Privacy Policy
Last updated 2026-08-18
This privacy policy covers two distinct processing activities, presented separately:
- The
usekayu.comwebsite — the marketing site you are currently reading. It is the subject of sections 1 to 8. - The Kayu mobile app — the iOS app downloaded from the App Store. Its broader processing is described in the "The Kayu app" section further down.
The data controller is the same for both: Lucas Tostee (see §1).
1. Who we are (the controller)
The usekayu.com website and the Kayu app are published by Lucas Tostee, sole proprietor (auto-entrepreneur / micro-entreprise regime), registered in France.
- Controller within the meaning of GDPR Art. 4(7): Lucas Tostee.
- Registered address: 66 rue des Remparts, 33000 Bordeaux, France.
- SIRET: 830 928 412 00014 (SIREN 830 928 412).
- Privacy contact:
app.kayu@gmail.com. - No Data Protection Officer (DPO) is appointed. The processing described does not require one under GDPR Art. 37: Kayu performs neither large-scale systematic monitoring nor large-scale processing of special-category data.
- Kayu is established in the European Union; no EU representative under GDPR Art. 27 is required.
2. What the website collects
The usekayu.com website is a marketing site. It has no form, no sign-up, no email capture, and no waitlist. It sets no advertising cookie and performs no cross-site tracking.
The site uses only the following:
- A locally stored country vote (
kayu-site-vote). If you indicate which country you would like Kayu to cover, your choice is stored in your browser'slocalStorage, on your device. This data contains no personal information, is tied to no identifier, and is never sent to a server: it only remembers that you have already voted. You can clear it at any time by clearing the site's data in your browser. - A dismissed-banner flag (
kayu-sticky-dismissed). If you close the floating download button, that fact is stored in your browser'ssessionStorageso it does not come back during the same visit. It contains no personal information, is tied to no identifier, is never sent to a server, and disappears when you close the tab. - A language cookie (
NEXT_LOCALE). A strictly functional cookie that remembers your language preference (French or English) so the site displays in the right language. It is exempt from consent under Article 82 of the French Data Protection Act (a cookie strictly necessary for the service you requested). - Cookieless audience measurement (Vercel Web Analytics). See §3.
The two browser-storage entries above are display preferences you asked for by acting on them, and neither builds a profile or follows you anywhere. Like the language cookie, they fall outside the consent requirement of Article 82 of the French Data Protection Act.
3. Website audience measurement (Vercel Web Analytics)
The site uses Vercel Web Analytics, a cookieless audience-measurement tool.
- Purpose: to measure site traffic in aggregate (page views, popular pages, approximate origin), in order to understand what interests visitors and improve the site.
- How it works: the tool sets no cookie, generates no persistent identifier, and does not track visitors across sites. Measurements are aggregated; no reusable individual record is built.
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — knowing the traffic to our own marketing site, a routine interest whose impact on you is minimal since no profile is built and no data is sold.
- Retention: aggregate audience data is kept by Vercel for the duration of our analytics subscription (at most 24 months), then deleted or consolidated into anonymous statistics.
- Why there is no cookie banner: in line with the CNIL's guidance on audience measurement, an audience-measurement tool is exempt from consent when it is strictly limited to measuring the site's own audience, sets no cookie or tracker within the meaning of Article 82, does not cross-reference data with other processing, does not track browsing across sites, and does not serve advertising. Vercel Web Analytics meets these conditions: it is cookieless, has no cross-site tracking, and no advertising purpose. No consent banner is therefore required.
You retain a right to object to this legitimate-interest processing (GDPR Art. 21): write to us at app.kayu@gmail.com.
4. Who receives the website's data (processors)
- Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) — host of the site and provider of the cookieless audience measurement. Acts as a processor under a Data Processing Agreement (DPA). Any transfers to the United States are safeguarded (see §6).
The marketing site itself shares no data with the other providers listed below: those are involved only for the mobile app (see the "The Kayu app" section).
5. Your rights (site and app)
Under GDPR (Articles 15 to 22) and Quebec Law 25 (sections 27 and following), you have the right to:
- Access (Art. 15) — obtain a copy of the data we hold about you.
- Rectification (Art. 16) — correct inaccurate data. One exception we state up front: if you sign in to the app with an email address, that address is the identifier of your account and is fixed when the account is created. Neither you nor we can change it afterwards — to use a different address, delete the account and create a new one (see §E).
- Erasure (Art. 17) — delete your data. For the app, delete your account at Settings → Account → Delete account; a few records sit outside the account and are removed by email instead. Section E sets out what each route covers.
- Restriction (Art. 18) — pause processing.
- Portability (Art. 20) — receive your data in a structured, machine-readable format.
- Object (Art. 21) — object to legitimate-interest processing, including the site's audience measurement.
- Withdraw consent at any time where consent is the basis (Art. 7(3)).
To exercise these rights, write to app.kayu@gmail.com. We respond within one month (GDPR Art. 12(3)).
6. International transfers
The site's audience-measurement and hosting data may be processed by Vercel Inc. in the United States. This transfer is safeguarded by the European Commission's Standard Contractual Clauses (GDPR Art. 46) incorporated into Vercel's Data Processing Agreement, and where applicable by Vercel's certification under the EU–US Data Privacy Framework.
App data controlled by Kayu is processed entirely in the European Union (AWS eu-west-3, Paris). Two nuances, stated plainly because they would otherwise look like gaps:
- Sign in with Apple involves Apple Inc. processing your authentication in the United States, under the EU–US Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795).
- A sign-in code leaves Paris and is then delivered to the mailbox provider you chose. If that provider stores mail outside the EEA — Gmail, Outlook.com and iCloud all do, at least in part — the message reaches you there. That last leg is not something we can route: you chose the address, and delivering to it is exactly what you asked us to do. Sign in with Apple avoids it entirely, because no code is sent.
Apart from those, no transfer outside the EEA takes place.
7. Right to lodge a complaint
If you believe we have not handled your data correctly, you can complain to your supervisory authority. We will not retaliate.
- France (CNIL): Commission Nationale de l'Informatique et des Libertés, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
www.cnil.fr. - Quebec (Commission d'accès à l'information): 525, boulevard René-Lévesque Est, Bureau 2.36, Québec (Québec) G1R 5S9.
www.cai.gouv.qc.ca. - Other EEA users: your local supervisory authority — list at
https://edpb.europa.eu/about-edpb/about-edpb/members_en.
8. Changes to this policy
This policy may evolve as Kayu grows. The "Last updated" date at the top reflects the most recent change. Previous versions remain available in our public Git history.
The Kayu app
The section below concerns the Kayu mobile app (iOS), which is distinct from the marketing site above. The app processes more data because it lets you optionally create an account. The controller remains Lucas Tostee (§1) and the contact remains app.kayu@gmail.com.
Signing in is optional. Most of the app — search, scanning, equivalences, pins — works without an account, and nothing in this section applies to you until you choose to create one.
A. What the app collects
In Phase 0 (the current, free, non-subscription phase), the app collects:
- Device identifier (UUID). The identifier iOS gives us for this device (
identifierForVendor, or a random UUID we generate ourselves if iOS supplies none), sent with every backend request. Attributes usage to one installation without identifying you personally. We cannot reset it from inside the app: it changes when you delete Kayu from your device. - Email address you enter (email sign-in). Only if you sign in with your email address rather than with Apple. Stored in AWS Cognito as your account identifier, and used to send the one-time codes you sign in with. Because it is the account identifier, it cannot be changed afterwards (see §5).
- Apple ID identifier (
sub) and the email address Apple gives us. Only if you sign in with Apple. Apple returns either your real address or a private relay address (@privaterelay.appleid.com). This address is stored only — we send nothing to it, not even sign-in codes: Apple authenticates you, so no code is needed. - Cognito user identifier (
cognitoSub). A UUID Cognito generates, anchoring your account across sessions. - Anonymous telemetry events (via TelemetryDeck). Such as
app_open,first_scan,drug_detail_view. They carry no drug names, search queries, free-text content, or your IP address (dropped at ingest). While you are signed in they are labelled with your Cognito identifier, so your activity before and after signing in belongs to the same series; signing out or deleting your account detaches that label from anything sent afterwards. You can turn them off at any time in Settings → Privacy → Share usage analytics. - Crash, freeze and error reports. When the app crashes or freezes, iOS hands us a report on the next launch (Apple's MetricKit framework): the crash or signal codes, how long a freeze lasted, the call stack, and the device metadata Apple attaches to it — device model, operating-system version, app build, region format. Separately, when a network request fails, the app records a stable error label (
network,decoding,server, …), the HTTP status, and the fixed name of the feature that failed — never the address called. These reports carry your device identifier. They carry no drug name, search text or scanned code. The same Settings → Privacy → Share usage analytics switch turns them off, and once off nothing is uploaded. - Backend logs (AWS CloudWatch). Request metadata; our API access log additionally records the IP address the request came from. Retention in §D.
- Feedback, country votes, document requests. Stored in our Postgres database. Country votes and document requests are anchored to your device identifier — never to your account. Feedback carries no identifier at all — only the category, your comment, the screen it came from, the language and the app version.
- Pinned medicines, recently viewed medicines, preferences. Stored locally on your device; not transmitted in Phase 0.
Signing in with Apple and signing in with an email address create two separate accounts, even if the address is the same in both. We never match accounts by email address.
We do not collect: name, postal address, payment information, health data, biometric data, precise location, photos, contacts. We no longer collect phone numbers — sign-in by SMS was withdrawn before launch and never reached the public App Store release.
B. Purposes and legal bases (app)
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| The email address you enter, Cognito identifier | Create and authenticate your account; send you a one-time sign-in code by email each time you sign in | Performance of a contract (Art. 6(1)(b)) — the account service you asked for. Sending the code is part of delivering it, so it does not rest on your consent and there is nothing to opt out of |
| Apple ID identifier | Authenticate you via Sign in with Apple | Performance of a contract (Art. 6(1)(b)) |
| Email address received from Apple | Anchor your Apple identity to your account; reserved for Phase 1 marketing, only after explicit opt-in | (a) Contract (Art. 6(1)(b)) for storage; (b) Consent (Art. 6(1)(a)) for marketing, not active today |
| Bounce and spam-complaint notices about sign-in emails | Stop sending to an address that rejects our mail, and protect the deliverability of everyone else's codes | Legitimate interest (Art. 6(1)(f)) |
| Device identifier | Attribute requests to one installation | Legitimate interest (Art. 6(1)(f)) |
| Telemetry events | Understand usage to improve the app | Legitimate interest (Art. 6(1)(f)) — opt-out available |
| Crash, freeze and error reports | Find and fix the defects that make the app crash, freeze or fail | Legitimate interest (Art. 6(1)(f)) — the same opt-out applies |
| Backend logs | Diagnostics, security, abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Country votes, document requests, feedback | Roadmap and product quality | Legitimate interest (Art. 6(1)(f)) |
A Legitimate Interest Assessment (LIA) is documented for each legitimate-interest basis, available on request.
A sign-in code is not marketing. If you sign in with your email address, we send a one-time code to that address every time. That is a transactional message: it exists only to let you into your own account, the account cannot work without it, and it rests on Art. 6(1)(b) — not on your consent. There is no opt-out, because opting out would mean not being able to sign in. If you would rather receive nothing from us at all, use Sign in with Apple (no code is sent) or use Kayu without an account — most of the app works signed out.
Marketing is separate, and does not exist yet. No marketing list exists, so no address of yours is on one. We will send no marketing email until you explicitly opt in through an in-app toggle (planned for Phase 1, not yet shipped). If that ships and you turn it on, your action is your consent under Art. 6(1)(a), and you can withdraw it at any time (Art. 7(3)) by turning the same toggle off or writing to us — as easily as you gave it.
C. Recipients (app)
- AWS (Amazon Web Services EMEA SARL, Luxembourg). All backend services — Cognito (authentication), Amazon SES (sending your sign-in code emails, from our own
usekayu.comdomain), Amazon SNS (carrying bounce and spam-complaint notices about those emails back to us), RDS Postgres (database), CloudWatch (logs), S3 — run in region eu-west-3 (Paris, France). AWS acts as a processor under the Data Processing Addendum incorporated in the AWS Customer Agreement. - Apple Inc. (Cupertino, California, USA). For Sign in with Apple, Apple acts as a separate, independent controller, under the EU–US Data Privacy Framework adequacy decision.
- TelemetryDeck (TelemetryDeck GmbH, Germany). Anonymous telemetry processor.
- Vercel Inc. (USA). Host of the marketing site (see §4); does not receive the app's account data.
We do not share your data with advertisers or data brokers.
D. Retention (app)
| Data | Retention |
|---|---|
| Cognito account (sign-in email address, identifiers) | Until account deletion; tokens expire 30 days after last sign-in |
| Email address (Apple) | Until account deletion or invalidation of the relay address on Apple's side |
| Email delivery records (bounce and spam-complaint notices from Amazon SES) | While your account exists. If mail to your address hard-bounces, or you mark a Kayu message as spam, your address goes on our SES suppression list so we stop writing to it. Ask us at app.kayu@gmail.com and we will take it off |
| Backend logs (CloudWatch) | It depends on the log: 14 days for the API access log, 30 days for the diagnostics and sign-up-trigger logs. Our remaining backend functions write to log groups with no expiry configured today, so those entries are kept until we delete them. We are bringing them under a 30-day limit. |
| Crash, freeze and error reports | Held with the diagnostics logs above, and purged with them at 30 days |
auth.signin sign-in records | 1 year, then purged. Kept to investigate suspicious sign-ins and abuse, and to relate a device's usage to an account in our own logs (Art. 6(1)(f), Art. 32). Deleting your account does not remove them |
| Anonymous telemetry events | 90 days (TelemetryDeck default) |
| Feedback, votes, document requests | Not linked to your account, so deleting it does not affect them. Votes and document requests are device-anchored and kept until you ask us to delete them (§E). Feedback carries no identifier and is kept indefinitely |
| Pins, recently viewed medicines, preferences (on device) | Pins and recently viewed medicines: until account deletion (§E), uninstall, or app-data clear. Country, language and theme preferences survive account deletion |
E. Account deletion
You can delete your account at any time from the app: Settings → Account → Delete account. It is immediate and cannot be undone.
Deleted straight away: your Cognito account record — the sign-in email address you entered, or your Apple identifier and the address Apple gave us — deleted, not deactivated, so signing in again afterwards gives you a new and empty account; your sign-in tokens, which are revoked; and the data held on that device, meaning your pinned medicines and your recently viewed medicines. Your country, language and theme preferences are left alone. If you use Kayu on several devices, only the one you ran the deletion from is cleared.
Not reached by that button. Country votes and leaflet requests are recorded against the device, not against your account, so deleting the account does not remove them — write to app.kayu@gmail.com and we will delete them, within one month (GDPR Art. 12(3)). Feedback is stored with no identifier at all, so we cannot locate one person's entry; if your comment identifies you, tell us what you sent and roughly when, and we will find it. Server logs cannot be deleted line by line and expire on the schedule in §D.
Telemetry. Events already sent while you were signed in keep your Cognito identifier at TelemetryDeck until they age out at 90 days (§D). Nothing sent after deletion carries it.
Sign in with Apple. Deleting your Kayu account does not remove Kayu from your Apple Account. To do that: Settings → your name → Sign in with Apple → Kayu.
F. Automated decision-making and children
The app performs no automated decision-making with legal or similarly significant effects (GDPR Art. 22) and no profiling. The app is not directed at children under 15 (the French digital age of consent transposing GDPR Art. 8); the App Store age rating is 17+. If you believe a child has created an account, write to app.kayu@gmail.com.
This document was drafted with AI assistance and reflects regulatory requirements as understood on 18 August 2026. It is not a substitute for review by a licensed lawyer. Before any major change, review it against the current text of the cited regulations.