Privacy
Last updated: 2026-05-24
This page documents three areas: (1) AI Advisor conversations, (2) authentication, and (3) the AI sub-processor. The full GDPR Art. 13 policy will be published soon (Story 6.2).
AI advisor conversations
Data stored
- Each message: role (user/assistant) and text content.
- Device IDs cited (cameraIds) extracted from the Oracam catalog.
- Technical metadata: tokens used (tokensUsed), processing duration, locale (FR only at MVP).
- Timestamps: creation date (createdAt) and last update (updatedAt).
Identifier
Firebase uid if you are signed in; otherwise, a server-side conversation identifier resolved by the oracam_conv cookie (HTTP-only, SameSite=Lax, 1 year, opaque value).
IP address
SHA-256 hashed (ipHash) server-side; never stored in clear text.
oracam_conv cookie
Technical cookie `oracam_conv` (HTTP-only, SameSite=Lax, 1-year duration): required to link your messages to your AI Advisor session and enable later deletion; no advertising purpose.
Retention period
12 active months (visible to the user) + 12 archive months (operator access only), then automatic deletion (FR48).
Your rights
You can immediately delete your conversations with the button below, or request access to their content by email (GDPR Art. 15):
Access to your conversations: ia@oracam.eu.
For the full AI policy, see Oracam AI Policy.
Authentication providers
Three methods at MVP
Google, Apple, magic-link email. Oracam stores no passwords (NFR-Sec7).
Data collected per provider
Email, Firebase uid (never displayed or shared with third parties).
Technical sub-processors
- Google LLC — Sign in with Google (non-EU transfer: Google Standard Contractual Clauses).
- Apple Inc. — Sign in with Apple (non-EU transfer: Apple Standard Contractual Clauses).
- Google Firebase Authentication — orchestrates the three flows + sends magic-link emails (region europe-west1).
Purpose
Saving your past conversations and durable identification for migrating anonymous history to your account.
Account retention
Until deletion is requested by the user (GDPR Art. 17). Deleting the account also deletes the linked conversations.
AI sub-processor — Mistral
Sub-processor identity
Mistral AI SAS, France, EU.
Processing purpose
Generation of the AI Advisor’s responses (language model).
Categories of data transmitted
Text content of user messages + product context (device IDs and characteristics from the Oracam catalog). No user identification data (no email, no uid, no IP — the IP is hashed before any processing).
Processing location
EU (France).
Legal framework
GDPR Article 28 (sub-processing). Mistral signs a standard DPA; link to their policy: mistral.ai/terms/#privacy-policy.
| Sub-processor | Purpose | Processing location | Policy |
|---|---|---|---|
| Mistral AI | Generation of the Advisor’s responses (language model) | EU — France | Mistral privacy policy |
See also Oracam AI Policy.
Cookies set by Oracam
| Cookie | Category | Duration | Purpose |
|---|---|---|---|
| oracam_conv | Functional (extended session) | 1 year | Anonymous conversation resumption with the AI Advisor |
Sub-processors (GDPR Art. 28)
| Sub-processor | Purpose | Processing location | Policy |
|---|---|---|---|
| Google LLC | "Sign in with Google" provider | United States (SCC) | Google privacy policy |
| Apple Inc. | "Sign in with Apple" provider | United States (SCC) | Apple privacy policy |
| Google Firebase Authentication | Auth orchestration + magic-link emails | EU (`europe-west1`) | Firebase privacy policy |
| Mistral AI | Generation of the Advisor’s responses (language model) | EU — France | Mistral privacy policy |