Privacy Policy
Last updated : 2026-04-19
CINNOVELIA (hereinafter "we"), publisher of the Lockal application and website, is committed to protecting your privacy. This policy explains what data is collected, why, and how to exercise your rights under the General Data Protection Regulation (GDPR).
1. Principle — Lockal is local-first
The Lockal application runs your AI models, documents and prompts locally on your machine. Your conversations, indexed files and user content are never transmitted to our servers.
2. Data processed on the website
a) Analytics — Plausible Analytics
We use Plausible Analytics, a privacy-friendly analytics tool. Plausible sets no cookies, uses no persistent identifier and collects no personally identifiable data. Data is aggregated and anonymous (pages visited, country, browser, traffic source). No consent is required (CNIL position). Plausible hosting: European Union.
b) Server logs
Our host OVHcloud keeps technical logs for security and diagnostic purposes (IP address, timestamp, requested URL, user-agent). Retention: 12 months. Legal basis: legitimate interest (service security).
3. Data processed in the Lockal application
a) Account and licensing
If you create an account or activate a paid module, we process: email, name (optional), license key, purchase and activation history. Legal basis: contract performance. Retention: lifetime of the account + TODO years for accounting obligations.
b) Payment
Payments are processed by TODO (e.g. Stripe, Paddle, LemonSqueezy). We never store your card data. See the provider's policy for details.
c) Customer support
When you contact us (email, form), we process the information you provide to respond. Retention: TODO.
d) Usage telemetry (opt-in)
The Lockal application may send usage statistics via
PostHog (pseudonymized
events: app launch, modules used, OS type, version, technical errors).
PostHog associates your events with a random pseudonymous identifier
(distinct_id) generated locally and stored on your machine. No
name, email or user content is associated with this identifier.
Data is hosted in PostHog's European Union region (Frankfurt, Germany).
This telemetry is disabled by default and is only enabled with your explicit consent, given at first launch or from the application preferences. You can disable it at any time, which deletes the local identifier and stops any sending. Legal basis: consent (GDPR art. 6-1-a).
The content of your activity (prompts, conversations, documents, model outputs) is never transmitted, even with telemetry enabled. Only license verification for paid modules communicates with our servers, with the strict minimum required.
4. Data recipients
Your data is only accessible by CINNOVELIA and our technical subprocessors:
- OVH SAS (France) — hosting of the website and license servers (datacenters located in France).
- Scaleway SAS (France) — transactional email delivery via the Scaleway TEM service (sending servers located in the European Union).
- PostHog Inc. (United States) — opt-in application usage telemetry, data stored in PostHog's EU region (Frankfurt, Germany).
- TODO payment provider (e.g. Stripe, Paddle, LemonSqueezy) — payment processing.
No data is sold to third parties for commercial purposes.
5. Transfers outside the European Union
Our primary servers are in France (OVHcloud) and transactional emails are sent from the European Union (Scaleway TEM). For these two subprocessors, your data does not leave the EU.
PostHog Inc. is a US company (Delaware, United States). Although data is stored in PostHog's EU region (Frankfurt), a transfer within the meaning of the GDPR exists due to potential access by the US parent company. This transfer is governed by the European Commission's Standard Contractual Clauses (decision 2021/914) and the Data Privacy Framework, under the DPA signed with PostHog.
The payment provider may also be located outside the EU: TODO specify (e.g. Stripe — United States, with Standard Contractual Clauses).
6. Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, port and object to the processing of your data, and to decide on the fate of your data after death. To exercise these rights: dpo@lockal.ai. You may also lodge a complaint with the French CNIL (cnil.fr).
7. Cookies and analytics
The website sets no tracking cookies and does not use persistent identifiers to follow visitors. Only strictly necessary cookies may be set for website operation (language preference, etc.) — no consent required.
Anonymous analytics are collected via Plausible Analytics (see §2-a): pages visited, country, browser, traffic source, screen resolution. This data is aggregated, contains no personal identifier and does not rely on cookies. In line with the French CNIL's position, this is exempt from consent.
8. Changes
We may update this policy. The "last updated" date is shown at the top of this page. Substantial changes will be flagged on the website.
9. Contact
Questions about your data: dpo@lockal.ai.