Privacy Policy

Last updated: July 1, 2026

1. Controller

The data controller is the publisher named in the legal notice. Contact: privacy@safety-data-sheet.org.

2. What we collect

  • Search queries · the substances and CAS numbers you look up, to compute trending searches and improve results.
  • Technical logs · IP address, user agent, timestamp, referrer, for security and abuse prevention.
  • AI chat messages · questions you send to the assistant, transmitted to our AI provider for processing.
  • Cookies and analytics · only after your consent (see cookie banner).

3. Legal basis (GDPR Art. 6)

  • Legitimate interest · service operation, security, abuse prevention.
  • Consent · analytics and advertising cookies.
  • Contract performance · paid SaaS features, if any.

4. Retention

  • Search logs · 13 months maximum.
  • AI chat transcripts · 30 days for abuse review, then deleted or anonymized.
  • Account data (if any) · duration of the account + 3 years.

5. Subprocessors

We use the following processors, which may store data in the EU or the US under Standard Contractual Clauses:

  • Hosting and database · Lovable Cloud (Supabase infrastructure).
  • AI model provider · Google (Gemini via Lovable AI Gateway).
  • Data sources (public APIs, no personal data transmitted) · PubChem, ECHA, OSHA.

6. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to lodge a complaint with the CNIL (cnil.fr). Send requests to privacy@safety-data-sheet.org.

7. Cookies

Only strictly necessary cookies are set by default. Analytics and advertising cookies require your prior consent through the banner, which you can withdraw at any time.

8. Security

We apply reasonable technical and organizational measures (TLS in transit, encryption at rest at the hosting layer, access controls). No system is completely secure and we cannot guarantee absolute protection.

9. Children

The Service is not intended for children under 16. We do not knowingly collect data from minors.