Last updated: MM/DD/YYYY · Version: 1.0
| Category | Specific data | GDPR legal basis |
|---|---|---|
| Account | First name, last name, email, password (bcrypt hashed), registration date | Contract performance (art. 6.1.b) |
| Billing | Billing address, payment history (amounts, dates, PDF invoices) | Legal accounting obligation (10 years, art. 6.1.c) |
| Payment | No banking data stored. Full processing by Stripe (PCI-DSS level 1). | Contract performance |
| Application usage | Action logs, submitted prompts, generated content, quota usage metrics | Contract + legitimate interest (product improvement) |
| Platform OAuth tokens | Access tokens, refresh tokens, granted scopes (AES-256 encrypted) | Explicit consent (art. 6.1.a) |
| Data from social networks | See section 4 (detailed by platform) | Explicit consent |
| Technical data | IP address, browser type, OS, language, pages visited, session duration | Legitimate interest (security, fraud prevention, aggregated stats) |
| Marketing communications | Email for newsletters, product notifications, commercial offers | Consent (opt-in, unsubscribe possible anytime) |
We never sell your data to third parties. No personal data is used for external advertising purposes.
When you connect your account to a third-party platform via OAuth, Aria CEO accesses only the data strictly necessary for the requested features. You can revoke this access anytime from your account or the third-party platform settings.
Scopes: instagram_basic, instagram_content_publish, pages_show_list, pages_read_engagement, pages_manage_posts, business_management, email, public_profile.
Data retrieved: basic profile info, list of your Facebook Pages and Instagram Business accounts, engagement metrics on your own posts, media published via Aria CEO.
Scopes: user.info.basic, video.list, video.upload, video.publish.
Sign in scopes: openid, email, profile. YouTube scopes if enabled: youtube.upload, youtube.readonly. Compliance with Google API Services User Data Policy and Limited Use requirements.
Scopes: openid, profile, email, w_member_social.
Data retrieved: Apple ID, email (real or relayed), name (optional). Compliance with Apple Sign In Guidelines.
| Sub-processor | Role | Location | Guarantees |
|---|---|---|---|
| Supabase | User database & auth | EU (Paris/Frankfurt) | GDPR · DPA · SOC 2 |
| Vercel | Website & API hosting | USA | SCC · DPA · ISO 27001 |
| Stripe | Payment processing | EU (Ireland) + USA | PCI-DSS L1 · SCC · DPA |
| Meta Platforms | OAuth Instagram & Facebook | EU + USA | SCC · DPA |
| TikTok | OAuth TikTok | EU + other | SCC · DPA |
| OAuth Sign in / YouTube | EU + USA | SCC · DPA | |
| OAuth LinkedIn | EU (Ireland) + USA | SCC · DPA | |
| Apple | Sign in with Apple | USA | SCC |
Some sub-processors are located in the United States. These transfers are governed by Standard Contractual Clauses (SCC) approved by the European Commission, ensuring protection equivalent to GDPR. For US transfers, we also rely on the Data Privacy Framework when sub-processors are certified.
To exercise these rights, write to contact.ariaceo@gmail.com with proof of identity. Response within 1 month maximum.
See dedicated page: Account deletion and User data deletion.
Detailed in our Cookies Policy. No advertising or profiling cookie is used without your explicit consent.
Aria CEO is strictly reserved for adults (18+). We do not knowingly collect minors' data. If a minor created an account by mistake, contact us for immediate deletion.
This policy may be updated. You'll be notified by email of substantial changes at least 30 days before they take effect.
If you believe your rights are not respected, you can file a complaint with the CNIL (French data protection authority): cnil.fr · 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.