Privacy policy
This page describes the personal data ABEERY processes, why, and who can access it. It describes only what the product actually does today.
Last updated: 13 September 2026
Who is responsible
ABEERY is published by Bastien Reytier, a sole trader established in France. The business is currently being registered; its legal identifiers will be added here as soon as they are issued.
For any question or request: contact@abeery.com
Two distinct roles, never confused
For people who open an ABEERY account, we are the data controller: we decide why and how their data is processed.
For the contacts our customers import or collect through ABEERY, we are a processor: the customer decides, we carry out. A request about those contacts goes to the customer concerned, and we help you reach them.
What data, and what for
- Account and profile: email address and password, handled by our authentication host, plus the display name and avatar. Purpose: opening the session, identifying who performed an action, reaching the account holder.
- Onboarding questionnaire: the answers describing the customer's activity, offers and channels. Purpose: configuring the delivered account.
- Visitors to public pages: a randomly drawn visit identifier, the traffic source, the landing page and the referring site. No IP address, no device identifier and no browser fingerprint are recorded.
- Our customers' contacts: name, email address, phone, company, activity notes, first and last visit origin, and marketing consent status with its date. Purpose: the customer's sales follow-up, on their behalf.
- Access log: when a member of the ABEERY team accesses a customer's data, the record stores their identity, the mandatory reason they entered, the timestamp, their IP address and their browser. This log can neither be modified nor erased.
Cookies and local storage
Three cookies only, all necessary to operate: the session cookies that keep you signed in, an interface language cookie kept for one year, and an authorisation return marker that expires after fifteen minutes and carries no data.
No advertising cookie, no third-party tracker and no external audience measurement tool is set. The visit identifier on public pages lives in the tab's memory, disappears when it closes, and identifies nobody.
Who hosts and who processes for us
- Supabase — database, authentication and file storage. Data hosted in France, Paris region.
- Vercel — application hosting. Server code runs in the United States, so personal data transits there while being processed, even though it is stored in France.
- Brevo — sending transactional and marketing email on behalf of our customers.
- OpenAI and Anthropic — text generation and on-demand analysis. See the next section for what is sent to them.
What is sent to an artificial intelligence model
An analysis never runs on its own: it is triggered by a click. What is sent consists of totals and counts — number of contacts by status, revenue, at most five offer names. No email address and no user identifier are included, and no third-party service credential is read.
Two exceptions, and they are the only ones. Tone personalisation reads the content the customer has published themselves. The pre-meeting summary sends the display name of the contact concerned, without their email or phone number.
Permissions requested from platforms
- Instagram: identifying the connected professional account, and publishing the content the customer asks to publish. Messaging and comment permissions are not requested.
- TikTok: publishing the videos the customer asks to publish.
- Meta Ads: read-only access to the customer's advertising campaigns, to report and analyse their results. No writing, no campaign creation and no campaign modification. This read access is requested in the same submission as Instagram publishing and is not implemented yet.
- Cal.com: reading the profile and the bookings, to show them in the customer's calendar.
The authorisations issued by these platforms are encrypted before being stored, and the key that decrypts them is not held in the database.
Retention periods
Account data is kept for as long as the account exists. Beyond that, no general period has been settled to date, and we prefer to write this rather than announce a deadline nothing would enforce. Two known exceptions: the access log cannot be erased, and accounting records follow statutory retention obligations.
Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, as well as the right to lodge a complaint with the French data protection authority.
These rights are exercised by writing to contact@abeery.com. We reply within one month. The procedure for erasure is described on the data deletion page.