Legal
Privacy Policy
Last updated : August 24, 2026
Who we are
mysaas.blog is operated by Cédric Tournier, a French sole trader (entrepreneur individuel) operating under the trade name Avalonia, registered under number 533 501 839 R.C.S. Paris, with its principal establishment at 50 rue Saint-André des Arts, 75006 Paris, France.
Cédric Tournier, operating under the trade name Avalonia, acts as the data controller under Regulation (EU) 2016/679 (GDPR) for all personal data collected through the mysaas.blog platform.
Data we collect
We collect the following data depending on how you use the platform.
Account and authentication
Email address (required), display name (optional), avatar (optional), magic link login token (temporary, expires after 15 minutes), a password credential for dedicated reviewer accounts generated by an administrator, reviewer label, assignment, expiration and revocation metadata, and session data (IP address, browser user-agent). Passwords are stored only as one-way hashes.
Public profile
Username, biography, personal website URL, links to your Twitter/X, GitHub, and LinkedIn profiles, and booking link (Calendly/Cal.com).
Published content
Posts (build logs): title, content, excerpt, tags, publication date. Comments published on posts. First-party analytics events on founder/post pages and outbound links (views, clicks, estimated engaged time, acquisition source, technical visit data).
Payment and access entitlement
Stripe customer identifier, Checkout Session and payment identifiers, amount, currency, payment status, evidence of consent to immediate access, pass start and expiration dates, and any revocation date. We do not store your complete card number.
Qualified reads and creator earnings
To allocate a pass’s net amount, we record the signed-in reader, pass, article, and creator identifiers, together with visible active time and maximum reading depth. The same article/pass combination counts only once. We also retain allocation calculations, their status, and payout or reversal references.
Creator payout account
Stripe directly collects the identity, business, and bank-account information required for its verification. mysaas.blog retains the connected Stripe account identifier, transfer and payout capability status, the number of outstanding requirements, and transfer references. We do not store your complete bank details.
Third-party authentication data
If you choose to sign in with Google or GitHub, we receive your identifier, email address, and name from those services. No other access to your accounts is requested.
AI assistants and MCP
When you connect an MCP host (for example ChatGPT), we process tool-call content and results, files or image URLs supplied for import, granted OAuth scopes, and technical metadata required for security. Keys and tokens are never requested in conversation text.
Legal basis and purposes
Performance of a contract (Art. 6(1)(b) GDPR)
Managing your account, magic link authentication, publishing your posts and comments, displaying your public profile, processing purchases, delivering the expertise pass, calculating creator earnings, and executing payouts.
Legitimate interest (Art. 6(1)(f) GDPR)
First-party audience measurement (views/clicks, estimated engaged time, source attribution, technical dimensions), security and fraud prevention, and platform improvement.
Sharing with third parties
We do not sell or rent your data. We rely on technical processors to operate the platform.
Stripe
Payment and creator payout provider
Email address, customer/payment or connected-account identifiers, amount, currency, payment or payout status, identity and bank information required by Stripe, and technical fraud-prevention data. Card and bank-account details are entered and processed directly by Stripe.
UseSend
Transactional email provider
Email address — only for sending your login magic link.
Cloudflare R2
File storage
Uploaded files (avatars, images used in posts).
Google (OAuth)
Optional authentication
Google email address and user identifier if you choose this sign-in method.
GitHub (OAuth)
Optional authentication
GitHub email address and user identifier if you choose this sign-in method.
OpenAI / ChatGPT (MCP)
Connected assistant host
Request data, editorial content, tool results and OAuth metadata when you connect ChatGPT or another MCP host. The host also applies its own privacy policy.
OpenRouter (AI translation)
Translation generation provider
Source text, title, excerpt and HTML are sent only when you request an AI translation. OpenRouter may route the request to the configured model; consult its terms for downstream processing.
Your data may also be disclosed where required by law or to protect our legal rights.
Retention period
Your data is kept for as long as your account remains active. When you delete your account, your profile, posts, comments, and sessions are deleted, except for transaction, allocation, anti-fraud, and payout records that we must retain to meet legal obligations or defend our rights.
Magic link tokens automatically expire after 15 minutes and are invalidated after use. OAuth grants remain active until revoked, expired, or the account is deleted. OAuth security logs and idempotency keys are retained only as long as needed for security, support, and retry deduplication (idempotency keys expire after seven days). Transaction data and related evidence are retained for the accounting, tax, and evidentiary periods required by applicable law, including after account deletion where legally required.
Your GDPR rights
Under the GDPR, you have the following rights regarding your personal data.
To exercise these rights, contact us at legal@mysaas.blog. You also have the right to lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
Security
We implement appropriate technical measures to protect your data: encrypted communications (HTTPS), single-use authentication tokens with limited lifetime, reviewer passwords stored only as one-way hashes, revocable sessions and OAuth grants, and restricted database access. Authentication is handled through magic links, OAuth, or a password for a dedicated reviewer account.
Changes
We may update this policy at any time. The date of the latest update appears at the top of this page. If we make a material change, we will notify you by email. Continued use of the platform after notice constitutes acceptance of the updated policy.
Contact
For any question about this policy or to exercise your rights:
Avalonia — Cédric Tournier, entrepreneur individuel
533 501 839 R.C.S. Paris · 50 rue Saint-André des Arts
75006 Paris, France
legal@mysaas.blog