Privacy policy
Last updated: 23 September 2026
1. Who is responsible
The data controller is AI4Docs, SAS (société par actions simplifiée), 941 484 537 R.C.S. Paris (registered 3 March 2025), 60 rue François Ier, 75008 Paris, France. For anything about your data, write to hello@peoplewant.app.
2. If you use PeopleWant
- Account — your email address and, if you sign in with GitHub or Google, your name and profile picture. Purpose: giving you access. Legal basis: the contract.
- Subscription — your plan, its status and your Stripe customer identifier. Card details and billing address are collected and kept by Stripe, never by us. Legal basis: the contract and our accounting obligations.
- Custom radars — the text you write, kept confidential. It is used to rank opportunities for you and as a search brief to find public conversations on the same themes; those conversations join the common radar, your text does not. Legal basis: the contract.
- Usage events — which pages of the product you open and which sources you click, tied to your account, to measure whether the product is useful and to improve it. We never record the text of your radars in these events. Legal basis: our legitimate interest.
- Emails — the email sent when a custom radar finds a match (subscribers) and, if we open one later, a free weekly email (only after you confirm your address). Every email has a one-click unsubscribe link. Legal basis: the contract, or your consent for the free email.
3. Cookies
We use a few strictly necessary cookies only: your sign-in session, protection against cross-site request forgery and, for one hour, the email you typed before checkout. We use no advertising cookie, no cross-site tracker and no third-party analytics cookie, which is why there is no cookie banner.
4. If you wrote a public post that we quote
PeopleWant analyses conversations published publicly on the platforms it covers, accessed through their official interfaces. For each post we keep the text needed for the analysis, its link and date, and a one-way pseudonymous hash of the author’s handle — used only to avoid counting the same person twice. We do not store handles in clear, build profiles of authors, or try to identify anyone. Opportunity pages show short excerpts with a link to the original; excerpts containing email addresses, phone numbers or handles are filtered out automatically.
Legal basis: our legitimate interest in studying public market discussions, balanced against yours by pseudonymisation and short quotation. You can object at any time: send the link of your post to hello@peoplewant.app and it is removed within 7 days, no justification needed. Posts deleted at the source are removed automatically.
5. Who processes data for us
- Vercel (hosting, United States) and Supabase (database, European Union)
- Stripe (payments)
- Resend (sending emails)
- TypeSafe AI, and the model providers reached through Vercel AI Gateway (Anthropic, OpenAI, Google) — they process the public posts we analyse and, for subscribers, the text of custom radars. They do not receive your email address or payment data.
Some of these providers are located outside the European Union. Transfers rely on the European Commission’s standard contractual clauses or on an adequacy decision (EU–US Data Privacy Framework).
6. How long we keep data
- Account and radars: until you ask us to delete your account (one email to us), then erased within 30 days.
- Invoices and payment records: 10 years, as required by French accounting law.
- Usage events: 25 months.
- Free email subscribers: until you unsubscribe; unconfirmed addresses are deleted after 30 days.
- Public posts analysed: 12 months after their publication date, or until removal at the source or on request.
7. Your rights
Under the GDPR you may access, correct, delete or export your data, restrict or object to its processing, and withdraw your consent at any time. Write to hello@peoplewant.app; we answer within one month. You can also lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with the authority of your country.
8. Security
Data is encrypted in transit and at rest, access to the database is restricted to our application, secrets never reach the browser, and we never store passwords: sign-in relies on single-use links or on your GitHub or Google account.