Your data, explained clearly
Oh Miaou is still a pilot project. The controller’s complete legal identity and postal address must be added before commercial launch.
1. Who is responsible for your data?
The Oh Miaou project lead is currently the data controller. For any question, request or withdrawal of consent, email contact@ohmiaou.com. No data protection officer has been appointed at this stage.
2. What data do we collect?
- Account: name, email, encrypted password digest, account and session dates.
- Cat profile: name, age or birth date, optional breed, lifestyle, play preferences and the companionship goal you choose.
- Private companionship journal: selected photos, captions, short moments, optional notes and their dates. They are available to the journal owner and to the people the owner explicitly invites into the private circle. Export to another app happens only when you initiate it.
- Weekly rituals and recaps: the suggested attention, your selected reaction and recaps computed from journal entries. Oh Miaou does not request health data to personalise these suggestions.
- Mobile app and notifications: platform, app version, language, time zone, notification setting and a protected device token when you enable reminders.
- Limited app measurement: predefined functional steps such as activation, profile completion, ritual interaction, moment creation, recap use and web-selection opens. Journal titles, notes, captions and photos are never copied into those events.
- Mobile app diagnostics: errors, sampled technical traces, app version and build, platform, operating system, device model and technical state. Oh Miaou sends Sentry no name, email address or account identifier; the native Android SDK may nevertheless attach a pseudonymous installation identifier to correlate crashes from the same device. Screenshots and view hierarchy capture are disabled, and JavaScript events are scrubbed of cookies, headers, bodies, query parameters and free-form fields. Sentry may also infer an approximate geographic area from the network transport; the raw IP address is not retained in the project.
- Play survey: your cat’s age group, living environment, household size, play preferences, frustrations, buying habits, recent spending range, pilot interest, discovery channel and optional comments.
- Contact choices: your email only when you ask for the study summary or launch news, together with the date and scope of your consent.
- Attribution: limited campaign parameters such as source, medium and campaign, used to understand how people found the survey.
- Interest list: email and consent choices.
- Quiz referral: verified sponsor account identifier, personal code, progress, verified participant account identifier and a pseudonymous identifier for each validated quiz. The participant account is used only to prevent fake profiles, self-referrals and duplicate credits; it does not subscribe anyone to communications. The signed proof contains neither a participant email nor quiz answers.
- Mobile feedback and reports: category, reason, optional details, technical identifiers for the journal, content or collaboration concerned, and your email only when you ask for a reply. No photo or journal text is attached automatically.
- Technical data: session, security and browser information needed to operate and protect the service.
No payment card details are requested by the survey or interest list.
3. Why do we use it?
- To provide the cat profile, private journal, personalised weekly attention and recap you request.
- To deliver app reminders you have enabled. Push permission is separate from marketing consent.
- To analyse aggregated needs and improve the app, based on Oh Miaou’s legitimate interest in making the service useful and reliable.
- To detect and fix mobile app errors and slowdowns from minimised technical diagnostics, based on Oh Miaou’s legitimate interest in maintaining a reliable and secure service. Any approximate area inferred by Sentry is used neither for personalisation nor advertising.
- To send the study summary or launch information when you have explicitly consented.
- To review mobile feedback and reports, moderate the private circle and take proportionate action when necessary.
- To prevent abuse, keep the site secure and respond to your requests.
Your answers do not create an order, reservation or payment. Personal data is not sold.
4. How long do we keep it?
- Account, cat profiles, journal, photos, rituals, reactions and recaps: for the life of the account, then deleted when it is closed unless a specific legal obligation applies.
- Mobile installations and notification tokens: while notifications remain enabled on that device, for no more than 180 days without contact from the app, or until the account is closed. A token reported invalid by the delivery service is deleted as soon as that feedback is processed.
- Survey responses: no longer than 18 months after the study closes, unless you request earlier deletion.
- Study-summary email: until the summary is sent or you withdraw consent.
- One-off cat portrait email: the address is used to complete that delivery but is not added to an Oh Miaou list without a separate recurring consent. The email provider’s technical records follow its contractual retention period.
- Mobile feedback and reports: while under review, then for no more than 12 months after closure to document the decision and repeated abuse, unless longer retention is needed to establish, exercise or defend a legal claim.
- Marketing consent: until withdrawal. Contact-list addresses are then deleted or immediately detached from retained research answers. A non-reversible HMAC fingerprint is kept for three years solely to prevent accidental re-enrolment.
- Pseudonymous measurement events: no longer than 13 months. A weekly automated purge removes older events; abuse-limiting identifiers and expired verifications have shorter retention periods.
- Sentry diagnostics: during the current new-account trial, for no more than 90 days for error events and 30 days for full performance traces. A later move to the Developer plan would reduce both periods to 30 days. Service backups are deleted no later than 90 days after creation. Control events may be removed sooner from Sentry.
- Security logs, if enabled: only for a proportionate incident-analysis period, with a target maximum of 12 months.
5. Who can access it?
Access is limited to the project lead and the technical providers strictly needed for hosting, databases, authentication, analytics and transactional email. Resend carries transactional emails, mobile feedback and reports. The legal identity and region of the managed PostgreSQL provider still need to be confirmed before commercial launch. Any transfer outside the European Economic Area must rely on a recognised GDPR safeguard.
Sentry (Functional Software, Inc.) processes minimised mobile crash and performance diagnostics. The project’s event data is hosted in Sentry’s European region in Germany. Server-side scrubbers are enabled and raw IP address storage is disabled, although an approximate geographic area may still be inferred while a diagnostic is processed. Account and service-configuration data are part of a global control plane. The DPA and safeguards applicable to any transfers must be accepted and archived before commercial launch.
The S3-compatible provider for connected private photos has not yet been selected. Connected photo uploads will remain disabled until its legal identity, storage region, data-processing agreement and any international transfers are documented in this notice.
6. Analytics and local storage
The mobile app keeps only the local information needed to operate: session, preferences, private cache and files awaiting upload. This state is separated by account. Signing out removes session secrets and private cached data; confirmed account deletion also clears the associated local state.
Optional measurement may use Plausible Analytics, Vercel Analytics, Google Analytics and Google Ads, depending on the active configuration. None is loaded before you explicitly accept in the consent banner. Before that choice, no navigation event is sent, no visitor identifier is created and no campaign attribution is stored. Measurement consent does not enable ad personalisation or user-data sharing with Google.
“Reject all” and “Accept all” have equal prominence. You can change or withdraw your choice at any time with the “Manage trackers” button. Withdrawal removes Oh Miaou’s stored visitor identifier and attribution, and prevents optional measurement tools from loading again.
On the first visit to the homepage, the browser may locally indicate a French or English preference. This language detection uses neither geolocation nor a third-party service. The functional ohmiaou_locale cookie keeps the language detected or selected for twelve months, and a manual choice always takes priority. It is not used for advertising or profiling.
7. Your rights
Depending on the processing, you may request access, correction, deletion, portability or restriction, object to processing based on legitimate interests, and withdraw consent at any time. Contact contact@ohmiaou.com. We normally reply within one month.
You may also complain to the French data protection authority, the CNIL.
8. Changes and security
Access is authenticated, passwords are not stored in plain text and data should be encrypted in transit. This notice will be completed as the pilot becomes a commercial service, and material changes will be announced before they take effect.