Privacy Policy

Last updated: August 3, 2026

This policy describes how idem0 processes the personal data of its users.

1. Data controller

The data controller is idem0, 60 Rue François 1er, 75008 Paris, France.

For any question regarding your data or to exercise your rights: contact@idem0.dev

2. What idem0 does (context)

idem0 is a technical service (proxy) that sits between your application and AI model providers (Anthropic, OpenAI). It adds an idempotency guarantee: when the same request is sent multiple times, idem0 returns the original response instead of re-executing it. This context underlies the processing described below.

3. Data processed, purposes and legal bases

a) Account data

  • Data: email address, login credentials (via magic link or Google OAuth).
  • Purpose: account creation and management, authentication.
  • Legal basis: performance of the contract (Art. 6.1.b GDPR).
  • Retention: as long as your account is active; deleted when you delete your account.

b) Billing data

  • Data: subscribed plan, billing history, Stripe customer identifier.
  • Purpose: subscription and billing management.
  • Legal basis: performance of the contract (Art. 6.1.b) and legal obligation (accounting retention, Art. 6.1.c).
  • Retention: for the duration of the relationship, then invoice retention for the legal period (10 years).
  • Note: payment data (card details) is processed directly by Stripe; idem0 has no access to it.

c) Content passing through the proxy

  • Data: the requests you send to AI models pass through idem0 to be forwarded to the provider. These requests may contain personal data if you include any in your prompts.
  • Important point on requests: idem0 does not retain the content of your requests. Only a one-way cryptographic fingerprint (SHA-256 hash) is stored, solely to recognize an identical request. The original request content cannot be recovered from this fingerprint.
  • Responses: the response generated by the model is retained, in encrypted form (AES-256-GCM), to enable replay (idempotency).
  • Purpose: to provide the idempotency and replay guarantee.
  • Legal basis: performance of the contract (Art. 6.1.b).
  • Retention: 30 days, then permanent deletion.

d) idem0 API keys

  • Data: the keys you generate are stored in hashed form (SHA-256) — never in plaintext. The full key is shown to you only once, at creation.
  • Purpose: authentication of your calls to the service.
  • Legal basis: performance of the contract.

e) Your provider keys (Anthropic / OpenAI) — BYOK model

  • idem0 operates on a « BYOK » (Bring Your Own Key) basis: your provider API keys pass through the service to be forwarded to the provider, but are never retained, stored, or logged by idem0.

f) Audience measurement

  • Data: pages viewed, in anonymous and aggregated form.
  • Tool: Vercel Analytics, which sets no cookies and performs no cross-site tracking. Measurement is anonymous.
  • Purpose: to understand site usage in order to improve it.
  • Legal basis: legitimate interest (Art. 6.1.f), the measurement being anonymous and without trackers.

4. Cookies

idem0 uses only strictly necessary technical cookies for authentication and session management (set by our provider Supabase). These cookies are essential to the operation of the service and do not require consent.

idem0 uses no advertising, tracking, or audience-measurement cookies (Vercel Analytics operating without cookies).

5. Recipients and sub-processors

idem0 relies on the following sub-processors to provide its service:

  • Anthropic — AI model provider (request processing) — United States
  • OpenAI — AI model provider (request processing) — United States
  • Cloudflare — Proxy infrastructure — International (edge)
  • Supabase — Storage (accounts, encrypted data) — European Union (Ireland)
  • Vercel — Application hosting and audience measurement — United States / international
  • Stripe — Payment processing — International
  • Google — Authentication (OAuth) — International
  • Resend — Transactional email delivery — International

6. Transfers of data outside the European Union

Some of our sub-processors, in particular the AI model providers (Anthropic, OpenAI) and the hosting providers (Vercel, Cloudflare), are located in the United States or operate international infrastructure. The content of your requests is therefore transferred to the United States when forwarded to your chosen model provider.

These transfers are governed by Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR), contractual safeguards provided by these sub-processors. Anthropic and OpenAI further guarantee, for their API offerings, that transmitted data is not used to train their models.

7. Location of data at rest

The data that idem0 retains (accounts, encrypted responses) is stored primarily within the European Union (Ireland). Some technical infrastructure components (temporary cache) may be replicated on international infrastructure but contain only encrypted data.

8. Your rights

Under the GDPR, you have the following rights: access, rectification, erasure, restriction, objection, and data portability. You may also withdraw your consent where a processing operation relies on it.

To exercise these rights, contact us at: contact@idem0.dev

You also have the right to lodge a complaint with the French data protection authority (CNIL — www.cnil.fr).

9. Security

idem0 implements appropriate technical measures, including encryption of responses at rest (AES-256-GCM), hashing of API keys and request fingerprints, and non-retention of provider keys and request content.

10. Changes

This policy may be updated. The last-updated date appears at the top of the document.

back to home