Skip to content
Nacre

Privacy Policy

Last updated: 27 July 2026

Nacre is a private journaling app. This policy explains what data we process, why, where it is stored, and your rights. Our starting principle: you own your data — no ads, no reselling, ever.

1. Data controller

Nicolas Serra, sole trader (entrepreneur individuel) — SIREN 843 299 751, SIRET 843 299 751 00019, France. Contact: contact@affiniteam.io (postal address provided on request at that address). See the legal notice.

2. Data we process

  • Account (optional): your email address. If you use “Sign in with Apple” or “with Google”, the identifier and email those providers share.
  • Journal content: your entries (text), moods, the location you choose to attach to an entry, the photos and voice notes you add, your quests, characters, and the links between them.
  • Technical data: a device identifier used to coordinate sync, authentication tokens, and the IP address of your requests, processed transiently by server logs and by the rate limits that protect the API from abuse.
  • Subscription: if you subscribe to Nacre Plus, an anonymous app identifier, the purchased product and its expiry date. We never see your payment details — Apple or Google collect the payment.
  • AI Chapters: if — and only if — you turn the feature on, the journal content needed to generate a chapter is sent to our AI processor. See section 7.

What we do not collect: no advertising identifier, no third-party tracker, no behavioural analytics. Writing reminders are local notifications scheduled by the app on your device: no push token is created and no notification server is contacted. Crash reporting exists in the code but is not enabled today; if we enable it, this page will be updated first.

3. Legal bases

ProcessingLegal basis (GDPR)
Account, backup and sync of your journalPerformance of a contract — art. 6(1)(b)
Managing your Nacre Plus subscriptionPerformance of a contract — art. 6(1)(b)
AI ChaptersYour consent — art. 6(1)(a), withdrawable at any time
Security, abuse prevention, rate limitingLegitimate interest — art. 6(1)(f)
Accounting and legal obligationsLegal obligation — art. 6(1)(c)

4. Local use without an account

The app works fully offline, with no account. In that case your data stays on your device and is never sent to us. An account only exists to back up and sync your journal across multiple devices.

5. Where and how it is stored

  • On your device: a local database (SQLite), protected by the operating-system sandbox and an optional biometric lock.
  • On our servers (if you have an account): a PostgreSQL database hosted by Laravel Cloud (Laravel Holdings, Inc.) on Amazon Web Services EMEA SARL infrastructure, in the eu-west-3 (Paris, France) region — inside the European Union.
  • Your files (photos, voice notes): on Cloudflare R2 (Cloudflare, Inc.) object storage, separate from the database.
  • All traffic between the app and the server uses HTTPS.

6. Encryption — honest threat model

The text fields of your synced content (titles, entries, quest descriptions, character names and notes) are encrypted at rest on the server. However, that encryption uses a server-readable key: it is not end-to-end (E2E). This means we can technically access content — which is what makes account recovery and AI Chapters possible. End-to-end encryption remains a goal for a later version. We prefer to be honest about this rather than promise privacy the current implementation does not guarantee.

7. AI Chapters

Nacre can read back your journal and write its story — the “Chapters” feature. It is off by default and only runs after you explicitly turn it on (Settings → AI). Until you do, no journal content is sent to any AI provider.

  • What is sent: the entries covering the period of the requested chapter — their text, date and mood — along with the titles of the quests and the names of the characters linked to them. Not your email address, not your identity, not your files (photos, voice notes).
  • To whom: Anthropic PBC (United States), through its API, acting as a processor.
  • What they do with it: Anthropic does not use content submitted through its API to train its models. It may be retained briefly for safety purposes, then deleted.
  • How to undo it: turn the feature off in settings. Generation stops immediately and chapters already written are no longer shown in the app, including offline. They do remain stored on our servers: to have them erased, write to contact@affiniteam.io — and deleting your account erases them along with the rest of your data.

A chapter is machine-written text derived from what you wrote. It can be wrong, misread you, or invent things. Give it no more authority than a draft.

8. What we never do

  • No advertising.
  • No reselling of your data.
  • No cross-app tracking, no ad profiling.
  • No reading of your journal outside the cases described here, and no automated decisions producing legal effects concerning you.

9. Retention and deletion

  • A deleted entry first goes to trash, then is permanently erased after 30 days, including its files on object storage.
  • The technical deletion markers used to propagate an erasure to your other devices are purged after 90 days.
  • You can delete your account at any time in Settings → Account: your server-side data and access tokens are removed immediately, and your photos and voice notes are erased from storage right after by a dedicated job.
  • AI Chapters are the exception: they are not stored on your device and do not pass through the trash. They are kept on our servers until you delete your account, or earlier if you ask us to erase them.
  • Your local data stays on your device until you uninstall the app or clear the journal.

10. Your rights

  • Export: you can export your entire journal (Markdown / TXT / JSON) at any time, for free, without asking us for anything.
  • Access, rectification, erasure, restriction, portability, objection, and withdrawal of your consent for AI Chapters — under the GDPR and the French Data Protection Act.
  • To exercise these rights: contact@affiniteam.io. We answer within one month.
  • You may also lodge a complaint with the French CNIL, 3 place de Fontenoy — TSA 80715, 75334 Paris Cedex 07 (cnil.fr), or with your own national supervisory authority.

11. Sub-processors

ProviderRoleLocation
Laravel Cloud (Laravel Holdings, Inc.) / Amazon Web Services EMEA SARLHosting of the API and databaseParis, France (eu-west-3)
Cloudflare, Inc. (R2)Storage of your photos and voice notesCompany established in the United States
Anthropic PBCAI Chapter generation — only if you enable the featureUnited States
RevenueCat, Inc.Nacre Plus subscription managementUnited States

Each acts as a processor, on instruction and under its data processing agreement. This list is kept current; any addition will be published here.

Apple and Google sit in a different position and are deliberately not in that table: when you choose “Sign in with Apple” or “with Google”, and when you subscribe through their billing, they process your data for their own purposes, as independent controllers rather than on our instructions. What they do with it is governed by their privacy policies, not ours.

12. Transfers outside the European Union

Your PostgreSQL database — so the text of your journal — is hosted in France. Two caveats we would rather state plainly than let you assume everything stays on French soil:

  • Your photos and voice notes are stored on Cloudflare R2 (Cloudflare, Inc.), whose storage location is not restricted to the European Union: those files may be held outside the EU.
  • Laravel Holdings, Inc. and Cloudflare, Inc. are US companies: their engineering teams can access the systems they operate remotely, even when the data physically sits in France.

Those transfers, like the ones to Anthropic and RevenueCat, rely on the European Commission's Standard Contractual Clauses and, where applicable, on the provider's EU-US Data Privacy Framework certification.

13. Minors

The app is not directed to people under 15 — the digital consent age in France — nor, in countries where that age is higher, to people below it. If we learn that an account was created below that age, we delete it.

14. Security

HTTPS in transit, encryption at rest for text fields, strict account isolation verified by automated tests, rate limiting on sensitive endpoints, an optional biometric lock on device. If you think you have found a vulnerability, write to contact@affiniteam.io — we answer quickly and we do not pursue good-faith reports.

15. Changes

If anything changes, we will update the date at the top of this page and, where the change matters, notify you in the app.