Personal data
Privacy policy
What the service records, why, for how long, and what you can demand.
Last updated: August 18, 2026
In short: no advertising trackers, no audience measurement, no data resale. The five cookies we set exist to sign you in, to protect the forms you submit and to remember your language. During a walk, your positions leave your phone only if you ticked the box offered to you before setting off.
Who processes your data
The publisher of the service, identified in the legal notice, is the data controller for everything that runs the platform itself: accounts, authentication, service emails, security and administration logs.
It acts as a processor, within the meaning of Article 28 GDPR, for data produced during a walk (traces and memos): those are handled on behalf of the organisation or author who designed the tour, who is the controller for them and decides what becomes of them. This split of roles is governed by the contract signed with each client.
For any question or request about your data: stephane@chaperot.net.
What the service records
| Processing | Data | Legal basis | Retention |
|---|---|---|---|
| Account | Email, first and last name, password (never in clear: only its hash is stored), role, creation and last sign-in dates. | Performance of the contract (Art. 6.1.b). | Lifetime of the account, then deletion within 30 days. |
| Sessions and security | Session token fingerprints, IP address and browser at sign-in time. | Legitimate interest: protecting accounts and detecting session theft (Art. 6.1.f). | 30 days at most; revoked immediately on sign-out. |
| Service emails | Recipient address, message type (verification, password reset), delivery status and any error. | Performance of the contract, and legitimate interest in proving a message was sent. | 12 months. |
| Administration log | Who acted, what action, values before and after, IP address. | Legitimate interest: traceability of sensitive operations. | 12 months. |
| Tours | Content uploaded by the designer: tour name, place, texts, audios, design archives, and the name of the last editor. | Performance of the contract. | Lifetime of the owning account. |
| Walk trace | Timestamped positions recorded while walking, distance covered, start and end times, visitor's name. | Consent (Art. 6.1.a), taken before setting off and withdrawable at any time. | Until deleted by the tour's designer, or on the visitor's request. |
| Walk memo | Voice recording or written note, optional position of the spot where it was left, author's name. | Consent: a memo exists only if you record and send it. | As above. |
None of this data feeds advertising profiling, marketing outreach or automated decision-making. None of it is sold or rented.
The walk: what leaves the phone, and what does not
During a walk your position is read continuously by your browser so that sounds fire in the right place. That computation happens on your device. Until you tick the box, no position is sent to the service.
- Sending the trace is offered before setting off, never mid-walk, and the box is never ticked in advance.
- Your answer is remembered on the device so you are not asked again at every walk; you can change it before the next one starts.
- A sent trace is visible only to the tour's designer, who sees a name, never your email address.
- A memo, spoken or written, is only sent when you send it; attaching your position to it stays optional.
- Withdrawing consent means unticking the box — which stops any further sending — and, if you wish, asking for traces already sent to be deleted, at the contact address above.
A movement trace says a great deal about the person who produced it. It is treated as what it is — sensitive in practice — and is never cross-referenced with other walks, nor with your account data beyond the link needed to let you have it deleted.
Cookies and local storage
The service sets five cookies. All of them are necessary for it to work: none measures audience, follows you from site to site, or serves advertising.
| Name | Purpose | Lifetime |
|---|---|---|
emvc_access | Keeps you signed in from page to page. Unreadable by page code (httpOnly). | 15 minutes |
emvc_refresh | Renews your session without asking for your password again. Also httpOnly. | 30 days |
emvc_csrf | Protects forms and saves against requests forged by another site. | 30 days |
emvc_locale | Remembers the language you read the site in. | 1 year |
emvc_skin | Remembers that you arrived from a walk, so shared screens are shown in their phone-adapted form. | 1 day |
The service also uses the browser's storage, which is subject to the same rules as cookies:
| Where | Purpose | Lifetime |
|---|---|---|
| Studio local database | Keeps the tour you are designing on your own machine, audios included, so the work survives a closed tab or a lost connection. | Until the tour is deleted or browser data is cleared. |
| Studio display preferences | Which panels are open, the last tab you used, the number of the last saved revision. | As above. |
emvc_gps_share | Records your answer to the trace-sending offer. It is the register of your choice, not a tracker. | As above. |
| Opening animation | Remembers that the opening animation has already been shown, so it is not played at you twice. | For the lifetime of the tab. |
Why you are shown no cookie banner
Article 82 of the French Data Protection Act, which implements the ePrivacy Directive, requires prior consent for any reading or writing in your device — except where it is strictly necessary to deliver the service you asked for. Authentication, protection against forged requests, remembering your language and the display customisation you triggered yourself fall within that exemption as the CNIL describes it. Nothing set here falls outside it. Asking you for consent the law does not require would be making you click for nothing.
You can clear these cookies and storages at any time from your browser settings. You will then be signed out, and a tour being designed that had not been saved to the service would be lost.
Who else sees this data
Data is disclosed to no one beyond the providers needed to run the service, bound by contract and acting only on instruction:
- Host and file storage — servers and object storage located in the European Union (Paris region). See the legal notice.
- Email delivery — a transactional sending provider receives your address and the content of the service message meant for you (address verification, password reset).
- Google Fonts — the site's typefaces are served by Google LLC. Displaying a page therefore sends your IP address to that provider, established in the United States. No cookie is set through it.
- Base maps — in the Studio only, displaying the map sends your IP address to the OpenStreetMap and Esri tile servers. The mobile explorer shows no map at all.
When a designer imports a sound from a web address, it is the service's server that fetches it: the visitor's browser never contacts the source site, and leaves no trace there.
Data may also be disclosed to judicial authorities upon a lawful request.
Transfers outside the European Union
Hosting, file storage and the database all stay within the European Union. Two exceptions, limited to display: Google Fonts and Esri satellite imagery, whose publishers are established in the United States and receive the visitor's IP address on that account. Those transfers rely on the mechanisms of Chapter V GDPR (adequacy decision or standard contractual clauses).
Your rights
You have the right of access, rectification, erasure, restriction and objection, the right to portability of the data you provided, and the right to withdraw your consent at any time where processing rests on it — withdrawal does not affect what was done beforehand.
These rights are exercised with stephane@chaperot.net. You will receive an answer within one month. Proof of identity may be asked for where there is serious doubt about who is asking, and only in that case.
Where the data concerns a walk, the request may be sent either to the service or to the organisation that designed the tour: it will be passed on to whoever must answer it.
You may also lodge a complaint with the French data protection authority, the CNIL (cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07), or with the supervisory authority of your own country of residence.
Security
Traffic is encrypted in transit. Passwords are never stored in clear. Session tokens are out of reach of page code, expire on their own, and replaying a revoked token immediately invalidates the whole session concerned. Access to tours is checked on every request, and a tour stays private until its owner publishes it.
Minors
The service is not aimed at children under 15. A tour can be followed without an account; a trace or memo sent by a child under 15 requires the agreement of the holder of parental authority, who may ask for its deletion at the contact address above.
Changes to this policy
This policy may be updated to follow changes in the service or in the law. The date of the last change appears at the top of the page; a substantial change to processing that rests on your consent will be brought to your attention.