Privacy Policy
Last updated: 08/03/2026
Mental Loadless (hereinafter "the Application") is published by SmartAILabs. We place great importance on protecting your personal data. This privacy policy explains what data we collect, why, and how we use it.
1. Data Collected
We collect the following data:
• Identification data: email address, display name (via Azure Entra External ID)
• Family data: family members, dietary preferences, allergies, diets
• Usage data: shopping lists, calendar events, homework, household chores, food inventory
• Private space data: private tasks, notes, wellbeing tracking (accessible only by the user concerned)
• Technical data: device identifiers for push notifications, authentication tokens
• AI data: conversation history with the Coco assistant, memorized preferences
• Location data: device position, for local weather and to set a household place from where you are standing; declared household places (“zones”) and crossings (arrival, departure)
2. Purpose of Processing
Your data is used to:
• Provide the Application's features (family management, shopping, calendar, etc.)
• Personalize the AI assistant Coco's suggestions
• Send push notifications (reminders, alerts)
• Manage your Premium or Coco+ subscription
• Improve the Application and fix bugs
3. Legal Basis
Data processing is based on:
• Contract performance: providing the Application's service
• Consent: collected at first launch for AI processing and notifications
• Legitimate interest: service improvement, security
4. Subprocessors and Transfers
Your data is hosted and processed by:
• Microsoft Azure (Cosmos DB, Azure Functions) — France Central region (Europe)
• Azure OpenAI Service (GPT-5, GPT-5 mini, GPT-5 nano, GPT-5.4, o4-mini) — text and images — European Union (EU data zone) — retained ≤ 30 days for abuse monitoring, no model training
• Azure AI Speech (Whisper STT, TTS Neural) — West Europe, Sweden, France Central
• Azure Communication Services — Transactional email delivery — European Union
• Azure Entra External ID — Authentication
• RevenueCat — In-app subscription management
• PostHog and Google Firebase / Analytics — Usage measurement, on consent only
• Sentry — Technical error reports — Germany
• Open-Meteo (OpenMeteo GmbH) — Weather forecasts from your coordinates — Switzerland (European Commission adequacy decision of 15 January 2024) — technical logs that may contain geographical coordinates, deleted after 90 days
• Nominatim — OpenStreetMap Foundation — City name and place lookup — United Kingdom and the Netherlands, backups in the EU (adequacy decision renewed on 19 December 2025)
• Apple (iOS) / Google (Android) — System geocoding of an address you type — United States
• Microsoft Exchange Online / Microsoft Graph — Receiving emails forwarded to your household address — European Union
All AI data — text and images alike — is processed within the European Union, in compliance with GDPR: deployments are provisioned in the “EU data zone”, which guarantees the Union as the perimeter without pinning a single country.
Location follows two opposite regimes. Weather sends your device coordinates to Open-Meteo and then to Nominatim. Household places send none: the device evaluates entry and exit itself — including in the background, when the app is closed — and transmits only the place concerned, the direction and the time; the centre of a declared place is stored encrypted, under a key specific to your household. No map, no trip history, no continuous position.
5. Data Retention
Your data is retained as long as your account is active. If your account is deleted, all your data will be permanently removed from our servers within 30 days.
6. Your Rights
Under the GDPR, you have the following rights:
• Access: obtain a copy of your data
• Rectification: correct inaccurate data
• Deletion: delete your account and all your data (available in the Application)
• Portability: receive your data in a structured format
• Objection: object to certain processing
• Restriction: request restriction of processing
To exercise your rights, contact us at: contact@mentalloadless.com
7. Security
We implement appropriate technical and organizational measures:
• Encryption of data in transit (HTTPS/TLS) and at rest
• Secure authentication via OAuth2 PKCE (Azure Entra)
• API keys stored server-side only (never in the application)
• Rate limiting on APIs (20 requests/minute per user)
• Private space data partitioned by user
8. Contact
For any questions regarding this policy:
SmartAILabs
Email: contact@mentalloadless.com
You may also file a complaint with the CNIL (French Data Protection Authority) or your local data protection authority.
9. Children's and Minors' Data
The application allows adding minor children's profiles. Explicit parental consent is collected and recorded before each addition.
For more information about the collection and processing of minors' data, see our dedicated policy: mentalloadless.com/en/children-privacy