Privacy Policy
Last updated: February 2026
1. Data Controller
The data controller for personal data collected on methodes.eu and via the Méthodes mobile app (hereinafter "Méthodes") is Loïc Dixneuf, an individual based in Clermont-Ferrand, France.
Contact: contact@methodes.eu
2. Data Collected
Méthodes is intended for individuals aged 16 years and older. In accordance with Article 8 of the GDPR, minors who are 16 years and older may provide autonomous consent to the processing of their personal data in connection with this service.
If you are under 16 years old, you should not use Méthodes or create an account.
On the Google Play Store, Méthodes is categorized as a non-child-directed application.
3. Purposes of Processing
Méthodes collects the following data in the course of its operation:
- User Account: username, email (optional), age (optional), password (hashed with Argon2)
- Journal: mood, energy, stress, text notes, custom feelings
- Habits: name of habits, daily completions
- Routines: morning and evening routines, execution history
- Focus: pomodoro sessions, durations, identified obstacles
- Groups: group membership, posts, reactions
- Subscription: Stripe or Google Play identifiers (no banking data is stored on our servers)
- Push Notifications: subscription endpoint, encryption keys, FCM tokens (Android)
- Technical Data: session cookie (HTTP-only, secure), time zone, notification preferences
4. Data Shared with Third Parties
No data is sold. The following data is transmitted to third parties exclusively for the operation of the service:
- FCM Token: unique device identifier assigned by Firebase Cloud Messaging, necessary for push notifications delivery
- Google Analytics (GA4): anonymized usage data (pages viewed, interactions), collected only with your consent
Méthodes does not collect the following data: geographic location, contacts, photos, microphone, camera, advertising identifier (GAID/IDFA), device files or contents.
5. Legal Basis
- Service operation and access to your personal space
- Data synchronization in offline mode
- Calculation of personal statistics (visible only to you)
- Sending push notifications and email reminders (if enabled)
- Payment processing and subscription management
- Moderation of shared content in groups
- Usage analysis via Google Analytics (with consent only)
6. Data Retention
- Consent: Your registration for the service constitutes consent to the processing of the data necessary for its operation. Enabling Google Analytics requires a separate consent.
- Performance of the Contract: Payment processing and provision of the service.
- Legitimate Interest: Service security, prevention of abuse, moderation.
7. Account Deletion
You can delete your account at any time from Settings > Danger Zone in the app. Deletion is immediate and results in:
Stripe (payment processing)
- Email and user identifier — for creating the customer account and sending receipts
- The purchase history is generated and stored by Stripe
Firebase Cloud Messaging (Android notifications)
- FCM token (device identifier) — for delivering notifications
- Notification title and content
Browser push service (Web Push)
- Push endpoint and encryption keys — for sending notifications
OVH SAS (transactional emails)
- Email and first name — for sending reminders (habits, journal, routines)
- Email — for password reset
Google Play Developer API (Android purchase validation)
- Purchase token and product identifier — to verify the validity of the subscription
- No additional personal data is transmitted
Google Analytics (GA4)
- Anonymized usage data — collected only with your consent
- No personally identifiable information is transmitted to Google Analytics
8. Your Rights
Under the GDPR, you have the following rights:
- INTERNET: communication with the Méthodes server for data synchronization and authentication
- POST_NOTIFICATIONS: sending push notifications (habit reminders, pomodoro alerts). Requires your explicit permission.
- FOREGROUND_SERVICE / FOREGROUND_SERVICE_SPECIAL_USE: keeps the pomodoro timer active when the app is in the background
- WAKE_LOCK: prevents the device from going to sleep during an active focus session
- SCHEDULE_EXACT_ALARM: precise scheduling of pomodoro phase-end notifications
- REQUEST_IGNORE_BATTERY_OPTIMIZATIONS: ensures reliability of notifications and the timer despite Android battery optimizations
Méthodes does not use and does not request the following permissions: location (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION), camera (CAMERA), microphone (RECORD_AUDIO), contacts (READ_CONTACTS), file storage (READ_EXTERNAL_STORAGE), phone state (READ_PHONE_STATE).
9. Hosting
Data is hosted by <strong>DigitalOcean</strong>, in data centers located in Europe (Amsterdam / Frankfurt).
- Account and associated data (journal, habits, routines, focus sessions, breathing, groups you belong to, preferences): lifetime of the account. For free accounts, data older than 24 months may be deleted after prior notice, with a free full export available at any time; premium accounts keep their history with no time limit. Immediate deletion on request (see section 10).
- Authentication sessions (cookie
auth_session): 30 rolling days, renewed automatically if you remain active. - Password reset tokens: 1 hour maximum, purged automatically.
- Notification logs (
notification_log): 7 rolling days (automatically purged by a scheduled task). - Moderation logs and reports: 1 year (from the decision), to ensure service security and traceability of decisions. They are anonymized if the user concerned deletes their account.
- Proof of consent (table
consent_log): 3 years after the end of the contractual relationship, in accordance with CNIL recommendations. - Billing and subscription data (Stripe / Google Play identifiers, invoices): 10 years, in compliance with accounting and tax obligations (Art. L123-22 of the French Commercial Code).
- Encrypted database backups: 30 rolling days, in object storage hosted in the European Union, automatically destroyed upon expiration.
If you delete your account, all of the personal data listed above is deleted immediately, except for data whose retention is required by law (billing) or justified by a limited legitimate interest (anonymized moderation logs, proof of consent).
10. Transfers Outside the EU
You can delete your account at any time from Settings > Danger zone in the app. The deletion request triggers a 30-day grace period during which you can cancel from settings. After this period, the deletion is permanent and irreversible, and results in:
- Deletion of all your personal data (journal, habits, routines, focus sessions, posts)
- Leaving all your groups (groups where you are the sole owner are deleted)
- Cancellation of your Stripe or Google Play subscription
- Anonymization of moderation logs and reports concerning you
11. Cookies
In accordance with the General Data Protection Regulation, you have the following rights:
- Access: obtain a copy of your personal data
- Rectification: correct your inaccurate data (from your profile)
- Deletion: delete your account and all your data (from settings)
- Portability: export your data in CSV format (from settings)
- Objection: object to the processing of your data
To exercise these rights, use the features available in the app or contact us at contact@methodes.eu.
You can also file a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés, the French data protection authority): www.cnil.fr.
12. Contact
Data is hosted by DigitalOcean, in data centers located in Europe (Amsterdam / Frankfurt).
The following security measures are implemented:
- Encryption of communications via HTTPS/TLS
- Password hashing with Argon2 (algorithm recommended by OWASP)
- HTTP-only, Secure, SameSite session cookies
- Database accessible only from the server's internal network
13. Transfers Outside the EU
Your main data is hosted in Europe. Some processors (Stripe, Firebase/Google) may process data in the United States under the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCC). Only strictly necessary data is transmitted to them (see section 7).
14. Cookies
- Session cookie (necessary): maintains your authentication while you browse. This cookie is strictly necessary for the service to work and does not require consent.
- Google Analytics cookies (GA4) (consent): collect anonymized usage data to improve the service. These cookies are only enabled with your explicit consent.
For more details, see our cookie policy.
15. Contact and Changes
For any question about the protection of your personal data, you can contact us at: contact@methodes.eu.
This privacy policy may be modified at any time. The date of the last update is displayed at the top of this page. In case of substantial changes, users will be notified via the app.