Last updated: June 8, 2026
We take the protection of your personal data very seriously. This policy explains what data we collect, why, and how you can exercise your rights.
The data controller for personal data collected through the Les Copains application is:
Les Copains is published by a private individual, on a non-professional basis, and the service is provided free of charge on a lasting basis (no transaction or payment). For any questions regarding the protection of your data, you can contact us at the address above.
When using the Les Copains application, we collect the following categories of data:
| Data | Description | Purpose | Legal Basis |
|---|---|---|---|
| Email address | Provided during registration or via Google Sign-In | Account creation and management, important communications | Contract performance |
| GPS location | Real-time geographic position, foreground only, on demand during a walk | Show nearby spots, detect arrivals/departures (geofence), share your presence, community alerts | Consent |
| Photos | Dog profile photos, spot photos | Display profiles and enrich spot listings | Contract performance |
| Full name and nickname (human) | Full name and/or nickname you provide for your account | Identify you to your friends and to walk participants | Contract performance |
| Dog name | Provided when creating the dog profile | Social identification, friend search, community display | Contract performance |
| Detailed dog profile | Breed, age, temperament, sex, size, vaccination status, neutering, status (in heat) | Personalise experience and facilitate encounters between compatible dogs | Contract performance |
| Social graph | Friendship links (copains) and the list of blocked users | Manage your friends, share your presence and hide unwanted users | Contract performance |
| Phone number (optional) | Only if you choose SMS authentication. The number is never stored in the readable database: only a verification timestamp (phoneVerifiedAt) is stored; the number itself is handled by Firebase Authentication |
Account authentication and security | Contract performance |
| FCM token & device identifier | Technical identifier of your device (iOS identifierForVendor / Android ID) used as the key for the notification token | Sending push notifications (friend walking, alerts) and managing registered devices | Consent |
| Gamification | Experience points (XP), level, badges and walk streak | Engage and reward use of the application | Contract performance |
| Chat messages | Messages exchanged during active walks | Real-time communication between owners at the same spot | Contract performance |
| Community reports | Reports of hazards (foxtails, poison, etc.), lost dogs, proximity alerts and associated votes | Community safety, proximity alerts | Legitimate interest |
| Stability data (Crashlytics) | Crash stack traces, device model, OS version and app state at the time of a crash, associated with your technical identifier (uid) | Diagnose crashes and improve the stability of the application | Legitimate interest |
We never collect:
Your phone number is only collected if you opt for SMS authentication (see table above); it remains optional.
| Data | Retention Period |
|---|---|
| User account and dog profile | Until account deletion (immediate deletion, no archiving) |
| Inactive account | Deleted after 24 months of inactivity |
| Location history (walks) | Kept for the duration of your use of the service and deleted with your account (no automatic scheduled deletion) |
| Spot photos | Until deleted by the user or account closure |
| Chat messages | 30 days after the walk ends |
| FCM token | Until sign-out or app uninstallation |
| Community alerts | 90 days, unless kept active by the community |
| Technical logs | 90 days maximum |
We never sell your data. We only share data necessary for the application to function with the following data processors, who act on our instructions:
| Processor | Role | Data Shared | Policy |
|---|---|---|---|
| Google Firebase | Database (Firestore), authentication, notifications (FCM) | Profile data, messages, location, FCM token (email is managed exclusively by Firebase Authentication and never persisted in the Firestore database that other users can read) | firebase.google.com/support/privacy |
| Cloudinary | Photo hosting (avatars, spots) | Uploaded photos only, via server-signed uploads | cloudinary.com/privacy |
| Vercel | Server API hosting (push notifications, Cloudinary signing, account cleanup) | API requests authenticated with a Firebase ID token | vercel.com/legal/privacy-policy |
| Firebase Crashlytics (Google) | Crash reports and stability diagnostics | Error stack traces, device model, OS version and app state at the time of a crash (no profile data) | firebase.google.com/support/privacy |
| Nominatim / OpenStreetMap | Reverse geocoding (turning coordinates into a place name/address) | One-off GPS coordinates of a spot (no user identifier) | osmfoundation.org/wiki/Privacy_Policy |
These providers act as data processors and are contractually bound to protect your data in accordance with the GDPR.
If you choose to sign in via a third-party identity provider, that provider acts as an independent data controller (not as our processor): it handles your data under its own privacy policy.
| Identity provider | Role | Data Shared | Policy |
|---|---|---|---|
| Google Sign-In | OAuth authentication via Google (independent controller) | Email and Google name (if Google login chosen) | policies.google.com/privacy |
| Apple Sign In | OAuth authentication via Apple ID (independent controller) | Apple email (or relay alias) and name (if Apple login chosen) | apple.com/legal/privacy |
Some features intentionally make data visible to other users:
You stay in control of this sharing: you can remove a co-owner, hide/block a user, or delete published content.
When you delete your account, the community content you have published (alerts, spots, reviews) may be retained to preserve the integrity of shared information, but it is then disassociated from your identity (anonymised).
Google Firebase, Cloudinary and Vercel may store or process data on servers located outside the European Union (notably in the United States). These transfers are governed by the European Commission's Standard Contractual Clauses and/or the EU-US Data Privacy Framework, ensuring a level of protection equivalent to that required in Europe.
The Nominatim / OpenStreetMap geocoding service is hosted on the OpenStreetMap Foundation's servers located in the European Union: no transfer outside the EU takes place for this feature.
Geolocation is used in the foreground only (when the application is open and active): we never track your location in the background. Your position is sampled roughly every 10 metres, at high accuracy, and only on demand during a walk.
It is used to: show nearby walking spots, automatically detect your arrival at and departure from a spot (geofence), and share your presence with other users present. A walk's history may contain the positions and routes recorded during it.
You can decline or disable geolocation at any time from your device settings. The application remains usable without it, in a degraded version (certain proximity features are then no longer available).
We implement the following technical and organisational measures:
Under the General Data Protection Regulation (GDPR — EU 2016/679), you have the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Obtain a copy of your personal data | Email to copainsapp@gmail.com |
| Rectification | Correct inaccurate or incomplete data | From the profile in the app or by email |
| Erasure | Request deletion of your account and data | From app Settings → "Delete my account" |
| Portability | Receive your data in a machine-readable format | Email to copainsapp@gmail.com |
| Objection | Object to certain processing (e.g. notifications) | Notification settings in the app or by email |
| Restriction | Restrict processing in certain circumstances | Email to copainsapp@gmail.com |
| Withdraw consent | Withdraw consent at any time (location, notifications) | App settings or your device settings |
In accordance with Article 12(3) of the GDPR, we will respond to any request within a maximum of one month. You may also, at any time and without any prior step, lodge a complaint with your national data protection authority. In France: CNIL — www.cnil.fr.
Les Copains is intended for people aged at least 15 years old, the age of digital consent in France. We do not knowingly collect personal data from people under 15. If you are a parent or guardian and believe your child has provided us with data, please contact us at copainsapp@gmail.com so we can delete it.
Les Copains is a mobile application. We do not use any cookies or advertising trackers. The only technical identifiers used are:
These identifiers are strictly technical: they are not used for any advertising targeting or tracking.
We may update this policy at any time. In the event of a substantial change, you will be notified via the application. The last-updated date at the top of this document will be revised. Your continued use of the application after notification constitutes acceptance of the changes.
For any questions, requests or to exercise your rights:
Email: copainsapp@gmail.com
We are committed to responding within 30 days.