Privacy policy
In short
- Outside of a trip you start, BienRentré doesn't know where you are.
- With "Progress only", no location is ever kept or shown.
- With "Approximate location", we receive your exact location but only ever save and show a location rounded to about a hundred metres.
- Your loved ones never see your trip history.
- Nothing you share is ever sold, to anyone, ever.
- You can export your data or delete your account at any time, from the app.
This policy describes what BienRentré (the app, the bienrentre.app website, and the beta sign-up) knows about you, why, for how long, and who it may be shared with. It applies to anyone who uses BienRentré: to you when you start a trip, and to a loved one who follows you.
Who is responsible for your data
- Data controller: DryIA (SASU), 54 avenue Niépce, 93220 Gagny, France — see the legal notice
- Privacy contact: confidentialite@bienrentre.app or bonjour@bienrentre.app
- Data Protection Officer (DPO): none appointed to date; for any question about your data, write to
confidentialite@bienrentre.app
What BienRentré knows about you, and why
Your account
When you sign up, we receive your username, display name, email address and password (never stored in plain text: only its encrypted version is). You can optionally add a profile picture and a phone number.
Your phone number is only shown to a loved one during a trip in alert, on the "Call" button of the alert screen: it's information you choose to provide, for that one purpose.
At sign-up, you confirm you're 15 or older (see "Minors" below): this confirmation is timestamped, with no identity check.
Your personal settings (how long positions are kept, how arrival is confirmed, etc.) are saved to make the safety net work the way you want.
Your saved addresses
The label you choose ("Home", "Théo's place"…), the category, the coordinates and the arrival-detection radius are saved to detect your arrival. These coordinates are never shown to your loved ones: only the label you chose can appear.
Your loved ones, the links you share, and your watchers
We record who you add as a loved one, the sharing level you choose for each of them (progress only, approximate location, or precise location), and whether someone has muted your milestone updates. A loved one sees the connection between you, but never your past trip history.
Tracking links you share (on WhatsApp, by text, or by email) let anyone who receives them follow a trip without creating an account.
Your trips and locations
During a trip, we receive your location to calculate your progress, adjust the expected arrival time, and detect your arrival. What we keep and show depends on the sharing level you chose:
- Progress only: your location passes through our servers, but it is neither saved nor shown to anyone.
- Approximate location: we receive your exact location (needed for the calculation), but we only ever save and show a location rounded to about a hundred metres.
- Precise location: your real location is shown, live, to the people you've allowed — until you arrive.
As soon as a trip ends (arrival or cancellation), your starting point and the route are deleted. The rest of the trip — and the log of who was notified, and when — is kept for twelve months at most, then deleted.
If you use timer mode, or if you declined the location permission, no GPS location is collected at all: the safety net then works without location.
An arrived trip stays visible to your loved ones for 12 hours, then disappears: we don't keep a visible history for them.
Outside of a trip you start yourself, BienRentré collects no location.
Learned durations
To refine the expected arrival time for your regular trips, BienRentré can remember how long your past trips actually took. This information is never shown to your loved ones. The "Learn my durations" setting, in your Profile, is on by default; you can turn it off at any time, which immediately erases the durations already remembered. If you export your data, this setting and the observed durations are included.
This feature also depends on a switch we control on our servers: while it's off, the setting stays hidden in your Profile and nothing is learned, whatever you choose. As of the date of this policy, this switch is off.
Tracking links without an account (/t/…)
Someone who receives a tracking link sees your first name, the trip's status, your progress, the estimated arrival time and, depending on the sharing level, a map. This page is accessible to anyone with the link, with no account needed.
To display the map, this page loads map tiles and a mapping library hosted elsewhere: the visitor's IP address is then shared with those services (see "Who we share your data with").
Groups and "everyone gets home" rooms
In a group, members can see who's on the way and who's home. In a room run by a partner (a student night out, a festival, an event), the organiser never sees any location, trip or identity: only three aggregate counters (signed up, on the way, home safe), hidden below 5 participants. An organisation room never shows a first name.
A time-bound event has its members and invitations deleted 48 hours after it ends. In an organisation room, a member inactive for 90 days is removed. The aggregate counters contain no identity and are kept beyond that.
If you report a room, the reporter is anonymised after 90 days, and the report is deleted after 12 months.
Notifications and logs
Every notification (departure, milestone, running late, alert, arrival) is logged: who it was sent to, when, and whether it was delivered. This log lets you know who was notified; it's deleted with the trip it belongs to (so within 12 months at most), and also when you delete your account — including notifications you received about someone else's trip.
Your device
To send you notifications, we store a technical identifier for your device (a token), its platform (iOS or Android), and the last time it was seen. This token is deleted automatically if it becomes invalid, and with your account.
We also use an authentication token (valid for 90 days, extended while you're on a trip) to recognise your device without asking for your password every time.
Signing in with Google or Apple
If you choose to sign in with Google or Apple [disabled by default as of today], we receive the identifier that service gives us (never your password with Google or Apple), the associated email address, and the date of that sign-in; we verify the identity token with Google or Apple. This information is kept until you unlink that sign-in method from your profile, or delete your account. An Apple refresh token is kept encrypted, so we can revoke it with Apple when you unlink Apple or delete your account. If your account's address is an Apple relay address ("Hide My Email"), emails we send you still reach you, forwarded by Apple.
Emails we send you
We send you emails related to your account's security (address verification, password reset) and, if you share a tracking link by email, emails to the person you're notifying. These emails go through our sending provider, Brevo.
Crash reports
If the app runs into a technical error, a report is sent to Google Firebase Crashlytics, enabled by default. This report never contains your user ID, location, destination, name or email: everything is scrubbed before sending. You can turn this off in Profile; any not-yet-sent reports are then deleted.
Beta sign-up
The website's sign-up form collects only your email, language, phone type, whether you want to test the beta, and your confirmation that you're 15 or older — no IP address, no name, no link to a BienRentré account.
Your sign-up is confirmed by email (double opt-in): a link valid for 48 hours. Without confirmation, your address is deleted within 7 days of signing up at the latest. Once confirmed, it's deleted within 12 months of confirmation at the latest, or 30 days after the launch email if you received one first. You can unsubscribe in one click at any time, and ask for your address to be deleted at any time (bonjour@bienrentre.app). We only publish aggregate statistics about the waiting list, never an individual address.
As a precaution, sign-up only opens in production once this privacy policy is published, in both French and English.
How long we keep your data
| Data | Duration |
|---|---|
| Account | As long as it exists; permanently deleted 30 days after deletion |
| Addresses, contacts, links | With the account |
| Trip (excluding start point and route) and its log | Within 12 months of the trip ending, at the latest |
| Trip start point and route | Deleted as soon as the trip ends |
| GPS locations during a trip | 30 days by default, adjustable from 1 to 90 days; none with "Progress only" |
| Arrived trip, visible to loved ones | 12 hours |
| Members of an event / organisation room | 48 hours after the event ends / 90 days of inactivity |
| Room report | Reporter anonymised at 90 days, report deleted at 12 months |
| Sign-in token | 90 days, extended during an active trip |
| Linked Google/Apple identity (identifier, provided address, dates, encrypted Apple token) | Until that sign-in method is unlinked, or the account is deleted |
| Unconfirmed / confirmed beta sign-up | 7 days / 12 months at the latest (or 30 days after the launch email) |
| Database backups | The 14 most recent service updates |
| Logs kept by our email provider (Brevo) | The period set by Brevo in its terms |
| Crash reports (Crashlytics) | 90 days, the period set by Google Firebase |
Legal basis
- Performance of a contract: account, trips, locations per the level you chose, notifications, devices, emails related to account security, signing in with Google or Apple.
- Your consent: crash reports (can be turned off), learned durations (can be turned off), beta sign-up.
- Our legitimate interest: technical monitoring of the service, fighting abuse (login attempts, mass sending of links), moderating reported rooms.
- Legal obligation: none identified to date.
Who we share your data with
We never sell your data. Some tasks are handed to providers, only for what's needed for their job:
| Provider | What it receives | Why |
|---|---|---|
| Hostinger (host, data in France) | The entire database and files of the service | Hosting BienRentré |
| Brevo | The recipient's email address and the email's content | Sending transactional emails |
| Google Firebase Cloud Messaging | Your device token, the notification's content | Sending push notifications |
| Google Firebase Crashlytics | A scrubbed crash report, with no identifier | Diagnosing technical issues |
| Google (Google sign-in) | Your identifier, your email, a verified token | Letting you sign in with Google [disabled by default to date] |
| Apple (notifications, Apple sign-in) | Your device token (iOS), a verified identity token | iOS notifications, Apple sign-in [disabled by default to date] |
| IGN, the French National Institute of Geographic and Forest Information (map tile provider, Géoplateforme service, France) | The IP address of anyone viewing a map and the map area displayed | Displaying maps in the app and on /t/… |
| jsDelivr (content delivery network) | The IP address of anyone viewing the /t/… page |
Loading that page's mapping library |
| healthchecks.io | No personal data: only the time and IP address of our server | Checking that the safety net keeps running |
Transfers outside the European Union. Your data is hosted in France: hosting doesn't involve any transfer outside the European Union. Our map tile provider, IGN, is a French public body. Only Google and Apple operate international infrastructure. Google (Firebase) covers its transfers under the EU–U.S. Data Privacy Framework, to which it is certified, and under the European Commission's standard contractual clauses; Apple covers them under standard contractual clauses.
Your rights
You can, at any time:
- Access your data and get a copy of it (portability): export everything attached to your account from the app.
- Correct it: from your profile.
- Have it erased: delete your account from the app (see "Account deletion"); it's permanently deleted within 30 days.
- Withdraw your consent: turn off crash reports or learned durations in Profile; unlink a Google or Apple sign-in.
- Object to a use of your data or ask a question: write to us at confidentialite@bienrentre.app or bonjour@bienrentre.app.
- File a complaint with a data protection authority (in France, the CNIL, www.cnil.fr), if you feel your rights aren't respected.
Minors
BienRentré is available from age 15. At sign-up, you confirm you're at least that age, through a timestamped checkbox. This isn't an identity check: we rely on your declaration.
Security
Your password is never stored in plain text. Sensitive data (like the Apple sign-in token) is encrypted. Access tokens expire and are limited to what your use of the app needs.
Updates to this policy
The version and effective date of this policy are shown at the top of this page. Any change comes with a new version number and date.
Contact us
For any question about your data, write to us at confidentialite@bienrentre.app or bonjour@bienrentre.app.