Privacy policy
Last updated: 12 August 2026
1. Data controller
The data controller is Yelhaa AI, publisher of the Yelhaa service, a company incorporated in France.
Its full company details — legal form, share capital, registration numbers, registered office and hosting providers — are set out in the legal notice.
Any request concerning your personal data goes to fondateur@yelhaa.info.
Processing is governed by Regulation (EU) 2016/679 (GDPR) and by French law n° 78-17 of 6 January 1978, known as the loi Informatique et Libertés. The competent supervisory authority is the CNIL (Commission nationale de l'informatique et des libertés).
2. Data minimisation
Only the data required to run your account and the service is collected. There is no advertising profiling, no resale of data, and no automated decision-making producing legal effects within the meaning of Article 22 GDPR.
3. Data processed, purposes and legal bases
The table below lists what the service actually records, as it appears in its database schema.
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address, account identifier, creation date | Create and maintain the account, authenticate access | Performance of a contract — art. 6(1)(b) |
| Plan, Stripe customer and subscription identifiers, renewal date | Manage the subscription and access to quotas | Performance of a contract — art. 6(1)(b) |
| Monthly generation counter and current period | Enforce the plan quota | Performance of a contract — art. 6(1)(b) |
| Ideas you submit, generated prompts, chosen template and domain, number of re-selections | Provide the service and give you access to your history | Performance of a contract — art. 6(1)(b) |
| Name, email, message and consent from the contact form | Answer your request | Consent — art. 6(1)(a) |
| Technical logs and rate-limiting counters | Service security, abuse prevention | Legitimate interest — art. 6(1)(f) |
| Accounting records relating to payments | Comply with accounting and tax obligations | Legal obligation — art. 6(1)(c) |
No payment card data is ever received or stored by Yelhaa. Payment is handled entirely by Stripe, which collects that data as a controller in its own right for that operation.
4. Recipients and processors
Data is shared only with the providers strictly necessary to run the service. Each acts on documented instructions, under a contract compliant with Article 28 GDPR.
| Provider | Role | Data concerned |
|---|---|---|
| Supabase | Authentication and database | Account, generations, counters, contact messages |
| Stripe | Payment and subscription management | Customer and subscription identifiers, payment data |
| OpenAI | Generation engine and chat | The idea you type, attached file text, and the produced prompt |
Some of these providers may process data outside the European Union. Such transfers are covered by the European Commission's standard contractual clauses or by an adequacy decision, in accordance with Chapter V GDPR.
5. Processing by the generation engine
The idea you type is processed by the generation engine — OpenAI, on infrastructure operated by that provider — in order to produce your prompt. Do not enter special categories of personal data within the meaning of Article 9 GDPR (health, political opinions, religious beliefs, sexual orientation, biometric data), nor trade secrets you would not want leaving your machine.
The text you submit is treated as data, never as an instruction to the system: a command hidden inside an idea is not executed.
6. Retention periods
- Account and generations: kept for as long as the account exists, then deleted when the account is deleted.
- Contact form messages: kept for as long as needed to handle and follow up on the request.
- Accounting records: kept for ten years, in accordance with article L123-22 of the French Code de commerce.
- Technical security logs: kept for a limited period, proportionate to the abuse-prevention purpose.
Periods not set by law are decided by the publisher and reviewed whenever the service changes.
7. Your rights
You have the following rights over your personal data:
- Right of access (art. 15 GDPR) — confirm whether your data is processed and obtain a copy of it.
- Right to rectification (art. 16) — have inaccurate data corrected.
- Right to erasure (art. 17) — have your data deleted.
- Right to restriction of processing (art. 18).
- Right to data portability (art. 20) — receive your data in a structured, machine-readable format.
- Right to object (art. 21), in particular to processing based on legitimate interest.
- Right to withdraw consent at any time (art. 7(3)), without affecting the lawfulness of processing carried out before withdrawal.
- Right to give directions on what happens to your data after your death (art. 85 of the loi Informatique et Libertés).
Deleting your account and its associated data is available directly from the Account page. For anything else, write to the address given in section 1.
If you believe your rights are not being respected, you may lodge a complaint with the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr).
8. Security
- Access to data is partitioned per user at the database level (row level security): a session can only read its own rows.
- API keys and internal secrets are never stored in user data, nor exposed to the browser.
- Contact form messages can neither be read nor written from the browser: they are inserted exclusively through a server route.
- Sensitive endpoints are rate-limited.
9. Data breaches and applicable penalties
In the event of a personal data breach likely to result in a risk to your rights and freedoms, the CNIL is notified within 72 hours (art. 33 GDPR) and you are informed without undue delay where the risk is high (art. 34).
Failure to meet these obligations is punishable. Beyond the administrative fines under Article 83 GDPR — up to €20 million or 4% of total worldwide annual turnover — the French Code pénal notably provides:
- Article 226-17 — failure to implement security measures protecting personal data: five years' imprisonment and a €300,000 fine.
- Article 226-18 — collecting data by fraudulent, unfair or unlawful means: five years' imprisonment and a €300,000 fine.
- Article 226-21 — using data for a purpose other than the one it was collected for: five years' imprisonment and a €300,000 fine.
- Article 226-22 — disclosure harming the reputation or privacy of the person concerned: five years' imprisonment and a €300,000 fine.
10. Cookies and trackers
The service sets only the cookies strictly necessary for it to work, notably those keeping your session authenticated. These are exempt from consent under article 82 of the loi Informatique et Libertés.
No advertising cookie and no consent-requiring analytics tracker is set. Were that to change, a consent banner would be put in place before any such cookie is set, with refusing as simple as accepting.
11. Minors
The service is not intended for people under 15. In France, a minor's consent to the processing of their data in the context of an online service is only valid from that age (art. 45 of the loi Informatique et Libertés); below it, the authorisation of the holder of parental authority is required.
12. Changes
Any substantial change to this policy is brought to your attention before it takes effect, and the date at the top of this page is updated.
© 2026 Yelhaa