Privacy policy
Last updated: September 2026
1. Data controller
Aurélien Créchet, sole trader. Contact: contact@copalio.fr
2. Data collected and purposes
- First name, surname, email. Purpose: creating and managing the account. Legal basis: performance of the contract
- Hashed password. Purpose: authentication. Legal basis: performance of the contract
- Google or Apple sign-in identifier, if you use that sign-in method. Purpose: authentication. Legal basis: performance of the contract
- Stripe billing data. Purpose: managing the subscription. Legal basis: performance of the contract
- Co-parenting data (children, schedule, expenses, messages, notes, address book, incident log, documents). Purpose: providing the service. Legal basis: performance of the contract
- Push notification tokens (browser, Android and iOS mobile apps). Purpose: sending the notifications you turn on. Legal basis: consent
- Photo of a child, if a parent adds one. Purpose: visual identification of the child in the app. Legal basis: performance of the contract
- Hashed IP address, timestamps. Purpose: security and fraud prevention. Legal basis: legitimate interest
- Feedback given voluntarily at the end of a trial or after a cancellation (reason selected, optional free-text comments, email address, hashed IP address). Purpose: improving the service. Legal basis: legitimate interest
Feedback and reviews
The emails sent at the end of a trial and following a cancellation contain a link to a feedback form. This link carries a signed identifier, valid for 30 days, whose only purpose is to prefill your email address: it gives no access to your account or to the data in your family space. The form can also be reached without this link; you then type in the address yourself, and you may leave it blank.
Giving feedback is optional and has no effect on your account, your subscription or your data. Free-text comments are encrypted at rest (AES-256), like messages and notes. Your email address, if you provide it, is used only to reply to you: it is not added to any mailing list and is not passed on to any third party.
3. Security measures
- Email addresses indexed by SHA-256 fingerprint, never stored in plain text
- Messages, notes and sensitive information encrypted with AES-256 on our servers
- Passwords hashed with bcrypt
- Communications encrypted with HTTPS/TLS
- Payments processed by Stripe (PCI-DSS Level 1): no bank details on our servers
Messages and notes are encrypted at rest: the data is stored encrypted and decrypted only to be shown to you in the app. This is not end-to-end encryption. The publisher refrains from accessing the content of exchanges between parents, except where required by law or by a request from a competent authority.
Images uploaded in the app
Images uploaded in the app (expense receipts, attachments to notes and to the incident log, images in messages, photo of a child) are stored on our servers outside the web root: they cannot be reached from any public address. They are shown only to the registered members of the family space concerned, after authentication. Unlike messages and notes, these files are not encrypted at rest.
A photo of a child is optional. Either parent can add, replace or remove it at any time, from the “My family” page. It is visible only to the registered members of the family space: it does not appear in documents shared by link, in exportable summaries and case files, or in any email.
Image moderation
Any image uploaded in the app may be reviewed by the publisher, either following a report by a user, or as part of the checks on children’s photos, which are recorded for that purpose as soon as they are added. The sole purpose of this review is to check that the content complies with the rules, and it is based on our legitimate interest in preventing unlawful use of the service. An image found to be non-compliant is made inaccessible in the app, and the ability to add images may be suspended for the account concerned. A non-compliant image is not erased: it is kept offline and may be passed on to the competent authorities upon lawful request.
4. Retention periods
- User account: for the duration of the contract. If the account is deleted, the profile is anonymised immediately (see the “Deleting your account and your data” page)
- Family space with no active subscription: paused, data kept for 3 months, then permanently erased
- Security logs: 12 months
- Billing data: 10 years (legal obligation)
- Invitations not accepted: 30 days
- Photo of a child: erased immediately when it is removed or replaced, when the child is removed from the family space, and when the family space is deleted or reaches the end of its retention period. The only exception is an image found to be non-compliant during moderation, which is kept offline
- Audience measurement: 13 months (anonymous data, see section 7)
- Feedback given: 12 months for the elements that identify you (email address, free-text comments, hashed IP address, link to your account). They are erased at the end of that period. Only anonymous data remains (reason selected, language, date), kept for statistical purposes. You can ask for feedback to be erased before then by writing to contact@copalio.fr
Content created in a family space (schedule, expenses, messages, notes, incident log) belongs to that space and stays available to the other members after one of them leaves or deletes their account. The conditions under which it is erased are set out on the Deleting your account and your data page.
5. Recipients
Your data is neither sold nor transferred. We use only the processors strictly necessary for the service to work:
- IONOS SARL, a subsidiary of IONOS SE (hosting): servers located in Germany, European Union
- Stripe Inc. (payment): transfers covered by the EU standard contractual clauses
- Google LLC (optional Google sign-in): transfers covered by the EU standard contractual clauses
- Apple Inc. (optional Apple sign-in): transfers covered by the EU standard contractual clauses
- Google LLC (Firebase Cloud Messaging, for push notifications in the mobile apps if you turn them on): transfers covered by the EU standard contractual clauses
Sharing documents by link: when you create a sharing link (summary, case file, report), anyone who has the link can view the document for as long as it is valid (60 days at most). You can revoke the link at any time from the app. This sharing is entirely your own decision.
6. Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, portability and objection.
- Portability: you can export all the data in your family space at any time, in CSV and text format, from your settings, including while the space is paused
- Erasure: see the “Deleting your account and your data” page
To exercise your rights: contact@copalio.fr. We reply within 30 days. Some erasure requests concern content shared with another parent: they are considered against the rights and freedoms of the other people involved. You can lodge a complaint with the CNIL (the French data protection authority) or with the data protection authority of the EU member state where you live.
7. Audience measurement
Copalio uses an in-house audience measurement system, with no cookies or third-party trackers, hosted on our own servers in the European Union. The data collected is strictly limited to: the page viewed, the type of device (mobile, tablet, computer), the browser and the operating system. No IP address is kept: an anonymous identifier is generated by cryptographic hashing with a salt that changes every day, which makes it impossible to follow a visitor beyond 24 hours. This data is kept for 13 months at most, for purely statistical purposes, is never matched with your user account and is never passed on to a third party. In line with the CNIL recommendation on audience measurement cookies, this processing is exempt from prior consent.
8. Cookies
Copalio uses only cookies that are strictly necessary for the service to work (session, CSRF protection). No advertising cookies or third-party tracking cookies are set. The in-house audience measurement (see section 7) does not use cookies.