Who is responsible
The data controller is the publisher named in the legal notice: not provided yet, not provided yet. Write to not provided yet for any question about your data.
What we collect and why
- Your account — name, email address, your password (stored only as an Argon2id hash, never readable), favourite genres, language and notification choices. To run your account; legal basis: the contract (these terms).
- Your season — the festivals you attend, your private map pins, the sets you want reminders for. To provide the service; basis: the contract. Map pins are visible to you alone.
- The forum — topics, replies, likes and reports. Posts are public: anyone can read them, with your display name. Basis: the contract.
- Festival suggestions — the text you send. To improve the catalogue; basis: our legitimate interest.
- Security — for each signed-in browser or phone: its type, an IP address and when it was last used, so you stay signed in and can see and sign out your devices; failed sign-in attempts, to stop password guessing; a bot check (Cloudflare Turnstile) on the sign-in and sign-up forms. Basis: our legitimate interest in keeping accounts safe.
- Emails — sign-up codes, sign-in links, password resets and account notices, sent only because an action needs them. No marketing email. Basis: the contract.
- The mobile app — a device key (its public half), a device name and, if you allow notifications, a notification address. To secure the app and notify you; basis: the contract.
Who else handles it
Only providers who help run the service, each for its task alone: our host (OVH SAS) stores everything; the email provider we use delivers our emails; Cloudflare runs the bot check; Google, only for the features above that are switched on (Analytics, AdSense, Maps, notifications to the Android app). None of them may use your data for their own purposes. We sell no data and share none for advertising beyond what you accept.
Transfers outside Europe
Cloudflare and Google may process data in the United States. These transfers rely on the EU–US Data Privacy Framework or on the European Commission's standard contractual clauses.
How long we keep it
- Your account and everything in it: until you delete the account, which erases it at once. Your forum posts stay, without your name, so conversations keep their sense.
- Signed-in devices: while signed in (12 hours, 30 days with "keep me signed in", 90 days for the app), then 30 days before the record is deleted.
- Failed sign-in attempts: 1 day.
- Sign-up codes and sign-in links: 10 to 30 minutes, then they no longer work.
- Our server's technical logs (IP address, page asked for): 14 days.
Your rights
Wherever you live, you can see, correct, download and delete your data: Profile & settings has an export (JSON) and a delete button, and everything else is one email away at not provided yet. You may also object to or restrict a use, and withdraw a consent at any time. No decision about you is made by automated means. We answer within one month.
If you think we got something wrong, tell us first; you can also complain to a data protection authority — ours is CNIL (Commission nationale de l'informatique et des libertés), France — cnil.fr.
Residents of California: we do not sell or share personal information as defined by the CCPA/CPRA.
Children
PsyShift is not for anyone under 16. If a younger child has made an account, write to us and we will delete it.
How we protect it
Encrypted connections (HTTPS) everywhere, passwords stored as Argon2id hashes, sign-in tokens stored only as hashes, the mobile app's every request signed by a key its phone keeps, and access to the console limited to named operators, each of their actions logged.