Privacy policy
Last updated: 24 September 2026
This policy explains how INNOFI SASU (“we”, “Branch Pilot”) processes personal data when you visit branchpilot.ai or use the Branch Pilot application and API. It applies in addition to the terms of service and the list of sub-processors.
1. Who is responsible
For the data of visitors and account holders (your email, your account, your usage), INNOFI is the data controller.
For the data contained in the payloads your workflows send to a decision endpoint, you are the controller and INNOFI is your processor: we process that data only to return a decision, according to your instructions and our data processing agreement, available on request.
2. What we process, and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, name, language, time zone | Create and secure your account, send sign-in links and service emails | Performance of the contract |
| Billing identity, VAT number, invoices (through Stripe; we never store card numbers) | Invoice and collect payment | Performance of the contract, legal obligations |
| Decisions, versions, API keys (hashed), test cases | Provide the service | Performance of the contract |
| Runs: pseudonymized input, output, probabilities, engine, latency, cost, your feedback | Show your history, compute usage and statistics, improve your decisions | Performance of the contract, legitimate interest (service quality) |
| Usage counters | Enforce plan quotas | Performance of the contract |
| Aggregated website analytics (Plausible, cookie-less) | Understand which pages are useful | Legitimate interest (no personal data is collected) |
| Emails you send us | Answer you | Legitimate interest |
We do not sell personal data and we do not use your data to train models.
3. Pseudonymization before inference
Before any call to a decision engine, Branch Pilot replaces personal data in the payload with neutral tokens (<EMAIL_1>, <PHONE_1>, …): the fields you declare as personal data, plus emails, phone numbers, IBANs, national identifiers, URLs and dates detected in free text. The correspondence between tokens and real values exists only in memory, for the duration of the request, and is never written anywhere. The engines receive and the history keeps the pseudonymized payload only.
This is a strong safeguard, not a guarantee: a piece of identifying information that our detection does not recognize in free text (for example “my neighbour at 12 rue X”) will be sent as is. Declaring your sensitive fields and using the strict mode reduce this risk.
4. Transfers outside the European Union
Your account data and history are stored in the European Union (Supabase on Amazon Web Services, Paris region).
Pseudonymized payloads are sent to TypeSafe AI in the United States for inference, under a data processing agreement and the European Commission’s standard contractual clauses, with the pseudonymization above as an additional safeguard. When the fallback engine is used, pseudonymized payloads are processed by Mistral AI in the European Union.
The website and application interface are delivered by Netlify’s global network; payments are handled by Stripe. See the sub-processors for the full list and locations.
5. Retention
- Account data: for the life of the account, then deleted within 30 days of a deletion request.
- Runs: 7 days on the Free plan, 30 days on paid plans, then automatically purged.
- API keys: until revoked; revoked keys are kept as a trace without the key itself.
- Invoices and accounting records: 10 years, as required by French law.
- Emails: 3 years after the last exchange.
6. Your rights
You can access, rectify, erase or export your data, object to or restrict certain processing, and define instructions for your data after death. Most of it is available directly in the application (Settings). For the rest, write to hello@branchpilot.ai; we answer within one month. You may also lodge a complaint with the CNIL (cnil.fr).
7. Security
API keys are stored as SHA-256 hashes and shown once. Access to your data is restricted to your account by row-level security. Data is encrypted in transit and at rest. Engine calls are made from server functions with credentials that never reach the browser.
8. Cookies
The website uses no advertising or third-party cookies. The application stores your session, language and theme in your browser to keep you signed in and to remember your preferences. Analytics use Plausible, which sets no cookie and collects no personal data.
9. Changes
We will announce material changes to this policy by email to account owners at least 30 days before they take effect.
Contact: INNOFI SASU, [street address], 07210 Chomérac, France — hello@branchpilot.ai.