Céoù

Privacy Policy

Last updated: 17 September 2026

On this page

Who is responsible for your data

Céoù is independently developed and published by Antony Monreal, the controller responsible for the processing described here. For questions or requests about your data: contact@ceou.eu. This policy covers the Céoù app and its presentation website, ceou.eu.

Your account and inventory

To use your own inventory, you provide an email address, a password and a display name. A profile photo is optional: a Céoù image is provided by default. Supabase authentication manages your password; the developer does not view it in plain text.

We store what you add: places, rooms, plans, storage spots, containers, items, photos, descriptions, barcodes, receipts and warranty information, as well as item moves, loans, home moves and boxes. You choose the content you enter. The information needed for your account and inventory is processed to provide the service you request.

The sharing you choose

Friends, invitations and access permissions let you share selected places with other people. Your display name and avatar may be visible to people you interact with. Shared content is accessible according to the permissions granted. Sharing a home move is a separate option.

You can change or revoke access in the app. Revoking access cannot remove a copy or screenshot someone has already kept. When you record a loan, any contact name or details you enter also become part of your records.

Hosting and data on your device

Céoù accounts, inventory and usage records are hosted with Supabase in the project’s configured European region (Stockholm). Connections use HTTPS and access permissions limit the data each account can access. This does not mean all the providers listed below process their data within the European Union.

Some data and your preferences are cached on your device to speed up the app and let you browse previously synced inventory without a connection. This cache is not used for advertising tracking.

Why we use this data

Accounts, inventory, requested sharing, allowances and purchase management are processed to provide the service. Troubleshooting, abuse prevention and cost monitoring serve our legitimate interest in keeping the service reliable and secure. Processing that requires your agreement, including AI and advertising choices where required, relies on your consent. Any data required by law is processed to meet those obligations.

You can organise and search manually without enabling AI or requesting an ad. Declining a device permission only prevents the feature that needs it, such as taking a photo or using the microphone.

AI photo analysis

When you request an analysis, the selected photo is sent to Google’s Gemini API to suggest the items it contains or read a handwritten storage spot, box or container code. A separate agreement is requested before first use. You can correct the suggestions before adding them to your inventory. To read a code with the camera, an image is captured automatically after a short framing delay and sent to Gemini if no Céoù QR code is detected. Up to three spaced attempts are possible if reading fails. Reading stops when a code is recognised, when you close the camera or when the app goes into the background. The code fills the search field, where you choose whether to open the matching box or container. Code images are not added to your inventory; temporary files created for reading are deleted from the device after processing. You can also type the code or read its QR without AI. Internet access is required.

Céoù does not keep a copy of the photo in its analysis counter. A photo you deliberately save to an item remains in your inventory. Google applies its API data processing and security terms, which can include technical retention to prevent abuse. Photos should therefore not be assumed to be immediately erased by every provider.

The voice assistant

Conversation uses Gemini Live: microphone audio is streamed to Google, which generates spoken replies. Information needed for your requested searches and actions, such as an item’s name, storage location or a loan, may be sent during the conversation. The assistant asks for your agreement before first use. Recording stops when you close the conversation or the app goes into the background.

If the simple assistant is used, the phone’s speech recognition converts your speech to text. Depending on the device and its settings, Apple or Google may process this audio on their servers. Gemini then interprets the text command.

Céoù stores session durations for allowances and cost monitoring, without archiving audio recordings or transcripts in these counters. Google applies its API terms, including security and abuse prevention measures.

Barcodes

Product lookup sends the scanned code to UPCItemDB to find a name and image. The network request also communicates technical data, including your IP address. Displaying a product image may contact the website hosting it. Your complete inventory is not sent for this lookup.

Notifications and technical errors

If you allow notifications, a delivery identifier provided by Expo is linked to your account. It is used for reminders and useful events such as friend requests or loans. Delivery may involve Expo, Google and Apple depending on your phone. Permissions are managed in your device settings.

When an error occurs, Céoù may record a technical message, error trace and diagnostic context linked to the account. These logs help investigate and fix problems. They are not a continuous recording of your screen or conversations.

Subscriptions and usage counters

When purchases are available, RevenueCat and Google Play present, verify and restore Céoù Plus. RevenueCat receives your technical account identifier, purchase status and technical information about the app and device. Céoù does not receive your bank details. Test offers are labelled in the app.

Photo analysis counts, AI token usage, conversation durations and bonus credits are linked to your account in Supabase, along with dates and verification records. They support cost monitoring, allowances and duplicate prevention. Resetting a monthly allowance does not erase the corresponding technical history.

Optional advertising

Google AdMob rewarded ads start when you request a bonus and the feature is available. Choosing to watch an ad is separate from consenting to personalised advertising. Google’s form presents the choices required for your region; revisit them under Profile → Plan and AI extras → My advertising choices when that option is available.

The advertising service processes IP addresses (which can indicate approximate location), device or advertising identifiers depending on permissions, ad interactions and diagnostic data. These support ad delivery, measurement and fraud prevention. Google and the partners identified in the form may receive them. Non-personalised ads do not necessarily mean no data is collected.

To verify a reward, Google receives the technical account identifier and a unique request identifier. Céoù stores the verification result and awarded bonus. Céoù does not send your inventory, photos or conversation content to advertising services. Demo ads also use Google’s technical services.

The website and getting in touch

The presentation website contains no ads, audience analytics or marketing trackers. Its pages load no third-party fonts or scripts. The host still receives technical information needed to serve pages, such as IP addresses and request dates, and may keep security logs.

The survey links to Google Forms: opening it contacts Google under its own privacy rules. If you provide an email to take part in testing, it is used to contact you about that. You can ask not to be contacted again. Email exchanges are used to respond to your requests.

Processing outside the European Union

Google services (Gemini, AdMob, Google Play and Forms), RevenueCat, Expo and UPCItemDB may process data outside the European Union. Their terms describe processing locations and applicable safeguards, including standard contractual clauses or adequacy decisions where applicable. Provider policies and terms are linked on the web version of this page. For details about a transfer or its safeguards: contact@ceou.eu.

Retention and deletion

Account information and inventory content are kept while the account exists or until you delete them. Account-linked technical histories, including AI counters, reward checks and error logs, may remain until account deletion. Support correspondence is retained while handling the request and its follow-up.

Deleting your Céoù account does not automatically delete data held separately by Google Play, RevenueCat or other providers. Transaction records and data needed for their legal obligations or fraud prevention may be retained under their rules. Contact us about Céoù-related data requests involving these providers. Technical backups can retain copies until they are replaced.

Your rights and choices

You can request access, correction, deletion, restriction and, where applicable, portability of your data, and object to processing based on legitimate interests. You can withdraw consent for future processing without affecting processing already carried out lawfully. For AI, stop using it and contact us to withdraw your recorded agreement; advertising choices and device permissions have their own settings.

To exercise a right or request an export, email contact@ceou.eu, preferably from your account’s email address. We normally respond within one month; if an extension is needed in cases allowed by the GDPR, we will let you know. Identity verification may be needed if there is doubt. You can also complain to the CNIL at cnil.fr or your local data protection authority.

To delete your account in the app: Profile → My account → Delete my account. Without the app, email us with “Account deletion” as the subject. If you have a subscription, cancel it separately in Google Play: deleting Céoù or your account does not cancel it.

Deleting your account and your data

In Céoù: Profile → My account → Delete my account. Your password is requested to confirm. After successful deletion, account access is removed and the action is permanent.

Without the app: email contact@ceou.eu from your account’s email address with “Account deletion” as the subject. Requests are normally handled within one month, after any necessary checks.

Deletion removes the profile, owned places and their inventory, plans, photos stored under the account, associated loans, moves and boxes, sharing, invitations, counters and linked logs. Places owned by others remain theirs; you lose access. Records they entered themselves, such as a loan, may remain in their own inventory.

Backup copies disappear as they are rotated. Payment and advertising providers apply their own retention obligations; contact us if your request also concerns Céoù-related data held by them.

A Google Play subscription must be cancelled separately in Google Play. Deleting the account or uninstalling the app does not stop renewal.

Our providers’ privacy information

Contact

For any question about your data, or to exercise a right of access, correction or export: contact@ceou.eu

Back to home