← Back to Connect
Peaufine Connect

Privacy Policy

Last updated: June 22, 2026

Peaufine Connect is a tool that trust-based brands use to find the right people and correspond with them. This policy explains what data we handle, who is responsible for it, and the rights people have. The short version: your relationships and your contacts belong to you, we do not sell data, and we do not run surveillance.

1. Who we are

Peaufine Connect is operated by Peaufine By MC ("Peaufine", "we", "us"), based in France, at peaufinebymc.com. For any privacy question you can reach us at support@peaufinebymc.com.

2. Two roles: controller and processor

Connect involves two different kinds of data, with two different responsibilities.

  • Your account data (you are the data subject, we are the controller). When you sign up and use Connect, we control the data needed to run your account.
  • Your contacts' data (you are the controller, we are the processor). The prospects and people you reach through Connect are your contacts. You decide who they are and why you contact them; we process that data on your behalf and under your instructions. You are responsible for having a lawful basis to contact them. Connect provides the mechanism and the proof; you own legal responsibility in your jurisdiction.

3. What we collect

From you, the brand:

  • Account information: your email, name, and authentication details.
  • Your brand context document and settings, which Connect reads to do its work.
  • Gmail connection metadata when you connect an account to send letters (we request the minimum scope needed and never read your unrelated mail).
  • Subscription and billing information, processed by Stripe; we do not store full card details.
  • Usage and log data: how you use Connect, plus standard security logs (IP, timestamps).

On your behalf, about your contacts:

  • Names, publicly listed professional contact details, public bios, and the public source where they were found.
  • Relationship state and letter metadata (status, depth, summaries), and the lawful-basis and consent records you create in the Trust ledger.
  • We use only publicly listed information. We do not scrape private accounts, we do not buy behavioral data, and we never use pixel or open tracking.

4. How we use data

  • To run the service: find relevant people, draft letters, send them on your behalf, track relationships, and maintain your records.
  • To keep your consent and suppression records and produce your exportable proof of compliance.
  • For security, fraud prevention, and to enforce our Acceptable Use Policy.
  • We do not sell personal data, we do not serve ads, and we do not use your data to train third-party models beyond generating your own letters.

5. AI-assisted letters

Letters generated in Connect are AI-assisted, produced with a large language model (currently OpenAI's gpt-4o-mini) and then reviewed and approved by you before anything is sent. We disclose this in line with the transparency obligations of the EU AI Act. You are the author and the sender; Connect is the assistant.

6. Sub-processors

We rely on a small set of providers to deliver Connect. Each processes data only as needed:

  • Supabase: database and authentication.
  • Vercel: hosting and delivery.
  • OpenAI: AI generation of letters.
  • Google (Gmail API): sending letters and transactional notifications, only when you connect an account.
  • Stripe: billing.

Some providers process data in the United States or other countries. Where required, transfers rely on Standard Contractual Clauses approved by the European Commission. You can request details at support@peaufinebymc.com.

7. Retention and the two-layer consent design

We keep account data while your account is active and for a reasonable period afterward. Consent records are kept as long as needed to prove lawful basis. Opt-outs are different on purpose: to honor someone's opt-out forever, we keep a permanent but minimal suppression record that stores only a one-way hash of the contact address plus the opt-out time, never the address itself. This lets us respect "never contact me again" permanently while still minimizing the personal data we retain.

8. Your rights

If you are in the EU or EEA, you have rights under the GDPR: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. People in the UK and other regions have comparable rights under their own laws. For your own account data, contact us at support@peaufinebymc.com. For a contact's data that a brand processes through Connect, the brand is the controller and the request is handled with them; we assist as processor. You may also lodge a complaint with your supervisory authority, such as the CNIL in France or the ICO in the UK.

9. Security

Every brand's data is isolated at the database with row-level security, so no brand can read another's. Data is encrypted in transit, access follows least privilege, and our sensitive functions are locked down. No system is perfectly secure, but we take this seriously and design for it.

10. Children

Connect is a tool for businesses and is not directed at children. It is not intended for anyone under 18, and you must not use it to contact minors.

11. Changes

We may update this policy as Connect evolves or the law changes. We will revise the date above and, for material changes, give you notice.

12. Contact

For any privacy question or to exercise a right, email support@peaufinebymc.com.

PeaufineConnect

Relational intelligence for trust-based brands. Letters, not broadcast. Your data stays yours.

Connect
HomeThe DrawPresenceTrust
Legal
Privacy PolicyTerms of ServiceAcceptable UseCookie Policy
Contact
support@peaufinebymc.com
© 2026 Peaufine By MC. All rights reserved.Letters sent through Connect are AI-assisted.