Privacy Policy
This is an English translation of the French original. In case of conflict, the French version prevails.
This privacy policy describes how OneFolder (“the Application”, “we”) collects, uses, and protects your personal data, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).
1. Who is the data controller?
The controller of personal data collected via the OneFolder mobile application (“the Application”) is:
Julien Cochard, publisher of the OneFolder application
Contact: contact@onefolder.fr
2. What is OneFolder?
OneFolder is a mobile app that lets you scan, organize, annotate, and export invoices and receipts. Access to the cloud service requires an account created with an email address (sign-in with a one-time code).
3. What data do we collect?
Depending on how you use the Application, we may process the following categories:
- Account data: email address used for authentication (sending an OTP code).
- User content: invoice information entered or pre-filled (merchant name, address, date, amount, any VAT, notes), custom labels, and invoice images (photos / scans / imported files).
- Session technical data: authentication tokens stored securely on the device to keep you signed in.
- Device permissions: the Application may request access to the camera and photo library solely to capture or import invoices. The microphone is not used.
- Diagnostic technical data: in the event of an error or crash (and for certain reliability indicators such as the result of an OCR analysis: success with fields filled, success with no fields, or failure), technical information may be sent to our monitoring tool (device type, operating system, Application version, error traces / stack traces). Invoice images and OCR text are not sent to this tool.
We do not intentionally collect bank payment data beyond what appears on the documents you choose to import. OneFolder does not include advertising. A third-party error-diagnostics tool (Sentry) is used for service reliability, as described below; it is not an advertising or marketing-profiling tool.
4. For what purposes?
- Create and secure your account (email / OTP authentication).
- Provide scan, filing, search, edit, and export features (PDF / Excel).
- Automatically extract certain invoice information via OCR analysis (pre-fill).
- Sync your data across devices when you are signed in.
- Ensure security, maintenance, error / crash diagnosis, and support of the service.
- Comply with our legal obligations where applicable.
5. Legal bases (GDPR)
- Performance of the contract: providing the OneFolder service requested by the user.
- Legitimate interest: security, abuse prevention, improving service reliability (including error and crash monitoring).
- Legal obligation where applicable.
- Consent for certain device access (camera, photos), managed at the operating-system level.
6. Where and how is your data stored?
- Signed-in account: your invoices, labels, and photos are stored in our cloud infrastructure provided by Supabase (database and file storage). The project is hosted in the European Union (Ireland / West EU region at the time of writing). Each account is isolated from the others.
- Session: sign-in tokens are kept locally on your device via the system’s secure storage (Secure Store).
- Offline / local fallback mode: some data may be cached locally on the device for the Application to work.
7. OCR analysis (Mistral)
When you start analyzing an invoice, the relevant images are transmitted securely to a OneFolder server function (hosted on Supabase), which calls Mistral AI’s OCR / extraction service in order to pre-fill certain fields (merchant, address, date, amount).
Images and text from OCR are processed solely for this extraction purpose. The Mistral API key is not embedded in the mobile app; it is kept on the server.
Provider: Mistral AI (a company established in France / the EU). For more information, see Mistral’s documentation and privacy policy.
8. Error diagnostics (Sentry)
To detect and fix Application crashes and errors, we use Sentry (Functional Software, Inc.), configured on Sentry’s European infrastructure.
In particular, we transmit: device type, operating system, Application version, technical error traces, and aggregated reliability indicators (for example the result of an OCR analysis: fields filled, no fields, or failure). We do not knowingly send invoice images, OCR text, or detailed invoice content to Sentry.
For more information: Sentry’s privacy policy.
9. Recipients and processors
In the course of the service, your data may be processed by:
- Supabase — authentication, database, file storage, server functions.
- Mistral AI — OCR and information extraction from invoice images.
- Sentry (Functional Software) — error and crash monitoring (technical diagnosis), with European hosting.
- Authentication email sending provider configured via Supabase (e.g. an SMTP service such as Resend) to deliver OTP codes.
We do not sell your personal data. We do not share it with advertisers.
10. Transfers outside the EU
We favor hosting in the EU (Supabase West EU; Sentry project configured on the European region). Some processors may carry out processing or technical support involving transfers outside the EU. In that case, appropriate safeguards (standard contractual clauses or equivalent mechanisms) are put in place with the providers concerned.
11. Retention periods
- Account (email address): kept for as long as your account is active, then deleted within 24 hours of account deletion.
- Invoices and extracted data: kept until you delete them and for as long as your account is active. Deleting an invoice in the Application results in its deletion from our servers within 24 hours.
- Session: until sign-out or expiry / invalidation of the token.
- Technical logs and diagnostic events (including via Sentry): kept for a limited period necessary for security, diagnosis, and improving service reliability.
You can sign out at any time from the Application. Signing out ends the cloud session; it does not automatically delete content already synced to our servers. Deleting your account, available in the Application, results in deletion of your data within the timeframes stated above.
12. Your rights
Under the GDPR, you have, as applicable, rights of access, rectification, erasure, restriction, objection, portability, and the right to lodge a complaint with the CNIL (or the authority in your country of residence).
To exercise your rights: contact@onefolder.fr
13. Security
We implement reasonable measures to protect your data: code-based authentication, per-user cloud access controls, private storage of invoice photos, server-side storage of API secrets, and secure storage of sessions on the device. No system is infallible; we encourage you to protect access to your phone and email.
We do not access the content of your invoices and photos, except at your request as part of support, or where required by law or by the security of the service.
14. Children’s data
OneFolder is not intended for children under 16. If you believe a minor has sent us data, contact us for deletion.
15. PDF / Excel exports
Exports are generated on your device (temporary files / cache) and opened with system tools. Any later transmission (email, messaging, personal cloud) is your responsibility and governed by the services you use.
16. Changes
We may update this policy. The update date will appear at the top of the document. In the event of a material change, we may inform you in the Application or by email.
17. Contact
For any question about this policy or your data: contact@onefolder.fr