In short
Espir is a mindfulness app for mealtimes. It needs very little to work, and that is deliberate.
We do not collect your weight, your calories, or what your meals are made of. We do not sell any data. We show no advertising. No advertising tracker is built into the app.
This document explains exactly what is stored, why, where it lives, and how you can delete it.
1. Who is responsible for your data
The data controller is:
COLLIN LOUIS, sole trader (French *micro-entreprise*)
Business registration number (SIREN): 853 113 090
Registered address: LC DEVELOPMENTS, 60 rue François Ier, 75008 Paris, France
Contact: contact@espir.io
For any question about your data, write to that address. We reply within one month at the latest.
Given the size of the business and the nature of the processing involved, no Data Protection Officer has been appointed. This is consistent with Article 37 of the GDPR.
2. The data we process
2.1 On install — the anonymous account
An account is created automatically the first time you open the app, without you entering anything. This account is anonymous: it is not linked to any email address, any verified identity, or any phone number.
It takes the form of a technical identifier (UID) randomly generated by Firebase Authentication. That identifier exists only to connect your meals and preferences to your device.
On first launch, the app also asks you for a first name. It is used solely to personalise the messages you see inside the app. It is not verified, cross-referenced, or used for anything else: you are perfectly free to enter a made-up name or any word you like.
Legal basis: performance of a contract, namely providing the service you asked for by installing the app.
2.2 If you create an identified account
You can, whenever you choose, turn your anonymous account into an identified one via Apple, Google, or an email address. This lets you recover your data if you change devices.
In that case, we additionally store your email address.
If you use "Sign in with Apple", you can ask Apple to hide your real address. We then receive a relay address of the form xxxx@privaterelay.appleid.com and never learn your actual email.
We store no passwords. Authentication is handled entirely by Firebase Authentication.
Legal basis: performance of a contract.
2.3 Your meals
For each meal recorded in the app:
- the meal type (breakfast, lunch, dinner, snack)
- the name you give it, if you give it one
- the date, start time, and end time
- the number of bites counted
- the total duration of the meal
- the average time elapsed between two bites
- the personal notes you write freely
Those notes are a free space. They are not read, analysed, or automatically processed by us. They are simply kept so that you can read them again.
Espir is not a medical device. The app makes no diagnosis, offers no treatment, and is not a substitute for the advice of a healthcare professional. We do not collect health data within the meaning of Article 9 of the GDPR, and we recommend that you do not record any in your notes.
Legal basis: performance of a contract.
2.4 Your preferences
The settings you choose in the app: gesture colour, haptic feedback, meal reminders, language, visual theme.
Legal basis: performance of a contract.
2.5 A few usage-related details
So that the app works properly from one session to the next, we also store:
- the date you last opened the app
- the total number of meals you have recorded, which feeds the statistics shown in your journal
- the list of articles you have already read in the Discover section, so they are not flagged as new
This information stays within your account and serves only you. It is neither aggregated for statistical purposes nor shared with anyone.
Legal basis: performance of a contract.
2.6 Your subscription
If you subscribe, the transaction is handled entirely by the store you downloaded the app from: Apple through its in-app purchase system, or Google through Google Play Billing. We never see your payment card details. They never pass through our servers at any point.
We use RevenueCat to know whether your subscription is active. RevenueCat receives a pseudonymous identifier tied to your account, your subscription status, its start and renewal dates, and the transaction history passed on by Apple or Google.
If you request a refund on Android beyond the 48-hour window, Google forwards your request to us. We then receive the purchase date and the email address of the account concerned, solely in order to handle that request.
Legal basis: performance of a contract.
2.7 Technical data collected automatically
The app includes Firebase Performance Monitoring, a tool that measures the app's stability and speed. It automatically collects, in pseudonymous form:
- your device model and operating system version
- the country the app is used from
- the network connection type and carrier
- app start-up times and network request durations
This data cannot identify you personally and is never combined with the content of your meals.
Legal basis: legitimate interest, namely detecting and fixing technical problems in order to keep the service working properly. You may object to this processing by writing to contact@espir.io.
2.8 Meal reminders
Reminders are local notifications. They are scheduled directly on your device and triggered by it. No data is sent to a server to make them work, and we do not know whether you received or opened them.
They are active only if you enable them and grant the corresponding system permission. You can turn them off at any time, in the app or in your phone's settings.
Legal basis: consent.
3. What we do not collect
To remove any ambiguity, Espir neither collects nor processes:
- your weight, height, or body mass index
- calories, macronutrients, or the nutritional composition of your meals
- photographs of your meals
- your precise location
- your address book, contacts, or files
- your advertising identifier (IDFA on iOS, AAID on Android)
No advertising network, tracking pixel, or behavioural analytics tool is built into the app. No data is sold, rented, or transferred to a third party for commercial purposes.
For readers in the United States: we do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law and comparable state privacy laws. We have never done so, and we have no plans to.
4. Who else has access to your data
We rely on a deliberately small number of technical providers. Each acts as a processor, on our instructions, under a contract compliant with Article 28 of the GDPR.
No other third party has access to your data, other than where we are legally required to respond.
5. Where your data is stored
We will say it plainly: your data is hosted in the United States.
The Firestore database used by Espir sits in Google's nam5 region, a multi-region zone spread across several data centres located in the United States. Performance data is likewise processed on Google's servers.
This transfer outside the European Union is covered by two mechanisms recognised under European law:
- the EU–US Data Privacy Framework, the adequacy decision adopted by the European Commission on 10 July 2023, under which Google LLC is certified
- the European Commission's Standard Contractual Clauses, incorporated into the data processing terms of Google Cloud and Firebase
RevenueCat, Inc. is a US company and likewise processes subscription-related data in the United States, on the basis of the Standard Contractual Clauses.
6. How long we keep your data
Your data is kept for as long as your account exists.
As soon as you delete your account, it is erased permanently. We keep no copy, archive, or backup for commercial purposes.
Two exceptions, which are outside our control:
- Firebase's technical backups may retain a residual trace for a short period before being overwritten by automatic rotation
- billing records held by Apple, Google, and RevenueCat are kept in line with their own accounting and tax obligations
Technical performance data is retained by Firebase according to the service's default retention period, which does not exceed ninety days.
7. How to delete your account
Deletion is available directly in the app, at the very bottom of the Profile page.
It is immediate and irreversible. It erases your authentication account together with all your meals, notes, and preferences stored in our database.
Please note: deleting your account does not cancel your subscription. A subscription can only be cancelled from your Apple account settings or your Google Play account settings. That procedure is described in our Terms of Use.
If you prefer, you can also ask us to delete your account by email at contact@espir.io.
8. Your rights
The General Data Protection Regulation gives you the following rights:
- Access — to confirm whether data concerning you is being processed, and to obtain a copy
- Rectification — to correct inaccurate or incomplete data
- Erasure — to request deletion of your data
- Restriction — to request that processing be temporarily suspended
- Portability — to receive your data in a readable, reusable format
- Objection — to object to processing based on our legitimate interest
- Withdrawal of consent — at any time, for processing that relies on it, without affecting what was done beforehand
To exercise these rights, write to contact@espir.io. We may need to ask for something that verifies your identity, so that we do not hand your data to someone else.
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr. If you live in another EU country, you may also contact your own national supervisory authority.
9. Security
Traffic between the app and our servers is encrypted in transit (TLS). Data stored in Firestore is encrypted at rest by Google.
Access to data is restricted by Firestore security rules: each account can read and write only its own data. A single person holds administrative access to the database.
No system is infallible. In the event of a data breach posing a risk to your rights and freedoms, we undertake to notify the CNIL within seventy-two hours and to inform you directly where the law requires it.
10. Minors
Espir may be used from the age of 15, the age at which French law recognises a minor's capacity to consent to the processing of their own data.
Below the age of 15, use of the app requires the agreement of a parent or legal guardian.
We do not knowingly collect data concerning children under 15 without that agreement. If you are a parent or guardian and would like a child's data erased, write to us at contact@espir.io and we will delete it without delay.
11. Changes to this policy
This policy may change, particularly if the app evolves or a technical provider is replaced.
If we make a substantial change, we will tell you in the app before it takes effect. The last-updated date at the top of this document tells you which version you are reading.
12. Contact us
A question, a doubt, a request: contact@espir.io
Espir — COLLIN LOUIS, sole trader — SIREN 853 113 090