Privacy Policy
Last updated: July 2026
1. Identity of the data controller
The data controller for personal data collected through the spira application and the spiraapp.com website is:
spira technologies — Société par Actions Simplifiée (SAS) with a capital of €1,000
Registered office: 5 rue Carle Vernet, 92310 Sèvres
RCS Nanterre (registration in progress)
Represented by Pierre Arvy, President
Contact: no-reply@spiraapp.com
2. Data collected and purposes
We collect the following data for the specified purposes:
Account data: email address, first name, date of birth, gender — necessary for account creation and service personalization.
Morphological data: height, weight, fitness goals — necessary for generating adapted programs.
Health data (with explicit consent): information related to menstrual cycle, injuries, physical conditions shared with the spira AI Coach — used solely to personalize training recommendations.
Activity data: training history, performance, progress, completed sessions — necessary for tracking your progress and adapting the program.
Conversations with AI Coach: messages exchanged with the integrated AI assistant — used to personalize responses and improve the service.
Technical data: device type, operating system, application version, anonymous technical identifiers — used for technical support and service stability purposes.
Navigation data: anonymous audience measurement via Plausible Analytics (no cookies, no identifiable personal data).
3. Legal basis for processing
Each processing is based on a legal basis under the GDPR:
Contract performance: account creation, service provision, subscription management, customer support.
Consent: processing of health data (menstrual cycle, injuries), sending push notifications, Plausible audience measurement. You can withdraw your consent at any time from the application settings.
Legitimate interest: service improvement, security, abuse prevention, aggregated and anonymous usage analysis.
4. Data retention period
Your data is retained for the duration of your account's existence, then deleted within 30 days following the deletion request or account closure.
By exception, certain data may be retained beyond this period to comply with legal obligations:
– Billing and payment data: 10 years (French Commercial Code)
– Data necessary for dispute management: until the expiration of applicable statute of limitations (generally 5 years).
5. Subprocessors and transfers outside the EU
We use the following subprocessors, selected for their GDPR compliance:
Google Firebase (Google LLC, USA) — authentication, database, storage. Data hosted in the European Union (eur3 region). Safeguards: Standard Contractual Clauses (SCC).
RevenueCat (RevenueCat Inc., USA) — in-app subscription management. Safeguards: SCC.
Stripe (Stripe Inc., USA) — payment processing. PCI-DSS certified. Safeguards: SCC.
Brevo (Sendinblue SAS, France) — sending transactional and service emails. Data hosted in France/EU.
Plausible Analytics (Plausible Insights OÜ, Estonia) — anonymous navigation statistics, no cookies, no identifiable personal data. Data hosted in the EU.
None of this data is sold to third parties for advertising purposes.
6. Your rights
Under the GDPR (Articles 15 to 22), you have the following rights regarding your data:
Right of access: obtain a copy of the data concerning you.
Right to rectification: correct inaccurate or incomplete data.
Right to erasure: request the deletion of your data ("right to be forgotten").
Right to restriction: suspend the processing of your data in certain cases.
Right to data portability: receive your data in a structured, machine-readable format.
Right to object: object to processing based on legitimate interest.
Right to withdraw consent: withdraw your consent at any time without affecting the lawfulness of previous processing.
To exercise these rights: from your account Settings in the application, or by email at no-reply@spiraapp.com.
In case of unresolved complaint, you may contact the CNIL: www.cnil.fr.
7. Cookies and trackers
The spiraapp.com website uses no tracking or advertising cookies.
Audience measurement is performed via Plausible Analytics, an open-source tool that does not place any cookies, does not collect any identifiable personal data, and does not perform cross-site tracking. No cookie consent banner is required for this measurement.
The spira mobile application does not use cookies. Technical identifiers (Firebase Auth UID) are stored locally on the device and are never shared with third parties for advertising purposes.
8. Security
We implement appropriate technical and organizational measures to protect your data:
– Data encryption in transit (HTTPS/TLS 1.2+)
– Data encryption at rest (Firebase Storage, Firestore)
– Secure authentication via Firebase Authentication
– Access to production data restricted to team members on a need-to-know basis
– Regular security reviews
In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours in accordance with Article 33 of the GDPR, and we will notify you directly if the risk is high.
9. Contact
For any questions regarding this privacy policy or the exercise of your rights, please contact us:
Email: no-reply@spiraapp.com
Via the application: Settings → Help → Contact us
This policy may be updated. The last update date is shown at the top of the page. In case of substantial modification, we will inform you by email or via a notification in the application.