← Longward Français

Privacy policy

Longward is operated by Pierre-Louis FETET, the controller under the GDPR. For any question or request about your data: Fetetpierre@gmail.com.

Data processed

Longward processes your email address, the technical identifier of your account, and the information you enter in your dashboard: accounts, assets, loans, income, spending and goals.

The service also processes the technical data needed for sign-in and security: a session cookie, and your IP address at the moment you request a code, used to limit abuse.

Purposes and legal bases

PurposeLegal basis
Create and secure your account, sign you in by codePerformance of the service you request (article 6.1.b)
Produce, store and synchronise your dashboard across your devicesPerformance of the service you request (article 6.1.b)
Limit abusive sending and attempts to guess a codeLegitimate interest in protecting the service and its users (article 6.1.f)

Recipients

Your dashboard data is intended for you alone and for the people strictly authorised to administer Longward. It is never sold, shared or used for advertising.

Three processors are involved, each covered by a data processing agreement under article 28:

ProcessorRole
CloudflareSite hosting, server-side processing, D1 database created in the European Union jurisdiction
SupabaseEmail address verification and delivery of one-time codes, Frankfurt region
ResendDelivery of the emails carrying sign-in codes

Transfers outside the European Union

The European Union jurisdiction of the D1 database constrains the storage and the execution of the database to European territory. On its own it does not guarantee that no access happens from another country: Cloudflare states that server-side processing may query a European database from another region. Cloudflare and Supabase are also companies whose groups are established outside the Union; their transfers are covered by their processing agreements and by the European Commission standard contractual clauses.

Resend is established in the United States. Sending a sign-in code is therefore a transfer outside the European Economic Area, covered by its processing agreement, the standard contractual clauses, and its participation in the EU–US Data Privacy Framework.

Retention

DataRetention
Account and dashboard dataFor the lifetime of the account. Erased immediately when you delete your account
Account left unusedDeleted after 3 years without sign-in
Sign-in session30 days at most. Destroyed as soon as you sign out
Anti-abuse counters (email address, IP address)15 minutes per email address, 1 hour per IP address
Technical database backupsOverwritten automatically at the end of the Cloudflare D1 restore window, 30 days at most
Email delivery logsKept by Resend under its own retention policy

Deleting your account immediately erases your wealth data, your active sessions and your sign-in identity. The technical backups above then expire on their own, with no further action.

Your rights

You have the right of access, rectification, erasure, restriction of processing, objection to processing based on legitimate interest, and portability of your data.

Erasure is available directly in the application, under Account, without writing to anyone. Export of your data is under Data. For the other rights, write to Fetetpierre@gmail.com.

You may also lodge a complaint with the CNIL, the French supervisory authority, at cnil.fr.

Cookies and storage on your device

Longward uses a session cookie and your browser local storage to sign you in, remember your preferences, work offline and synchronise your data. These are strictly necessary to the service you request: they do not require your prior consent.

No advertising tracker, no audience measurement and no third-party cookie is used.

Security

Sign-in uses a one-time code: there is no password to steal. Session tokens are never stored in clear text. Data is encrypted at rest and in transit by the host. Each account is isolated from the others, on the server as well as in the browser.

This is not end-to-end encryption: technical processors and the authorised administrator can technically reach the data when the operation or the security of the service requires it.

Version of 13 September 2026. The French version is the reference text.