Florimel

Privacy Policy

Last updated: 16/06/2026 Effective date: 16/06/2026

1. Who we are

This Privacy Policy explains how Kawaru ("we", "us", "our") processes personal data in connection with the Florimel application and website at florimel.app (the "Service").

We are the controller of the personal data described below. Where we use the word "you", we mean a user or visitor of the Service.

2. Our approach

Florimel is designed to be privacy-first. We keep the personal data we collect about you to a minimum, we host your data within the European Union, and we do not sell your data or use it for advertising.

That said, Florimel is a personal-timeline application: by design, you enter and store significant amounts of your own personal information inside it. This policy describes both the limited data we collect to run the Service and how we handle the content you choose to store in it.

3. What personal data we process, and on what legal basis

3.1 Account and authentication data

3.2 Content you store in Florimel ("Your Content")

3.3 Payment and transaction data

3.4 Technical and log data

3.5 Communications

4. Cookies and local storage

Florimel uses a strictly necessary session cookie to keep you logged in. Under the ePrivacy rules this does not require consent, and we set no cookies for analytics, profiling or advertising.

We keep a small, first-party product counter to understand whether the Service works: it records only that a handful of moments happened and when — for example a signup, a saved memory, or a return visit — together with your account number so we can tell a first return from a repeat. It contains none of the content you write, no IP address, and is never shared with, or collected by, any third party. There are no third-party analytics or tracking tools of any kind. Event rows are deleted after 12 months. For the two first-time counts, Florimel keeps a yes/no marker until your account is deleted so that a later visit or subscription is not counted as your first one again.

Some optional features embed third-party components — in particular the Spotify player widget — which may set their own cookies or use local storage when you choose to load them. Those are controlled by the third party under its own policy (see Section 7). If you do not activate those features, those third-party cookies are not set.

5. AI processing (transcription and data identification)

To make Florimel work, the Service uses AI models to transcribe your voice input and to identify and structure information within Your Content.

6. Where your data is stored

The Service and your stored data are hosted on a virtual private server provided by Hostinger, located in France (European Union). Our hosting provider acts as our processor under a data processing agreement.

7. Third-party services and recipients

We share personal data only as needed to run the Service. We do not sell personal data. The third parties below process data in the roles described:

Service What it does in Florimel Data involved Role & location Transfer safeguard
Hostinger Hosting / infrastructure All stored data Processor; servers in France (EU) Within EU
Mistral AI (Voxtral) Default transcription & data identification Voice input and relevant content Processor; EU Within EU
Paddle Payment processing & invoicing (Merchant of Record) Billing & transaction data Independent controller / reseller; UK UK adequacy decision
Spotify Optional in-app music player widget Account/listening data you connect Independent controller; EU/US DPF / SCCs (as applicable)
Last.fm Outbound link only (no embedded widget) None until you follow the link Independent controller; UK UK adequacy decision
Google Calendar Optional read-only import of calendar events you authorise Calendar data you grant access to Independent controller; EU/US EU–US Data Privacy Framework + SCCs
Google Street View Retrieves an image for an address you enter manually The address you submit Independent controller; EU/US EU–US Data Privacy Framework + SCCs
Nominatim (OpenStreetMap) Address auto-completion The text you type to search Independent controller; EU Within EU
Anthropic / OpenAI Only if you supply your own key — transcription/identification Content you process via your key Independent controller; US DPF / SCCs (your contract with them)

Optional integrations (Spotify, Google Calendar) are activated only when you connect them, and you can disconnect or revoke access at any time — for Google services, also via your Google Account permissions page. Where we use Google APIs, our use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: Google Calendar access is read-only and used only to provide the feature you enabled.

8. International transfers

Most processing takes place inside the EU (Hostinger, Mistral, Nominatim) or in a country recognised by the European Commission as providing adequate protection (the UK, for Paddle and Last.fm).

Where data is transferred to the United States — namely to Google for the Calendar and Street View features, and to Anthropic/OpenAI only if you choose to use your own key — the transfer is protected by the recipient's certification under the EU–US Data Privacy Framework and/or by Standard Contractual Clauses. The Data Privacy Framework is currently valid but is the subject of an ongoing legal challenge before the EU courts; we monitor its status and maintain Standard Contractual Clauses as a fallback safeguard.

9. How long we keep your data

10. Your rights

Under the GDPR you have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interest; and withdraw consent at any time (without affecting processing already carried out).

How to exercise them:

Right to complain: If you believe we have not handled your data lawfully, you may lodge a complaint with the Belgian Data Protection Authority — Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels (contact@apd-gba.be). You may also complain to the supervisory authority in your own EU country of residence.

11. Security

We protect your data with measures appropriate to the risk, including encryption in transit (TLS), hashed password storage, access controls, and EU-based hosting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We strongly encourage you to keep your own copy of any content that is important to you.

12. Age limit

Florimel is intended for adults. You must be at least 18 years old to create an account. We do not knowingly process the data of minors; if we learn that we have, we will delete the account.

13. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or within the Service before they take effect. The "Last updated" date above shows the current version.

14. Contact

For any question about this policy or your data: dpo@kawaru.eu.