.
3. Data We Do NOT Collect
We do NOT have access to your plaintext messages.
All conversations are end-to-end encrypted using AES-256-GCM with keys derived from your password via PBKDF2. Encryption and decryption happen exclusively in your browser. Our servers only ever see encrypted ciphertext blobs. Even if compelled by law enforcement, we cannot provide message content because we do not possess the decryption keys.
4. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR) — processing your email, hashed password, and encrypted data is necessary to provide the GoPrivox service you signed up for.
- Legitimate interest (Art. 6(1)(f) GDPR) — usage statistics are processed for abuse prevention, rate limiting, and service improvement, balanced against your privacy rights.
5. Third-Party Data Processors
| Processor | Purpose | Data Shared |
|---|---|---|
| AWS (Amazon Bedrock) | AI model inference | Conversation content (in transit for inference only, not stored by AWS) |
| Stripe | Payment processing | Email, payment details (managed by Stripe) |
| RevenueCat | Subscription management | User ID, subscription status |
6. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of access — request a copy of all personal data we hold about you.
- Right to rectification — request correction of inaccurate personal data.
- Right to erasure — request deletion of your account and all associated data.
- Right to data portability — export your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest.
- Right to lodge a complaint — with the CNIL (French Data Protection Authority) or your local supervisory authority.
To exercise any of these rights, email privacy@goprivox.com or use the data export and account deletion features in your account settings.
7. Cookies
GoPrivox uses essential cookies only for authentication session management (NextAuth.js session token). We do not use any tracking cookies, analytics cookies, advertising cookies, or third-party cookies. No cookie consent banner is required because we only use strictly necessary cookies as defined by the ePrivacy Directive.
8. International Data Transfers
Our infrastructure is hosted in AWS EU regions (eu-west-1, eu-central-1). Your encrypted data is stored and processed within the European Union. AI model inference via Amazon Bedrock is performed in EU regions. Payment processing through Stripe may involve transfers to the United States under Stripe's Data Processing Agreement and Standard Contractual Clauses.
9. Data Retention
Your account data and encrypted conversations are retained for as long as your account is active. Usage statistics are retained for billing and rate-limiting purposes. When you delete your account, all associated data (including encrypted conversations, usage statistics, and team memberships) is permanently deleted via cascading database deletion. This deletion is irreversible.
10. Contact
For any privacy-related questions, data requests, or complaints, contact us at: