Zepraug

Privacy Policy

Protection of your personal data — in accordance with the General Data Protection Regulation (GDPR, EU 2016/679).

1. Data controller

Name: ZEPRAUG & CO

Legal form: SASU with €1,000 share capital, RCS Paris 103 751 970

Registered office: 173 rue de Courcelles, 75017 Paris, France

Legal representative: Louis Langevin (President)

For any request related to your personal data, contact: contact@zepraug.com

2. Data collected

Identity and account data:

Full name, email address, password (encrypted). These data are either provided directly at signup or received from Sign in with Apple or Google Sign-In. In the Google Sign-In case, the only data received from Google are: verified email address, full name, and Google's unique identifier (sub). No profile picture, birthdate, phone number, or contact list is accessed. See section 4-quat for the full Google Sign-In disclosure.

Fitness profile data:

Sport goal, practice level, practice constraints (availability, equipment, preferences), weight, height, waist and hip measurements. These data are entered voluntarily by the user.

Conversations:

The full history of your exchanges with the AI assistant is saved so you can revisit your previous conversations.

Payment data:

Subscriptions are processed exclusively via In-App Purchase (Apple App Store on iOS, Google Play on Android) through RevenueCat. Zepraug stores no card number — only an anonymous customer identifier is kept.

Connection data:

IP address, session data (via Supabase Auth).

3. Legal bases for processing (article 6 GDPR)

Performance of contract (Art. 6.1.b): delivery of the AI coaching service, account and subscription management.

Legitimate interest (Art. 6.1.f): service improvement, security, fraud prevention.

Consent (Art. 6.1.a): processing of fitness profile data (goal, level, practice constraints) for personalization of advice.

4. Subprocessors and recipients

SubprocessorPurposeLocation
SupabaseAuthentication, databaseUSA (AWS)
Google (Gemini API)AI response generationUSA
Google LLC (Google Sign-In OAuth)OAuth authentication (account creation and login)USA
ResendEmail deliveryUSA
VercelFront-end hostingUSA
RevenueCatiOS / Android subscription management (In-App Purchase)USA
Apple App StoreiOS in-app purchase processing (subscription billing)USA
Google Play BillingAndroid in-app purchase processing (subscription billing)USA
Expo Push ServicePush notifications relay to APNs (iOS) and FCM (Android)USA
AssemblyAIVoice transcription (dictation)USA

Your data is never sold or shared for commercial purposes with third parties.

4-quat. Google Sign-In

Zepraug uses Google Sign-In as one of several optional authentication methods (alongside email/password and Sign in with Apple). This section discloses how the application accesses, uses, stores, and shares Google user data, in accordance with the Google API Services User Data Policy and the Google APIs Terms of Service.

Scopes requested (access): openid, email, profile only. No sensitive or restricted scopes are requested. Zepraug never accesses Gmail, Drive, Calendar, Google Fit, Contacts, or any other Google API.

Data received: verified email address, full name, and Google's unique identifier (sub). No profile picture is synchronized from Google — in-app avatars come exclusively from user-uploaded images.

Purpose (use): exclusively to create a Zepraug account or to log in to an existing one. Data received from Google is never used for marketing, profiling, advertising, training AI models, or any other secondary purpose.

Storage: the verified email address and full name are stored in Supabase Auth (auth.users) and mirrored to the public.profiles table at signup. The Google sub identifier is managed inside Supabase Auth and is not duplicated elsewhere. Security measures applied to these data are detailed in section 8.

Sharing: no third-party sharing. Data only transits through the technical subprocessors already listed in section 4 (Supabase for authentication and storage, Vercel for hosting). Never sold, never disclosed to advertisers, never shared for commercial purposes.

Retention: data received from Google Sign-In follow the same retention policy as account data — kept for the duration of the subscription, then 3 years after closure (legal limitation, see section 6).

Deletion: you may delete your account at any time from the in-app account closure flow or by emailing contact@zepraug.com. Account deletion also removes the corresponding Supabase Auth entry (including the Google sub identifier) and erases the Google-derived data.

4-bis. Marketing consent and push notifications

The toggle « Coach communications » in your in-app Profile is the unique opt-in for both marketing emails and push notifications sent by the human coach. It is opt-in only (off by default) and timestamped at activation.

You can disable it at any time. Toggling it off stops all coach push and marketing emails immediately. Transactional notifications (rest day reminder, streak warning) are not gated by this consent and continue to work as long as push notifications are allowed at the OS level.

Push tokens (Expo Push Token) are stored per device in our database and removed when the device unregisters or when our system detects an invalid token (DeviceNotRegistered).

4-quinquies. Commercial prospecting and email tracking

Channels used: email and in-app push notifications. We never use SMS, and we never make commercial phone calls. Your phone number is not collected for account signup.

Legal basis. Promotional emails (product news, offers) and coach push notifications are sent only with your prior consent (Art. 6.1.a GDPR, Art. L. 34-5 CPCE), collected via an unchecked box at signup or the « Coach communications » toggle in your Profile. As an exception provided by law, we may inform our paying customers about similar Zepraug services without prior consent, with a one-click opt-out in every message.

Service emails. Onboarding help, weekly training tips, inactivity reminders and monthly reports are sent as part of the service, based on our legitimate interest in helping you use the app (Art. 6.1.f GDPR). Each of these emails carries a visible link to manage your preferences, and you can turn each of them off individually, in the app or from that link, without closing your account.

Transactional and legal emails (sign-in codes, subscription confirmations, trial-end and renewal notices required by French consumer law) are not prospecting and cannot be unsubscribed from as long as your account is open.

Email tracking pixels: we use none. Our emails contain no invisible tracker measuring whether or when you open them, and we keep no open or click statistics per person. Some links do carry a signed identifier: the preference and unsubscribe links, so that only you can change your own settings, and the buttons that open the app, so we can send you to the right screen and detect that the app is not installed on your device. That last signal is used only to stop sending you emails whose buttons cannot work.

Proof of consent. Each decision (given or withdrawn), its date, its origin and the version of the wording shown to you are recorded in a dedicated log, kept as evidence and accessible to you on request.

4-ter. Human coach data access (90-day TTL)

Subscribers who use the human coach explicitly grant the human coach access to their fitness data (programs, workout logs, body measurements, conversations) so that personalized advice can be provided. Per GDPR data minimization, this access automatically expires 90 days after activation. You can extend it by 90 days or revoke it at any time from your Profile.

Every access by the coach to your data is logged in an audit trail (action, timestamp) viewable on request via contact@zepraug.com.

5. International transfers

Some of our subprocessors are located in the United States. These transfers are governed by:

  • The EU-US Data Privacy Framework (DPF) for certified companies (Google, Apple)
  • Standard Contractual Clauses (SCCs) of the European Commission

6. Retention period

Account data: kept for the duration of the subscription, then 3 years after closure (legal limitation).

Chat history: kept for the duration of the subscription. Deleted upon account closure on request.

Google Sign-In data: follow the account data policy (subscription duration + 3 years after closure). See section 4-quat for the full Google user data disclosure.

Payment data: kept by Apple App Store and Google Play according to their own retention policies. Zepraug only retains an anonymous RevenueCat customer identifier.

Connection logs: 12 months maximum.

7. Your rights (articles 15 to 21 of the GDPR)

You have the following rights:

  • Right of access — obtain a copy of your personal data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion of your data
  • Right to portability — receive your data in a structured format
  • Right to object — object to the processing of your data
  • Right to restriction — restrict the processing of your data

To exercise your rights, contact us at: contact@zepraug.com

Response time: 30 days maximum.

In case of difficulty, you may file a complaint with the French data protection authority (CNIL): www.cnil.fr

8. Data security

Your data is protected by encryption in transit (TLS/SSL) and at rest (AES-256 via Supabase). Access to data is strictly restricted and subject to row-level security rules.

9. Note about health data

Zepraug does not collect health data within the meaning of article 9 of the GDPR. Fitness profile information (sport goal, level, practice constraints, weight, waist measurement, hip measurement) is wellness and physical condition data, not medical data. No diagnosis, BMI calculation or medical recommendation is performed.

On the iOS mobile application, Zepraug may read your weight from Apple Health (HealthKit) with your explicit consent, in order to pre-fill measurement tracking. This data is stored only in your Zepraug profile and is not shared with any third party. You can disable this synchronization at any time from your profile.

Zepraug is intended for healthy individuals. If you have a pathology, we invite you to consult your doctor before using the service.

10. Cookies

Zepraug uses the following cookies:

Strictly necessary cookies (consent-exempt — CNIL):

  • Authentication cookies (Supabase Auth)
  • Session cookies

Analytics and advertising cookies (Google Tag Manager):

Zepraug uses Google Tag Manager with Consent Mode v2. By default, all analytics and advertising cookies are refused (ad_storage, analytics_storage, ad_user_data, ad_personalization). Tags work in degraded mode (statistical modeling) without setting tracking cookies. A consent management banner (CookieYes) is in place to allow users to accept or refuse these cookies.

Last updated: April 2026 · Terms of Use · Terms of Sale · Legal Notice