Privacy notice
Version 2026-07-27.1 · Controller: TitreSimple
TitreSimple is an ephemeral dossier product for preparing a French titre de séjour file. We design for GDPR: consent where required, data minimization, short retention, and tools so you can access, export, restrict, or erase your data.
Lawful bases & consent
Core dossier preparation and AI document checks run only after you opt in. Checkboxes start unchecked. Each grant or revoke is stored in an immutable consent log (purpose, decision, policy version, time, and technical metadata such as IP / user agent when available).
Application processing
Store your questionnaire answers and checklist progress for up to 72 hours so you can prepare your titre file.
Purpose id: application_processing
AI document checks
Send document images temporarily to our OCR provider to extract fields and check constraints. Files are not kept after the check.
Purpose id: ai_ocr_validation
Email notifications
Send optional product emails about your dossier (expiry reminders). Off by default; identity email stays with Clerk.
Purpose id: email_notifications
Revoke anytime in Privacy settings. Revoking AI checks blocks new OCR uploads immediately. Revoking application processing blocks creating or updating dossiers.
What we do not keep
- Uploaded document files — processed in memory for checks, then discarded.
- No long-term archive of passport, lease, or similar PDF/image binaries.
- Email is not copied into our dossier database; sign-in identity stays with Clerk.
What we store briefly
- Clerk user id, account type, and optional organization label.
- Questionnaire answers, checklist progress, and temporary OCR field extracts — only with the relevant consent.
- Default retention: 72 hours from last activity, then deletion (lazy purge on access + hourly scheduled purge).
- OCR field extracts are cleared when you export your preparation package.
- Consent audit history until you delete your account.
Your rights
Use Privacy settings while signed in:
- Access & portability — Download my data (machine-readable JSON of profile, dossiers, and consent history). Document files are not included because we never store them.
- Erasure — Delete a single dossier, or delete account & dossiers (cascades app data and requests Clerk account deletion).
- Restriction — Restrict processing (Art. 18) to block OCR, export, and automated dossier updates until you lift it.
- Withdraw consent — Toggle each purpose off; new processing for that purpose stops.
- Rectification — Edit answers in your active dossier while it exists; identity email is managed in your Clerk account.
Security measures
- TLS in transit; ephemeral dossier TTL; zero file retention.
- Consent and processing-restriction gates on sensitive APIs.
- Auxiliary text sent to OCR is PII-stripped where patterns are detected.
- User ids in operational logs can be pseudonymized.
- Internal security breach register for Art. 33/34 incident tracking.
Sub-processors & transfers
We use processors listed on /privacy/subprocessors (Vercel, Clerk, Anthropic, optional Supabase). Prefer EU regions where configurable.
Data Protection Officer
Contact: dpo@titresimple.app. We aim to support supervisory authority notification timelines where a personal-data breach must be reported.
This notice describes how the product is built. It is not a substitute for formal legal counsel or a full DPIA. A machine-readable record of processing activities is maintained in the project as docs/ropa.json.