Privacy Policy
Last updated: September 2026
1. Who we are
GovToDate is a regulatory intelligence service that monitors official government and regulatory sources and delivers personalised alerts when rules change that affect your situation.
References to "GovToDate", "we", "us", or "our" in this policy refer to Alain Freund EI (SIRET 130 532 286 00015), 5 rue Trarieux, 92600 Asnières-sur-Seine, France, publisher and data controller of this service (full legal identification is provided in the Mentions légales). If you have questions about how your data is handled, contact us at privacy@govtodate.com.
2. What data we collect
2.1 Account data
When you create an account we collect your name and email address. This is provided directly by you during sign-up and is stored securely via Supabase.
2.2 Profile data
To personalise your regulatory feed, we ask for:
- Nationality and country of residence
- Occupation and employment status
- Life situation details (housing, family, vehicle, healthcare, education, assets) — all optional
- Topic subscriptions (which regulatory areas you follow)
This information is used exclusively to filter and personalise the regulatory alerts we surface for you. It is not used for advertising, profiling, or any purpose beyond delivering the service.
2.3 Usage data
We collect basic technical data when you use the service: pages visited, scan timestamps, and feature usage. This helps us identify bugs and improve the product. We do not track behaviour across third-party websites.
2.4 Payment data
All payments are handled by Stripe. We do not store your card number, CVV, or full payment details on our servers. We receive only a customer ID and subscription status from Stripe to manage your plan.
2.5 Anonymous analytics
We generate anonymised, aggregated snapshots of demographic distributions (e.g. how many users live in France, how many are in the healthcare sector) to understand our user base. These snapshots contain no user ID and cannot be linked back to any individual.
3. How we use your data
- To deliver the service — personalising alerts, running scans, sending email digests
- To manage your account — authentication, plan management, billing
- To communicate with you — regulatory alerts, account notices, product updates (you can unsubscribe at any time)
- To improve the product — analysing aggregate usage patterns and fixing issues
- To comply with legal obligations — where required by law
We do not use your data to serve advertisements. We do not build advertising profiles. We do not sell your data to any third party.
3bis. Legal bases (GDPR art. 6)
We process your data on the following legal bases: performance of the contract(account, scans, alerts, billing), your consent for the optional life-situation fields you choose to fill in — including health-coverage and family information, used solely to personalise your alerts and revocable at any time by clearing the fields in your account — and legitimate interest for service security, debugging, and cost monitoring.
4. Who we share your data with
We share data only with the following service providers, strictly to operate the platform:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database and authentication | All account and profile data |
| Stripe | Payment processing | Email, billing details |
| Resend | Transactional email delivery | Email address, alert content |
| Tavily | Regulatory web search and page content extraction | Search queries, public URLs (no personal identifiers) |
| Google (Vertex AI, European Union) | AI analysis of regulatory content | Regulatory text and the profile attributes needed to personalise the analysis (e.g. nationality, occupation, life situation), processed under the provider's data-processing agreement and not used to train models |
| Plausible Analytics | Privacy-friendly audience measurement | Aggregated page-view statistics only — no cookies, no personal identifiers, no cross-site tracking; data hosted in the EU |
| Cloudflare (Turnstile) | Bot protection on login and sign-up | IP address and browser signals, used solely to distinguish humans from bots |
We do not share your data with any other third parties. We do not sell or rent your data.
5. International data transfers
AI processing takes place inside the European Union. Since 23 August 2026, Google Vertex AI runs for GovToDate in the europe-west4 region (Amsterdam, Netherlands). Your profile — including the life-situation details you choose to provide — therefore does not leave the European Union to be analysed. Because Google remains a provider whose parent company is established in the United States, we continue to rely on its EU-US Data Privacy Framework certification and on Standard Contractual Clauses for any residual access (support, administration).
Other processors are located outside the European Economic Area, mainly in the United States: Tavily (official-source search), Stripe (payments), Vercel and Railway (hosting), and Cloudflare (bot protection). Where personal data is transferred outside the EEA, we rely on the EU-US Data Privacy Framework certification of the provider where available (Stripe, Vercel, Cloudflare) and on the European Commission's Standard Contractual Clauses otherwise. The content of your questions and the profile attributes used to personalise answers transit these processors solely to deliver the service. Plausible Analytics processes and stores its aggregated statistics entirely within the European Union. Your account and profile data are stored by Supabase in the European Union (Frankfurt, Germany) and are not transferred outside the EEA for storage.
6. Data retention
Indicative durations: conversations and profile data are kept until you delete them or your account; internal cost logs are reviewed and purged on a 24-month cycle; usage-learned source pages expire automatically after 180 days without being cited; server-side caches hold fetched public pages for at most 7 days.
We retain your account and profile data for as long as your account is active. If you delete your account, all personally identifiable data is deleted within 30 days. Aggregated anonymous analytics data is retained indefinitely as it cannot be linked to any individual.
Scan results and alert history are retained for up to 24 months to allow you to review your regulatory history. You can request earlier deletion at any time.
7. Your rights
Depending on where you live, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your account and associated data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing in certain circumstances
- Restriction — request that we limit how we process your data
- Complaint — lodge a complaint with a supervisory authority; in France, the CNIL (cnil.fr)
To exercise any of these rights, contact us at privacy@govtodate.com. We will respond within 30 days.
8. Cookies
We use only essential cookies required to keep you logged in and maintain your session. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies that report your behaviour to external services.
For audience measurement we use Plausible Analytics, a cookieless tool that produces only aggregated statistics for our own use: it sets no cookies or persistent identifiers, does not track you across other websites, and its data cannot be cross-referenced with your account. This configuration falls within the CNIL's consent exemption for audience measurement, which is why no cookie banner is shown. Your browser's local storage is used only for functional preferences (theme, language, session state).
9. Security
All data is transmitted over HTTPS. Database access is protected by row-level security policies, meaning each user can only access their own data. Payment data never touches our servers — it is handled entirely by Stripe's PCI-compliant infrastructure.
10. Children
GovToDate is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify you by email. Continued use of the service after changes constitutes acceptance of the updated policy.
12. Contact
For any privacy-related questions or requests, contact us at: privacy@govtodate.com