Privacy Policy
Protection of your personal data — in accordance with the General Data Protection Regulation (GDPR, EU 2016/679).
1. Data controller
Name: ZEPRAUG & CO
Legal form: SASU with €1,000 share capital, RCS Paris 103 751 970
Registered office: 173 rue de Courcelles, 75017 Paris, France
Legal representative: Louis Langevin (President)
For any request related to your personal data, contact: contact@zepraug.com
2. Data collected
Identity and account data:
Full name, email address, password (encrypted). These data are either provided directly at signup or received from Sign in with Apple or Google Sign-In. In the Google Sign-In case, the only data received from Google are: verified email address, full name, and Google's unique identifier (sub). No profile picture, birthdate, phone number, or contact list is accessed. See section 4-quat for the full Google Sign-In disclosure.
Fitness profile data:
Sport goal, practice level, practice constraints (availability, equipment, preferences), height, weight, and your body measurements: waist, hips, chest, arm, shoulder, thigh, calf and neck. You enter these yourself, with one exception: if you allow health synchronization, your latest weigh-in read from Apple Health or Health Connect updates the weight on your fitness profile.
Health data (mobile application, optional):
If you allow it, the mobile application reads data from Apple Health (iOS) or Health Connect (Android). Part of it falls under article 9 of the GDPR. Your nights, your resting heart rate, its variability and your cardio capacity are saved on none of our servers: they are summarised on your phone. If, and only if, you switch Zepo on, a thirty-day summary of those measurements is sent to Google Gemini so it can answer you. Section 9 states exactly what is read on each platform, what it is used for, who receives it and how long it is kept.
Conversations:
The full history of your exchanges with the AI assistant is saved so you can revisit your previous conversations.
Payment data:
Subscriptions to the mobile application are processed exclusively via In-App Purchase (Apple App Store on iOS, Google Play on Android) through RevenueCat. The two offers sold on the web — the coach workspace and the 1:1 follow-up — are paid by card through Stripe. In both cases Zepraug stores no card number: only a customer identifier held by the payment provider is kept.
Connection data:
IP address, session data (via Supabase Auth).
3. Legal bases for processing (article 6 GDPR)
Performance of contract (Art. 6.1.b): delivery of the AI coaching service, account and subscription management.
Legitimate interest (Art. 6.1.f): service improvement, security, fraud prevention.
Consent (Art. 6.1.a): processing of fitness profile data (goal, level, practice constraints) for personalization of advice.
4. Subprocessors and recipients
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database | United Kingdom (AWS London) |
| Google LLC (Google Gemini) | AI response generation, only if you switch Zepo on. Zepraug uses the paid tier, which excludes any use of your exchanges to train Google's models. Google keeps requests and answers for at most 55 days, solely to detect abuse, then deletes them. Transfer covered by the EU-US Data Privacy Framework. | USA |
| Google LLC (Google Sign-In OAuth) | OAuth authentication (account creation and login) | USA |
| Resend | Email delivery | USA |
| Vercel | Front-end hosting | USA |
| RevenueCat | iOS / Android subscription management (In-App Purchase) | USA |
| Apple App Store | iOS in-app purchase processing (subscription billing) | USA |
| Google Play Billing | Android in-app purchase processing (subscription billing) | USA |
| Expo Push Service | Push notifications relay to APNs (iOS) and FCM (Android) | USA |
| AssemblyAI | Voice transcription (dictation) | USA |
| Stripe | Card payment for the coach workspace and the 1:1 follow-up (web only) | USA |
| Sentry | Crash reports and performance traces of the mobile application | Germany (EU region) |
| PostHog | Product usage measurement (screens opened, actions taken) | European Union (EU region) |
| Meta Platforms | Advertising campaign measurement and attribution (section 4-sexies) | USA |
Your data is never sold. It is shared only with the subprocessors above, for the purposes stated next to each. What goes to the last one, and what never does, is set out in section 4-sexies.
4-quat. Google Sign-In
Zepraug uses Google Sign-In as one of several optional authentication methods (alongside email/password and Sign in with Apple). This section discloses how the application accesses, uses, stores, and shares Google user data, in accordance with the Google API Services User Data Policy and the Google APIs Terms of Service.
Scopes requested (access): openid, email, profile only. No sensitive or restricted scopes are requested. Zepraug never accesses Gmail, Drive, Calendar, Google Fit, Contacts, or any other Google API.
Data received: verified email address, full name, and Google's unique identifier (sub). No profile picture is synchronized from Google — in-app avatars come exclusively from user-uploaded images.
Purpose (use): exclusively to create a Zepraug account or to log in to an existing one. Data received from Google is never used for marketing, profiling, advertising, training AI models, or any other secondary purpose.
Storage: the verified email address and full name are stored in Supabase Auth (auth.users) and mirrored to the public.profiles table at signup. The Google sub identifier is managed inside Supabase Auth and is not duplicated elsewhere. Security measures applied to these data are detailed in section 8.
Sharing: the data transits through the technical subprocessors already listed in section 4 (Supabase for authentication and storage, Vercel for hosting). It is never sold. Our server sends your email address to no advertising network. Until 27 August 2026 our code held one path that would have done so — a SHA-256 digest of your address, posted to TikTok when you subscribed. It required an access token that is not configured in production, so it transmitted nothing; it has now been deleted rather than left dormant. Section 4-sexies says what advertising measurement still covers.
Retention: data received from Google Sign-In follow the same retention policy as account data — kept for the duration of the subscription, then 3 years after closure (legal limitation, see section 6).
Deletion: you may delete your account at any time from the in-app account closure flow or by emailing contact@zepraug.com. Account deletion also removes the corresponding Supabase Auth entry (including the Google sub identifier) and erases the Google-derived data.
4-bis. Marketing consent and push notifications
The toggle « Coach communications » in your in-app Profile is the unique opt-in for both marketing emails and push notifications sent by the human coach. It is opt-in only (off by default) and timestamped at activation.
You can disable it at any time. Toggling it off stops all coach push and marketing emails immediately. Transactional notifications (rest day reminder, streak warning) are not gated by this consent and continue to work as long as push notifications are allowed at the OS level.
Push tokens (Expo Push Token) are stored per device in our database and removed when the device unregisters or when our system detects an invalid token (DeviceNotRegistered).
4-quinquies. Commercial prospecting and email tracking
Channels used: email and in-app push notifications. We never use SMS, and we never make commercial phone calls. Your phone number is not collected for account signup.
Legal basis. Promotional emails (product news, offers) and coach push notifications are sent only with your prior consent (Art. 6.1.a GDPR, Art. L. 34-5 CPCE), collected via an unchecked box at signup or the « Coach communications » toggle in your Profile. As an exception provided by law, we may inform our paying customers about similar Zepraug services without prior consent, with a one-click opt-out in every message.
Service emails. Onboarding help, weekly training tips, inactivity reminders and monthly reports are sent as part of the service, based on our legitimate interest in helping you use the app (Art. 6.1.f GDPR). Each of these emails carries a visible link to manage your preferences, and you can turn each of them off individually, in the app or from that link, without closing your account.
Transactional and legal emails (sign-in codes, subscription confirmations, trial-end and renewal notices required by French consumer law) are not prospecting and cannot be unsubscribed from as long as your account is open.
Email tracking pixels: we use none. Our emails contain no invisible tracker measuring whether or when you open them, and we keep no open or click statistics per person. Some links do carry a signed identifier: the preference and unsubscribe links, so that only you can change your own settings, and the buttons that open the app, so we can send you to the right screen and detect that the app is not installed on your device. That last signal is used only to stop sending you emails whose buttons cannot work.
Proof of consent. Each decision (given or withdrawn), its date, its origin and the version of the wording shown to you are recorded in a dedicated log, kept as evidence and accessible to you on request.
4-sexies. Advertising campaign measurement
Zepraug advertises on Meta. To know which of those adverts actually bring people in, the mobile application embeds Meta's measurement kit. The last paragraph of this section covers TikTok, which is on its way out.
What is sent: two moments, and two only — the installation and opening of the application, which the kit logs on its own, and the start of a subscription and its renewal, which our subscription manager (RevenueCat) relays to Meta with the amount, the currency and the identifier of the product bought. Nothing else about you travels: not the creation of your account, not a session, not a weight, not a measurement, not a health figure, not a line of your conversations.
Which identifiers: on iOS, your device advertising identifier (IDFA) if you allowed it in the tracking prompt the application shows at launch, plus Apple's own attribution mechanism (SKAdNetwork), which carries no identifier. On Android, the system advertising identifier. So that a subscription can be tied back to the advert that led to it, the application also passes the anonymous identifier issued by Meta's own kit to our subscription manager. Your email address is not part of any of this: our server sends it to no advertising network.
Where it goes: to Meta Platforms, outside the European Union (section 5).
How to stop it: on iOS, in Settings → Privacy & Security → Tracking, where you can withdraw the authorization you gave at launch at any time; refusing it costs you no feature. On Android, this measurement is not preceded by any prompt inside the application: it is governed by your system settings, under Privacy → Ads, where you can delete or reset your advertising identifier.
Separately from advertising, the application sends crash reports to Sentry and product usage measurements to PostHog, both hosted in the European Union (section 4). Those two receive no advertising identifier.
TikTok, on its way out (27 August 2026): TikTok was a second advertising network here, and we are removing it. The removal does not land everywhere at the same moment, and we would rather say so than let a policy claim more than it can. On our servers it is done: the code that could post your subscriptions to TikTok was deleted on 27 August 2026 — it required an access token that is not configured in production, so it had transmitted nothing. In the mobile application, TikTok's measurement kit leaves with version 4.0. Until you have installed that version, the one already on your device keeps sending TikTok the creation of your account and your subscriptions. In the meantime you can withdraw the tracking authorization (iOS, Settings → Privacy & Security → Tracking) or reset your advertising identifier (Android, Privacy → Ads), and those events stop being tied to you. This paragraph will disappear once version 4.0 has replaced the earlier ones.
4-ter. Human coach data access (90-day TTL)
Subscribers who use the human coach explicitly grant the human coach access to their fitness data (programs, workout logs, daily steps, weight and body measurements, conversations) so that personalized advice can be provided. Per GDPR data minimization, this access automatically expires 90 days after activation. You can extend it by 90 days or revoke it at any time from your Profile.
Since the Zepo assistant no longer receives your daily steps or your weight (section 9), the human coach you authorized is their only outside recipient. When you send a free consultation, the weight on your fitness profile is included in the message the coach receives, so that the advice matches your situation.
Every access by the coach to your data is logged in an audit trail (action, timestamp) viewable on request via contact@zepraug.com.
5. International transfers
Some of our subprocessors are located in the United States. These transfers are governed by:
- ▸The EU-US Data Privacy Framework (DPF) for certified companies (Google, Apple)
- ▸Standard Contractual Clauses (SCCs) of the European Commission
6. Retention period
Account data: kept for the duration of the subscription, then 3 years after closure (legal limitation).
Chat history: kept for a rolling 24 months, then deleted. Deleted in full when the account is closed.
Health measurements (Apple Health / Health Connect): sleep, resting heart rate, its variability, VO2max and activity minutes are kept by us nowhere at all: they are stored on none of our servers. They are summarised on your phone and, if you have switched Zepo on, that summary is sent to Google Gemini with each message and each letter: sent, never stored on our side. Your steps, your weight, your eight body measurements and your daily check-in (the energy and soreness you log) follow the account data policy above, because they feed your long-term progress charts. See section 9.
Zepo letters: the text of each Sunday letter is kept with your account data, so you can read it again. The health facts that produced it are not saved with it: the letter keeps its paragraph about your nights, we keep no memory of those nights.
Google Sign-In data: follow the account data policy (subscription duration + 3 years after closure). See section 4-quat for the full Google user data disclosure.
Payment data: kept by Apple App Store and Google Play according to their own retention policies. Zepraug only retains an anonymous RevenueCat customer identifier.
Connection logs: 12 months maximum.
7. Your rights (articles 15 to 21 of the GDPR)
You have the following rights:
- ▸Right of access — obtain a copy of your personal data
- ▸Right to rectification — correct inaccurate data
- ▸Right to erasure — request deletion of your data
- ▸Right to portability — receive your data in a structured format
- ▸Right to object — object to the processing of your data
- ▸Right to restriction — restrict the processing of your data
To exercise your rights, contact us at: contact@zepraug.com
To delete your account and the data attached to it, the two ways of asking are described on the account and data deletion page.
Response time: 30 days maximum.
In case of difficulty, you may file a complaint with the French data protection authority (CNIL): www.cnil.fr
8. Data security
Your data is protected by encryption in transit (TLS/SSL) and at rest (AES-256 via Supabase). Access to data is strictly restricted and subject to row-level security rules.
9. Note about health data
Zepraug processes two distinct categories of data, and they do not follow the same rules.
Fitness profile information (sport goal, level, practice constraints, weight, waist measurement, hip measurement) is wellness and physical condition data, not medical data. From those figures the application computes markers, and shows them to you as they are: a body mass index placed within the World Health Organization ranges, calorie needs, a weekly slope. It makes no diagnosis and gives no medical advice.
On the mobile application, and only if you allow it, Zepraug reads data from your health application. It only reads: Zepraug writes nothing there, and modifies or deletes nothing that other applications wrote. The sessions you start from the Zepraug app on your watch are recorded by the watch itself, as watchOS does for every workout. On iOS, from Apple Health (HealthKit): your steps, your sleep duration, your resting heart rate and its variability, your estimated VO2max, the heart rate recorded during your sessions, your recorded workouts and your weight.
On Android, through Health Connect, Zepraug reads the same categories: your steps, your sleep duration, your resting heart rate and its variability, your estimated VO2max, your recorded workouts and your weight. Those measurements are only written into Health Connect by your watch or your tracking app: if you do not have one, they stay absent, and that is a normal state. Health Connect also limits what we may read to the thirty days preceding your authorization, plus whatever is written after it: on Android, the history picked up on the day you connect does not go back further than a month.
Part of this data falls under article 9 of the GDPR: your sleep, your resting heart rate, its variability, your VO2max and the activity minutes measured by your watch. It serves two purposes and no others. The first: showing you your daily condition and adapting the training suggestions you are shown, which happens on your phone. The second, only if you switch Zepo on: answering you. A thirty-day summary of those measurements then travels with each message and each letter to Google Gemini. We do not use this data for advertising, for profiling, or to train models, and Google trains none of its own on it either: Zepraug uses the paid tier of the API, which excludes it.
The legal basis we rely on is your explicit consent (art. 9(2)(a) GDPR), and it is asked twice, because these are two distinct decisions. READING is collected inside the application, on a dedicated screen describing what is read and what it is used for, separate from the permission your phone asks for on its own side; you withdraw it in your phone settings, where the permission was granted to the system, and the application does not see that, so it cannot log it: the permission you revoked is what proves it, and the reading stops at once. SENDING TO ZEPO is collected on a sheet of its own, which names Google Gemini, the United States and each measurement concerned before you decide; you withdraw it with the same switch, in Profile, Privacy and your data. Each of these decisions, its date, its origin and the version of the wording shown to you are recorded in our consent log, the withdrawal as much as the grant.
These measurements are saved on none of our servers: they stay on your phone, where everything the application shows you from them is computed. This has a price and we would rather write it: if you change device or reinstall, only what your health application can hand back comes with you, which is ninety days on iOS and thirty days on Android.
Until this update, this section stated that none of these measurements reached an artificial intelligence service. That had stopped being true on 6 September 2026: on that day the application started attaching a thirty-day health summary to your questions, and this page did not say so. We would rather write it than let you find it. From this update onwards, that summary is sent only if you have switched Zepo on, and here is exactly what travels.
Every message sent to Zepo carries to Google Gemini: your message and the photos you attach to it; your first name, your sex, your age, your height, your goal, your level and your practice constraints; your sessions and your log for the last ninety days. Added to that, if and only if you have switched Zepo on, a summary of your last thirty days: your steps (days known, median, best day with its date), your daily check-in (how many were logged, average energy and soreness, weakest weekday and strongest weekday), your weight (latest weigh-in with its date, number of weigh-ins, change over thirty days), your nights (how many, median duration, the shortest and the longest with their dates, median by weekday), your resting heart rate (median over the known days, last seven days against the days before) and your cardio capacity (VO2max). Your heart rate variability and your activity minutes never travel at all.
The Sunday letter is a separate send, and it carries: your first name; your week's sessions (how many days, how many mobility and cardio sessions, your weekly target); your nights, once Zepo is switched on (how many, the average, the change against the previous week, how many consecutive weeks in the same direction, and the two longest with their dates); your days under six thousand steps, with their dates; your average protein at midday and in the evening, over how many logged days; and two exercises compared with three weeks earlier. Nothing of your nights is saved with the letter: the facts stored beside it carry no sleep at all.
When Zepo is not switched on, no health summary is sent: Zepo answers without your measurements, and it says so rather than inventing them. Of everything that does travel, nothing new is saved on our side: your messages and Zepo's answers are kept in your conversation history, the text of your letters is kept with your letters, and the data section 6 files with your account stays there. The summary itself is recomputed on your phone at each send and is written to none of our servers. The letter keeps its paragraph about your nights, and we keep no memory of those nights.
Your weight travels in two shapes, and we would rather name the second than let you find it on your own: the dated weigh-in of the summary above, which only travels once Zepo is switched on; and the transformation verdict, computed by the application, which carries the direction of your progress, a weekly slope in percent and, depending on the case, a maintenance figure in kilocalories per day or a number of weeks to your target weight. Never a weight in kilos, neither today's nor the one you are aiming for.
Being sent to an AI provider is not the same as being hosted, and we would rather write which is which. Your daily steps, your weight, your eight body measurements and the daily check-in you log stay saved in your Zepraug space, with our database subprocessor (section 4), because they are what build your progress charts. Their outside recipients are the human coach you explicitly granted access to (section 4-ter) and, once Zepo is switched on, the summary described above. This data is never sold or shared for commercial purposes.
Two points in this section describe a version of the application that has not reached the stores yet: the rolling year kept on your device, and the erasure of that store when you delete your account. They arrive with the next update. In the version installed today, these measurements are saved on none of our servers either, and uninstalling the application is what erases whatever your phone holds of them.
Retention: the article 9 measurements (sleep, resting heart rate, variability, VO2max, activity minutes) are kept nowhere on our side: they stay on your device, which holds a rolling year of them — beyond that, the oldest days are dropped as new ones arrive — and deleting the application deletes what is left. Your steps, your weight, your body measurements and your daily check-in follow the account data policy (section 6), because they feed your long-term progress charts. Your conversation history is kept for a rolling 24 months, and Zepo's answers may quote the figures it received. At Google's end: Google keeps requests and answers for at most 55 days, solely to detect abuse, then deletes them.
You can switch this reading off at any time from your phone settings, where you granted it: Apple Health on iOS, Health Connect on Android. Switching it off stops the reading going forward; it erases neither what your device has already kept, nor what is saved in your Zepraug space. Zepo is switched off elsewhere, inside the application: Profile, Privacy and your data. Sending stops at once, the date of your withdrawal is recorded in our consent log, and everything else in the app keeps working. Cutting the health reading in your phone settings also removes your measurements from Zepo's answers, since there is then nothing left to summarise.
What we host — your steps, your weight, your body measurements, your daily check-in, your conversation history — can be deleted on request at any time (section 7), and deleting your account erases all of it. The article 9 measurements are not with us, so there is nothing to ask us for: they are erased by uninstalling the application, and deleting your account erases them too — on the device you delete it from, and on that one only. If you have used Zepraug on another phone, uninstalling the application there is what erases the copy left on it.
Zepraug is intended for healthy individuals. If you have a pathology, we invite you to consult your doctor before using the service.
10. Cookies
Zepraug uses the following cookies:
Strictly necessary cookies (consent-exempt — CNIL):
- ▸Authentication cookies (Supabase Auth)
- ▸Session cookies
Analytics and advertising cookies (Google Tag Manager):
Zepraug uses Google Tag Manager with Consent Mode v2. By default, all analytics and advertising cookies are refused (ad_storage, analytics_storage, ad_user_data, ad_personalization). Tags work in degraded mode (statistical modeling) without setting tracking cookies. A consent management banner (CookieYes) is in place to allow users to accept or refuse these cookies.
Last updated: 9 September 2026 · Terms of Use · Terms of Sale · Legal Notice · Account deletion