Privacy policy
Protection of personal data: EU Regulation 2016/679 (GDPR) and the French Data Protection Act (loi Informatique et Libertés)
Last updated: 3 septembre 2026
This translation is provided for your convenience. In the event of any discrepancy, only the French version of this document is legally binding. Read the French version
1. Data controller
| Data controller | Tribulys |
| SIREN | 104 623 095 |
| Registered office | Lille (59000), Nord, France |
| Data contact | [email protected] |
For any question regarding the processing of your data or the exercise of your rights, contact us at [email protected].
2. Data collected
2.1 Identification and account data
When you create your account: email address, chosen display name, password (stored in hashed, unreadable form), registration date and time, internal unique identifier.
2.2 Data entered in the Service
The information you record in Tribulys to coordinate care for your loved one:
- Care journal: timestamped notes, observations, alerts, author of the entry, note type.
- Calendar: events, appointments, caregiver visits, schedules.
- Medications: medication name, dosage, intake times, administration confirmations.
- Health record and emergency sheet: allergies, conditions, vital signs, information useful in an emergency and other health details entered voluntarily.
- Documents: files uploaded by care-circle members, which may contain medical information.
- Messaging: messages exchanged between members and, when this feature is used, audio recordings or voice messages.
- Circle: information about invited members (email, role: family, nurse, doctor, physiotherapist, home care worker).
2.3 Payment data
For paid subscriptions: on the Web, payment-card data is collected and managed directly by Stripe; in the iOS app, payment is processed by Apple through the App Store; in the Android app, payment is processed by Google through Google Play Billing. RevenueCat technically synchronizes subscription status between Tribulys and the app stores without receiving full bank-card details. Tribulys never stores bank card details. We retain only transaction references, billing history and information required for accounting (amount, date, product, status and transaction identifier).
2.4 Technical data, notifications and usage measurement
For security and proper operation of the Service: IP address depending on the technical services used, browser and operating system, device type, pages or routes viewed in normalized form, connection timestamps and technical error logs.
For notifications, a technical device or push-subscription identifier and the account's pseudonymous identifier may be sent to OneSignal. Tribulys notifications contain no medical information; they invite the user to open the app.
Tribulys uses PostHog to measure deliberately defined product events, with no automatic capture, session recording or medical content; the account identifier is pseudonymous and paths containing identifiers are normalized before transmission. Sentry is used to diagnose errors and performance, with personal data disabled by default and mechanisms to mask and remove sensitive information.
The public website may use Google Analytics according to the applicable consent choices. These tools are used for audience measurement and service improvement, never to sell data or build advertising profiles from health data.
3. Purposes and legal bases of processing
| Provision of the Service | Performance of the contract (Art. 6(1)(b) GDPR): account creation, management of the journal, calendar, medications, circle. |
| Health data | Explicit consent (Art. 9(2)(a) GDPR): medication tracking and notes of a medical nature. You may withdraw this consent at any time. |
| Billing & accounting | Legal obligation (Art. 6(1)(c) GDPR): invoices retained for 10 years (French Commercial Code, Art. L. 123-22). |
| Security & fraud prevention | Legitimate interest (Art. 6(1)(f) GDPR): connection logs, detection of abnormal access. |
| Improvement of the Service | Legitimate interests (Article 6(1)(f) GDPR): limited, pseudonymized usage measurement designed to exclude medical content from analytics events. No health data is used for advertising purposes. |
| Service communications | Performance of the contract (Article 6(1)(b) GDPR): transactional emails and notifications required for coordination according to the user's preferences. |
4. Retention periods
| Account data | For the duration of the active subscription + 3 years after termination (civil contractual limitation period: Art. 2224 French Civil Code). |
| Coordination and health data | For the lifetime of the active care circle, then according to the deletion process described on the Account deletion page and the applicable backup retention periods. |
| Billing data | 10 years from the close of the accounting year (legal obligation: Art. L. 123-22 French Commercial Code). |
| Technical logs | Retained for a limited period proportionate to security, diagnostic and abuse-prevention needs, according to the configuration of the relevant providers. |
| Session cookies (Supabase) | For the period required for authentication and secure session renewal, according to the Service configuration. |
| cookie-banner.ca | Period set by the consent manager to remember your choices. |
5. Data recipients: processors
Tribulys uses technical providers to deliver, secure, measure and bill the Service. Only data necessary for their function is transmitted, in accordance with applicable contracts, privacy policies and safeguards.
Supabase Inc. : database and authentication
Role: Service data storage and account authentication, with application access controls and encrypted communications.
Stripe : Web payments
Role: processing card payments made on the Web. Full payment-card details are processed by Stripe and are not stored by Tribulys.
Apple : payments in the iOS app
Role: processing subscriptions purchased through Apple In-App Purchase and the App Store.
Google : Android payments, distribution services and notifications
Role: distributing the Android app, Google Play Billing for subscriptions, and Firebase Cloud Messaging as the transport infrastructure for Android push notifications.
RevenueCat, Inc. : technical management of mobile subscriptions
Role: synchronizing purchases and subscription entitlements with the App Store and Google Play. RevenueCat receives the identifiers and technical information needed to validate purchases, but not full payment-card details.
OneSignal, Inc. : push notifications
Role: managing push subscriptions and delivering notifications. Tribulys sends the necessary technical identifiers; notification content is designed not to expose medical information.
Sentry : technical diagnostics
Role: error detection and performance measurement. Tribulys disables personal-data transmission by default and sanitizes URLs, identifiers and other sensitive information before transmission; any error replays are configured to mask text, fields and media.
PostHog : product usage measurement
Role: measuring functional events defined by Tribulys. Automatic capture, session recording, surveys and exception capture are disabled; no health content is intentionally transmitted.
Vercel Inc. : application hosting
Role: deploying and running the web application and its application functions.
Google Analytics : public website audience measurement
Role: audience statistics for the marketing site when measurement is enabled in accordance with the applicable consent choices.
Tribulys never sells, rents or transfers your personal data to third parties for commercial or advertising purposes.
6. Transfers outside the European Union
Tribulys gives preference to European hosting regions when this option is available. Some technical providers are international or US companies and may process certain data outside the European Economic Area. In that case, transfers must rely on a mechanism recognized by the GDPR, such as an adequacy decision, the European Commission's Standard Contractual Clauses or another applicable safeguard offered by the provider.
7. Data security
Tribulys implements appropriate technical and organisational measures to protect your data against any unauthorised access, alteration, disclosure or destruction:
- TLS (HTTPS) encryption of communications;
- Encryption of data at rest when provided by the storage infrastructure;
- Passwords managed by the authentication service in a form unreadable by Tribulys;
- Authentication with limited-lifetime tokens and secure renewal;
- Row Level Security (RLS): each user can access only data from the care circles to which they belong;
- Android backup explicitly disabled to prevent uncontrolled copying of local native-shell data;
- Logging and monitoring of abnormal access;
- Access to production data restricted to authorized persons under the principle of least privilege.
If a data breach poses a risk to your rights and freedoms, Tribulys applies the notification obligations set out in Articles 33 and 34 GDPR.
8. Your rights
In accordance with the GDPR and the French Data Protection Act (loi Informatique et Libertés), you have the following rights over your data:
| Right of access | Obtain confirmation that data concerning you is being processed and obtain a copy of it (Art. 15 GDPR). |
| Right to rectification | Have inaccurate or incomplete data corrected (Art. 16 GDPR). Directly accessible from your Settings. |
| Right to erasure | Right to be forgotten: request the deletion of your data under the conditions set out in Art. 17 GDPR (except where legal retention obligations apply). See how to delete your account. |
| Right to data portability | Receive your data in a structured, commonly used and machine-readable format (Art. 20 GDPR). Export available from the Service. |
| Right to object | Object to processing based on Tribulys's legitimate interest (Art. 21 GDPR), unless there are compelling legitimate grounds. |
| Right to restriction of processing | Obtain the restriction of processing in certain situations (Art. 18 GDPR). |
| Withdrawal of consent | Withdraw your consent to the processing of health data at any time, without affecting the lawfulness of processing carried out before its withdrawal. |
| Automated decision-making | Tribulys does not carry out any automated decision-making or profiling producing legal effects concerning you. |
To exercise any of these rights, send your request by email to [email protected] We may request only the information strictly necessary to verify your identity when there is reasonable doubt about who made the request. We respond within the time limits set by Article 12 GDPR.
10. Health Data Hosting (HDS)
11. Complaints: supervisory authority
If you consider that the processing of your data does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority, in France the Commission Nationale de l'Informatique et des Libertés (CNIL) :
| Website | www.cnil.fr |
| Postal address | CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 |
| Phone | +33 (0)1 53 73 22 22 |
We encourage you to contact us first at [email protected] in order to resolve any issue amicably.
12. Changes to this policy
Tribulys reserves the right to amend this policy to reflect changes to the Service, regulations, mobile platforms or its providers. If a material change is made, we will inform users by an appropriate means when required by law. The update date shown at the top of this page is authoritative.