1. Data controller
FluidOps, published by an individual. Contact: dpo@fluidops.app.
2. Data we collect
- Account: email, password (hashed), first/last name, username, photo, bio, location, Stripe plan and identifiers, preferences (notifications, cookies, theme, language).
- Content: projects, tasks, sprints, comments, activity, as well as content entered in the tools (5 Whys, Eisenhower, RACI, OKR, Ansoff, SONCAS/CAP, GE/McKinsey, etc.) and the history of AI analyses.
- Integrations: GitHub token (stored), Google and Microsoft tokens (session), and data exchanged with these services (calendar events, GitHub repositories/issues, authorised Drive files), if you connect them.
- Security: IP address, connection log, usage counters (abuse prevention).
- Audience measurement (only if you accept it): pages viewed, labels of buttons clicked, technical errors, temporary session identifier, without the content of your projects.
- Proof of cookie consent: a random visitor identifier and your choices, kept for 1 year if you accept marketing (a refusal is remembered only for the current session).
- Voice dictation: audio is not stored by FluidOps.
We hold no banking data: Stripe processes payments directly.
3. Purposes and legal bases
Performance of the contract (account, service, tools, billing, AI assistant and dictation that you trigger), legitimate interest (security, fraud prevention, abuse prevention, moderation), consent (non-essential cookies including audience measurement, weekly summary), legal obligation (accounting).
4. Retention
For as long as the account is active. Deletion or anonymisation when the account is deleted, subject to accounting obligations (10 years). Proof of cookie consent: 1 year (marketing accepted; if you refuse, the banner is shown again at each visit). Audience measurement data: kept for a limited period.
5. Integrations (Google, GitHub, Microsoft)
- Google Calendar / Drive (Google Identity sign-in, access limited to the "calendar events" and "files created or chosen with the app" permissions): FluidOps sends Google the titles, dates and descriptions of tasks turned into events, and reads the list of authorised Drive files. The access token stays only in your browser's memory (about one hour) and is not stored by FluidOps.
- GitHub: the personal access token you enter is stored at Supabase and is never sent back to your browser; calls to GitHub go through a server function. FluidOps reads your repositories and issues for task import.
- Microsoft Outlook (Microsoft Graph, "Calendars.ReadWrite" permission): FluidOps sends Microsoft the events created from your tasks. The sign-in token is kept in your browser's local storage until you disconnect.
Each integration is optional; disconnecting (or revoking the token with the third party) ends FluidOps' access. The data transmitted is then processed by these services under their own policies.
6. Artificial intelligence and voice dictation
AI assistant, Pecha Kucha and fallback voice transcription: the text or audio you submit is sent to Google (Gemini API) through a secure function hosted by Supabase. It is used only to produce your answer; audio is not stored, while the history of AI analyses is saved in your project. Instant voice dictation: on Chrome, Edge and Safari it is provided by the browser's speech recognition service (Google or Apple depending on the browser), without going through FluidOps; the browser asks your permission to use the microphone. Do not submit sensitive data.
7. Recipients and processors
Supabase (hosting, database, authentication, storage, functions), Cloudflare (hosting and delivery of the application), Stripe (payments), Resend (notification emails), Google (Gemini API, reCAPTCHA anti-bot, Google Tag Manager and Google Ads (ad conversion measurement) only after your marketing consent, and Google Drive/Calendar/sign-in if you use them), GitHub and Microsoft if you connect these integrations. The typeface is hosted by FluidOps: no calls to Google Fonts. We do not sell data to third parties.
8. Transfers outside the European Union
Some processors (Stripe, Google, Cloudflare, Resend, Microsoft, GitHub, and Supabase depending on the chosen region) may process data outside the EU, with the safeguards provided for by the GDPR.
9. Cookies and trackers
Four categories: necessary (always active: login session, security, remembering your choice, theme), functional (calendar connections you enable yourself), audience measurement (our internal measurement stored in Supabase, and Google Tag Manager, loaded only if you accept it) and marketing (Google Ads: measurement of conversions — sign-up, start and success of a payment — and of the effectiveness of our ads, through Google Tag Manager, only if you accept it; Google may set cookies and process your IP address and the ad-click identifier). If you accept audience measurement we also keep the origin of your visit (campaign parameters utm_*, gclid) in our internal measurement. Nothing non-essential is activated without your consent. The service also uses the browser's local storage (localStorage/sessionStorage) for these functions. You can change your choice at any time from Account Settings > Privacy, or via the "Cookies" button on the site.
10. Minors
The service is reserved for people aged 15 or over, or with the permission of a legal guardian. In school use, the teacher or institution is responsible for supervising minor students.
11. Your rights
Access, rectification, erasure, restriction, objection, portability, post-mortem directives, and withdrawal of consent at any time. Exercise them from Account Settings for some data, or by email to dpo@fluidops.app. We reply within one month at most. You may lodge a complaint with the CNIL (www.cnil.fr).
12. Security
Encryption in transit, row-level access control (Row Level Security), hashed passwords, security headers (CSP).
13. Changes to this policy
It may be updated; a substantial change means prior notice.
14. Contact
dpo@fluidops.app