Privacy Policy
Last updated: September 1, 2026
1. Data controller
Data controller: Timothée Miminoshvili, sole proprietor (trade name TEL-MI Labs) — SIREN 847 659 216
Address: 72 rue de Dantzig, Hall 14, 75015 Paris, France
Data protection contact: Timothée Miminoshvili — dpo@pictoflow.com
General email: contact@pictoflow.com
2. Data collected
2.1 Account data (parent or professional)
- Username (required)
- Email address (required)
- Password (required — stored only in hashed form, never in plain text)
2.2 Data relating to children
The account is created and managed by an adult. Within their space, they can create child profiles containing:
- a first name or nickname and a display color;
- an optional avatar;
- the content created for the child: cards (images and labels), schedules, sequences, rewards, board progress.
Uploaded images may contain photos. We recommend using only what the child needs: a nickname is enough, and a photo is never required (see section 3).
2.3 Technical data
- IP address — used for security, and kept only in hashed (non-reversible) form in the consent record
- Browsing information (user agent, language)
- Technical device identifier (required for multi-device synchronization)
- Consent data (record of your choices)
- Technical logs kept by our hosting providers (short duration)
2.4 Subscription data (if applicable)
- Billing information (processed by Stripe)
- Payment history and subscription status
- Your card numbers never pass through our systems: they are entered directly with Stripe.
3. Protection of children's data
picto-flow is a service intended for parents and caregivers of children. Children deserve specific protection of their data; here are our commitments:
- No child accounts: the account belongs to the adult. No data is collected directly from the child.
- The parent stays in control: child profile data is entered by the holder of parental authority (or the caregiver they have authorized), who exercises all rights over this data (see section 8).
- Data minimization: a nickname and a color are enough to create a profile. No date of birth and no medical information are requested.
- No exploitation: children's data is used only to operate the service. Never for advertising, never for profiling, never shared with third parties.
- No commercial message ever appears in the interface used by the child.
4. Purposes of processing
- Provide the picto-flow service (creating cards, schedules, board tracking)
- Manage accounts and authentication
- Ensure security and prevent abuse (anti-bot protection)
- Diagnose technical errors (error reports with a pseudonymized identifier — see section 7)
- Manage subscriptions and billing
- Answer your requests (support)
5. Legal bases
5.1 Performance of a contract (article 6.1.b GDPR)
- Account management, provision of the service, subscription management
- Child profile data, entered by the parent, is processed under this same contract.
5.2 Legitimate interest (article 6.1.f GDPR)
- Security and abuse prevention
- Technical error diagnosis
- Support and assistance
5.3 Legal obligation (article 6.1.c GDPR)
- Retention of billing data (accounting and tax obligations)
- Proof of consent collection
5.4 Consent (article 6.1.a GDPR)
To date, no processing is based on consent: we use neither audience measurement nor advertising trackers. If this were to change, your consent would be collected before any tracker is set, and this policy would be updated.
6. Retention periods
6.1 Account and content data
- Active account: kept as long as the account exists
- Account deletion: immediate erasure from our active systems (profiles, cards, images, preferences); copies held in our security backups are overwritten within 30 days at most
- Inactive account: deleted after 2 years of inactivity, preceded by an email notice and a 30-day period during which simply signing in is enough to keep the account
6.2 Records and billing
- Record of your acceptance of the Terms of Use and of your consent choices: 5 years (statutory limitation period) — after account deletion, this record is kept in a form dissociated from your identity
- Invoices: 10 years (accounting obligation)
- Payment data: kept by Stripe according to its own obligations
6.3 Technical data
- Technical logs: short durations set by our hosting providers
- Local trackers: see the Cookie Policy
7. Data recipients
7.1 Internal access
picto-flow is operated by a sole proprietorship with no staff: only the data controller accesses the data, strictly as needed (assistance, maintenance).
7.2 Processors
| Processor | Role | Data location |
|---|---|---|
| Supabase | Database, authentication, image storage, server functions | European Union (Ireland) |
| Vercel | Website and application hosting | United States (safeguards: see 7.3) |
| Stripe | Payments and billing | United States (safeguards: see 7.3) |
| Brevo | Sending service emails (confirmation, password reset) | France (European Union) |
| Sentry | Technical error diagnosis | European Union (Germany) — user identifier pseudonymized (hashed) before being sent |
| Cloudflare | Anti-bot protection (Turnstile) and DNS | United States (safeguards: see 7.3) |
We never sell or rent any data. No advertising third party has access to your data or your children's data.
7.3 Transfers outside the European Union
Application data (accounts, profiles, content) is hosted within the European Union. Some processors (Vercel, Stripe, Cloudflare) are established in the United States: these transfers are governed by the European Commission's standard contractual clauses and/or their certification under the EU–US Data Privacy Framework.
8. Your rights (and your child's)
Under the GDPR, you have the following rights:
- Right of access (article 15): know what data is held and obtain a copy
- Right to rectification (article 16): correct inaccurate data
- Right to erasure (article 17): request deletion of your data
- Right to restriction (article 18): temporarily suspend processing
- Right to portability (article 20): retrieve your data in a structured format
- Right to object (article 21): object to processing based on legitimate interest
- Right to withdraw consent: at any time, for any processing that would rely on it
Child profile data: these rights are exercised by the holder of parental authority (or their authorized representative), from the account hosting the profile.
9. Exercising your rights
9.1 Directly in the application
- Access and portability: "Download my data" button in the GDPR Portal
- Rectification: your username can be changed in the application; for other data (email address…), write to us
- Erasure: account deletion from the settings (immediate effect)
9.2 By email
- Contact: dpo@pictoflow.com
- Response time: 1 month maximum (extendable by 2 months for complex requests, in which case you would be informed)
9.3 Complaints
- CNIL: www.cnil.fr
- Or the supervisory authority of your country of residence
10. Data security
10.1 Technical measures
- Encryption in transit (HTTPS/TLS)
- Password hashing (bcrypt — never stored in plain text)
- Strict account isolation: each account can only access its own data, enforced by the database itself (Row Level Security)
- Pseudonymization of the user identifier in error reports
- Secure backups (encrypted in transit)
10.2 Organizational measures
- Access limited to the data controller alone
- Security reviews at every major evolution of the service
- Ongoing awareness of the operator regarding data protection
11. Cookies and trackers
picto-flow only uses trackers that are strictly necessary for the service to work — no audience measurement, no advertising trackers. Details: Cookie Policy.
12. Changes to this policy
This policy may be updated to reflect changes in our practices, new legal requirements, or the addition of new services. You will be notified of significant changes via the website, by email (if you have an account), or in the application.
13. Contact
13.1 General questions
Email: contact@pictoflow.com
13.2 Data protection contact
Contact: Timothée Miminoshvili — dpo@pictoflow.com
13.3 Exercising GDPR rights
GDPR Portal: GDPR Portal
14. Accessibility {#accessibilite}
We aim for WCAG 2.2 AA compliance. If you encounter any accessibility issue, write to us at support@pictoflow.com.
Version history:
- 1.0 (December 2024) - First GDPR-compliant version
- 1.1 (July 2026) - Real data controller, factual corrections
- 1.2 (July 2026) - Actual processing (removal of audience measurement; declaration of Vercel, Brevo, Sentry, Cloudflare), "Protection of children's data" section, clarified retention periods, accuracy corrections
- 1.3 (September 2026) - 30-day grace period before deletion of an inactive account: email notice, then 30 days during which simply signing in is enough to keep the account
Last updated: September 1, 2026