Version 2.2 — published and effective 20 September 2026
This privacy policy (hereinafter the 'Policy') describes how DAPFOR SAS (hereinafter 'the Provider', 'we', 'us', or 'our') collects, uses, stores, and protects the personal data of users of the Zestly service (hereinafter 'the Service'), accessible via the website https://zestly.org (https://zestly.org) and mobile applications.
This Policy is drafted in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679), the French 'Data Protection Act', and the California Consumer Privacy Act (CCPA) where applicable.
The data controller is DAPFOR SAS, 26 rue Hector Berlioz, 92500 Rueil-Malmaison, France. For any questions regarding your data, contact us at: info@zestly.org
• Account data: name, email address, password (encrypted)
• Profile data: preferences, settings
• Educational content: documents and images you upload
• Generated content: tests, quizzes, exams, summaries, and results
• Communications: support requests and correspondence
• Voice data: audio recordings transmitted via the voice input feature for transcription (processed in real time, not durably stored by Zestly)
• Learning session data: flashcard session history, submitted answers, scores, and progress
• Referral/affiliate program data: for users who apply to or participate in the referral/affiliate program — contact details, distribution channel, payout method (PayPal email, bank details)
• Written work: photographs or scans of the handwritten answer pages you submit (or that the material owner submits for a member of their group), their transcription, and the generated comments and report — see section 2.4
• Public candidate data: when you use content shared through a public link without an account, your answers and results are attached to a technical identifier of your device, not to an account
• Device data: device type, operating system, browser type, unique device identifiers, push notification token (APNs or FCM) if you enable notifications
• Usage data: features used, time spent, actions taken
• Connection data: IP address, access times, pages viewed
• Location data: approximate location based on IP address (country/region level only)
• Usage counters: number of items created per content type, allowance units remaining, date of the last grant and cumulative volume used; connection counters (device, platform, first and last use, number of active days and hours)
• Marketing attribution data: a technical identifier kept in the local storage of your browser (a device identifier and, where applicable, the referral code recorded on your first visit); a record of each arrival through a referral link or through the public page of a material: device identifier, IP address, date and time, type of source
• Authentication providers: if you sign in via Google or Apple, we receive your name and email
• Payment providers: Stripe, Apple, or Google provide transaction confirmation (we do not receive or store your payment card details)
When you use the "written work" format, you photograph or scan the answer pages you filled in by hand and submit them to the Service. These images are personal data: they contain your handwriting, your answers and, where applicable, anything else you wrote on them.
• Processing: each page is transmitted to our artificial intelligence provider (section 5.1), which transcribes the handwritten text and assesses the answers against the material's answer key; a second processing step produces an overall report. The images are used for no other purpose.
• No identification by handwriting: handwritten text is processed only to recognise its content. It is not used to identify or authenticate a person, is not subjected to any biometric processing and does not feed any handwriting-recognition model.
• Data subject: the person who wrote the answers. Where this is a child who is a member of a family or class group, the parent, guardian or teacher who owns the material is responsible for submitting the pages and for the corresponding consent (section 9).
• Access: a submitted work is visible only to its author, to the material owner and to the co-managers of the group concerned. The page images are hosted on our servers at unpredictable technical addresses that are never published or indexable and are communicated only to authorised accounts; anyone holding such an address can nevertheless open the file (section 5.2). The public link of a written work only gives access to the blank answer sheet and to the submission form.
• Retention: the images and results are kept as long as the material and the author's account exist, then deleted with them (section 7).
We process your data to:
• Provide, maintain, and improve the Service
• Create and manage your account
• Process subscriptions and payments
• Generate personalized educational content
• Enable sharing of tests and exams with other users
• Send service-related communications
• Respond to support requests
• Ensure security and prevent fraud
• Comply with legal obligations
• Analyze usage and improve user experience (using anonymized/aggregated data)
• Send push notifications to your devices (only with your explicit consent)
• Optimize your flashcard learning experience (adaptive review of unmastered cards)
• Enable group owners to track the progress of their members
• Transcribe and assess submitted written work and produce its report
• Automatically detect manifestly unlawful content among uploaded images and entered topics (moderation)
• Provide the example library and measure its use
• Inform you of changes to the Service and to the contractual documents (in-app announcements and push notifications)
We process your data based on:
• Contract performance: to provide the Service you requested
• Legal obligations: to comply with applicable laws
• Legitimate interests: to improve and secure the Service, prevent fraud
• Consent: for optional communications or where specifically required
• The consent of the holder of parental responsibility: for the processing of a child's data within a family or class group, including handwritten written work (section 9)
• Legitimate interests, as regards automatic content moderation, in order to protect users and minors and to meet our obligations towards the app stores
We share data with trusted service providers:
• Hosting: Scaleway SAS (France/EU) — servers and data storage
• Artificial intelligence: providers of generative models (text, vision, speech recognition and synthesis) established in the United States, under EU standard contractual clauses — analysis of your documents and generation of quizzes, exams, summaries and flashcards; exam conversation and assessment; transcription and assessment of handwritten pages; transcription of your voice recordings and read-aloud of content. Audio recordings are transmitted in real time and are not retained beyond immediate processing. For the profiles of children who are members of a family Group, we use only providers whose terms exclude the use of content to train their models and limit its retention to 30 days for abuse-monitoring purposes, except where the law or safety requires longer. The named list of current sub-processors is provided on request (section 8.3)
• Automatic content moderation: an automatic-classification provider established in the United States — analysis of uploaded images (before they are stored) and of entered topics to detect manifestly unlawful content; only the classification result is kept
• Email delivery: Resend (or self-hosted SMTP) — transactional emails (login codes, invitations, notifications)
• Payments: Stripe, Inc. — web payment processing
• App Distribution: Apple Inc., Google LLC — app store services
• Authentication: Google, Apple — if you use social sign-in
• Push notifications: Apple Inc. (APNs) and Google LLC (Firebase Cloud Messaging / FCM) — push notification delivery; your device identification token is transmitted to them for this purpose
• Analytics: usage and marketing-channel attribution data (referrer, campaign/UTM parameters, pages viewed) — used to understand which channels bring visitors; may be linked to your account if you are logged in
When you share tests, exams, or flashcards:
• Recipients can view the content and their results
• You control who receives shared content
• Public links make content accessible to anyone with the link
Within collaborative groups:
• The group owner and co-managers can view the results, scores, and progress of all group members
• Group members can only see their own results
• When sending an invitation, the recipient's email address is used to create or retrieve an account
For written work:
• The material owner and the group co-managers can see the works submitted by group members, including the page images, the transcription and the comments
• A work submitted through a public link is visible to its author and to the material owner
• No written work is ever published, listed or indexable; the page images are served at unpredictable technical addresses — anyone holding such an address can open the file, but these addresses are neither published nor indexable and are communicated only to authorised accounts (section 2.4)
For the example library: catalogue materials are public; your use of a material (results, sessions) remains attached to your account or, without an account, to the technical identifier of your device, and is visible only to you.
We may disclose data if required by law, court order, or to protect our rights, safety, or property.
In case of merger, acquisition, or sale of assets, user data may be transferred to the successor entity.
We never sell your personal data to third parties.
When you take out a subscription after arriving through the link or through a material of a partner in the affiliate programme, that partner sees in their dashboard your first name followed by the initial of your surname, your profile picture where your account has one, the start date of your subscription and the amount of their commission. Your email address, your full name and your payment details are never disclosed to them.
The partner also sees aggregate counters of the number of distinct devices that opened their links and their materials, broken down by origin and over the last thirty days; those counters do not allow you to be identified individually.
The legal basis for this disclosure is the partner's legitimate interest and ours in measuring and remunerating the subscribers they bring. You may object by writing to us (section 8.3).
Your data is primarily stored in the European Union. When data is transferred outside the EU (e.g., to US-based service providers), we ensure appropriate safeguards:
• EU Standard Contractual Clauses
• Adequacy decisions by the European Commission
• Binding Corporate Rules where applicable
| Data Type | Retention Period | |-----------------------------------|---------------------------------------------------------| | Account data | Duration of account + 30 days after deletion | | Educational content | Until deleted by the user or with the account; made inaccessible immediately, then erased at the next purge of disabled data | | Generated content | Until deleted by the user or with the account; made inaccessible immediately, then erased at the next purge of disabled data | | Shared test results | Until deletion by content owner | | Connection logs | 12 months | | Billing information | 10 years (legal requirement) | | Support communications | 3 years | | Push notification tokens | Duration of account + 30 days after deletion | | Voice data (audio) | Not retained — real-time processing only | | Flashcard session history | Until deleted by the user or with the account; made inaccessible immediately, then erased at the next purge of disabled data | | Written work (page images, transcription, results) | Until deletion of the material or of the author's account | | Exam conversation history | 90 days after the end of the exam (the report stays attached to the exam) | | In-app notifications | 90 days | | Automatic moderation results | Duration of the account + 12 months — to detect repeat violations and answer requests from the authorities | | Account-deletion register (email address) | 3 years after the last deletion — solely to enforce the limit on the number of account deletions | | Usage and connection counters | Lifetime of the account — deleted with the account | | Marketing attribution data (arrivals, sources, campaign parameters) | 12 months |
You have the right to:
• Access your personal data
• Rectify inaccurate data
• Erase your data ('right to be forgotten')
• Restrict processing
• Data portability (receive your data in machine-readable format)
• Object to processing based on legitimate interests
• Withdraw consent at any time
• Lodge a complaint with the CNIL (French Data Protection Authority): https://www.cnil.fr (https://www.cnil.fr)
California residents have the right to:
• Know what personal information is collected
• Request deletion of personal information
• Opt-out of the sale of personal information (we do not sell data)
• Non-discrimination for exercising privacy rights
To exercise your rights, contact us at: info@zestly.org
We will respond within 30 days (or as required by applicable law). We may request verification of your identity before processing requests.
The Service may be used by children through a member profile managed by a parent or legal guardian (Family plan) or within a class group managed by a teacher: the adult who owns the group creates or invites the child's profile, gives consent to the collection and supervises the processing of the child's data. A child under 13 may only use the Service through such a profile; outside that framework, we do not knowingly collect data from children under 13. If you believe we have collected such data outside this framework, please contact us immediately.
Age of digital consent. Where the applicable law sets an age of digital consent above 13 — 15 in France (Article 45 of the French Data Protection Act) — consent to processing based on consent is given, below that age, by the holder of parental responsibility jointly with the minor. For users aged 13 to 17 using the Service independently, this consent is required depending on the jurisdiction; parents remain responsible for managing their children's data.
Artificial-intelligence providers. What the child produces themselves in a family Group profile — the oral exam exchanges, answers to quizzes and flashcards, handwritten pages — is entrusted only to providers whose terms exclude the use of content to train their models and limit its retention to 30 days, except where the law or safety requires longer (section 5.1).
A child's written work. In the most common scenario, the child writes the answers by hand and an adult (parent, guardian or teacher) photographs and submits the pages, or the child submits them from their own member profile. The data subject is the child; consent to the processing of the images and their transcription (section 2.4) is given by the holder of parental responsibility or, for a class group, by the institution, under the conditions of Article 2 of the Terms of Use. The adult who owns the material alone decides whether to switch on the public link of a written work; that link only gives access to the blank sheet. The links to the submitted pages and to the results are presented only to authorised accounts, and neither is ever published or indexable; the page images themselves can be opened by anyone holding their technical address (section 5.2).
Educational institutions. Teachers and institutions that enrol minor pupils in a class group declare that they hold the authorisations required by the law applicable to them for this processing; enrolment by a teacher does not replace the consent of the holder of parental responsibility where that consent is required.
We implement appropriate technical and organizational measures:
• Encryption of data in transit (TLS) and at rest
• Secure password hashing
• Access controls and authentication
• Regular security assessments
• Employee training on data protection
• Incident response procedures
No system is completely secure. If you discover a security vulnerability, please report it to: info@zestly.org The Publisher's authorised staff may, for support purposes or to fight abuse, access an account and view it as the user sees it; every such access is logged.
We use essential cookies for:
• Authentication and session management
• Security and fraud prevention
• Remembering your preferences
We also use your browser's local storage, rather than cookies, to keep a technical device identifier — which allows trial-mode allowances to be attached to a single device, among other things — and, where applicable, the referral code recorded on your first visit. That code is kept there until a subscription is taken out.
We further record on our servers arrivals on the Service for audience measurement and marketing attribution (section 2.2), including arrivals through a referral link or through the public page of a material. These records are kept for the period stated in section 7.
We do not use advertising cookies or third-party tracking for advertising purposes, and we do not disclose this data to advertising networks.
The Service may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies before providing any personal data.
We may update this Policy periodically. Significant changes will be notified via email or in-app notification. Continued use after notification constitutes acceptance.
The current version is always available at https://zestly.org/legal/privacy (https://zestly.org/legal/privacy)
This Policy may be translated into several languages. In case of divergence, the French version prevails.
For privacy-related questions or to exercise your rights:
DAPFOR SAS 26 rue Hector Berlioz 92500 Rueil-Malmaison, France Email: info@zestly.org
You can delete your account at any time from the Profile (/profile) page of the application or website ("Delete account" button), or by writing to us at info@zestly.org. Deletion takes effect immediately: it is no longer possible to log in to the account and the email address is detached from it.
What is deleted immediately: your profile and preferences, your authentication credentials, your notifications, your summaries, your group memberships (owners are informed) and the groups you own, with the corresponding loss of access for their members. Your usage and connection counters are also deleted. Marketing attribution data attached to your account is also deleted.
What is deactivated immediately and then permanently deleted: your materials, uploaded documents, quizzes, exams, flashcard sessions and written work become inaccessible as soon as the account is deleted, and are then erased from our servers within the periods of section 7 (no later than 30 days after deletion for account data, and according to the period stated for each type of content). Public links attached to your materials stop working.
What is kept: billing information and payment records (10 years, legal obligation); connection logs (12 months); a trace of the email address in a deletion register, used solely to limit the number of successive deletions and re-creations of the same account (section 7); copies of a library material made by other users; subscriptions taken out through Apple or Google, which remain managed by those stores and can be attached to a new account.
Deleting a parent or teacher account closes the groups it owns; the content of members (children, pupils) attached to those groups is treated in the same way. Members keep their own account.
To exercise your right to erasure over data that account deletion does not cover, write to us (section 8.3).
• Version 2.2 — 20 September 2026: artificial-intelligence sub-processors designated by category and guarantees required for children's profiles (sections 5.1, 9); age of digital consent (section 9); access to written-work page images (sections 5.2, 9); content retention periods aligned with the life of the account (section 7).
• Version 2.1 — 20 September 2026: added marketing attribution data (sections 2.2, 7, 11, 16), what a partner in the affiliate programme sees about you (section 5.5) and a description of browser local storage (section 11).
• Version 2.0 — 20 September 2026: added handwritten written work (sections 2.1, 2.4, 3, 4, 5.1, 5.2, 7, 9), automatic content moderation (sections 3, 4, 5.1, 7), the example library (sections 3, 5.2), in-app announcements (section 3), authorised staff access (section 10) and the section "Deleting your account and data" (section 16) as well as usage and connection counters (sections 2.2, 7, 16); introduced the version number and this history.
• Version 1.x — May 2026: last revision prior to the introduction of the history.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.