Privacy Policy
Last updated: July 2026
Who we are
The Consent app is developed and published by Studio Kairos Apps, an independent publisher.
Contact: consentement.kairos@gmail.com
General philosophy
The app is built on a data minimization principle: we only collect what is strictly necessary for it to function. No real identity information is required to use the app.
Data collected
3.1 On your device (local storage only)
The following data is stored exclusively on your phone, in a local database. It never leaves your device unless otherwise stated below.
| Data | Description | Stored where |
|---|---|---|
| Username | A freely chosen nickname, unlinked to your real identity | Local only |
| Session log | Timestamps of consents and withdrawals | Local only |
| Card agreements | Cards mutually confirmed with a partner | Local only |
| Session history | Summary of past encounters | Local only |
3.2 On our servers
Two types of data are transmitted to or stored on our servers, hosted within the European Union (Fly.io):
a) PDF fingerprints (stored permanently)
When an end-of-session PDF document is generated, a SHA-256 fingerprint is computed from the session data in canonical JSON form (consent and withdrawal timestamps, identifiers of cards played, participant's functional role) — not from the PDF file itself. The PDF contains this fingerprint; the fingerprint does not cover the document's formatting.
This fingerprint:
- contains no personally identifiable information
- is associated with a random session identifier (UUID) with no link to your identity
- cannot be used to reconstruct the document's content
- is stored permanently for its evidentiary value
b) Card plays (deleted at session close)
In À la carte Mode, the cards you play are temporarily stored on the server to enable real-time detection of mutual agreements. These records contain:
- a random session identifier (UUID)
- your functional role in the session (two distinct anonymous values, unlinked to your identity)
- the identifier of the card played
- timestamps of play and any withdrawal
These data are automatically deleted when the session is closed or expires automatically, whichever comes first.
3.3 Web browser — local storage
The web version of the app uses the browser's local storage (localStorage) to retain certain information between visits — for example your username and the state of your current session. Other data may be stored in the same way as the app evolves.
This mechanism is sometimes referred to generically as "cookies" in regulations, though it is technically distinct: localStorage data is never automatically transmitted to our server and remains strictly confined to your browser.
- are strictly necessary for the service to function — without them, the app cannot remember your username or maintain your session
- are not shared with third parties and serve no advertising or analytics purpose
- never leave your browser
- can be deleted at any time by clearing your browser's local storage (via your browser settings)
In accordance with the ePrivacy Directive, these trackers being strictly necessary for the explicitly requested service, no prior consent is required.
3.4 Push notifications (Android)
To alert you when a withdrawal of consent occurs while the app is closed or in the background, the Android app uses Google's notification service, Firebase Cloud Messaging (FCM).
For this purpose, a notification token (FCM token) is generated by your device and sent to our server, where it is associated with your current session (via a random identifier, never your identity). This token:
- is a technical delivery identifier specific to the app's installation on your device, periodically renewed by the system
- contains no personal data and cannot be used to identify you
- is automatically deleted from our servers when your session expires (same retention as session data)
The content of notifications we send via FCM is kept to a strict minimum: a simple technical signal ("a consent withdrawal has occurred"), with no username, no session content, no personal data whatsoever. The text shown on your screen is composed locally by the app, not transmitted over the network.
No Firebase analytics SDK is embedded and Google Analytics is disabled on our Firebase project — in line with our no-tracking principle.
3.5 Traffic analytics (website only)
The website uses Vercel Analytics, an audience measurement tool built into our hosting platform. This service operates without cookies or persistent identifiers: no data is placed on your device or in your browser.
Vercel measures aggregated metrics — pages visited, country of origin, device type — without building individual profiles or enabling identification.
- No cookie, no tracker placed on your device
- Aggregated data only — no individual tracking
- Legal basis: legitimate interest (audience measurement, exempt from prior consent)
Android app: no analytics tool is currently integrated. The Android app transmits no usage or traffic data.
For more information: Vercel privacy policy.
3.6 What we do not collect
- First name, last name, postal address
- Email address (unless you contact us directly)
- Phone number
- Date of birth
- GPS location data
- Photos or videos
- Biometric data
- Individual behavioral profiles, advertising or targeting data
3.7 Testing program
The app is in open testing on the Google Play Store. Sign-up for the program happens directly with Google, without going through us: we do not collect or retain any email address for this purpose.
Until July 20, 2026, testing was closed and the /testeurs page offered a form to collect email addresses for enrollment on the list of authorized testers. This form has been removed and the collected addresses have been deleted.
Some testers joined the Google group "Kairos App Testers." Membership is voluntary, reversible at any time, and managed by Google — we obtain no personal data from it.
Real-time messages (WebSocket)
The app uses a WebSocket connection to synchronize the two participants in a session in real time. Two distinct regimes apply depending on the message type:
Consent messages (Free Mode)
Consent and withdrawal messages are relayed ephemerally from one device to the other. They are not stored in a server-side database. Consent status is retained only on each participant's device.
Card plays (À la carte Mode)
Cards played are temporarily stored on the server to enable detection of mutual agreements and to reconstruct the state in the event of reconnection. These records contain only: the session identifier, the card identifier, the functional role, and timestamps. No username is stored server-side. These data are deleted when the session is closed or expires automatically.
The session disappears from the server's working memory as soon as both participants disconnect.
Purposes of processing
| Data | Purpose | Legal basis |
|---|---|---|
| PDF fingerprints | Verification of consent document integrity | Legitimate interest / legal obligation |
| Card plays | Real-time synchronization between participants | Performance of the service |
| Local data | App functionality, personal history | User consent |
| Web traffic (Vercel Analytics) | Aggregated website audience measurement | Legitimate interest |
Hosting and data transfers
Our server is hosted by Fly.io, within the European Union. No data transfers outside the EU are made.
Retention periods
| Data | Retention |
|---|---|
| PDF fingerprints | Indefinite (evidentiary value) |
| Card plays | Until session close or automatic expiry |
| Notification token (FCM) | Until automatic session expiry |
| Local data | Until uninstall or manual deletion |
Data sharing
We do not sell, rent, or share any personal data with third parties for commercial purposes.
The only third parties involved are:
- Fly.io (server host, EU) — Fly.io privacy policy
- Vercel Inc. (website host + traffic analytics) — Vercel privacy policy
- Expo / EAS (distribution platform) — in connection with the technical installation of the app
- Google (Firebase Cloud Messaging) — solely for the delivery of Android push notifications: only a technical device token and a minimal signal are transmitted, with no personal data; Google Analytics is disabled on our Firebase project Google privacy policy
Your rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Access: obtain a copy of data held about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Objection: object to a processing activity
- Portability: receive your data in a structured format
To exercise these rights, contact us at: consentement.kairos@gmail.com
We will respond within 30 days. You may also lodge a complaint with the competent data protection authority in your country of residence.
Deleting your data
Local data — you are in control
Data stored on your device is under your exclusive control:
- Delete a session: History → select a session → Delete
- Delete everything: uninstalling the app permanently removes all local data, without exception
These deletions are immediate and irreversible.
Server-side data — bilateral nature
Session data stored on our servers (PDF fingerprints and card plays) are bilateral consent records: they concern two participants equally and may constitute evidence of consent for either party.
Deleting these data at the request of one participant alone would deprive the other of their ability to establish or defend their rights. These data are therefore retained in accordance with the exception provided under Article 17(3)(e) of the GDPR (establishment, exercise, or defense of legal claims).
They are anonymized: they contain no real name, email address, or personal identifier — only a random session identifier and a functional role.
Why we cannot authenticate a deletion request
Since the app collects no personal identifier, we have no way to verify that a request comes from an actual participant in the session concerned. Accepting unverifiable requests would expose one participant to having their evidence deleted by the other — which is contrary to the app's protective purpose.
Minimum age
Two distinct regulatory frameworks apply to the app, with different thresholds — they coexist without contradiction.
GDPR threshold — varies by country
The GDPR lets each member state set its own age at which a minor may independently consent to the processing of their personal data (between 13 and 16 depending on the country). Since the app collects no date of birth or real identity data, it cannot verify users' ages: it is each user's responsibility to comply with the threshold applicable in their country of residence.
16+ — Content classification (Google Play Store)
The app is rated 16+ under the PEGI (Pan European Game Information) system on the Google Play Store. This rating concerns the themes covered (intimacy, sexuality in unlocked cards). It falls under the content policy of the distribution platform and is independent of data collection regulations.
The first threshold governs the right to process personal data; the second governs access to the app's content. These two regulatory frameworks are complementary.
Security
We implement the following technical measures to protect your data:
- Communications between the app and our server are encrypted via HTTPS/WSS (TLS)
- Local data is stored in the Android app's private area (Android sandbox), inaccessible to other apps
- PDF fingerprints cannot be used to reconstruct the original data
- The local database is encrypted at rest using SQLCipher (AES-256). The encryption key is generated on the device at first launch and stored in the Android hardware key store (Keystore), never transmitted to our servers. This protection is layered on top of Android application sandbox isolation.
Changes to this policy
In the event of a material change to this policy, we will notify you via an in-app notification. The date of last update is shown at the top of this document.
Contact
For any questions regarding this policy or the exercise of your rights:
Email: consentement.kairos@gmail.com
Studio Kairos Apps