Privacy Policy
Last updated: 28 May 2026
This policy describes how HipHip (hereafter "the service") collects, uses and protects your personal data under the General Data Protection Regulation (GDPR) and French data protection law.
Our guiding principle: we collect only the minimum data needed to run the service. No data is ever sold, rented or shared with third parties for commercial purposes.
1. Data controller
The data controller is the publisher of HipHip, who operates on a personal, non-professional basis and has chosen to remain anonymous to the public, in accordance with French law (see the legal notice).
For any question about your personal data or to exercise your rights, please contact: bisouslebo@gmail.com.
2. Data we collect
We only collect the following data:
Account data
- email address (used as login identifier and to contact you about the service);
- password, never stored in clear text: only its cryptographic fingerprint (salted bcrypt hash) is retained;
- account creation and last update dates.
Service usage data
- subjects and lessons you create (name, colour, description, order);
- scheduled review sessions (dates, method, duration, self-assessment, personal notes);
- display preferences (default view, J-method intervals);
- your calendar background image if you upload one, along with its display parameters (position, scale, opacity, rotation).
Minimal technical data
- server logs (IP address, timestamp, HTTP request) kept temporarily to ensure service security and troubleshoot incidents;
- in the event of an application error, a technical report is sent to our self-hosted error tracking tool (see section 8).
What we do not collect: no banking data, no precise location data, no biometric data, no data from third parties or social networks.
3. Purposes and legal bases
Each processing operation relies on a specific legal basis under GDPR article 6:
- Service provision (account, educational data, preferences, background image). Legal basis: performance of the contract between you and the service (art. 6.1.b). Without this data, the service cannot operate.
- Service security and abuse prevention (logs, rate limiting, error tracking). Legal basis: legitimate interest of the publisher in maintaining a reliable and secure service (art. 6.1.f).
- Anonymous audience measurement (cookieless aggregated statistics). Legal basis: legitimate interest in understanding overall service usage in order to improve it (art. 6.1.f).
4. Retention period
- Account and usage data: kept as long as your account is active. You can delete your account at any time from your settings.
- After account deletion: immediate and permanent erasure from the production database. Data may however persist for up to 7 days in the hosting provider's automatic backups, before being overwritten by backup rotations.
- Server logs: kept through the system's automatic rotation (systemd-journald), based on a disk-space quota; the oldest entries are progressively overwritten, typically after several weeks to several months depending on volume.
- Technical error reports: kept on our self-hosted tracking tool based on a storage quota; the oldest reports are automatically purged when the quota is reached.
- Deletion audit logs: an internal identifier (with no email or name) is retained for security and compliance reasons, without allowing you to be directly identified.
5. Data recipients
No data is shared with third parties for commercial purposes. The only recipients are:
- The publisher of the service, for technical management and support.
- OVH SAS as the hosting provider, acting as a technical processor (server storage and backups).
- Judicial or administrative authorities, solely upon legal request.
6. Data location and transfers
Your data is hosted on an OVH server located in the data centre of Frankfurt (Germany). Germany being a member of the European Union, your data is protected by the GDPR and is not subject to any transfer outside the European Union.
7. Cookies and local storage
The service only uses cookies and local storage that are strictly necessary for its operation. No consent banner is required for these trackers under article 82 of the French data protection law.
- Session cookie: keeps you signed in. Its lifetime is limited to your session and it is automatically deleted when you sign out.
- CSRF protection cookie: prevents certain request forgery attacks. Strictly technical.
- Browser local storage: remembers your language and a few display preferences. This data stays on your device and is never sent to us.
No advertising, profiling or cross-site tracking cookies are used.
8. Third-party tools and processors
All tools used to operate HipHip are self-hosted on the same OVH infrastructure (Frankfurt, EU). No data is sent to external providers.
- Umami (audience measurement, self-hosted): collects anonymous visit statistics (page views, browser type, country). Umami uses no cookie and does not allow identifying an individual visitor or tracking them over time.
- Bugsink (error tracking, self-hosted): records application errors so we can fix them. An error report contains the URL where the error occurred, the browser type (User-Agent), the error message and the technical stack trace. When you are signed in, your internal identifier (a random code, with no email or name) is attached to help diagnosis. Reports are purged regularly.
9. Data security
We implement reasonable technical measures to protect your data:
- encryption of communications between your browser and the server via HTTPS (TLS);
- passwords stored as salted bcrypt hashes (never in clear text, never reversible);
- rate limiting to prevent brute-force attacks and abuse;
- application-level protection against CSRF and XSS attacks;
- restricted and logged server access.
No system can guarantee absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, you will be informed within the timeframe required by the GDPR.
10. Your rights
Under the GDPR, you have the following rights over your data:
- Right of access: obtain a copy of the data we hold about you.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request the deletion of your data.
- Right to portability: receive your data in a structured, machine- readable format. An export feature is directly available in your settings.
- Right to object to processing based on legitimate interest.
- Right to restrict processing.
- Right to issue directives regarding what happens to your data after your death.
11. How to exercise your rights
Several rights can be exercised directly from your account settings ("Account" tab):
- export all of your data in a structured JSON file (right to portability);
- reset the content of your space, i.e. erase your subjects, lessons and sessions without deleting your account;
- permanently delete your account and all associated data (right to erasure).
For the other rights (access, rectification of your email, password change, objection, restriction, post-mortem directives) or for any other request, write to bisouslebo@gmail.com. We will respond within one month at the latest, in accordance with the GDPR. We may ask you to verify your identity to prevent impersonation.
12. Lodging a complaint with the CNIL
If, after contacting us, you believe that your rights are not respected, you have the right to lodge a complaint with the French data protection authority (CNIL):
CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
Website: www.cnil.fr.
13. Minors
Access to HipHip is reserved for persons aged at least 15 years, in accordance with French data protection law. By using the service, you confirm that you have reached this age. If you are under 15, you must not use the service without the prior consent of your parents or legal guardians. If we become aware that an account belongs to a person under 15 without parental consent, it will be deleted.
14. Changes to this policy
This policy may evolve to reflect changes in the service or legal obligations. The date of the last update appears at the top of this page. In case of a substantial change, you will be informed by a notice visible in the application or by email.

