← BACK TO 7BOOST.
This is an English translation provided for convenience. The legally binding version of this document is in French
view the French version.
7BOOST. Privacy Policy
Last updated: July 2, 2026
This privacy policy is intended to inform users of the 7BOOST. extension and website (hereinafter the "Service") about how their personal data is collected, used, retained, and protected, in accordance with the General Data Protection Regulation (GDPR), and in particular its Article 13.
1. Identity and contact details of the data controller
The Service is published on a non-professional basis by an individual, who acts as data controller within the meaning of the GDPR.
In accordance with Article 1-1, II of French Law No. 2004-575 of June 21, 2004 on confidence in the digital economy ("LCEN"), the publisher of the Service, an individual acting on a non-professional basis, exercises their right to preserve anonymity. Their identifying information has been provided to their hosting provider, who is bound by professional confidentiality.
Contact: contact@7boost.io
Website hosting: Vercel Inc. (440 N Barranca Avenue #4133, Covina, CA 91723, USA)
No Data Protection Officer (DPO) has been appointed. Under Article 37 of the GDPR, this appointment is only mandatory for public authorities, or for organizations whose core activities involve regular and systematic large-scale monitoring of data subjects, or large-scale processing of special category data (Article 9) or data relating to criminal convictions. The Service, published by an individual on a non-professional basis and not processing such data on a large scale, does not fall into any of these categories. Any question regarding personal data may be sent to the contact address above.
2. Personal data collected
As part of the use of the Service, the following categories of data are collected:
- Account data: username, email address, and password (encrypted), via the Supabase Auth authentication system, when creating an account.
- Usage data: number of "boost" requests and keyword extractions made per day, associated with the account identifier and a date (the "usage" table), in order to apply the daily usage limits.
- Content of prompts entered on supported third-party tools (auto-boost feature): when the user voluntarily enables the auto-boost feature for one or more supported third-party conversational AI tools (as of this update: ChatGPT (OpenAI), Claude.ai (Anthropic), Gemini (Google), and Mistral Vibe), the extension automatically reads the text entered by the user in that tool's input field at the moment it is sent, in order to transmit it to the Service for optimization, under the same terms as a prompt submitted manually from the extension's interface. This reading only occurs on the websites of supported third-party tools, only while the feature is enabled by the user, and only concerns the content of the input field at the moment it is sent.
- Local preferences: daily display counters, default keywords, preferred language, interface preferences, the activation status of the auto-boost feature, and the position of a visual indicator displayed on supported third-party tools, stored locally on the user's device via chrome.storage.local and not transmitted to the Service.
- Technical connection data: information strictly necessary for authentication to function (Supabase session token, including the access token and the refresh token), stored locally on the user's device via chrome.storage.local to enable the auto-boost feature described above to function, including when the extension's main interface is not open.
- Cryptographic fingerprint of the email address: after an account is deleted, a non-reversible fingerprint of the email address (HMAC-SHA256) is retained solely for the purpose of preventing abuse of the free trial (see Section 6).
The Service does not collect any banking data, health data, geolocation data, and does not carry out any profiling of users.
3. Purposes of the collection
The personal data described above is processed for the following purposes:
- To enable the creation, authentication, and management of the user account (username, email, password).
- To provide the core functionality of the Service, namely the optimized rewriting of prompts submitted by the user, whether manually from the extension's interface or automatically, when enabled by the user, via the auto-boost feature on supported third-party tools.
- To apply the daily usage limits and prevent abuse (usage data).
- To remember user preferences in order to improve their experience (local preferences).
- To prevent the abusive creation of multiple accounts aimed at circumventing the free trial period (cryptographic fingerprint of the email, retained after account deletion).
4. Legal basis for processing
- Performance of a contract: account creation, authentication, the provision of the prompt rewriting service, and the enforcement of usage quotas are necessary for the performance of the contract entered into with the user upon registration (Article 6(1)(b) GDPR).
- Legitimate interest: the retention of usage counters and quota verification serve the data controller's legitimate interest in ensuring the proper functioning and security of the Service (Article 6(1)(f) GDPR).
- Legitimate interest - fraud prevention: the retention, after an account is deleted, of a non-reversible cryptographic fingerprint of the email address serves the data controller's legitimate interest in preventing the abusive creation of multiple accounts aimed at circumventing the free trial limit. This purpose is recognized by Recital 47 of the GDPR as capable of constituting a legitimate interest (Article 6(1)(f) GDPR). Retention is strictly limited to the period necessary for this purpose (see Section 6).
5. Recipients and data sharing
Personal data is neither sold, rented, nor exchanged with third parties for commercial purposes. It may be transmitted to the following recipients, strictly to the extent necessary for the operation of the Service:
- Supabase Inc.: database hosting and authentication management, storage of usage data and of the cryptographic fingerprint of the email address. The Supabase instance used for the Service is hosted within the European Union. Supabase acts as a data processor within the meaning of the GDPR.
- Mistral AI (AI provider): receives the content of the user's prompt, whether submitted manually from the extension or automatically via the auto-boost feature on a supported third-party tool, (and, where applicable, style keywords and the desired output language) for the purpose of generating the optimized prompt. This content is transmitted for each request via a secure Edge function and is not retained by the Service beyond the processing of the request.
- Vercel Inc.: hosting of the Service's showcase website. Vercel Inc. is a company established in the United States. As such, visiting the showcase website may result in the recording of technical data, such as the visitor's IP address, by Vercel's infrastructure. Vercel Inc. is certified under the EU-U.S. Data Privacy Framework, which forms the basis for the transfer of this data to the United States (Article 45 GDPR). This framework is currently subject to ongoing regulatory scrutiny at the European level.
No personal data linked to the user's account (username, email, account identifier) is transmitted to Mistral AI. Only the text content of the prompt submitted by the user (and any associated style keywords) is sent, for the sole technical purpose of prompt optimization.
Mistral AI is a company incorporated under French law, headquartered within the European Union (Paris, France). The processing of prompt content by Mistral AI therefore takes place within the European Union, with no transfer to a third country, and in compliance with the GDPR obligations applicable to processors established in the European Union.
If the user chooses to include personal data (their own or that of third parties) in the text of their prompt, they are solely responsible for doing so. The Service does not control or filter the content of submitted prompts, whether submitted manually or via the auto-boost feature.
6. Data retention periods
- Account data (username, email, password): retained for the entire lifetime of the account. When the account is deleted, the plaintext email address is deleted immediately by the authentication system, and other identifying data is erased almost immediately. This data may persist in the hosting provider's technical backups for up to a further 30 days, outside the data controller's direct control. Exception - cryptographic fingerprint of the email address: an HMAC-SHA256 fingerprint (with the secret key retained exclusively server-side) is kept after the account is deleted, solely to detect any attempt to abusively recreate an account in order to benefit from a new free trial. This fingerprint alone does not make it possible to recover the original email address. It is automatically deleted by a scheduled technical process 18 months after the date the account was deleted. The account deletion date (deleted_at) is retained for as long as necessary to calculate this period, i.e. for a maximum of 18 months.
- Usage data (daily counters): deleted immediately upon account deletion. For active accounts, this data is retained for as long as necessary to apply the daily limits and detect any abnormal usage.
- Prompt content: not retained by the Service after the request has been processed, whether the prompt was submitted manually or via the auto-boost feature. The AI provider may apply its own retention policy, as described in its terms of use.
- Local preferences and session token (chrome.storage.local): stored on the user's device, including the session token persisted locally for the auto-boost feature to function. They are not automatically deleted upon account deletion and remain on the device until manually deleted or until the extension is uninstalled. Logging out of the account from the extension, however, deletes the locally stored session token.
7. Data security
The data controller implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure, including:
- The API key for the AI provider is stored exclusively in the server-side Edge function secrets and is never exposed in the extension's code or accessible client-side.
- Every request to the processing functions is subject to authentication verification (JWT token); any unauthenticated request is rejected.
- Passwords are managed in encrypted form by the authentication provider (Supabase Auth) and are never stored in plain text.
- Data tables are protected by Row Level Security rules; writes to the database are only possible via the Service's Edge functions.
- The cryptographic fingerprint of the email is computed using HMAC-SHA256. This is pseudonymized data: it does not make it possible to identify a user without having both the secret key (retained server-side only) and the email address to test against it. It is never exposed client-side.
- The session token stored locally (chrome.storage.local) for the auto-boost feature to function is accessible only to the extension itself; it is not accessible to web pages visited by the user, nor to other extensions installed in the browser.
8. User rights
In accordance with the GDPR, every user has the following rights over their personal data:
- Right of access: obtain confirmation that data concerning them is being processed and obtain a copy of it (Article 15 GDPR). With regard to the cryptographic fingerprint retained after account deletion, the data controller can confirm the existence or absence of such a record, without disclosing its raw value.
- Right to rectification: request correction of inaccurate or incomplete data (Article 16 GDPR).
- Right to erasure: request deletion of their personal data, including by deleting their account (Article 17 GDPR). The residual retention of the cryptographic fingerprint after account deletion is justified by the legitimate interest in fraud prevention and automatically ends after 18 months.
- Right to object: object, on legitimate grounds, to processing based on the data controller's legitimate interest (Article 21 GDPR). Any objection request will be examined individually. With regard to the cryptographic fingerprint retained after account deletion, the data controller reserves the right to maintain this processing where the objection request is made in a context suggesting an attempt to circumvent the free trial, such retention then being based on compelling legitimate grounds within the meaning of Article 21(1) GDPR.
- Right to data portability: receive the data provided in a structured, commonly used, machine-readable format (Article 20 GDPR).
- Right to restriction of processing: request restriction of the processing of their data in certain cases provided for by the GDPR.
These rights may be exercised by writing to contact@7boost.io. A response will be provided within one month of receipt of the request, a period which may be extended by a further two months in the case of complex requests or a high volume of requests, in accordance with Article 12(3) of the GDPR.
9. Right to lodge a complaint
If, after contacting the data controller, the user considers that their rights are not being respected, they may lodge a complaint with the French Data Protection Authority (CNIL):
- Online: www.cnil.fr
- By post: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
10. Cookies and trackers
The 7BOOST. website does not currently use any analytics, advertising, or personalization cookies requiring prior consent. Only cookies strictly necessary for the Service to function (notably those related to authentication within the extension) may be used, and these do not require consent under the ePrivacy Directive and CNIL guidelines.
Should future developments introduce cookies subject to consent (for example, audience measurement tools), this policy will be updated and a consent collection mechanism will be put in place prior to the deployment of such cookies.
11. Changes to this privacy policy
The data controller reserves the right to modify this privacy policy at any time, in particular to comply with any regulatory, technical, or case-law developments. The applicable version is the one published on the website and extension at the date of consultation, with the date of last update indicated at the top of this document.