BACK TO HOME

Le Sentier Privacy Policy

Last updated: February 24, 2026

This Privacy Policy explains how L4Forge SAS processes personal data for Le Sentier (formerly La Forge).

1) Controller Identity

L4Forge SAS
222 rue de Bretigny
01210 Ornex
France
Privacy contact: admin@l4forge.com

Company references: SIREN 999235385, SIRET 999235385 00013, RCS Bourg-en-Bresse, EUID FR0101.999235385, VAT FR28999235385.

2) Scope

This policy applies to:

  • the Le Sentier iOS app;
  • our backend/API services used by the app;
  • our support and privacy pages.

It does not apply to third-party websites or services we link to.

3) Data We Collect

CategoryExamples
Account and authentication dataInternal account ID, username, passkey credential metadata (credential ID, public key, counter, device type/backed-up flag), authentication challenge records, refresh-token hashes.
Profile settingsLanguage, timezone, notification preference flags.
User contentChat messages/prompts, workshop content, bivouac step inputs, generated summaries/plans/Leo notes, profiles.
Voice input data (optional)Audio submitted by you for speech-to-text and returned transcription text.
Notification data (optional)Push token, device type and device name/model string, scheduled notification records, delivery/open status.
Technical, usage, and security dataTimestamps, request and error logs, model/provider operation metadata used for reliability and abuse prevention.
Support dataEmails and support/feedback messages you send us.

We do not collect passwords for Le Sentier logins.

We do not receive your Face ID/Touch ID biometric templates. Biometric matching is handled by your device platform.

4) How We Collect Data

  • Directly from you: account creation, app usage, messages, settings, support requests.
  • Automatically from app activity: technical logs, timestamps, delivery/open events.
  • From authentication and platform flows: passkey ceremonies and push token registration.
  • From processors acting on our behalf (hosting, AI, transcription, notifications, feedback forms).

5) Why We Use Data and Legal Bases (EU/EEA/UK)

PurposeLegal Basis
Create and secure accounts; authenticate users with passkeys.Performance of a contract.
Provide core app features (chat, workshops, bivouac, documents).Performance of a contract.
Send push reminders/notifications when enabled.Consent (which you can withdraw anytime).
Transcribe voice input when you use microphone features.Consent.
Prevent abuse, secure systems, detect fraud, and debug incidents.Legitimate interests.
Meet legal and regulatory obligations.Legal obligation.

Some data is required to provide Le Sentier (for example authentication and core content storage). If you do not provide required data, parts of the service may not function.

6) Sharing and Processors

We use service providers to run Le Sentier. We do not sell personal data to data brokers.

  • Supabase: database, authentication, and backend data storage.
  • Vercel: backend hosting and server infrastructure.
  • Google (Gemini / Vertex AI): AI generation for chat features.
  • Anthropic: AI generation for profile features.
  • Deepgram: speech-to-text transcription for optional voice input.
  • Expo Push Service (and Apple APNs): push notification delivery.
  • Tally: user feedback form submissions.

7) International Transfers

Your data may be processed in countries outside your own, including outside the EU/EEA/UK (for example by some service providers). Where required, we use contractual and organizational safeguards (including standard contractual safeguards) to protect transferred data.

8) Retention

Data TypeRetention
Account profile and core user contentKept until you delete your account.
Voice transcription requestsProcessed on request; no separate long-term audio archive by us.
Notification records and push-delivery/open logs1 month.
Server/application logs1 month.
Support requestsUp to 24 months.
BackupsRolling 30 days.
Username reservationsExpires after 5 minutes.
WebAuthn ceremony recordsShort-lived; removed shortly after expiry (cleanup buffer up to 1 hour).
Refresh token recordsRefresh tokens expire after 30 days; expired/revoked records are cleaned up with a short additional buffer (up to 7 days).

9) Deletion and Data Rights

In-app account deletion path: Profile -> Danger Zone -> Delete Account.

After deletion is confirmed, operational data is removed from active systems; residual backup copies are removed within normal backup rotation (up to 30 days).

If you are in the EU/EEA/UK, you may request: access, rectification, erasure, restriction, objection, and data portability.

  • Contact: admin@l4forge.com
  • We aim to respond within 30 days.
  • You may also lodge a complaint with your local supervisory authority (for France: CNIL).

10) Security

We use administrative, technical, and organizational safeguards, including encryption in transit, access controls, and least-privilege access. No method of storage or transmission is fully risk-free, but we work to protect your data.

11) Children

Le Sentier is not intended for children under 13.

12) AI and Automated Decisions

Le Sentier provides AI-generated guidance and planning support. It is not a medical or mental-health service and is not designed for emergencies. We do not use solely automated decision-making that produces legal or similarly significant effects about you.

13) Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the date at the top of this page and, when appropriate, through in-app notice.

14) Contact

Questions about this policy can be sent to admin@l4forge.com.