Privacy policy

Dernière mise à jour : July 28, 2026

1. Data controller

Mathieu Corne — Sole Proprietorship (Entrepreneur Individuel) SIREN: 943 061 820 Address: 50 avenue des Champs-Élysées, 75008 Paris Email: privacy@opalecrest.com

2. What this policy covers

This policy describes the processing carried out by Opale ID (opale.id), the identity service that lets you authenticate with other services. Processing specific to each connected service is governed by that service's own privacy policy.

3. Data processed and purposes

Account — email address, password (stored as a hash, never in clear text), username, optional recovery email. Purpose: creating and maintaining your account. Legal basis: performance of the contract. Security — two-factor authentication secret (if enabled), recovery codes, active sessions (IP address, device, date, service the connection originated from). Purpose: securing access to your account and letting you spot a suspicious login. Legal basis: legitimate interest in security, and performance of the contract for MFA you enable. Connected services and consents — the list of services you have connected to, and for each the state of your consents (granted, refused, withdrawn, with their date). Purpose: letting you know who accesses what and revoke it. Legal basis: performance of the contract and consent. Public profile — activation, services made visible, personal links. Purpose: displaying a public profile if you choose to. Legal basis: consent. This option is disabled by default.

4. What is shared with connected services

When you sign in to a service through Opale ID, only the data matching the permissions you grant is shared with it. Your password is never shared with a third-party service. You can review and withdraw each permission from your dashboard; withdrawal applies going forward and does not erase data the service has already received, which is governed by its own policy.

5. Retention periods

Account data is retained for as long as your account exists, then deleted when you delete it. Sessions expire automatically and revoked sessions are purged. Consent history is retained for the duration of the relationship, then for as long as needed to evidence it. Security data (MFA, recovery codes) is deleted when you disable the feature or delete your account.

6. Recipients and hosting

Your data is never sold, rented, or shared for advertising purposes. It is processed by our technical subprocessors: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA for application hosting and Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 for the database. These providers may process data outside the European Union; such transfers are governed by the European Commission's standard contractual clauses.

7. Security

Passwords are stored as cryptographic hashes and cannot be reconstructed. Session tokens are stored hashed. Traffic is encrypted in transit. Two-factor authentication is available and recommended.

8. Your rights

You have the right to access, rectify, erase, port, object to, and restrict the processing of your data, as well as the right to withdraw your consent at any time. You can exercise most of these rights directly from your dashboard (review, export, account deletion, revoking consents and sessions). For any other request, write to privacy@opalecrest.com: we respond within 30 days at most.

9. Complaints

If you believe your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris — cnil.fr.

10. Cookies

Opale ID sets a single session cookie (oid_session), strictly necessary for authentication to work. No analytics or advertising cookies are used, so no consent is required on that basis.

11. Changes to this policy

This policy may be modified. Substantial changes take effect 15 days after publication on the site.

12. Contact

For any question about your personal data: privacy@opalecrest.com