Privacy policy
LISA is a habit-coaching service for people living with Crohn’s disease or ulcerative colitis. To do that job it necessarily handles information about your health. This page says exactly what we hold, why, who else touches it, and what you can make us do about it.
This policy covers the LISA website and the LISA application.
1. Who is responsible
The controller of your personal data is KAPTOR, a French SARL with share capital of €10,000, registered office Hangar 15, Quai des Chartrons, 33300 Bordeaux, France, registered under SIREN 894 296 466 (RCS Bordeaux). It acts through its manager, Arnaud Autran.
For anything in this policy — including every request under section 6 — write to arnaud.autran@kaptor.io. A person reads it. We answer within one month.
2. What we collect
Account data. Your email address and authentication identifiers, so you can sign in and so we know whose plan is whose.
Onboarding and questionnaire answers. What you tell us at sign-up about your diagnosis, symptoms, energy, sleep, diet and daily life. This is health data. It is the input the plan is built from.
Your plan and your progress. Which habits you were given, which days you held them, which are earned and which are still locked.
Your conversations with the coach. Everything you write to Lisa, and everything she writes back, including the daily check-ins.
Subscription data. Your subscription status, its renewal dates, and the customer identifier given to us by our payment provider. We never see or store your card number.
Contact form submissions. Your name, email address, the subject you picked and your message.
Technical data. Server logs from our hosting and functions provider, kept for security and debugging.
We do not collect your postal address, your phone number, your social-security or insurance numbers, or any document from your medical file.
3. Why we are allowed to hold it
| What | Why | Legal basis |
|---|---|---|
| Account, plan, progress, subscription | Running the service you paid for | Performance of a contract — GDPR Art. 6(1)(b) |
| Health data: questionnaire answers, coach conversations | Building and adapting your plan, and pausing it when you report a warning sign | Your explicit consent — GDPR Art. 9(2)(a) |
| Contact form | Answering you | Your consent — Art. 6(1)(a) |
| Server logs, anti-abuse measures | Keeping the service up and unabused | Legitimate interest — Art. 6(1)(f) |
| Invoices and accounting records | We are required to keep them | Legal obligation — Art. 6(1)(c) |
Health data is a special category under Article 9 of the GDPR. We process it only on the basis of the explicit consent you give when you start onboarding. You can withdraw that consent at any time — see section 6. Withdrawing it means we can no longer run a plan for you, so it ends the service.
4. Who else touches your data
We do not sell your data. We do not share it with advertisers. We do not use it to train anyone’s general-purpose models. These are the only third parties involved, each doing one job:
Google Ireland Limited / Google LLC — Firebase. Authentication, database, server functions and
hosting. Your account data, plan, progress and conversations are stored here. Servers are in the
United States (us-central1).
Anthropic PBC — the AI coach. The content of your conversations and the plan context needed to answer you are sent to Anthropic’s API to generate Lisa’s replies. Your name, email address and account identifiers are not sent. Anthropic processes the request, returns the reply, and does not use it to train its models. Servers are in the United States.
Stripe Payments Europe, Ltd. Payment and subscription management. Stripe receives your email address and your payment details directly — your card details go to Stripe, never to us.
Sendinblue SAS (Brevo). Sending the daily check-in emails and delivering contact-form messages. Receives your email address and the content of the message being sent. Servers are in the European Union.
Transfers outside the EU. Firebase and Anthropic process data in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, together with the EU–US Data Privacy Framework where the provider is certified under it.
5. How long we keep it
- Account, plan, progress and conversations: for as long as your account exists, then deleted within 30 days of you closing it or asking us to.
- Subscription and invoice records: 10 years, because accounting law requires it.
- Contact form messages: the message is emailed to us and is not stored in any database. It lives in our mailbox, and we delete it within 12 months of the matter being closed.
- Anti-abuse counters for the contact form: an irreversible hash of your IP address, kept 24 hours. The IP address itself is never written down.
- Server logs: 30 days.
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to a particular use. You can withdraw your consent to health-data processing at any time, which ends the service going forward but does not undo what was lawful before. You can also tell us what should happen to your data after your death, under French law n°2016-1321.
To exercise any of these, email arnaud.autran@kaptor.io. We reply within one month.
If you think we have got it wrong, you can complain to the CNIL — cnil.fr — or to the courts.
7. Automated decisions
Lisa is built on a large language model, so parts of your plan are generated automatically. It is not a decision that produces legal effects for you: it is a suggestion of daily habits, drawn from a fixed, human-curated catalogue, with rules in code limiting what may ever be recommended. Medication and medical treatment are never in scope. A human being — you — decides whether to act on any of it.
8. Cookies and tracking
This website sets no cookies. There is no analytics, no advertising pixel, no session recording and no third-party script of any kind. Nothing here follows you anywhere.
The application stores what is strictly necessary to keep you signed in. That is an essential function, and it is not used to track you.
9. Children
LISA is for adults. You must be 18 or over to subscribe.
10. Security
Traffic is encrypted in transit. Access to the database is governed by per-user rules so one account cannot read another’s data, and the parts of your record written by the service — your plan, your conversations, your billing status — cannot be altered from a client at all. If a breach ever affects your rights and freedoms, we will tell you and the CNIL, as the law requires.
11. Changes
We may update this policy to keep it accurate and lawful. The date at the top always reflects the last change. If a change materially affects how we handle health data, we will tell you directly rather than quietly editing this page.