CompanionMines Paris - PSL
Privacy

Your data, in plain words

Last updated 15 September 2026

Working draft for the pilot phase — to be validated by the programme team and the school's data-protection officer before general availability.

What we store

  • Your profile: name, school email, role (student / tutor / admin).
  • Your reflective journal and learning contract: the answers you write, week by week.
  • Your AI usage: one event per exchange (date, tool, mode, prompt score, and how many words the prompt contained — the word count is what the environmental counter is built on). A short subject line, taken from the start of the prompt, is kept so your history is readable. Depending on the programme's capture setting, the full prompt text is either stored or discarded. Nothing is captured outside the supported AI websites.
  • Accessibility preferences stay in your browser only and never reach our servers.

Who sees what

  • You see everything that is yours.
  • Your CARE tutor sees an item only after you explicitly share it, and you can withdraw sharing at any time. This is enforced in the database itself (row-level security), not just in the interface.
  • Programme admins see aggregate counts for the whole cohort, never individual journals, prompts or contracts.
  • We do not sell your data, and we do not transmit it to anyone beyond the processors named below.
  • The prompt library— the pre-prompts the teaching team publishes, and the prompts students choose to share with the cohort — is also published on a public address so the Prompt Tracker extension can offer it while you write. What travels is the prompt itself, its subject and its reuse counts. A shared prompt's author is nevernamed there: outside the app it is only "shared by a student".

Where and for how long

The database is hosted for the programme by Supabase, in Paris (AWS eu-west-3, France). The application runs on Vercel, with its server code executed in Paris. Both act as processors under contract with the programme; neither uses the data for any other purpose.

Your data is kept for the duration of your enrolment in the bachelor programme and deleted at the latest one year after you leave it, or earlier on request. Backups are kept for 30 days and then deleted.

The Socratic mirror

When the programme enables it (it is off today), your prompt and the dialogue so far are sent to Anthropic (USA), acting as a processor, to generate the next question; nothing is kept by them for training. Until then, the questions the extension asks come from a bank inside the extension, with no network call.

Cookies

The app uses authentication cookies only — the ones that keep you signed in. No advertising, no analytics trackers, no third-party cookies. That is why there is no cookie banner: nothing optional is set.

Your rights (RGPD)

You can access, rectify, export or erase your data at any time. Contact the programme team or the school's data-protection officer; requests are honoured within 30 days.

Data-protection contact: <data-protection contact — to be provided by the programme>— the school's DPO.