Mycelora Privacy Policy

This English version is provided for convenience. In case of any discrepancy between the English and French versions, the French version prevails.

Version: 1.6
Effective date: 8 October 2026
Controller: EvidencAI, SAS (simplified joint-stock company) with share capital of 180,000 euros, RCS Romans 103 591 806

Contents

  1. Preamble and legal characterisation
  2. Scope of the processing
  3. Categories of data processed
  4. Purposes and legal bases
  5. Processors and recipients
  6. Data from Google services and limited use
  7. Transfers outside the European Union
  8. Retention periods
  9. Security of processing
  10. Data subject rights
  11. Complaint to the French Data Protection Authority (CNIL)
  12. Cookies and trackers
  13. Changes to this policy

1. Preamble and legal characterisation

1.1 Description of the service

Mycelora is a persistent memory service for conversational assistants,
available at mycelora.ai. It stores, organises and returns to its
user the contextual elements of their projects: decisions, facts,
intentions, learnings, referred to in the application as
memories.

The user feeds their memory in three ways: by entering or
importing content into the application, through the automatic logging of
their exchanges with an assistant where they have enabled such logging, and through
the optional connection of external email and calendar sources.

Logging of exchanges is never enabled by default. Depending on
the assistant used, the user enables it either by installing the extension
provided for that purpose, or by configuring their assistant themselves so that it
transmits their exchanges to the service. In both cases, activation results
from a deliberate act by the user and may be withdrawn at any time, by
uninstalling the extension or removing that configuration.

1.2 Characterisation adopted

EvidencAI is an independent controller within the meaning of Article 4(7)
of Regulation (EU) 2016/679 for all data processed in connection with the
service. EvidencAI alone determines the purposes and means of such
processing.

Where the user connects an external source, the content collected
may include personal data of third parties (correspondents, participants
in a meeting). The user is the origin of this through their act of connection.
EvidencAI processes such data solely in the interest and for the sole benefit of that
user, without using it for any other purpose.

2. Scope of the processing

EvidencAI carries out the following processing operations:

  1. management of the user account: creation, authentication by password, by one-time code or by federated identifier, profile modification, deletion;
  2. receipt and structured storage of content entered, imported or logged by the user, as well as of the memories derived from it;
  3. transmission of such content to language models operated by a processor (see section 5), in order to extract memories from it, produce project summaries, end-of-session handovers, the daily brief and the analysis of convergences between projects;
  4. computation of vector representations of memories in order to enable semantic search;
  5. management of the connection of external sources by the user: the OAuth authorisation flow for the Google calendar, including encrypted storage of refresh tokens and their revocation, and the connection of a mailbox by address and app password (IMAP), including encrypted storage of that password and its erasure upon disconnection;
  6. periodic collection of messages and meetings from connected sources, and assessment of their relevance before any transformation into a memory;
  7. sending of transactional communications, including the daily brief where the user has enabled it;
  8. management of subscriptions, payments and invoicing;
  9. technical and security logging.

3. Categories of data processed

3.1 Identification data

Email address, hashed password or federated identifier, first name and surname
where provided, account preferences, authentication tokens and
associated logs.

3.2 Memory data

Memories and their metadata, project spaces, project
summaries, handovers, imported documents and their fragments, the
contact records created by the user, links established between memories and
the observations produced by the cross-project analysis.

In addition, where the user has enabled logging of their exchanges
within the meaning of section 1.1, the raw exchanges between the user and their
assistant, kept for at most ninety days after they are recorded, then
deleted automatically. They are not turned into memories.

This content is provided by the user and reflects their professional
and personal activity. It may include personal data of
third parties. It is not intended to contain special categories of personal data within the meaning of
Article 9 of Regulation (EU) 2016/679, and the user is asked not to
enter any.

3.3 Data from connected external sources

For each source connected by the user, EvidencAI processes the account
address, the connection status and the timestamps of collections, as well as,
for each item collected, the data described below according to the type of
source. For the Google calendar, the scope of authorisation granted is also
stored.

Google calendar (OAuth). The title of the meeting, an extract of its
content, the list of participants and the timestamp. The refresh token issued
by Google is stored encrypted in a dedicated vault, never in plain text, and is
never displayed to the user.

Calendar with an app password (CalDAV). The title of the meeting, an
extract of its content, the list of participants and the timestamp. The
password is stored encrypted in a dedicated vault, never in plain text, and is
erased upon disconnection.

Mailbox (IMAP, with an app password). The user may connect any email
service, Gmail included, by its address and an app password. This way of
connecting is separate from the Google calendar: it does not use Google's
application programming interfaces and section 6 does not apply to it.

3.4 Subscription and billing data

Plan subscribed to, subscription status, Stripe session and payment
identifiers, invoices. EvidencAI does not collect or store any bank card
data, such data being processed exclusively by Stripe.

3.5 Technical and security data

IP addresses, session identifiers, execution logs of server
functions, audit logs, rate-limiting counters, record of
language model usage.

3.6 Waiting list

Email address, language chosen, date and time of consent. To limit abuse, an irreversible fingerprint of the IP address is kept for two hours together with a request counter; the IP address itself is not recorded in the waiting list.

3.7 User feedback

Type of feedback (report, idea, other), text entered, screen from which it was sent, language. This feedback is read by EvidencAI to improve the service.

4. Purposes and legal bases

ProcessingPurposeLegal basis (GDPR)
Creation and management of the accountEnabling use of the servicePerformance of the contract (Article 6(1)(b))
Storage of memories and spacesProviding the memory servicePerformance of the contract (Article 6(1)(b))
Language model inference for extraction, summaries, the brief and cross-project analysisProviding the visible features of the servicePerformance of the contract (Article 6(1)(b))
Computation of vector representationsEnabling semantic searchPerformance of the contract (Article 6(1)(b))
Logging of exchanges between the user and their assistantEnsuring continuity of work: resuming a thread left open, state of the current thread, closing reminder, and usage counters of the memories recalledConsent of the user, given by enabling logging within the meaning of section 1.1 and withdrawable at any time (Article 6(1)(a))
Connection and collection of external sourcesFeeding the memory at the user's requestConsent of the user, given by the act of connection and withdrawable at any time (Article 6(1)(a))
Connection and collection of a mailbox by app passwordFeeding the memory at the user's requestConsent of the user, collected by a checkbox in the dashboard before connection, timestamped with the version of the text displayed, and withdrawable at any time (Article 6(1)(a))
Sending of the daily briefInforming the userConsent, withdrawable by unsubscribing (Article 6(1)(a))
Waiting listNotifying the person when the service opensConsent, collected by a checkbox and timestamped, withdrawable at any time (Article 6(1)(a))
User feedbackFixing and improving the serviceEvidencAI's legitimate interest (Article 6(1)(f))
Management of subscriptions, payments, invoicesCommercial performance and accounting obligationsPerformance of the contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c), Article L. 123-22 of the French Commercial Code)
Technical and security loggingSecurity of the service, detection of incidentsLegitimate interest (Article 6(1)(f)) and legal obligation (Article 32)

5. Processors and recipients

5.1 EvidencAI's processors

ProcessorServiceLocation of processing
Scaleway SASHosting of the web application, of the database, authentication and secrets vault servers and of the server functions (Supabase open-source software operated by EvidencAI), and inference of the language models served by its platformFrance (PAR1, Paris)
Stripe Payments Europe Ltd. and Stripe, Inc.Payment collection, invoicingIreland, with transfers to the United States governed by the standard contractual clauses
Scaleway SASDelivery of transactional emailsFrance

EvidencAI keeps the list of its processors up to date. Any change is
notified by publication of a new version of this policy.

5.2 Disclosure to third parties

EvidencAI does not disclose the personal data it processes to any third party for
commercial purposes. No data is sold, rented or used for
advertising purposes. EvidencAI may be required to disclose data to the
competent administrative or judicial authorities in response to a duly issued, legally binding
order (réquisition).

6. Data from Google services and limited use

This section sets out the processing of data that Mycelora accesses through
Google's application programming interfaces, in accordance with the Google API Services
User Data Policy, including its Limited Use
requirements.

Two paths must be distinguished: the Google calendar is connected through OAuth
and falls under this section; any email service, Gmail included, is connected
through IMAP with an app password, without any call to Google's application
programming interfaces, and falls under section 3.3.

6.1 What Mycelora accesses

When the user connects their Google calendar, Mycelora requests only the
https://www.googleapis.com/auth/calendar.readonly scope, which is read-only.
Mycelora does not request any write permission on the calendar, nor any OAuth
permission to access Gmail email. A Gmail account can be read only if the user
themself connects it through IMAP, with an app password, under the conditions of
section 3.3.

The address of the connected account is read at the time of authorisation, from the
user's list of calendars, solely for the purposes of displaying which account is
connected and avoiding connecting the same account twice.

6.2 What Mycelora does with it

The meetings collected are used exclusively to feed the personal memory
of the user who gave their authorisation, that is, to
produce the memories and the daily brief presented to them in
the application. These features are visible and directly accessible in
the interface.

To produce these memories, the content of the meetings is transmitted to
language models operated by a processor, under the conditions of
section 5. The sole purpose of this transmission is to provide the user with the
feature they requested.

6.3 What Mycelora does not do with it

EvidencAI does not use any data obtained through the Google interfaces to
develop, train or improve an artificial intelligence or
machine learning model
, whether generalised or not, beyond the personal
memory of the sole user concerned. The language models used by
EvidencAI are open models operated by Scaleway, in France, under a
professional offering that excludes training on the data transmitted by its customers.

EvidencAI does not transfer, sell or rent Google data to any third party, for
any advertising, database-building, audience measurement
or resale purpose.

No natural person reads the content of a user's Google data,
except in one of the following cases: the explicit and documented agreement of
that user, necessity for the security of the service or the resolution of an
incident affecting that account, or a legal obligation. Accesses of this kind
are logged.

6.4 How the user regains control

The user may disconnect their Google calendar at any time from the
Connections tab of their dashboard. Disconnection immediately revokes
the authorisation with Google, deletes the token stored in the vault and
stops collection. A checkbox also allows the user to request deletion
of meetings already collected.

The user may also revoke access directly from the
management page of their Google account, at
https://myaccount.google.com/permissions.

7. Transfers outside the European Union

The service's data is stored in France, in Paris, on the Scaleway
infrastructure. The web application and the language models used for
Mycelora's internal processing are also hosted in France, by
Scaleway.

Only one flow is likely to involve a transfer to a third country:
the payment flows to Stripe, which may involve a
technical transfer to the United States for the Stripe, Inc. component, governed by
the standard contractual clauses of the European Commission.

Since 30 August 2026, the database is no longer entrusted to the company
Supabase Pte. Ltd.: EvidencAI itself operates the Supabase open-source software
on the Scaleway infrastructure, in France, without any transfer to a third country.

8. Retention periods

8.1 Table of periods

CategoryPeriod
Account and profileFor the duration of use of the service; an account that has remained inactive for one year is deleted, together with all data attached to it
Memories recalled at least onceUntil deleted by the user
Memories never recalledPermanently deleted at the end of the period provided for their type in 8.2
Memories closed by the userUntil deleted by the user; never deleted by the automatic clean-up
Memories archived under previous versions of the serviceDeleted thirty days after being archived
Raw logged exchangesAt most ninety days after they are recorded, then automatic deletion
Context injection tracesSeven days, or twenty-four hours after their evaluation
Google calendar: items collectedNinety days; deletion on option upon disconnection
Calendar with an app password: items collectedNinety days; deletion on option upon disconnection
Mailbox: text of the messages collectedSeven days after its analysis
Mailbox: events collected (subject, participants, labels or folder)Ninety days; deletion upon disconnection on option for those collected since 24 September 2026
Memories created from external sourcesLike the other memories (8.2); they are not erased upon disconnection
Authorisation tokens and app passwordsTechnical lifetime, immediate deletion upon disconnection
Waiting listUntil the opening message is sent, and at most six months after public launch; immediate deletion upon simple request to contact@evidencai.com
User feedbackFor the duration of the account; deleted with it
Subscriptions, transactions, invoicesTen years from the close of the financial year (Article L. 123-22 of the French Commercial Code)
Technical and security logsSix months

8.2 End of life of memories never recalled

A memory is automatically deleted only if two conditions are met:

  1. it has never been recalled, either to the user or to their assistant, since its creation;
  2. it has exceeded the retention period provided for its type.

A memory recalled even once permanently falls outside the scope of this
rule: it is then kept until the user deletes it themselves.

Type of memoryPeriod before end of life
EventThirty days
IntentionThirty days
ReflectionSixty days
External signalSixty days
FactNinety days
DecisionNinety days
LearningNinety days
ContradictionNinety days
PositionOne hundred and eighty days
ContactNo period: a contact is never deleted by this rule

A memory that the user has closed is never deleted by the automatic
clean-up, regardless of its age and use. Closing is the action by
which the user keeps a memory permanently.

Pinning has a different effect: it highlights the memory in the interface and
in recalls, but it does not protect it from this rule. A pinned
memory that has never been recalled is deleted in the same way as any other.

Deletion is permanent. It is not preceded by any holding period and the
deleted memory cannot be restored. In return, the user has at
any time, from their dashboard, a screen showing them the memories
affected by this rule and allowing them to keep or delete them
themselves, as well as a full export of their memory.

At the end of these periods, the data is permanently deleted, with the
exception of data whose retention is required by a legal obligation.

9. Security of processing

  1. encryption of data in transit using TLS 1.2 or higher;
  2. storage of authorisation tokens, app passwords and secrets in a dedicated vault, encrypted, never in plain text and never returned to the interface;
  3. strict segregation of data between accounts, enforced at database level;
  4. application access keys with limited scope, each allowing only the operations necessary for its function, and periodic rotation;
  5. logging of access and sensitive operations;
  6. rate limiting and detection of abnormal use;
  7. incident management process and notification to the CNIL within seventy-two hours in the event of a personal data breach, in accordance with Article 33 of Regulation (EU) 2016/679.

10. Data subject rights

In accordance with Articles 15 to 22 of Regulation (EU) 2016/679, every data
subject has the rights of access, rectification, erasure,
restriction of processing, data portability, objection, withdrawal of consent and
to set out directives regarding the processing of their data after death.

Some of these rights are exercised directly from the dashboard:
the user views, modifies and deletes their memories, exports their memory and
deletes their account.

For the others, rights are exercised by message to
contact@evidencai.com or by post to the registered office, accompanied by information
allowing the identity of the requester to be verified. EvidencAI responds within the
one-month period provided for in Article 12(3), which may be extended by two months where
the request is complex.

The service does not carry out any decision based solely on automated processing producing
legal effects within the meaning of Article 22.

11. Complaint to the French Data Protection Authority (CNIL)

CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07, www.cnil.fr.

This remedy is without prejudice to any other administrative
or judicial remedy.

12. Cookies and trackers

The application uses only the cookies and local storage strictly necessary for
the operation of the service, in particular the authentication session. No
audience measurement or advertising cookie is placed.

13. Changes to this policy

EvidencAI may amend this policy to take account of
changes to the service, to legislation or to the recommendations of the CNIL and of the
European Data Protection Board. Any substantial change is
notified by publication and by email at least fifteen days before
it takes effect.


Contact

To date, EvidencAI has not appointed a data protection officer, as it is
not required to do so. The dedicated point of contact for data protection
questions is contact@evidencai.com.