Simplified data protection impact assessment (DPIA)
Updated: 28/09/2026
Translation provided for information only, not reviewed by a lawyer or a native speaker: only the French version is authoritative. Any other translation, automatic or not, is used at your own risk.
Summary of the data protection impact assessment, carried out using the CNIL's simplified template. Version of 28 September 2026, to be reviewed by the publisher before launch.
1. Description of the processing
- Purpose: explain an administrative document photographed or dropped by the user; find, on the device, the numbers useful for procedures.
- Data: text of documents (potentially social, financial or administrative health data), administrative identifiers, contact details. Data subjects: users and third parties named in the letters.
- Audience: includes vulnerable people (older people, foreign nationals, people who struggle with written text).
- Parties: the publisher (data controller), Cloudflare (hosting, processor), OVHcloud (AI, processor), PostHog (audience measurement with consent), Apple/Google/Stripe/RevenueCat (payments).
2. Design measures
| Risk | Measure |
|---|---|
| Leak of identifying data to the AI | Anonymisation on the device (rules + entity extraction), review by the user, only the masked text is sent |
| Retention of documents on the server | By default, no writing of the received text to the database; processed in memory; logs without content. Exception with explicit consent (option off by default, can be withdrawn, erased on withdrawal): masked text kept 12 months, excluding health documents, e-mail addresses and long strings of digits removed |
| Re-identification by the AI provider | Provider in the EU, contract with no retention and no training on the data |
| Health data | Medical documents excluded by the AI's triage; referral to the doctor |
| Unauthorised access to local data | Encrypted local database (SQLCipher); key in the phone's secure keychain; full erasure from the settings |
| Abuse and robots | App Attest, Play Integrity, Turnstile; limits per device and per IP; temporary blocking |
| Intrusive audience measurement | Explicit consent at first launch; no document content; EU hosting |
3. Residual risks
- A name without a title may escape automatic masking: review by the user and the absence of retention limit the impact. A small name-detection model is planned for version 2.
- The masked text passes through the publisher's server: it is never logged.
- On the website, the browser's local storage is encrypted with a non-exportable key, but remains accessible to any malicious extension installed by the user.
4. Conclusion
Given the design measures (local processing, no retention, European providers), the residual risk for individuals is judged low. The assessment is reviewed at every change of AI provider or architecture, and at the latest one year after launch.