SENSAÏ Privacy Policy
Version of 20 September 2026, applicable from that date.
This Policy describes the processing of personal data carried out by SENSAÏ, the purposes pursued, the retention periods, and the rights everyone has. It may evolve with the service; only the version in force, accessible at all times from the service, is authoritative, and earlier versions are retained and available on request.
It constitutes neither a record of processing activities nor a data protection impact assessment — the latter is the subject of a separate document.
Language. This Policy is natively drafted in SENSAÏ's six languages (French, English, German, Spanish, Portuguese, Korean); the version displayed is the one matching the language chosen in the service. The French version prevails in the event of divergence between language versions, for the same reasons as in the "Language" article of the Terms of Use.
1. Data controller and contact
The data controller is KENGNE NJILO Honoré Malachie, a French sole trader (entrepreneur individuel) under the micro-entreprise regime, SIREN 977 778 422 (SIRET 977 778 422 00013), 2 place du Muguet Nantais, 44200 Nantes, France ("MKN Coaching", the trading name of the entity "MKN Life & Career Coaching").
For any question or request relating to personal data: malachie@betterlifewithmk.com.
Appointing a data protection officer is not mandatory given the current size of the business — processing is not carried out at large scale within the meaning of Article 37 of the GDPR, given the number of people concerned to date; this will be reconsidered if the service's audience changes order of magnitude; a dedicated contact is in any event the address above.
2. Data concerned
Depending on the features used, SENSAÏ processes in particular:
- account data: e-mail address, password (kept only in hashed form), username, country of residence (mandatory at sign-up), declaration of being of age;
- profile and preference data: age range, time zone, language, first name or nickname given to SAM, gender and pronouns, declared relationship status, notification preferences, and other information the user chooses to provide;
- conversational content exchanged with SAM in writing and, when SAM Live is enabled, by voice (audio stream processed in real time, transcripts), including summaries and syntheses automatically generated for continuity between sessions, the session note given by the user, and derived indicators (Mental Fitness Score, engagement, recurring themes);
- RDP data, where the user subscribes to it: questionnaire responses (scale questions and written answers), intake information (age range, country, gender, orientation, relationship status), results and report, and, for a couple's journey, the identifier of the linked partner and the consents exchanged; where matching between single people is activated, the pseudonym and matching code chosen;
- usage and technical data necessary for the service's operation, security, diagnostics and improvement: connection logs, IP address, session identifiers, performance metrics for generated responses (response time, volumes, automated quality indicators);
- subscription- and payment-related information: payment session identifier, subscribed plan, subscription status, billing history; SENSAÏ neither receives nor retains card data, which is processed directly by the payment provider (§5);
- files uploaded by the user (for example a profile photo), where this feature is enabled.
Conversational content, RDP data, and messages linked to a situation of distress may reveal information relating to mental health, sex life or sexual orientation, family or relationship life, beliefs, or other elements sensitive within the meaning of Article 9 of the GDPR. SAM and the RDP are designed to collect this type of content as part of their function. Two distinct regimes apply. The writing of this information — the fact that SAM notes it down as the session unfolds — falls under performance of the contract: it is the very function of the service, described in the Terms of Use. SAM's re-reading of the four most sensitive categories (mental health and follow-up, spirituality and origin, identity and relationship life, topics to avoid) is subject to explicit consent within the meaning of Article 9(2)(a), collected through a dedicated gesture at the start of a session ("SAM's Memory"), refusable and revocable at any time from "What SAM knows about me". RDP data is subject to the same explicit consent, collected at subscription.
2.1 Your pseudonym protects you
SENSAÏ recommends that you choose a pseudonym and an e-mail address that does not carry your name. This is not a formality: it is what lets you tell SAM everything. Your name then appears nowhere with us, and if the platform were ever compromised, it is an avatar that would be exposed first.
But a pseudonym does not guarantee anonymity, and it would be dishonest to let you believe otherwise. It limits DIRECT identification. The content of what you say — a job, a city, an event, a combination of details — can allow you to be recognised indirectly. That is the reason we advise you not to share information that does not serve your support.
SAM will never ask you for your postal address, your phone number or your real name, and does not retain them. If you give one spontaneously in the course of a conversation, it stays within the content of that conversation — which you can delete — but it is never extracted into your memory profile.
A corollary, and it matters: to exercise your rights (§8), no proof of identity is asked of you. Verification is done through the account's e-mail address. Requiring an identity to exercise a right would contradict the pseudonymity on which the service is built.
2.2 What SAM retains about you, and what it never retains
SAM remembers from one session to the next. That is what makes the difference between real support and a string of unconnected conversations. Here is exactly what it keeps, and why.
What it retains — because without it, it would make you repeat your story every time:
| What is retained | What it is for |
|---|---|
| Your situation as you describe it: job, city, circle, life context | So you don't have to start over, and so what it offers you is adapted |
| The patterns it observes in you, your values, what you say about who you are, what your body signals | To name what recurs, instead of treating each session as an isolated event |
| Your goals, your commitments from one session to the next, exercises done and your reaction to them | To pick up the thread, and not offer you again what didn't work |
| The content of your sessions and their summaries | Continuity of the thread, and your own access to what was said |
| Your cultural background and your language, when you state them or they emerge from what you say | To adapt how it speaks to you — the same advice is not phrased the same way everywhere. These elements fall under Article 9 of the GDPR; they serve only this purpose |
What it never retains: your real name, your address, your phone number, your login credentials for other services, your banking details (they never pass through SENSAÏ, §5).
For how long: for as long as your account exists. No automatic purge is applied to coaching memory, and none is promised — a memory that erases itself after N months would give the illusion of a decision where there would only be a counter. You delete a session, messages, or your entire account whenever you want (§4, §8).
What you can do with this memory today: retrieve it in full (export, §8) and delete it (session by session, or with the account).
On what basis: SENSAÏ applies a hybrid model. ORDINARY memory — your situation, your goals, the patterns SAM observes, the content of your sessions — falls under performance of the contract: it depends on no separate gesture, exactly like the rest of the service, and is never blocking.
Four categories, which fall under Article 9 of the GDPR — your mental health and follow-up, your spirituality and cultural background, your identity and relationship life, and topics you prefer to avoid — remain subject to explicit consent within the meaning of Article 9(2)(a). This consent is now collected through a dedicated gesture, presented under the name "SAM's Memory", at the START OF A SESSION — at the first session for a new account, at the next session for an account that already exists — and no longer at sign-up, where a consent buried among other formalities would not have been a free and informed consent in the proper sense of the term. Without this gesture, these categories enter neither what SAM re-reads in session, nor the restitution of its memory, nor the improvement corpus (§3). The question is only asked again if the scope changes.
Reconsidering this decision, at any time, without deleting your account. Withdrawal is done from the "What SAM knows about me" page, via the "Withdraw this authorisation" button — a gesture of the same nature as the one that gave the agreement, in accordance with Article 7(3) of the GDPR. Withdrawal does not delete the account, does not cancel the subscription, and does not stop SAM from continuing to support you: only personalisation has fewer elements to work with.
Two authorisations, two independent levers. This one governs the Article 9 categories; the one in §3 governs the reuse of extracts to improve SAM. Refusing or withdrawing one never carries over to the other: it is possible to authorise sensitive memory while objecting to any contribution to the corpus, and vice versa.
What remains open, stated here rather than left to be discovered:
- This gesture concerns the RE-READING and REUSE of these categories, not their writing: SAM continues to note them in its internal journal even without agreement, so that an agreement given later immediately makes usable what has already been said. An agreement given today does not retroactively regularise earlier processing.
- Certain free-text fields — a significant life event, told in your own words — are not classified among these categories and may therefore escape the gesture, even when their content is of the same kind. This classification does not exist to date.
- Voice sessions (SAM Live) do not yet present this gesture; this feature is not open to the public.
2.3 What your data export contains, and what it does not
The export you trigger from your profile (§8) contains what SAM retains about you: your memory profile, your sessions with their messages word for word, the summaries, the session reviews, and what you yourself said about your sessions (your note, your written feedback).
It also contains the records of your contractual relationship: your RDP purchases (product, amount, dates, status, payment reference), the two agreements you gave before paying — with their date and the version of the text you had in front of you — and the log of billing events on your account. These are facts about you, not judgements, so they are delivered in self-service. Not included: the payment provider's technical identifiers and the internal state of the mechanism that collected your agreements — they say nothing about you, they say where the machine stands, and are provided on request like everything that is withheld.
Four elements are deliberately absent from it: the professional-referral score, the referral lock, the disengagement score, and what each session said about a possible crisis situation. These are not memories: they are conclusions the system has drawn about you, with their thresholds. A conclusion is best delivered with a human able to explain it and put it back in context, not in a downloaded file with no one to ask what a figure means.
Your right of access is not reduced by this: these elements are provided to you on simple request at the address in §1, free of charge, within the legal time limit, together with their explanation. It is the channel that is chosen, not the content. The internal procedure is written down (docs/legal/PROCEDURE_DPO.md). This distinction between a self-service channel and an assisted channel protects the person against an irreversible deletion made by mistake; it hinders no right, the outcome obtained being identical through both routes.
3. Purposes and legal bases
| Purpose | Main data | Legal basis |
|---|---|---|
| Providing conversational coaching (chat, voice), exercises, the Mental Fitness Score and the dashboard; ensuring continuity between sessions (summaries, memory) | account, profile, conversational content, indicators | performance of the contract; explicit consent for sensitive data |
| Providing the RDP: questionnaire, individual report, couple's report (subject to dual explicit consent of both people, revocable at any time), matching between single people (on explicit opt-in, via pseudonym and code, revocable) — feature not open to date | RDP data | performance of the contract; explicit consent (sensitive data, sharing with the partner, matching) |
| Adapting SAM's coaching from a summary of the RDP profile when accounts are linked | RDP summary (attachment style, cognitive profile, points of attention) | performance of the contract |
| Detecting messages signalling distress or danger, displaying orientation resources, interrupting the session, and notifying the service team | message content, country, language | legitimate interest (safety of persons) and, where applicable, protection of vital interests |
| Securing and administering the account (authentication, prevention of fraudulent access, abuse limitation, logging of sensitive actions) | account, technical data | legitimate interest / legal obligation |
| Managing discovery access (message count per calendar month), subscription, billing and accounting obligations | usage, subscription, billing | performance of the contract; legal obligation |
| Sending e-mails necessary to the service (account verification, password reset, invoices, security notifications) and, on opt-in, coaching follow-up e-mails ("SAM's letters", daily insight) | e-mail, summaries | performance of the contract; consent for follow-up e-mails |
| Measuring and improving coaching quality: automated quality indicators per session, aggregated usage statistics | technical data, conversational content | legitimate interest |
| Improving SAM's models and response quality from de-identified session extracts (removal of the user identifier, automatic masking of e-mails, numbers, web addresses, banking identifiers and other directly identifying data, followed by mechanical checking), including for the development of the Operator's own models | de-identified extracts of conversational content | legitimate interest with a right to object, for ordinary content; explicit consent (Article 9(2)(a) of the GDPR) for any content falling under Article 9 — see below |
| Responding to support requests and exercising people's rights | account, content of the request | performance of the contract; legal obligation |
No decision producing legal effects or significantly affecting the person is taken in an exclusively automated way: scores, indicators and reports are aids to reflection, and orientation in the event of distress is merely a display of information.
Improving the models — two regimes, depending on what the session contains.
For ordinary exchanges, the reuse of extracts rests on the Operator's legitimate interest in improving the quality of its service. Anyone may object in one click from their profile, at any time, without this affecting their access to the service.
For exchanges touching a special category of data within the meaning of Article 9 of the GDPR — health, beliefs, origin, orientation, emotional life — or carrying a signal of distress, legitimate interest is not enough. Article 9(2) exhaustively lists the conditions that authorise processing of such data, and legitimate interest is not among them. These extracts are therefore only entered into the corpus if the person has explicitly consented, through the gesture described in §2.2 — the very same one that authorises SAM to re-read this content from one session to the next. This consent is time-stamped, versioned, and can be withdrawn at any time.
Nothing is excluded by design. The corpus is not built by removing sessions: that would deprive SAM of learning precisely where it must be best, since it supports people who are struggling. What does not enter it is what a person has declined to give — and a refusal on sensitive matters never prevents their ordinary exchanges from contributing to it.
What is done to admitted extracts. As soon as a session touches Article 9 or carries a signal of distress, the extracts drawn from it are recorded with no reference to the account or the session, run through automatic cleaning as soon as they are written — nothing identifying is ever kept in the clear, even temporarily — and placed in quarantine, and thus out of any use, until a second pass has mechanically verified its own output. These measures aim to make re-identification impracticable; they add to consent, they do not replace it.
A consequence that must be stated frankly: once detached, these extracts can no longer be found or deleted on request. That is the exact flip side of their de-identification. Withdrawing consent prevents any future entry; it cannot take back what can no longer be linked to anyone.
4. Retention periods
| Data | Duration | Why this duration |
|---|---|---|
| Account and profile data | Lifetime of the account, then deletion (immediate or deferred by 30 days, see below) | For as long as you use the service. Deletion erases; it does not set aside. |
| Conversational content, summaries, scores, RDP results | Lifetime of the account, unless the user deletes a session or messages (possible at any time) | Memory IS the object of the service: it lives with the account. No automatic purge, so that a session from six months ago remains useful. |
| De-identified extracts used to improve the models | No time limit, retained after account deletion, with no link to identity | Detached from the account and the session, they can no longer be linked back to you — which is also why they can no longer be found or deleted on request. |
| Decision to refer to a professional, including its lifting | Lifetime of the account | A cancelled decision remains traceable: that is what allows it to be contested. |
| Expired or revoked login tokens | 7 days | Security: an expired token must not survive its expiry. |
| Audit logs of sensitive actions | Anonymised after 90 days (user identifier, IP and browser identifier erased) | Security and evidence, for the necessary time, then erasure of what identifies. |
| Data exports requested by the user | 30 days after production | The produced file is temporary; your original data is not erased by its deletion. |
| Billing events | Statutory accounting retention period: ten years (Article L. 123-22 of the French Commercial Code), dissociated from identity after account deletion | Legal obligation (Article L. 123-22 of the French Commercial Code). |
| Database backups | Encrypted daily copy, automatically erased after 30 days; a monthly copy is retained longer offline | To be able to restore the service and your data after an incident, without keeping copies indefinitely |
| Data retained by the payment provider | As per Stripe's policy | Policy specific to the payment provider. |
Account deletion: two paths coexist (see also the Terms of Use, Article 8) — immediate and irreversible deletion on explicit confirmation, or deactivation followed by an automatic purge 30 days later if the request has not been cancelled — to cancel a deferred deletion before its deadline, it is enough to write to support. In both cases, nearly all data linked to the account is erased (profile, conversational content, summaries, scores, RDP results, exercises, payment methods stored on the service side); the data of a linked RDP partner is not affected, the couple link being broken. Some data survives with no direct link to the person's identity (dissociated user identifier): audit logs, billing events, and de-identified extracts mentioned in §3.
5. Recipients and processors
The Operator's authorised personnel access data within the limits of their duties. To date, the Operator is the only person authorised; no third party accesses the content of conversations. The Operator's access to the content of conversations is limited to the following cases: handling a user's request, distress notification (§3), quality control on a limited sample of sessions, legal obligation.
The service's operation relies on the following categories of providers:
- Infrastructure hosting: Hostinger, server located in France. No infrastructure data is hosted outside the European Union.
- Database: a PostgreSQL instance operated directly by the Operator, on the French server mentioned above; no third-party database host is involved.
- File storage (profile photos and uploaded documents): Cloudflare (R2), acting as a processor, under its data-processing addendum; Cloudflare adheres to the EU–US Data Privacy Framework.
- Payment and billing: Stripe. SENSAÏ neither receives nor retains card data.
- Artificial intelligence model providers for text, to which the content of exchanges with SAM is transmitted to generate responses and associated analyses: Google (Google AI, Gemini models) and, via the OpenRouter routing platform, other third-party model providers (disabled by default in the current configuration). Conversational content is also transmitted to these providers for session summaries, automated quality evaluation, and de-identification of extracts (§3).
- Voice providers for SAM Live: no provider is activated to date — SAM Live is not open to the public. The provider selected, any retention periods for audio, and the qualification of voice under Article 9 will be specified in this Policy before any opening.
- Transactional e-mail delivery: Resend. An SMTP server takes over if this provider is unavailable.
- Asynchronous processing and cache infrastructure (queues, sessions): Redis, operated directly by the Operator, on the same French server; no third-party provider is involved.
The above inventory must be completed and validated (exact role, data received, country of processing, processing agreements) before publication. No data is sold or transmitted to third parties for advertising purposes.
6. Transfers outside the European Union
The content of your conversations is processed in Europe. Calls to artificial intelligence models go through Vertex AI's multi-region European access point, for which the provider commits that processing takes place within the European Union. This is not a setting someone could forget to set: it is the service's default value, written into its code and checked by an automated guard.
The provider, a company incorporated under US law, remains liable to access data from the United States in cases provided for by its contract. This situation falls under the European Commission's adequacy decision of 10 July 2023 on the EU–US Data Privacy Framework, to which it adheres, supplemented by standard contractual clauses where they apply.
On this provider's paid offers — the only ones used here — exchanges are not used to train its own models and are not subject to any human review. They are retained briefly, for the sole purposes of detecting prohibited use and meeting its legal obligations.
No voice provider is activated to date, SAM Live not being open to the public.
7. Security
Technical measures implemented in the service:
- hashed passwords, never stored or transmitted in the clear;
- authentication via a signed token (asymmetric-key JWT) transmitted through an
httpOnlysession cookie, restricted to the secure protocol in production and to the same origin (SameSite=Strict); - protection against cross-site request forgery (CSRF) on data-modifying requests;
- rate limiting of requests per period (per user and per IP address), temporary blocking after repeated failed sign-in attempts;
- audit logging of sensitive account actions;
- deterministic safety nets, independent of artificial intelligence models, for distress detection and to prevent any therapeutic self-presentation by SAM;
- two-stage de-identification (immediate mechanical masking, then controlled rewriting) of extracts retained for model improvement, with quarantine of any extract whose masking is not verified;
- protection against attempts to inject instructions into SAM's memory.
Encryption in transit (TLS) and at rest, management of administrator access, data partitioning by account. An encrypted copy of the database is deposited daily on storage distinct from the server, and its restoration is tested weekly — genuinely restored in a disposable database, not merely checked on paper. Archives remain encrypted, and the key does not live in the same place as they do. The Operator nonetheless guarantees neither a restoration deadline nor the total absence of loss, and it remains useful to export what you wish to keep yourself (§8). In the event of a data breach, the Operator notifies the CNIL within seventy-two hours and, where the risk is high, the people concerned without undue delay, in accordance with Articles 33 and 34 of the GDPR.
8. Rights of individuals
Subject to legal conditions and limits, anyone may request access, rectification, erasure, restriction, the portability of their data, may object to processing based on legitimate interest, and may withdraw a consent at any time (with no effect on the lawfulness of earlier processing).
From their profile, the user may directly: export their data (asynchronous processing, file available for 30 days; the content of the export and the four elements withheld from it are described in §2.3), delete a session or messages, delete their account (immediately or on a deferred basis), manage their opt-ins (follow-up e-mails, sharing with an RDP partner), revoke their consent to the couple's report, and manage their subscription.
Other requests are sent to malachie@betterlifewithmk.com. The Operator responds within one month, extendable by two months for complex requests, after verifying that the request genuinely comes from the person concerned — via the account's e-mail address, never via proof of identity (§2.1). A person may also lodge a complaint with the CNIL: https://www.cnil.fr/.
9. Minors
The service is reserved for people aged 18 and over and is not intended for minors. The Operator does not knowingly collect data from minors. If an account appears to belong to a person under 18, it is suspended then deleted along with its data. Any parent or guardian who believes a minor has created an account may write to malachie@betterlifewithmk.com. Registration refuses any declared age below 18, across all onboarding paths.
10. Cookies and trackers
The service only sets cookies strictly necessary for its operation, which do not require consent:
- an authentication session cookie, signed,
httpOnly, restricted to the secure protocol in production and to the same origin; - a technical cookie protecting against CSRF attacks, with the same restrictions.
The service uses no audience-measurement cookie, no advertising tracker, and no consent banner. Verification of 06/09/2026: no third-party tracker was found on the application or on the public pages of sensai.betterlifewithmk.com and rdp.betterlifewithmk.com; the only external resource loaded is the Google Fonts font service, which as a result receives the browser's IP address. The showcase site betterlifewithmk.com is hosted on a third-party site builder and remains governed by that provider's terms, distinct from this Policy.
11. Evolutions of this Policy
This Policy is dated and versioned. Any substantial amendment is notified to users holding an account, by e-mail or within the service, at least thirty days before it takes effect; successive versions are retained for five years.