01.Data controller
The data controller is OPENMETA, a French simplified joint-stock company (SAS) with share capital of €40,000, registered with the Alençon Trade and Companies Register under number 978 390 813, whose registered office is 5037 Chemin de la Veillotière, 61330 Ceaucé, France.
European identification number: FR6101.978390813.
For any request regarding your personal data, please contact OPENMETA at: support@openmeta.fr.
02.Purpose of the OpenMeta application
The OpenMeta application provides the general public with general health information, an orientation pathway, first-aid sheets, access to useful phone numbers and, depending on the features enabled, a nearby care search. Openmeta is not a medical device. The application does not diagnose, does not prescribe treatment and does not replace a healthcare professional, a consultation or emergency services. In case of immediate danger or serious doubt, the user must call 15 or 112.
03.People concerned
OpenMeta is intended for adult users. An adult may use the service for themselves or on behalf of a relative (a child or an elderly person).
A minor must not create an account alone or use the evaluation pathway without their legal representative. If autonomous creation by a minor is later allowed, appropriate information and consent processes will be put in place.
04.Data processed
OPENMETA processes the categories of data below. Data actually collected depends on the retained configuration and providers.
4.1 Account data
- Login email.
- Optional first name or nickname.
- Internal identifier (never shared publicly).
- Password: stored only as a cryptographic hash (bcrypt), never in plaintext.
- Account creation, login and deletion metadata.
4.2 Data provided during an evaluation
- Age or age range of the person concerned.
- Symptoms, answers to questions, free-form messages.
- Photos or documents you voluntarily submit.
- Voice messages when using voice input.
This data may reveal information about the person's health status and is therefore considered sensitive under the GDPR.
4.3 Location
When you use the nearby care search, the app may request access to the device's location, following OS rules. Depending on the implementation, location is processed on-device or transmitted to a provider needed for the feature. It is not retained beyond what is necessary. If you refuse location, manual search by city or ZIP code remains available.
4.4 Subscriptions and purchases
For subscriptions taken out on the openmeta.tech website, payment is processed by Stripe; OPENMETA never receives the full card number.
If a subscription or purchase is offered through the App Store (Apple) or Google Play, the transaction is handled by the app store. OPENMETA only receives the information necessary for the account to work: transaction ID, product purchased, status, validity dates. The full card number is never transmitted to OPENMETA.
4.5 Technical and support data
- Error logs, diagnostics and security telemetry.
- Device type, app version, operating system.
- Support exchanges (email, messages).
- Technical identifiers necessary for the services used (authentication, AI, transcription, purchases, hosting).
05.Purposes and legal bases
OPENMETA processes personal data to provide and improve the service, secure accounts, manage subscriptions and purchases, and comply with its legal obligations.
Consent for processing of health data is collected through a positive, specific and separate action prior to the start of the evaluation. This consent can be withdrawn at any time, without affecting the lawfulness of processing carried out before such withdrawal. Withdrawal prevents the use of the concerned features.
06.Processing by artificial intelligence
When the user voluntarily submits content (text, answers, voice, photo or document) as part of an AI-assisted feature, this content may be sent to a technical provider acting on behalf of OPENMETA.
Before any transmission, the user receives clear information about the categories of data concerned, the recipient, the purpose, the retention period, and the ability not to transmit. Their authorization is obtained before transmission.
Health data is neither sold nor used for advertising or profiling. Conversations are not persistently retained (session-only), even though temporary technical copies may exist during processing.
The AI provider's settings (region, retention, absence of training use) are governed by the contractual terms of the service used.
07.Recipients and subprocessors
Data may be shared, on a strictly need-to-know basis, with the following categories:
- Authorized OPENMETA personnel (operations, support, security).
- Infrastructure and website host.
- Authentication provider (accounts and sessions).
- OpenAI or any equivalent provider, for AI features.
- Transcription provider (voice input).
- Diagnostic and error tracking tools.
- Apple or Google, for purchases and subscriptions made via App Store or Google Play.
- Support and messaging providers.
- Legally empowered authorities, in case of legal obligation or procedure.
These providers act according to the purposes defined by OPENMETA and are bound by confidentiality and security requirements.
08.Transfers outside the European Economic Area
Some providers (particularly AI-related) may process all or part of the data from a country outside the EEA. In such cases, OPENMETA relies on GDPR-recognized mechanisms (adequacy decision, standard contractual clauses, with additional safeguards where necessary).
The exact countries, entities and mechanisms may vary depending on the provider. Corresponding information is provided in accordance with applicable requirements.
09.Retention periods
Upon expiration of the subscription, data is either deleted or irreversibly anonymized, except for legal retention obligations or for the defense of legal rights.
10.Security
OPENMETA implements technical and organizational measures suited to the sensitivity of the data:
- Passwords stored as bcrypt hashes.
- Communications encrypted in transit.
- Depending on the architecture: access restrictions, authentication of authorized personnel, logging, backup protection, vulnerability management, appropriate encryption, incident response procedure.
11.No advertising based on health data
OPENMETA does not sell personal data. Health data, evaluations, photos, documents and voice messages are never used for targeted advertising, data brokerage or commercial profiling.
12.User rights
Under the GDPR and the French Data Protection Act, you have rights of access, rectification, erasure, restriction, objection and portability regarding your data. You can also withdraw your consent at any time.
Under French law, you may issue directives regarding the fate of your data after your death (post-mortem directives).
Any request can be sent to support@openmeta.fr. In case of reasonable doubt, identity verification may be requested.
If you consider that your rights are not respected, you may lodge a complaint with the French Data Protection Authority (CNIL): https://www.cnil.fr/.
13.Account deletion
Account deletion can be initiated directly in the app, under 'About & help > Delete my account'. It covers the account and associated data, except information whose retention is legally required, necessary for security or the defense of legal rights. Where applicable, you are informed of the data that must be retained.
For Google Play, a dedicated public web page allows users to request account deletion. Account deletion URL: https://openmeta.tech.
For accounts created on openmeta.tech, deletion requests can be sent to support@openmeta.fr.
14.Changes to this policy
OPENMETA may update this policy to reflect the evolution of OpenMeta, the addition or change of providers, or to comply with new legal obligations. The last-updated date appears at the top of the document. In the event of a substantial change, appropriate information is provided to users.
15.Contact
OPENMETA 5037 Chemin de la Veillotière 61330 Ceaucé — France Phone: +33 2 59 16 64 45 Email: support@openmeta.fr