Mycelora Privacy Policy
This English version is provided for convenience. In case of any discrepancy between the English and French versions, the French version prevails.
Version: 1.6
Effective date: 8 October 2026
Controller: EvidencAI, SAS (simplified joint-stock company) with share capital of 180,000 euros, RCS Romans 103 591 806
Contents
- Preamble and legal characterisation
- Scope of the processing
- Categories of data processed
- Purposes and legal bases
- Processors and recipients
- Data from Google services and limited use
- Transfers outside the European Union
- Retention periods
- Security of processing
- Data subject rights
- Complaint to the French Data Protection Authority (CNIL)
- Cookies and trackers
- Changes to this policy
1. Preamble and legal characterisation
1.1 Description of the service
Mycelora is a persistent memory service for conversational assistants,
available at mycelora.ai. It stores, organises and returns to its
user the contextual elements of their projects: decisions, facts,
intentions, learnings, referred to in the application as
memories.
The user feeds their memory in three ways: by entering or
importing content into the application, through the automatic logging of
their exchanges with an assistant where they have enabled such logging, and through
the optional connection of external email and calendar sources.
Logging of exchanges is never enabled by default. Depending on
the assistant used, the user enables it either by installing the extension
provided for that purpose, or by configuring their assistant themselves so that it
transmits their exchanges to the service. In both cases, activation results
from a deliberate act by the user and may be withdrawn at any time, by
uninstalling the extension or removing that configuration.
1.2 Characterisation adopted
EvidencAI is an independent controller within the meaning of Article 4(7)
of Regulation (EU) 2016/679 for all data processed in connection with the
service. EvidencAI alone determines the purposes and means of such
processing.
Where the user connects an external source, the content collected
may include personal data of third parties (correspondents, participants
in a meeting). The user is the origin of this through their act of connection.
EvidencAI processes such data solely in the interest and for the sole benefit of that
user, without using it for any other purpose.
2. Scope of the processing
EvidencAI carries out the following processing operations:
- management of the user account: creation, authentication by password, by one-time code or by federated identifier, profile modification, deletion;
- receipt and structured storage of content entered, imported or logged by the user, as well as of the memories derived from it;
- transmission of such content to language models operated by a processor (see section 5), in order to extract memories from it, produce project summaries, end-of-session handovers, the daily brief and the analysis of convergences between projects;
- computation of vector representations of memories in order to enable semantic search;
- management of the connection of external sources by the user: the OAuth authorisation flow for the Google calendar, including encrypted storage of refresh tokens and their revocation, and the connection of a mailbox by address and app password (IMAP), including encrypted storage of that password and its erasure upon disconnection;
- periodic collection of messages and meetings from connected sources, and assessment of their relevance before any transformation into a memory;
- sending of transactional communications, including the daily brief where the user has enabled it;
- management of subscriptions, payments and invoicing;
- technical and security logging.
3. Categories of data processed
3.1 Identification data
Email address, hashed password or federated identifier, first name and surname
where provided, account preferences, authentication tokens and
associated logs.
3.2 Memory data
Memories and their metadata, project spaces, project
summaries, handovers, imported documents and their fragments, the
contact records created by the user, links established between memories and
the observations produced by the cross-project analysis.
In addition, where the user has enabled logging of their exchanges
within the meaning of section 1.1, the raw exchanges between the user and their
assistant, kept for at most ninety days after they are recorded, then
deleted automatically. They are not turned into memories.
This content is provided by the user and reflects their professional
and personal activity. It may include personal data of
third parties. It is not intended to contain special categories of personal data within the meaning of
Article 9 of Regulation (EU) 2016/679, and the user is asked not to
enter any.
3.3 Data from connected external sources
For each source connected by the user, EvidencAI processes the account
address, the connection status and the timestamps of collections, as well as,
for each item collected, the data described below according to the type of
source. For the Google calendar, the scope of authorisation granted is also
stored.
Google calendar (OAuth). The title of the meeting, an extract of its
content, the list of participants and the timestamp. The refresh token issued
by Google is stored encrypted in a dedicated vault, never in plain text, and is
never displayed to the user.
Calendar with an app password (CalDAV). The title of the meeting, an
extract of its content, the list of participants and the timestamp. The
password is stored encrypted in a dedicated vault, never in plain text, and is
erased upon disconnection.
Mailbox (IMAP, with an app password). The user may connect any email
service, Gmail included, by its address and an app password. This way of
connecting is separate from the Google calendar: it does not use Google's
application programming interfaces and section 6 does not apply to it.
- Access. This password gives access to the whole mailbox. Mycelora accesses it read-only: it does not modify, move, delete or mark any message. The password is stored encrypted in a dedicated vault, never in plain text, and is never displayed to the user.
- What is read. Emails received and sent from the time of connection: the last four hours at the first collection and at any reconnection, never the history of the mailbox. Attachments are never opened: only their name is noted.
- What is kept. The subject, the participants, the text of the message, cleaned and shortened (two thousand characters at most), and the labels or the folder of origin of the message.
- Analysis. These items are analysed by an artificial intelligence model hosted by Scaleway, in France. What matters for the user's projects becomes a memory, kept like the other memories (section 8.2).
- Periods. The text of the message is erased seven days after its analysis; the corresponding events are deleted after ninety days (section 8.1).
- Connection and disconnection. A mailbox is connected and disconnected only from the dashboard, never by a connected assistant. Disconnection immediately erases the password from the vault. An option also erases the emails collected from that mailbox since 24 September 2026; older ones are deleted by the ninety-day period. Memories already created remain in the user's memory.
3.4 Subscription and billing data
Plan subscribed to, subscription status, Stripe session and payment
identifiers, invoices. EvidencAI does not collect or store any bank card
data, such data being processed exclusively by Stripe.
3.5 Technical and security data
IP addresses, session identifiers, execution logs of server
functions, audit logs, rate-limiting counters, record of
language model usage.
3.6 Waiting list
Email address, language chosen, date and time of consent. To limit abuse, an irreversible fingerprint of the IP address is kept for two hours together with a request counter; the IP address itself is not recorded in the waiting list.
3.7 User feedback
Type of feedback (report, idea, other), text entered, screen from which it was sent, language. This feedback is read by EvidencAI to improve the service.
4. Purposes and legal bases
| Processing | Purpose | Legal basis (GDPR) |
|---|---|---|
| Creation and management of the account | Enabling use of the service | Performance of the contract (Article 6(1)(b)) |
| Storage of memories and spaces | Providing the memory service | Performance of the contract (Article 6(1)(b)) |
| Language model inference for extraction, summaries, the brief and cross-project analysis | Providing the visible features of the service | Performance of the contract (Article 6(1)(b)) |
| Computation of vector representations | Enabling semantic search | Performance of the contract (Article 6(1)(b)) |
| Logging of exchanges between the user and their assistant | Ensuring continuity of work: resuming a thread left open, state of the current thread, closing reminder, and usage counters of the memories recalled | Consent of the user, given by enabling logging within the meaning of section 1.1 and withdrawable at any time (Article 6(1)(a)) |
| Connection and collection of external sources | Feeding the memory at the user's request | Consent of the user, given by the act of connection and withdrawable at any time (Article 6(1)(a)) |
| Connection and collection of a mailbox by app password | Feeding the memory at the user's request | Consent of the user, collected by a checkbox in the dashboard before connection, timestamped with the version of the text displayed, and withdrawable at any time (Article 6(1)(a)) |
| Sending of the daily brief | Informing the user | Consent, withdrawable by unsubscribing (Article 6(1)(a)) |
| Waiting list | Notifying the person when the service opens | Consent, collected by a checkbox and timestamped, withdrawable at any time (Article 6(1)(a)) |
| User feedback | Fixing and improving the service | EvidencAI's legitimate interest (Article 6(1)(f)) |
| Management of subscriptions, payments, invoices | Commercial performance and accounting obligations | Performance of the contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c), Article L. 123-22 of the French Commercial Code) |
| Technical and security logging | Security of the service, detection of incidents | Legitimate interest (Article 6(1)(f)) and legal obligation (Article 32) |
5. Processors and recipients
5.1 EvidencAI's processors
| Processor | Service | Location of processing |
|---|---|---|
| Scaleway SAS | Hosting of the web application, of the database, authentication and secrets vault servers and of the server functions (Supabase open-source software operated by EvidencAI), and inference of the language models served by its platform | France (PAR1, Paris) |
| Stripe Payments Europe Ltd. and Stripe, Inc. | Payment collection, invoicing | Ireland, with transfers to the United States governed by the standard contractual clauses |
| Scaleway SAS | Delivery of transactional emails | France |
EvidencAI keeps the list of its processors up to date. Any change is
notified by publication of a new version of this policy.
5.2 Disclosure to third parties
EvidencAI does not disclose the personal data it processes to any third party for
commercial purposes. No data is sold, rented or used for
advertising purposes. EvidencAI may be required to disclose data to the
competent administrative or judicial authorities in response to a duly issued, legally binding
order (réquisition).
6. Data from Google services and limited use
This section sets out the processing of data that Mycelora accesses through
Google's application programming interfaces, in accordance with the Google API Services
User Data Policy, including its Limited Use
requirements.
Two paths must be distinguished: the Google calendar is connected through OAuth
and falls under this section; any email service, Gmail included, is connected
through IMAP with an app password, without any call to Google's application
programming interfaces, and falls under section 3.3.
6.1 What Mycelora accesses
When the user connects their Google calendar, Mycelora requests only thehttps://www.googleapis.com/auth/calendar.readonly scope, which is read-only.
Mycelora does not request any write permission on the calendar, nor any OAuth
permission to access Gmail email. A Gmail account can be read only if the user
themself connects it through IMAP, with an app password, under the conditions of
section 3.3.
The address of the connected account is read at the time of authorisation, from the
user's list of calendars, solely for the purposes of displaying which account is
connected and avoiding connecting the same account twice.
6.2 What Mycelora does with it
The meetings collected are used exclusively to feed the personal memory
of the user who gave their authorisation, that is, to
produce the memories and the daily brief presented to them in
the application. These features are visible and directly accessible in
the interface.
To produce these memories, the content of the meetings is transmitted to
language models operated by a processor, under the conditions of
section 5. The sole purpose of this transmission is to provide the user with the
feature they requested.
6.3 What Mycelora does not do with it
EvidencAI does not use any data obtained through the Google interfaces to
develop, train or improve an artificial intelligence or
machine learning model, whether generalised or not, beyond the personal
memory of the sole user concerned. The language models used by
EvidencAI are open models operated by Scaleway, in France, under a
professional offering that excludes training on the data transmitted by its customers.
EvidencAI does not transfer, sell or rent Google data to any third party, for
any advertising, database-building, audience measurement
or resale purpose.
No natural person reads the content of a user's Google data,
except in one of the following cases: the explicit and documented agreement of
that user, necessity for the security of the service or the resolution of an
incident affecting that account, or a legal obligation. Accesses of this kind
are logged.
6.4 How the user regains control
The user may disconnect their Google calendar at any time from the
Connections tab of their dashboard. Disconnection immediately revokes
the authorisation with Google, deletes the token stored in the vault and
stops collection. A checkbox also allows the user to request deletion
of meetings already collected.
The user may also revoke access directly from the
management page of their Google account, athttps://myaccount.google.com/permissions.
7. Transfers outside the European Union
The service's data is stored in France, in Paris, on the Scaleway
infrastructure. The web application and the language models used for
Mycelora's internal processing are also hosted in France, by
Scaleway.
Only one flow is likely to involve a transfer to a third country:
the payment flows to Stripe, which may involve a
technical transfer to the United States for the Stripe, Inc. component, governed by
the standard contractual clauses of the European Commission.
Since 30 August 2026, the database is no longer entrusted to the company
Supabase Pte. Ltd.: EvidencAI itself operates the Supabase open-source software
on the Scaleway infrastructure, in France, without any transfer to a third country.
8. Retention periods
8.1 Table of periods
| Category | Period |
|---|---|
| Account and profile | For the duration of use of the service; an account that has remained inactive for one year is deleted, together with all data attached to it |
| Memories recalled at least once | Until deleted by the user |
| Memories never recalled | Permanently deleted at the end of the period provided for their type in 8.2 |
| Memories closed by the user | Until deleted by the user; never deleted by the automatic clean-up |
| Memories archived under previous versions of the service | Deleted thirty days after being archived |
| Raw logged exchanges | At most ninety days after they are recorded, then automatic deletion |
| Context injection traces | Seven days, or twenty-four hours after their evaluation |
| Google calendar: items collected | Ninety days; deletion on option upon disconnection |
| Calendar with an app password: items collected | Ninety days; deletion on option upon disconnection |
| Mailbox: text of the messages collected | Seven days after its analysis |
| Mailbox: events collected (subject, participants, labels or folder) | Ninety days; deletion upon disconnection on option for those collected since 24 September 2026 |
| Memories created from external sources | Like the other memories (8.2); they are not erased upon disconnection |
| Authorisation tokens and app passwords | Technical lifetime, immediate deletion upon disconnection |
| Waiting list | Until the opening message is sent, and at most six months after public launch; immediate deletion upon simple request to contact@evidencai.com |
| User feedback | For the duration of the account; deleted with it |
| Subscriptions, transactions, invoices | Ten years from the close of the financial year (Article L. 123-22 of the French Commercial Code) |
| Technical and security logs | Six months |
8.2 End of life of memories never recalled
A memory is automatically deleted only if two conditions are met:
- it has never been recalled, either to the user or to their assistant, since its creation;
- it has exceeded the retention period provided for its type.
A memory recalled even once permanently falls outside the scope of this
rule: it is then kept until the user deletes it themselves.
| Type of memory | Period before end of life |
|---|---|
| Event | Thirty days |
| Intention | Thirty days |
| Reflection | Sixty days |
| External signal | Sixty days |
| Fact | Ninety days |
| Decision | Ninety days |
| Learning | Ninety days |
| Contradiction | Ninety days |
| Position | One hundred and eighty days |
| Contact | No period: a contact is never deleted by this rule |
A memory that the user has closed is never deleted by the automatic
clean-up, regardless of its age and use. Closing is the action by
which the user keeps a memory permanently.
Pinning has a different effect: it highlights the memory in the interface and
in recalls, but it does not protect it from this rule. A pinned
memory that has never been recalled is deleted in the same way as any other.
Deletion is permanent. It is not preceded by any holding period and the
deleted memory cannot be restored. In return, the user has at
any time, from their dashboard, a screen showing them the memories
affected by this rule and allowing them to keep or delete them
themselves, as well as a full export of their memory.
At the end of these periods, the data is permanently deleted, with the
exception of data whose retention is required by a legal obligation.
9. Security of processing
- encryption of data in transit using TLS 1.2 or higher;
- storage of authorisation tokens, app passwords and secrets in a dedicated vault, encrypted, never in plain text and never returned to the interface;
- strict segregation of data between accounts, enforced at database level;
- application access keys with limited scope, each allowing only the operations necessary for its function, and periodic rotation;
- logging of access and sensitive operations;
- rate limiting and detection of abnormal use;
- incident management process and notification to the CNIL within seventy-two hours in the event of a personal data breach, in accordance with Article 33 of Regulation (EU) 2016/679.
10. Data subject rights
In accordance with Articles 15 to 22 of Regulation (EU) 2016/679, every data
subject has the rights of access, rectification, erasure,
restriction of processing, data portability, objection, withdrawal of consent and
to set out directives regarding the processing of their data after death.
Some of these rights are exercised directly from the dashboard:
the user views, modifies and deletes their memories, exports their memory and
deletes their account.
For the others, rights are exercised by message tocontact@evidencai.com or by post to the registered office, accompanied by information
allowing the identity of the requester to be verified. EvidencAI responds within the
one-month period provided for in Article 12(3), which may be extended by two months where
the request is complex.
The service does not carry out any decision based solely on automated processing producing
legal effects within the meaning of Article 22.
11. Complaint to the French Data Protection Authority (CNIL)
CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07, www.cnil.fr.
This remedy is without prejudice to any other administrative
or judicial remedy.
12. Cookies and trackers
The application uses only the cookies and local storage strictly necessary for
the operation of the service, in particular the authentication session. No
audience measurement or advertising cookie is placed.
13. Changes to this policy
EvidencAI may amend this policy to take account of
changes to the service, to legislation or to the recommendations of the CNIL and of the
European Data Protection Board. Any substantial change is
notified by publication and by email at least fifteen days before
it takes effect.
Contact
To date, EvidencAI has not appointed a data protection officer, as it is
not required to do so. The dedicated point of contact for data protection
questions is contact@evidencai.com.