Privacy

Privacy notice

Last updated 2026-05-07. Plain language, written to be readable. The legal articles cited below are the actual basis we rely on.

Who we are (data controller)

Songe is operated by Tanguy Delume, individual entrepreneur registered in France [PLACEHOLDER: SIREN, VAT, registered address]. For any privacy question or data-subject request, contact tanguydelume@gmail.com.

We have not appointed a Data Protection Officer because the activity does not meet the conditions of GDPR Art. 37 (no large-scale special-category processing, no public authority). The contact above handles all data-subject matters directly.

What we collect, why, and on what legal basis

For each purpose, the legal basis under GDPR Art. 6 is given in parentheses.

  • Account & authentication — email, hashed password, optional Google profile claims (name, picture, sub-id) when you sign in with Google. (Art. 6(1)(b) — performance of contract.)
  • Generated content — your text prompts, reference images you upload, and the 3D scenes / renders we produce. (Art. 6(1)(b).)
  • Billing records — credit transactions, Stripe customer / subscription IDs, invoices. (Art. 6(1)(b) for processing the payment; Art. 6(1)(c) for the 10-year retention required by French Code de commerce L123-22.)
  • Operational logs — request URL, status, duration, IP, user-agent, error traces. (Art. 6(1)(f) legitimate interest — service stability + abuse prevention; balancing test on file.)
  • Safety / moderation logs — prompts flagged by our content classifier, login attempts, abuse signals. (Art. 6(1)(f) — protecting the service and third-party rights; required by EU Digital Services Act Art. 16.)
  • Transactional email — welcome, billing receipts, security alerts. (Art. 6(1)(b).) We do not send marketing email without separate consent.

We do not use your prompts, reference images, or generated outputs to train AI models. Anthropic, our model provider, processes API inputs under a zero-retention policy as part of our contract with them.

How long we keep it (retention)

  • Account: until you delete it via /profile.
  • Generated scenes (free tier): 30 days from creation, then auto-purged.
  • Generated scenes (paid tiers): for the contractual term plus 30 days.
  • Prompts & reference images: same as the scene they belong to.
  • Operational logs: 12 months maximum (CNIL recommendation).
  • Safety / moderation logs: 12 months for repeat-abuse detection, then purged.
  • Billing records: 10 years from the end of the financial year (French Code de commerce L123-22).
  • Backups: overwritten on a 30-day rolling cycle.

Who else processes your data (sub-processors)

We use the following sub-processors. Each is bound by a Data Processing Agreement.

  • Anthropic, PBC (United States) — model inference (Claude). Zero-retention API. Privacy policy.
  • Cloudflare, Inc. (United States) — hosting (Pages), CDN, DDoS / bot protection. Privacy policy.
  • Neon, Inc. (United States, EU region selectable) — managed Postgres database. Privacy policy.
  • Stripe Payments Europe Ltd. (Ireland / United States) — payment processing. Card data never touches our servers. Privacy policy.
  • Resend, Inc. (United States) — transactional email delivery. Privacy policy.
  • Google LLC (United States) — only when you choose "Sign in with Google." We receive a basic OAuth profile (sub-id, email, name, picture).

We will give 30 days' notice before adding or changing a sub-processor by updating this page and emailing registered users (GDPR Art. 28(2)).

International transfers

The sub-processors above process data in the United States and other countries outside the EEA. Transfers rely on:

  • The EU-US Data Privacy Framework adequacy decision for sub-processors certified under it (Anthropic, Cloudflare, Stripe, Resend); and
  • The European Commission's Standard Contractual Clauses (2021/914) for any sub-processor not covered by the DPF.

AI transparency (EU AI Act)

Songe is a generative AI service within the meaning of the EU AI Act. We comply with Art. 50(2) (effective 2 August 2026):

  • Generated outputs are clearly identified as AI-generated in the user interface.
  • Exported scene files include machine-readable provenance metadata (C2PA-compatible) identifying the content as AI-generated where the file format supports it.

Songe is not classified as a "high-risk AI system" under Annex III of the AI Act.

No automated decisions about you

We do not make decisions producing legal or similarly significant effects about you solely by automated means within the meaning of GDPR Art. 22. Our prompt classifier may flag a prompt as policy-violating; you can challenge that decision by emailing tanguydelume@gmail.com and a human will review.

Your rights

Under GDPR and the French Loi Informatique et Libertés, you have the right to:

  • Access the data we hold about you (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (Art. 17 — "right to be forgotten")
  • Restrict processing (Art. 18)
  • Receive a portable copy in a machine-readable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw any consent you have given (Art. 7)
  • Define directives for what happens to your data after death (Art. 85 LIL — French specificity); without directives, your account is closed and data deleted on proof of death from a representative.

The fastest path: /profileDelete account, which removes account, scenes, billing history, and subscriptions immediately and irreversibly. Or email tanguydelume@gmail.com; we respond within 30 days (the GDPR Art. 12 deadline).

You also have the right to lodge a complaint with the French data protection authority, the CNIL: cnil.fr/en/plaintes.

Children

Songe is not directed at children. The minimum age of use is 15 years (the French digital-consent age under Loi Informatique et Libertés Art. 45). Where applicable, COPPA (United States) sets a 13-year floor; we do not knowingly process the personal data of users under 15. If you become aware that a minor has created an account, contact us and we will delete it.

Cookies

We set one cookie: the authjs.session-token session cookie that keeps you logged in. It is "strictly necessary" for service operation and is exempt from the consent requirement under ePrivacy Directive Art. 5(3) and the CNIL 2020 guidelines. We do not use third-party analytics, advertising pixels, or any other tracking technology that would require a consent banner.

Security and breach notification

We protect your data with TLS in transit, at-rest encryption on the database, hashed passwords (bcrypt), least-privilege access controls, and monitoring. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours (Art. 33) and notify you directly without undue delay (Art. 34) where the risk is high.

Changes to this notice

If we change anything material, we will email registered users at least 14 days before the change takes effect and update the "Last updated" date. Routine clarifications that do not affect your rights may be made without notice.

Contact

Privacy questions, data-subject requests, or to report a concern: tanguydelume@gmail.com.