Sansoif

Privacy policy

Sansoif is built for personal tracking. Your detailed data stays on your device, and only the minimum needed for social features is sent to our servers.

Last updated: August 27, 2026.

Principles

Your detailed log stays on your device by default, and we keep what is sent to our servers to a strict minimum. No advertising, no data resale.

Data we collect

  • On your device: your detailed drink log (drinks, dates, optional notes) is stored locally.
  • Social account (optional): if you create an account for private groups, we receive a sign-in identifier via Apple or Google, your handle, and the weekly summaries you choose to share.
  • Where a drink was logged (optional): if you turn on "Save place with drinks", Sansoif attaches the device's GPS coordinates at that moment (latitude, longitude, accuracy) to the day concerned. This setting is off by default. When cloud backup is active, those coordinates are backed up with the day on our servers, readable by your account only. They are never shared with your friends or your groups.
  • Finding friends from your contacts (optional): off by default. Phone numbers and email addresses from your address book are normalised and hashed on your device; only those irreversible digests are sent, for the duration of the request, to be compared. They are neither stored nor logged. The only digests we keep are those of your own email address and phone number, if you registered them to be discoverable.
  • Crash reports: when the app crashes or slows down abnormally, a technical report (stack trace, device model, app and OS version, install identifier) is sent to Sentry. It contains none of your log, none of your drinks and none of your Health data.
  • sansoif.com website: audience measurement uses Simple Analytics, with no cookie or advertising tracker.

Apple Health / Health Connect

Syncing with Apple Health or Health Connect is strictly opt-in: you enable the source yourself and can disable it at any time.

Sansoif reads and writes a single data type: the number of alcoholic beverages (numberOfAlcoholicBeverages on Apple Health, AlcoholRecord on Health Connect). No other health data type is requested.

These values stay on the device: they are never backed up to our servers, never shared with your friends or your groups, and never passed to a third party. Everything that leaves the device is computed exclusively from entries you created yourself in Sansoif. This data is never used for advertising, marketing or statistical analysis.

Private groups

Private groups are invite-only. They share aggregated weekly summaries and indicators, never your raw log. Sensitive incidents never surface in groups.

Settings you control

Sansoif keeps sharing closed by default: several of the settings below are off out of the box, and you decide when to turn them on. Everything is configured in the app, screen by screen.

  • Share with my friends: share your day-by-day calendar with your Sansoif friends. Groups are configured separately.
  • Share incident counts: off by default. When enabled, friends can see incident totals, never your private notes.
  • Group calendar: visible or hidden, group by group. This choice is independent of sharing with friends.
  • Share my rewards: friends can see your progress badges (never your records). This is on by default; you can turn it off anytime.
  • Discoverable by my contacts: off by default. Requires a verified email or a registered phone number, which you add yourself under "Manage discovery" and can remove at any time.
  • Friends activity: off by default. Get a notification when a friend logs their day.
  • Lock with Face ID: when enabled, Sansoif asks for Face ID after a few minutes away from the app.
  • Delete your account: anytime from the app or from the Delete account page.

On the server side, no drink, calendar, incident or reward data belonging to another member is ever returned unless a privileged server function (security definer) has first verified an active friendship or shared group membership. None of these functions are reachable by a signed-out visitor.

Third-party providers

We do not sell or rent your data, and we share it with no advertiser. The only third parties that process it are the technical providers below, acting on our behalf and under our instructions, and contractually bound to a level of data protection at least equivalent to the one described in this policy.

  • Supabase, hosting for the social account's database and authentication. Data hosted in the European Union.
  • Sentry, app crash reports and performance measurements. Processed in the United States, under the European Commission's Standard Contractual Clauses. No content from your log ever transits through it.
  • Postmark, delivery of verification emails and moderation reports.
  • Apple and Google, account sign-in (Sign in with Apple, Sign in with Google) and push notifications. All we receive from them is an identifier, an email address and a display name.
  • Simple Analytics, audience measurement for the sansoif.com website only, with no cookie.

No data is passed to any artificial intelligence provider.

Retention periods

  • Data on your device: kept as long as the app is installed. Uninstalling erases it.
  • Social account and backup: kept as long as your account exists. After a deletion request, the account and associated server-side data are permanently deleted within 30 days.
  • Discovery digests (hashes of your email address and phone number): kept as long as you stay discoverable, then erased as soon as you remove the identifier. If you delete your account, they are erased with the other server-side data within 30 days.
  • Moderation reports: kept for as long as it takes to handle them, then for as long as needed to detect repeat behaviour from the same account. If the reported account is deleted, they are erased with the other server-side data within 30 days.
  • Crash reports: kept for 90 days by Sentry, then deleted automatically.
  • Server technical logs: kept for our host's retention period, a few days, then deleted automatically.

Beyond that, the only data remaining is what the law requires us to keep (accounting obligations on purchases, for example), for the period it prescribes.

Your rights

In accordance with the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data.

You can withdraw your consent at any time, without giving a reason: every optional collection described above (Apple Health, drink locations, discovery by contacts, sharing, notifications) is turned off from the very setting that turned it on, in the app.

You can delete your account at any time (see Delete account) or email us at support@sansoif.com. You may also lodge a complaint with the French data protection authority, the CNIL (cnil.fr).

Contact

Data controller: SXN Labs EURL (see legal notice). For any question about your data: support@sansoif.com.