Version française
Privacy Policy
Last updated: 2026-09-02 · Version v2.4
1. Data controller
The data controller is Teddy Barbin, sole trader (EI), trading as “Karukera Labs”, principal place of business Port Blanc, 97190 Le Gosier (Guadeloupe, France), SIREN 824 591 713. For any question, email privacy@virelya.app.
2. Data collected and purpose
Virelya only collects data necessary for the service.
- Card identity (first name, last name, role, company, professional email, phone, website, location, avatar, logo, background): provided by you. Purpose: generate your digital business card. Legal basis: contract performance (Art. 6.1.b GDPR).
- Authentication (email + hashed password, or Google OAuth): handled by Supabase. Purpose: secure your access.
- Approximate location (only if you enable Explorer): to display nearby cards. Legal basis: explicit consent.
- Photos (gallery or camera): only for backgrounds and avatars you select. No photo is read without your action.
- Messaging and calls (if you use these features): the content of messages you send (text and voice messages), plus metadata and any recaps of your calls. Purpose: deliver your conversations and calls with other users. Legal basis: contract performance (Art. 6.1.b). Important: these exchanges are not end-to-end encrypted — they are encrypted in transit and at rest, but remain technically accessible to Virelya for moderation and safety.
- Teams (if you create or join a team): your membership, role, posted announcements and the team's brand template. A team admin can see members and enforce a visual identity on your primary card. Legal basis: contract performance.
- Social features: recommendations you give or receive, referral code, view count of your cards. Purpose: networking and sharing features.
- Moderation: reports and blocks you submit. Purpose: community safety and terms enforcement. Legal basis: legitimate interest (Art. 6.1.f).
- Notifications: token stored to alert you (AI portrait ready, new message, team announcement, incoming call).
- Contact book (only if you grant permission via "Find your friends on Virelya" or at first launch): Virelya scans your contacts to identify people who already have a Virelya card and proposes them to add to your wallet. Server-side data processed: ONLY SHA-256 cryptographic fingerprints of normalized phones and emails — NEVER the plain values. An honest caveat: a SHA-256 fingerprint of a phone number is not irreversible — the set of possible numbers is small enough to be enumerated in full. The protection therefore does not come from the hashing itself but from the matching call: it requires a signed-in account and accepts at most 200 fingerprints per call, a cap enforced server-side. Privacy strategy: pattern similar to Signal/WhatsApp. The content of your contact book (names, nicknames, photos, personal notes) stays on your phone and is never transmitted. When a contact matches a Virelya user, their Virelya identifier may be added to that contact's entry in your phone book (a custom URL field, without modifying name or notes). Legal basis: explicit consent (GDPR Art. 6.1.a) — you can revoke this permission at any time in your phone's system Settings.
- Technical data (device model, OS, app version): aggregated and anonymized for diagnostics.
3. Sub-processors
Virelya relies on the following sub-processors. Each applies its own GDPR safeguards.
- Supabase (
eu-central-1 region, Frankfurt, Germany) — database, file storage and server function hosting.
- Cloudflare — delivery of the virelya.app site and of cards shared by public link.
- Expo Application Services (United States) — delivery of application updates.
- Sentry (Germany, DE region) — anonymized crash collection. Auth headers and tokens automatically redacted before sending.
- PostHog (EU cloud, hosted in Germany in Frankfurt; the publishing company is US-based) — product analytics (usage volume, journey). No session replay enabled. You can opt-out in Settings → Privacy.
- Brevo (Sendinblue, France) — sending of authentication emails: signup confirmation, password reset, address change.
- RevenueCat (United States) — Virelya Premium subscription management: account identifier and subscription status. No payment data passes through Virelya or RevenueCat; payment stays with Apple or Google.
- Google (Gemini, Maps) — AI image generation and map display. Text prompts you write and photos used for AI generation transit through their servers.
- OpenAI (United States) — logo image generation.
- LiveKit (United States) — real-time infrastructure for audio/video calls (only when you make or receive a call).
- AssemblyAI (United States) — automatic transcription of your call audio, only when you trigger a voice memo or a call recap. A temporary read link (30 minutes) is handed to it so it can read the recording; the resulting transcript is then summarised by Gemini. The recording uploaded for a voice memo is deleted from our storage once the recap has been produced.
- Apple / Google (push notifications) — only when enabled by you.
4. Retention
- Account data: as long as your account is active. Deleted within 30 days after account closure.
- Technical logs: 90 days maximum.
- Backups: 30 days after account deletion.
5. Your rights
In accordance with GDPR Articles 15-22, you have:
- Access: receive a copy of your data. Email privacy@virelya.app.
- Rectification: edit your data directly in the app, anytime.
- Erasure: Settings → Danger zone → Delete my account. Active data is deleted after every step succeeds; technical backups expire within 30 days. If you no longer have access to the app, use the account deletion request page.
- Portability: receive your data in a structured format (JSON).
- Opposition: refuse analytics in Settings → Privacy.
- Restriction: ask for a processing operation to be frozen while you contest it, at privacy@virelya.app (GDPR Article 18).
- Withdrawal of consent: where processing relies on your consent (location, photos, contacts, analytics), you may withdraw it at any time in Settings. Withdrawal does not affect processing carried out beforehand (GDPR Article 7(3)).
- Complaint: you can file a complaint with the CNIL, the French supervisory authority, or your local DPA (GDPR Article 77).
6. International transfers
Your account, card and messaging data is hosted in the European Union (Supabase, eu-central-1 region, Frankfurt). Leaving the Union: the prompts and photos sent to Google and OpenAI for image generation, call streams routed by LiveKit, call audio transcribed by AssemblyAI, subscription data processed by RevenueCat, and update delivery by Expo. These transfers rely on the European Commission Standard Contractual Clauses, or on the Data Privacy Framework for certified sub-processors. Cloudflare delivers the site from its global network; its parent company is US-based and its European establishment is Cloudflare Germany GmbH. Sentry and PostHog serve Virelya from their European regions.
7. Security
All communication is HTTPS-encrypted. Passwords are hashed (bcrypt via Supabase) — Virelya never sees your password in plain text. Data access is protected by Row Level Security at the database level.
8. Data protection officer, provision of data, automated decisions
Data protection officer. The publisher has not appointed a
data protection officer. Requests about your data are handled directly by the
data controller named in § 1, at
privacy@virelya.app
(GDPR Article 13(1)(b)).
What is required and what is not. Your email address and your
card data are necessary to perform the service: without them the account cannot
work. Location, photo access, contact-book access and analytics are optional —
refusing them does not prevent you from using Virelya (GDPR Article 13(2)(e)).
Automated decisions. Virelya makes no decision producing legal
effects concerning you, or similarly significantly affecting you, based solely
on automated processing (GDPR Articles 13(2)(f) and 22). AI image generation
produces a visual at your request; it decides nothing about you.
9. Contact
For any question, write to privacy@virelya.app. Reply within 30 days maximum.
Publisher
Virelya is published by Teddy Barbin, sole trader (EI),
trading as “Karukera Labs”.
Principal place of business: Port Blanc, 97190 Le Gosier, Guadeloupe, France.
SIREN 824 591 713 — SIRET 824 591 713 00014.
Publication director: Teddy Barbin.
Contact: support@virelya.app
Hosting providers
Application data — accounts, cards, messages, uploaded files and server
functions: Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre,
Singapore 049513. Data is hosted in the eu-central-1 region (Frankfurt, Germany).
The underlying hardware infrastructure is provided by
Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg.
The virelya.app site, legal pages and shared cards:
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States,
phone +1 650 319 8930. European establishment:
Cloudflare Germany GmbH, c/o Design Offices München Atlas,
Rosenheimer Straße 143C, 81671 Munich, Germany, phone +49 89 26207202.
Delivery of application updates:
650 Industries, Inc. (Expo Application Services), 624 University Avenue FL1,
Palo Alto, CA 94301, United States.
Published pursuant to article 6 III of the French Act of 21 June 2004 on
confidence in the digital economy.
Terms of Service · Delete my account · Back to Virelya