Privacy Policy

Last updated: MM/DD/YYYY · Version: 1.0

GDPR compliant (EU Regulation 2016/679) and aligned with third-party platform requirements (Meta Platform Terms, TikTok Developer Policy, Google API Services User Data Policy, LinkedIn API Terms). We apply principles of minimization, transparency, explicit consent and security by default.

1. Data controller

2. Data collected

CategorySpecific dataGDPR legal basis
AccountFirst name, last name, email, password (bcrypt hashed), registration dateContract performance (art. 6.1.b)
BillingBilling address, payment history (amounts, dates, PDF invoices)Legal accounting obligation (10 years, art. 6.1.c)
PaymentNo banking data stored. Full processing by Stripe (PCI-DSS level 1).Contract performance
Application usageAction logs, submitted prompts, generated content, quota usage metricsContract + legitimate interest (product improvement)
Platform OAuth tokensAccess tokens, refresh tokens, granted scopes (AES-256 encrypted)Explicit consent (art. 6.1.a)
Data from social networksSee section 4 (detailed by platform)Explicit consent
Technical dataIP address, browser type, OS, language, pages visited, session durationLegitimate interest (security, fraud prevention, aggregated stats)
Marketing communicationsEmail for newsletters, product notifications, commercial offersConsent (opt-in, unsubscribe possible anytime)

3. Processing purposes

We never sell your data to third parties. No personal data is used for external advertising purposes.

4. Data from third-party platforms (OAuth)

When you connect your account to a third-party platform via OAuth, Aria CEO accesses only the data strictly necessary for the requested features. You can revoke this access anytime from your account or the third-party platform settings.

4.1 Meta (Instagram & Facebook)

Scopes: instagram_basic, instagram_content_publish, pages_show_list, pages_read_engagement, pages_manage_posts, business_management, email, public_profile.

Data retrieved: basic profile info, list of your Facebook Pages and Instagram Business accounts, engagement metrics on your own posts, media published via Aria CEO.

4.2 TikTok

Scopes: user.info.basic, video.list, video.upload, video.publish.

4.3 Google & YouTube

Sign in scopes: openid, email, profile. YouTube scopes if enabled: youtube.upload, youtube.readonly. Compliance with Google API Services User Data Policy and Limited Use requirements.

4.4 LinkedIn

Scopes: openid, profile, email, w_member_social.

4.5 Apple (Sign in with Apple)

Data retrieved: Apple ID, email (real or relayed), name (optional). Compliance with Apple Sign In Guidelines.

5. Sub-processors and recipients

Sub-processorRoleLocationGuarantees
SupabaseUser database & authEU (Paris/Frankfurt)GDPR · DPA · SOC 2
VercelWebsite & API hostingUSASCC · DPA · ISO 27001
StripePayment processingEU (Ireland) + USAPCI-DSS L1 · SCC · DPA
Meta PlatformsOAuth Instagram & FacebookEU + USASCC · DPA
TikTokOAuth TikTokEU + otherSCC · DPA
GoogleOAuth Sign in / YouTubeEU + USASCC · DPA
LinkedInOAuth LinkedInEU (Ireland) + USASCC · DPA
AppleSign in with AppleUSASCC

6. Non-EU transfers

Some sub-processors are located in the United States. These transfers are governed by Standard Contractual Clauses (SCC) approved by the European Commission, ensuring protection equivalent to GDPR. For US transfers, we also rely on the Data Privacy Framework when sub-processors are certified.

7. Retention period

8. Data security

9. Your GDPR rights

To exercise these rights, write to contact.ariaceo@gmail.com with proof of identity. Response within 1 month maximum.

10. Account & data deletion

See dedicated page: Account deletion and User data deletion.

11. Cookies

Detailed in our Cookies Policy. No advertising or profiling cookie is used without your explicit consent.

12. Minors

Aria CEO is strictly reserved for adults (18+). We do not knowingly collect minors' data. If a minor created an account by mistake, contact us for immediate deletion.

13. Policy changes

This policy may be updated. You'll be notified by email of substantial changes at least 30 days before they take effect.

14. Contact & complaint

If you believe your rights are not respected, you can file a complaint with the CNIL (French data protection authority): cnil.fr · 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.