Legal

Privacy Policy

Last updated: 31 August 2026

This notice explains what personal information Focale collects, why we use it, who we disclose it to, how we disclose it, and the security practices we apply. It is written for GDPR Article 13 and the CNIL information-notice models.

1. Who is the controller

The controller is Valentin Marchaud, entrepreneur individuel, registered in France under SIREN 850496480, whose registered office is at 32 rue des Jeûneurs, 75002 Paris (in this notice, “Focale”, “we”, “us”).

We operate the Focale product at https://focale.io and https://app.focale.io. The product watches signup, checkout, and deploys on a live Lovable, Bolt, or Replit app, explains what broke in plain English, and can propose a proven fix. Access to your codebase is read-only. We do not take write access to your customer database. You approve anything near money or accounts.

Privacy questions and GDPR requests: founders@focale.io. We have not appointed a data protection officer.

2. What we collect

Information you give us

  • Email address: waitlist, magic-link sign-in, and team invites.
  • Account data: email, and GitHub user id if you sign in with GitHub.
  • App data you enter: app name, public URL, and builder (Lovable, Bolt, or Replit) if you provide it.
  • Messages you send in product chat, and the approvals you give for proposed fixes.
  • Optional waitlist note about what is painful in your app today.

Payment data

We do not collect full payment card numbers. Paid plans are billed by Stripe. We store Stripe customer and subscription identifiers, plan, and billing status. Stripe processes the card or other payment method on file.

Information from GitHub, if you connect a repository

GitHub sign-in and the GitHub App give us a GitHub user id, installation id, repository full name, default branch, pull request URLs and numbers, and read-only file contents needed to watch the app and to propose a fix. We do not get write access to your production database. We do not resell your codebase. We do not use it to train models, to build other products, or for anything except Focale features on your app: watch signup, checkout, and deploys, explain what broke, and propose a fix for your approval.

Watch data from your live app

When you ask Focale to watch signup, checkout, or deploys, we collect whether those flows succeeded or failed and the related runtime signals we need to explain what broke in plain English. That is the watch data for your app. It is not write access to your customer database.

Information collected automatically

  • A session cookie (focale_session) after you sign in. It is httpOnly, used to keep you signed in (30 days).
  • First-party events on focale.io: event name (for example page view, notify click, waitlist submit), path, referrer, and browser user agent, stored on our infrastructure.
  • IP address on waitlist signup, for abuse prevention.

Analytics

The marketing site does not load third-party advertising or analytics scripts.

3. How we use it (purposes and legal bases)

Providing the data marked as required (your email to create an account) is necessary for the contract. If you do not provide it, we cannot open the account.

  • Contract: create and keep your account, magic-link or GitHub sign-in, watch the flows you chose, send plain-English alerts, propose fixes for your approval, and bill paid plans.
  • Legitimate interests: keep the Service secure, prevent abuse, understand whether focale.io pages work (first-party events), and improve the product without selling your data.
  • Consent: waitlist “notify me” emails about launch and early access. You can unsubscribe or ask us to delete the address.
  • Legal obligation: keep billing records and respond to lawful requests.

We do not sell personal information. We do not use your information for interest-based advertising. We do not make automated decisions that produce legal or similarly significant effects. Proposed fixes wait for you; you approve anything near money or accounts.

4. Who we disclose it to, and how

We disclose personal information to the processors below so they can run their part of the Service. We do not sell lists. We do not give anyone write access to your customer database. We do not resell your codebase or use it except to provide Focale features.

  • Stripe — paid plan billing. Stripe processes the payment method on file.
  • GitHub — sign-in and read-only repository access, only to provide Focale features on your app.
  • Vercel AI Gateway — plain-English explanations and proposed fixes. Prompts may include watch data and read-only code excerpts needed for that task. We use the gateway with no retention: prompts are not stored by Vercel for training or later use.
  • Our infrastructure, hosted on OVH in France — accounts, sessions, watch data, and the product itself.

We may also disclose information to professional advisors under confidentiality, to a buyer or successor if we transfer the business, or to authorities when the law requires it.

5. Transfers outside the European Economic Area

We are based in France. Product data on our infrastructure is hosted on OVH in France. Stripe, GitHub, and Vercel AI Gateway may process data in the United States or other countries. Where GDPR requires a transfer tool, we rely on that processor’s published mechanism (adequacy decision and/or standard contractual clauses). You can ask us for more detail at founders@focale.io.

6. How long we keep it

  • Account and app records: while the account is open. Deleting the account removes product data, with best-effort purge of GitHub App installs, watch data, and the waitlist email.
  • Sessions: 30 days, then they expire.
  • Magic-link tokens: minutes.
  • Waitlist email: until you ask us to delete it or an account-delete purge runs.
  • First-party landing events: while we operate the waitlist and conversion stats, then deleted or anonymised.
  • Billing identifiers: as long as needed to bill, then as long as French accounting rules require us to keep invoices.
  • Watch data: while the app is connected, and for a limited period after disconnect as needed to operate and secure the Service.

7. Security practices

  • HTTPS on public hosts in production.
  • httpOnly session cookies, marked Secure in production.
  • Read-only codebase access through the GitHub App. We do not resell your code or use it except to provide Focale features.
  • No write access to your customer database.
  • You approve anything near money or accounts. By default every proposed fix waits for you.
  • Account deletion is available in the product for the signed-in user.

No internet service is perfectly safe. We use commercially reasonable technical and organisational measures; we cannot guarantee that unauthorised access will never occur.

8. Cookies

Essential: focale_session after sign-in. First-party events on the marketing site do not require a third-party advertising cookie.

9. Your rights

Under GDPR you may ask us to access, correct, delete, or restrict personal information, to receive a portable copy, to object to processing based on legitimate interests, and to withdraw consent (for example waitlist mail) without affecting earlier lawful processing. Write to founders@focale.io. We may need to verify it is you (for example by asking you to use the signed-in account or to confirm the email we hold).

You may lodge a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés), https://www.cnil.fr, or with your local supervisory authority if you live elsewhere in the EEA or UK.

10. Children

The Service is for founders running a live app. It is not directed at children under 18. If you believe we have collected a child’s data, contact founders@focale.io and we will delete it.

11. Changes

We will update the date at the top of this page when the notice changes. Material changes will also be posted on the Service or emailed to the address on the account when that is practical.

12. How to contact us

  • Privacy and product: founders@focale.io
  • Post: Valentin Marchaud, 32 rue des Jeûneurs, 75002 Paris