Legal information
Privacy policy
Last updated: September 29, 2026
This policy explains what personal data 2View processes, why, on what legal basis, for how long, who receives it and how to exercise your rights. It applies to the website, the application and the API.
Who is responsible
The controller is Jennifer Galais, sole trader (micro-enterprise), 95760 Valmondois, France, SIRET 508 622 560 00029. Contact for any personal data question: olympai@outlook.fr. No data protection officer has been appointed.
Controller or processor
2View is the controller for the data of its users (account, workspace, billing). For the data a workspace collects about the visitors and customers of its own website (tracking links, snippet, Stripe or API revenue events), the workspace owner is the controller and 2View acts as its processor, under the data processing terms in the Terms.
What 2View processes, why and on what basis
Account: e-mail, name, password (stored hashed by the authentication service), workspace memberships and roles.
Purpose: Create and secure your account, give access to your workspaces.
Legal basis: Performance of the contract (Art. 6(1)(b) GDPR).
Workspace content: product and brand profiles, generated content, schedules, experiments, reports, uploaded videos.
Purpose: Provide the Service: generate, plan, publish and analyse your content.
Legal basis: Performance of the contract.
Connected platforms: account identifiers, username, follower count, post statistics, access tokens (encrypted with AES-256-GCM, never sent to the browser).
Purpose: Publish the content you choose and measure its results, at your request.
Legal basis: Performance of the contract.
Billing: Stripe customer and subscription identifiers, plan, invoices. Card details are handled by Stripe only and never reach 2View.
Purpose: Bill subscriptions, keep accounting records.
Legal basis: Performance of the contract; legal obligation for accounting records (Art. 6(1)(c)).
Security logs: error log, audit log of sensitive actions, rate-limit counters keyed by a daily-salted hash of the IP address (the IP address itself is never stored).
Purpose: Keep the Service secure, prevent abuse, fix errors.
Legal basis: Legitimate interest in securing the Service (Art. 6(1)(f)).
Service e-mails: address and message content (confirmation, password reset, invitations, reports).
Purpose: Send the e-mails the Service needs to work.
Legal basis: Performance of the contract.
Visits to the landing page: a count per day and per source (utm_source of the link, else the referring site). No cookie, no identifier and no IP address: a visit cannot be traced back to a person. At sign-up, the source of the visit that led to it is kept with your account.
Purpose: Know which channels bring visitors and sign-ups, and improve the landing page.
Legal basis: Legitimate interest in measuring the audience of the site (Art. 6(1)(f)).
Artificial intelligence
To generate content and analyses, 2View sends the relevant parts of your workspace (product and brand profile, content, statistics) to its AI provider, Anthropic. Under Anthropic's commercial terms, this data is not used to train its models. Generated content is a draft: you review it before publishing.
Who receives the data
Only the people who need it within the publisher, and these processors, each for its own purpose:
- Supabase (database, authentication, file storage) — servers in Ireland (EU).
- Railway (application hosting) — United States.
- Anthropic (AI generation) — United States.
- Stripe (payments and invoices) — Ireland and United States.
- Google, only if you sign in with your Google account: it confirms your identity (name, e-mail address) — United States.
- The e-mail delivery service used for authentication e-mails.
- The platforms you connect yourself (TikTok, Meta, Google/YouTube, LinkedIn, X, Reddit), which receive the content you publish and send back your statistics.
Personal data is never sold or used for advertising.
Transfers outside the European Union
Railway, Anthropic, Stripe and Google are based in the United States. These transfers are covered by the European Commission's standard contractual clauses and, where the recipient is certified, by the EU–US Data Privacy Framework. A copy of the safeguards can be requested at olympai@outlook.fr.
How long data is kept
- Account and workspace data: as long as the account or workspace exists; erased immediately when you delete it (backups expire on the hosting provider's schedule).
- Access tokens of a platform: until you disconnect it.
- Tracking data (clicks, visits, visitor identifiers, hashed e-mails): 25 months at most, then deleted automatically.
- Error log: 90 days. Rate-limit counters: 24 hours. Unused invitations: 30 days after they expire.
- Landing page visit counts: aggregated, with no personal data. Sign-up source: as long as the account exists.
- Invoices and accounting records: 10 years (French Commercial Code, art. L.123-22).
Your rights
You have the right to access, rectify and erase your data, to restrict its processing, to object to processing based on legitimate interest, to data portability, and to give instructions about your data after your death. Most of these can be done directly in Settings → Data & privacy (export as JSON, delete a workspace or your account). Otherwise, write to olympai@outlook.fr: we answer within one month.
If you believe your rights are not respected, you can lodge a complaint with the CNIL (French data protection authority): cnil.fr — lodge a complaint
Security
Encrypted connections (HTTPS), platform tokens and secrets encrypted at rest, per-workspace access control enforced by the database, hashed passwords, no IP address stored in clear, audit log of sensitive actions.
Cookies
2View only sets cookies that are strictly necessary: sign-in session, chosen language, admin session and one-time security values during a platform connection. They are exempt from consent (article 82 of the French Data Protection Act); no advertising or audience-measurement cookie is used.
YouTube and Google data
If you connect YouTube or Google Analytics, 2View uses YouTube API Services and Google APIs to publish the videos you choose to your channel and to read your channel, video and analytics statistics. This data is used only to show your results in 2View and improve your content strategy; it is never sold or used for advertising.
2View's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect YouTube in Connections at any time, or revoke 2View's access from your Google account's security settings. Access tokens are then deleted, and so is the data 2View got from YouTube for that channel (statistics, subscriber history, channel name and picture): right away after a disconnect in 2View, within 30 days after a revocation from your Google account.
Reddit data
If you connect Reddit, 2View submits the text posts you wrote and approved to the subreddits you choose, when you click Publish or at the time you scheduled. It reads your username, your profile's follower count, and the statistics of those posts only (score, upvote ratio, comments, views when Reddit provides them); it reads no other Reddit content.
This data is used only to show your results and your own content recommendations in 2View. It is never sold, shared with advertisers, or used to train AI models.
You can disconnect Reddit in Connections at any time, or revoke 2View from your Reddit app preferences. Access tokens are then deleted; the statistics already collected can be deleted with your workspace or on request. Reddit: authorized applications
Tracking on your website
If you install the 2View snippet or use tracking links, you are the controller of that data and responsible for informing your visitors and obtaining their consent where required. The snippet supports a consent mode (data-consent="required") that waits for your consent banner before storing anything.
Professional use
2View is intended for professionals and is not directed at minors.
Changes
If this policy changes in a way that matters to you, you will be informed by e-mail or in the application before the change applies.