Security and data

What is true today, and only that.

Each point says where it stands. What is not done is written as such: a promise not kept is worse than no promise at all.

  • Live exists and runs
  • In progress being built
  • Planned decided, not started

What the assistant can do, and what it cannot

An assistant reads texts it does not control; a planted instruction could make it call a tool. We do not rely on its caution: what it must not do, it has no means of doing.

  1. 1

    Everyday use Live

    Reading, adding, changing one’s own data: the assistant acts at the user’s request. Every tool declares its nature — read, write or delete.

  2. 2

    Sensitive or irreversible Live

    The assistant asks; the human confirms outside the assistant, on a Nano page, with a code sent to the account’s phone number. Today: deleting the account.

  3. 3

    Administration Live

    Billing, subscriptions, prices, activation codes, countries: no assistant tool gives access to them. These operations are run by a human, through scripts on the server.

Limit: deleting an item inside a product (a record, a note) stays in the first circle until there is a recycle bin and roles.

Point by point

Hosted in France

Live
  • A server dedicated to Nano, rented from OVH, in France; the database lives there, and so do its backups.
  • A backup every night, fourteen kept; a copy the database cannot read back is rejected. On top of that, OVH backs up the whole disk every day, seven days kept.
  • A user outside the European Union has their data hosted in France and protected by the GDPR.

Sign-in

Live
  • An account is a phone number verified by a code.
  • The assistant connects through OAuth 2.1 (with PKCE): it opens Nano’s sign-in page and receives a token. It never sees the code.
  • One-hour access tokens, 90-day refresh with rotation, revocation. Codes and tokens are stored as hashes (SHA-256), never in clear. Five wrong attempts destroy a code.
  • Code sending is rate-limited by the server: per number, per IP address, and by a global daily cap.

In progress: real sending of codes by text message — built, being put into service. Today, sign-in is open to demonstration numbers only.

Each product in its own space

Live
  • A product’s data lives in its own space; a product that tries to read another’s is stopped.
  • The core knows no product. Automated tests fail if this rule is broken, and they have been seen failing when the fault was injected.

In progress: physically separating the service from administration, in two distinct databases, with no cross access rights. The architecture is approved; it is being built.

In progress: a product under test is served only to named testers, and its release goes through a validation signed on the exact fingerprint of its tools — built, being put into service.

Minimisation and retention

Live
  • No sensitive data is requested. Of an e-mail sent, we keep the proof (recipient, subject, date), never the content.
  • The web server keeps no access log, neither for our sites nor for the service.
Retention periods
DataPeriod
Account and data enteredOne year after last use; the user is warned a month before.
Item deleted by the userImmediately.
Backups14 days at most.
Tool-call log12 months.
Server system log30 days.
Sign-in code sending records2 days.
Expired tokens and codes7 days after expiry.
Accounting records10 years (legal obligation), detached from the deleted account.

User rights, self-service

Live
  • Copy of one’s data: from one’s assistant, in a reusable format (JSON), with no secrets; if large, sent as an attachment to the confirmed address, and to no other.
  • Account deletion: requested from the assistant, confirmed outside the assistant (circle 2). The assistant’s access ends at once.
  • Reminders: can be switched off from the link in every e-mail.
  • Any other request: support@fmnano.com, answered within a month.

Named processors

Live
ProviderRoleLocation
OVH SASServer, database, backups, domain namesFrance
Brevo (Sendinblue SAS)Sending e-mailsFrance and Belgium; some of its own providers outside the EU (United States, India), covered by standard contractual clauses
MicrosoftMailbox receiving support@fmnano.comEuropean Union, under Microsoft’s “EU Data Boundary” commitment; possible transfers to the United States, safeguarded

By default, Brevo inserts a pixel that measures whether e-mails are opened. We are working to switch it off; meanwhile, the privacy policy says so.

The assistant (OpenAI, Anthropic, Mistral…) is not our processor: the user chooses it and entrusts their conversation to it, under its publisher’s rules.

Incidents

Live
  • A written procedure, reviewed in calm times: contain without destroying evidence, assess the risk within 24 hours, notify the French data protection authority (CNIL) within 72 hours when there is a risk, inform the people concerned if that risk is high.
  • A breach register, kept even without notification: no entry at 29 September 2026.

Governance and documents

Live
  • Record of processing activities (GDPR article 30), drawn from the code and the server, not from intentions; list of processors with their agreements; breach procedure.
  • Data controller: Valier Holding. No data protection officer appointed at this stage: questions are handled by the president.
  • E-invoicing to the European EN 16931 standard: every document is validated against the official schemas (Factur-X, EN 16931, French rules); a document that fails does not go out. Transmission through an accredited platform: Planned

What Nano does not have yet

  • No certification (ISO 27001 or other).
  • No appointed data protection officer.
  • No real sending of codes by text message In progress
  • No physical separation yet between the service and administration In progress
  • No tamper-proof log of administrative actions Planned

The documents cited on this page — record of processing, processors, procedure — can be provided to an institution considering a pilot: ask for them.

The service’s privacy policy is published on fmnano.com.