Privacy Policy, Erudiam
Last updated: 1 June 2026.
This policy describes how Erudiam (the "Service") collects, uses, and protects your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the ePrivacy Directive 2002/58/EC. The applicable national data protection law is that of the controller's country: Belgian law (Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data), under the supervision of the Data Protection Authority (APD/GBA).
1. Data controller
- Identity: Jean de Loynes, independent sole trader (natural person, Belgian law) (enterprise number (BCE) and VAT number being assigned).
- Contact address: Avenue du Préau 20, 1040 Etterbeek, Belgium.
- GDPR email: privacy@erudiam.com
Data Protection Officer (DPO)
The Service does not currently process data on a large scale or special categories of data within the meaning of Article 9 GDPR; appointment of a DPO is not required (Article 37 GDPR). The designation will be reassessed as the Service grows. In the meantime, Jean de Loynes (publisher) acts as the GDPR contact point (privacy@erudiam.com).
2. Personal data collected
| Category | Concrete data | Source |
|---|---|---|
| Identification | Email address, hashed password (never plaintext, managed by Supabase Auth) | user |
| Profile | Interface language, target country, target competition (AD5...), optional exam date | user |
| Pedagogical | Question answers, FSRS state (spaced repetition), streak, sessions, scores | usage |
| Mock exams | mock_exam_attempts: phases, answers, duration, weighted score |
usage |
| Placement test | placement_test_attempts: served questions, answers, estimated level |
usage |
| EUFTE (written essays) | User-written text, metrics (words, minutes), optional friend review | user |
| Leaderboards (explicit opt-in) | Public alias leaderboard_alias, aggregated metrics (never name or email) |
user |
| Push notifications | Push endpoints (VAPID web or Expo mobile token), preferences (kind, local hour, TZ) | user |
| Account deletion | Scheduled deletion date (scheduled_deletions) |
GDPR |
| Error reports | Reported question, reason, free-text comment, tier (beta/live) | user |
| Referral (anti-fraud) | Lightweight hashed device fingerprint (truncated UA + colour depth + timezone + language) and hashed IP (salted SHA-256) when a referee is attached, never in clear, no canvas/WebGL fingerprint | usage |
Data NOT collected
The Service does not collect:
- application-level IP addresses in clear (no app-level IP logs, transient network logs at our hosting providers are used for security only, not exploited by the publisher). One exception: when a referral is attached, the IP is immediately hashed (salted SHA-256, never stored in clear) for anti-fraud purposes only, and purged after 90 days (see § 4);
- GPS or precise geolocation data;
- biometric data;
- special categories under Article 9 GDPR (health, political opinion, religion, sexual orientation, etc.);
- payment data (when the paid tier P5.i activates, payment processing will be delegated to Stripe or equivalent, this policy will be updated accordingly);
- third-party analytics: no PostHog, Plausible, Matomo, Google Analytics, Mixpanel, etc. are installed at this time;
- advertising or retargeting cookies.
Minors
The Service is intended for adult users preparing EPSO competitions (typically 18+ given university-degree requirement). Users under the age of 16 must have parental consent (Article 8 GDPR; French threshold is 15).
3. Purposes and legal bases
| Purpose | Legal basis | GDPR reference |
|---|---|---|
| Account creation and authentication | Performance of the contract | Art. 6(1)(b) |
| Pedagogical preparation (FSRS, mock, placement) | Performance of the contract | Art. 6(1)(b) |
| Push notifications (review reminders) | Explicit opt-in consent | Art. 6(1)(a) + ePrivacy |
| Leaderboards and public sharing | Explicit opt-in consent | Art. 6(1)(a) |
| Moderation (error reports) | Publisher's legitimate interest | Art. 6(1)(f) |
| Security, fraud prevention, auditing | Legitimate interest + legal obligation | Art. 6(1)(f) / 6(1)(c) |
| 14-day deferred deletion (GDPR) | Legal obligation | Art. 6(1)(c) (art. 17) |
4. Retention periods
| Data | Period |
|---|---|
| Active account (auth + profile) | Until account deletion |
| Inactive account (no login) | Notification after 24 months, deletion at 36 months |
| Pedagogical answers | Tied to the account; deleted with it |
| GDPR soft-delete | 14 days then hard-delete via RPC request_account_deletion |
| Hosting technical logs | Each subprocessor's policy (Vercel ~30d, Supabase ~7d) |
| Push subscriptions | While the device/browser keeps them; periodic clean-up |
| EUFTE share links | Default 30 days then unavailable for public read |
| Notification dispatch logs | 90-day rolling (to be confirmed at production launch) |
Referral anti-fraud fingerprints (device_hash, ip_hash) |
90 days then automatic purge (NULL) via purge_referral_fingerprints() + pg_cron |
| Referral attribution cookie | 30 days then expiry |
| In-app feedback + associated screenshots | 12 months after resolution, then deletion or anonymisation |
| Publisher-side technical logs (audit, security) | 12 months maximum |
| Database backups (Supabase, PITR) | Bounded window (plan-dependent, order of 7-30 days); deleted data ages out of backups when the window expires |
5. Recipients and subprocessors
No data is sold or transferred to third parties for commercial purposes. The following subprocessors operate strictly for the Service's technical operation, under standard DPA terms:
| Subprocessor | Role | Location | Cross-border transfer mechanism |
|---|---|---|---|
| Supabase, Inc. | Auth + PostgreSQL database + storage | eu-west-1 (Ireland) |
Data stored in EU. US parent, residual transfers covered by EU SCC 2021/914 + DPF where applicable |
| Vercel, Inc. | Web hosting (SSR + edge) | EU/US edge | EU SCC 2021/914 + DPF |
| Cloudflare, Inc. | CDN, anti-DDoS, R2 (planned) | EU/Auto | EU SCC 2021/914 + DPF |
| Anthropic PBC | AI grading of free-text EUFTE answers (Claude API) | US | EU SCC 2021/914 + DPF where applicable. Data sent: the answer text only, no direct identifier. Per Anthropic's commercial terms, API inputs are not used to train its models. |
| GitHub, Inc. | Source code hosting only | US | No user data |
| Google LLC (Drive) | Internal podcast source storage | US | No user data flows; admin only |
| Expo (Push) | Mobile push routing | US | Opaque token; no PII |
| Apple / Google | Web Push (APNs / FCM) via VAPID | US | Opaque token; no PII |
Following the Schrems II ruling (CJEU 2020) invalidating the Privacy Shield, US subprocessors rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework (Adequacy Decision 2023/1795).
Use of artificial intelligence (transparency, GDPR + AI Act art. 50)
Some features rely on an artificial intelligence model provided by Anthropic PBC (Claude API):
- EUFTE grading: when you explicitly request it and after consent, the text of your free-text answer is sent to the Claude API to produce a grade and educational feedback. Only the answer text is sent, with no direct identifier (email, name).
- No training on your data: per Anthropic's commercial terms, content sent via the API is not used to train its models.
- Consent and logging: AI use is subject to prior, revocable consent and is logged in a GDPR-compliant way.
- No automated decision: AI grading is an educational aid; it produces no automated decision with legal effect within the meaning of Art. 22 GDPR.
6. Data subject rights
Under Articles 15-22 GDPR, you have the following rights:
- Access (Art. 15), obtain a copy of your data via the planned
export-user-dataEdge Function; meanwhile contact privacy@erudiam.com. - Rectification (Art. 16), edit your data on the Settings page (locale, competition, exam date, leaderboard alias).
- Erasure (Art. 17), account deletion button in Settings
triggers
request_account_deletion: 14-day soft-delete (cancellable viacancel_account_deletion), then irreversible hard-delete. - Restriction (Art. 18), write to privacy@erudiam.com to freeze processing.
- Portability (Art. 20), JSON export in a structured format
(Edge Function
export-user-data). - Objection (Art. 21), one-click leaderboard opt-out in Settings; push opt-out under Notifications.
- Withdraw consent (Art. 7.3), anytime via Settings or browser permissions.
- Lodge a complaint (Art. 77), with the Belgian Data Protection Authority (APD/GBA), the competent supervisory authority for a controller established in Belgium (Rue de la Presse 35, 1000 Brussels, https://www.autoriteprotectiondonnees.be), or with the supervisory authority of your own EU Member State of residence.
Response time: 1 month (extendable to 3 months for complex requests, Art. 12(3) GDPR). Free of charge except for manifestly unfounded or excessive requests.
7. Security
Technical and organisational measures (Art. 32 GDPR):
- TLS 1.3 in transit (HTTPS enforced).
- Passwords hashed by Supabase Auth (server-side bcrypt; never plaintext).
- Row Level Security (RLS) enabled on every table without
exception; no
service_rolekey exposed client-side. - Strong authentication on the roadmap (2FA email magic-link / TOTP).
- Input validation client-side (Zod) and server-side (SQL CHECK + triggers).
- No secrets in source code; environment variables scoped by
NEXT_PUBLIC_*/EXPO_PUBLIC_*/ Supabase Functions secrets. - Daily Supabase backups (encrypted at rest by Supabase).
- Admin access auditing (table
adminswithgranted_at,granted_by,notes; nois_adminflag editable client-side). - A threat model is maintained internally.
8. Cookies and trackers
See the dedicated Cookie Policy. No advertising or third-party analytics cookies are used at this time. Only strictly necessary cookies (Supabase Auth session, locale preference) are deployed; they do not require prior consent under Article 82 LIL.
9. Push notifications
Web and mobile push notifications use granular opt-in (per kind: daily reminder, FSRS due, etc., plus a master toggle). No notifications are sent until the user opts in.
Users can:
- revoke all notifications via Settings → Notifications;
- revoke a specific device (uninstall mobile app or unsubscribe in the browser);
- change the local hour and timezone of delivery.
10. International transfers
Data is primarily stored within the European Union (Supabase eu-west-1 Ireland, Cloudflare R2 EU). Some technical subprocessors are US-based; transfers are governed by the EU Standard Contractual Clauses (2021/914) and the EU-US Data Privacy Framework (Adequacy Decision 2023/1795) where applicable.
11. Changes to this policy
This policy may evolve. Material changes will be notified:
- via in-app banner at next login;
- by email to active accounts when changes reduce user rights;
- with reasonable advance notice (at least 15 days) before entry into force.
History is kept in the project CHANGELOG.md.
12. Contact
- GDPR email: privacy@erudiam.com
- Postal: Avenue du Préau 20, 1040 Etterbeek, Belgium.
- Supervisory authority: Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels, https://www.autoriteprotectiondonnees.be