Consulter cette page en français
Privacy Policy
Self Therapie Formation â Member Area Last updated: 27 July 2026
1. Who is the data controller
The Member Area available at https://app.selftherapie.com is published and
operated by SELF THERAPIE FORMATION ("STF", "we"), a French limited
liability company (société à responsabilité limitée) with share capital of
âŹ5,000, registered with the Caen Trade and Companies Register under number
808 422 174, and registered as a vocational training provider under number
25 14 02886 14.
- Registered office: 30 avenue du 6 Juin, 14000 Caen â France
- Contact for any question regarding personal data: espace.membre@selftherapie.com, or by post: Service DonnĂ©es personnelles, SELF THERAPIE FORMATION, 30 avenue du 6 Juin, 14000 Caen â France
STF is the data controller within the meaning of the General Data Protection Regulation (GDPR).
2. Who this policy applies to
The Member Area is a private service, reserved for people enrolled in a Self Therapie Formation training programme, and for its trainers, supervisors and contributors. It is not open to the public: an account is only created where a contractual or educational relationship with STF already exists.
3. Data we process
3.1 Account and training data
| Category | Examples | Source |
|---|---|---|
| Identity | last name, first name, email address, display name, photo | you, or your enrolment file |
| Contact details | phone number, postal address | you, or your enrolment file |
| Training record | enrolments, sessions attended, hours logged, supervisions, interviews | STF and you |
| Content you create | discussion messages, uploaded documents, Selfi analyses, comments | you |
| Technical data | session identifier, sign-in log, display preferences | automatic |
3.2 Zoom data (optional integration)
The Member Area lets you connect your Zoom account so you can build a "Selfi" analysis from one of your cloud recordings, without having to download it and upload it again somewhere else.
This connection is entirely optional: the Member Area works fully without it. It is established only at your explicit request, through Zoom's official consent screen, and you can remove it at any time (see section 7).
Scopes requested from Zoom, and exactly what each is used for:
| Zoom scope | What we read | Why |
|---|---|---|
user:read:user | email address, display name, profile picture and user ID of the connected Zoom account | identify the connected account, show it in the account menu, and be able to delete your data if you remove the app from Zoom |
cloud_recording:read:list_user_recordings | the list of your cloud-recorded meetings over the last 12 months: topic, start date and time, size and type of each file | present the list of recordings for you to choose from |
cloud_recording:read:list_recording_files | the files of a given meeting and their temporary download URL | retrieve, at playback time, the view you selected |
cloud_recording:read:recording | the content of the selected video recording | let you watch it inside the Member Area |
We request no other scope. In particular, we have no access to your ongoing meetings, transcripts, in-meeting chat, participant lists, contact directory, or the recordings of other users on your Zoom account. We never join a meeting.
3.3 What we keep, and what we do not keep
We keep, in our database:
- the email address and user ID of your Zoom account;
- the date of the connection;
- an OAuth refresh token issued by Zoom, always encrypted (AES-256-GCM) before being written. The encryption key is never stored in the database: it exists only in the application's runtime environment. The provider hosting the database therefore cannot read this token;
- on the Selfi analysis you create: an internal reference (Zoom account ID, meeting ID, file ID) and the title you give it.
We do not keep:
- any video or audio file. Recording content is never copied, downloaded or saved on our servers. When you start playback, it is streamed from Zoom to your browser in chunks, and is never written to disk;
- the temporary download URL provided by Zoom: it is requested again for each playback, used immediately, and is never sent to your browser or stored;
- Zoom access tokens (valid for one hour): they exist only in the server's memory;
- your Zoom display name and profile picture: they are requested again from Zoom and held in memory for at most thirty minutes, never written to the database.
4. Why we process this data (legal bases)
- Performance of the training contract â managing your training record, enrolments, supervisions and educational analyses.
- Your consent â for connecting your Zoom account, given through Zoom's authorization screen and withdrawable at any time with no effect on the rest of your access.
- Legitimate interest â service security, prevention of unauthorised access, and improvement of the service.
- Legal obligations â retention of records relating to vocational training and invoicing.
Zoom data is never used for advertising, profiling or commercial analytics, and is never sold, rented or otherwise transferred to a third party.
5. Who can access a Zoom recording
Access is checked by our servers on every playback. The following people can watch a Zoom recording referenced in the Member Area:
- you, the owner of the connected Zoom account;
- the members you have explicitly shared the corresponding Selfi analysis with, and who accepted that share â typically a trainee sharing a session with their supervisor. Sharing is a deliberate act on your part, and you can end it at any time by removing the share or deleting the analysis. The recipient only gains access to that specific video â never to the rest of your Zoom account â and cannot re-share it: only the owner decides who sees it.
Site administrators cannot access your recordings through the Member Area's tools: when an administrator views a member's account (support, diagnostics), both the list of Zoom recordings and their playback are excluded.
No other member can access the recording, even knowing its address: the check is performed server-side, based on your session.
6. Processors and hosting
| Provider | Role | Location |
|---|---|---|
| Vercel | site hosting and execution | United States (iad1 region, Washington) |
| Ninox | business database hosting (including encrypted Zoom tokens) | Germany (Hetzner data centres, Nuremberg â ISO 27001) |
| Box | storage of uploaded files (documents, images, voice messages) | United States (Box default data centres) |
| Wix | migration of legacy accounts and conversations (transitional â authentication relies on our own database, and this residual use will be removed) | United States, Ireland, Israel (country recognised as adequate by the European Commission) |
| Ably | real-time messaging delivery (message content in transit, presence and read indicators â no durable storage) | global network (European Union and United States) |
| Google Workspace | delivery of notification emails | European Union / United States |
| Upstash | ephemeral rate-limiting counters (protecting sign-in and the assistant â IP address and email address, erased after a few minutes) | European Union (Frankfurt) |
| Anthropic | conversational assistant (the questions you ask it) | United States |
| Voyage AI | document search for the assistant (question text) | United States |
| Stripe / PayPal | payments (directory, top-ups) â card details are entered on their systems, never on ours | United States |
| Vimeo | playback of training videos (your IP address, via the embedded player) | United States |
| Apple / Google / Mozilla | delivery of push notifications, if you enable them | depending on your device |
None of these providers retains your Zoom recordings: the video stream passes through our host (Vercel) at playback time, in memory only, and is never written; no other provider receives it. Each provider acts solely for the stated function, never for its own purposes.
The privacy policies of Ninox and Wix, processors already declared in STF's
contractual documents, are available at https://ninox.com/en/privacy and
https://www.wix.com/manage/privacy-security-hub.
Where a transfer outside the European Union takes place, it is governed by the European Commission's standard contractual clauses.
7. Retention and deletion
| Data | Retention |
|---|---|
| Connected Zoom account (address, ID, encrypted token) | until disconnection, revocation, or removal of the app |
| Zoom access token | 1 hour at most, in memory |
| Cached Zoom name and picture | 30 minutes, in memory |
| Zoom reference held by a Selfi analysis | until the analysis is deleted |
| Account and training data | for the duration of the relationship, then archived for up to five years (civil limitation period) |
You can delete your Zoom data in two ways, with the same effect:
- from the Member Area â Zoom account menu in the "Add a Selfi" window, "Disconnect this account" command. We then revoke the token at Zoom, purge our caches and delete the record from our database;
- from Zoom â the "Added Apps" page of your Zoom account, "Remove" command. Zoom notifies us automatically: we delete the same data and confirm the deletion back to Zoom.
After deletion, Selfi analyses that pointed to a Zoom recording remain but can no longer play it: reconnect the account, or delete the analysis.
8. Security
- All communications are encrypted (HTTPS).
- Zoom tokens are encrypted before storage (AES-256-GCM); the key is held outside the database.
- Zoom recordings are unreachable from the site's administration tools, including when an administrator views a member's account.
- No token is stored in your browser; sessions rely on a technical cookie whose content is kept server-side.
- Your browser never receives a Zoom address: all exchanges with Zoom are made
from our servers, and only addresses on the
zoom.usdomain are accepted. - The authorization flow is protected against forgery by a signed token, valid for ten minutes.
9. Your rights
You have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to withdraw your consent at any time. Write to espace.membre@selftherapie.com, or by post to Service Données personnelles (address in section 1), enclosing proof of identity; we respond within one month, extendable by two months for a complex request.
You may also lodge a complaint with the French data protection authority
(Commission nationale de l'informatique et des libertĂ©s â CNIL), 3 place de
Fontenoy, 75334 Paris Cedex 07 â www.cnil.fr.
10. Cookies
The Member Area uses no advertising cookie and no third-party analytics tracker. Only strictly necessary cookies are set: session identifier and language preference.
11. Minors
The Member Area has no open sign-up: every account is created by STF as part of a vocational training relationship entered into with adults. The service is not directed at minors and we do not knowingly collect data concerning them.
12. Changes
Any change to this policy is published on this page, together with its update date. In the event of a substantial change affecting your Zoom data, we will inform you by email.
