Privacy Policy

Last updated: 5 June 2026

This Privacy Policy explains how Visamundi Vision, a service operated by Visamundi (SAS, RCS Nantes 828 148 189), collects, uses and protects your personal data when you use our travel email scanning service. We act as the data controller within the meaning of the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés).

We built Vision to read as little as possible and to keep what little it extracts firmly in your control. This document describes exactly what that means.

1. Data controller

The controller is Visamundi, SAS with share capital of 50 000 €, registered with the Nantes Trade and Companies Register under number 828 148 189, whose registered office is at 15 allée Duguay-Trouin, 44000 Nantes, France.

For any question about this policy or to exercise your rights, you can reach our data protection contact at contact@visamundi.co.

2. What we collect

Google account information

When you sign in with Google we receive your name, email address and profile picture. This is used to create and identify your account.

Gmail content (only travel emails)

If you grant Gmail access, we request the read-only scope and search your mailbox for travel booking confirmations only (flights, hotels, car rentals, trains, travel packages). For each matching email we process the subject, the sender and the body, with the body stripped of HTML and truncated to 4 000 characters. We never open attachments and we never read emails that are not travel-related.

To turn an ambiguous confirmation into structured data, that processed text may be sent transiently to our extraction engine, which combines deterministic rules with an AI model accessed through the Infomaniak AI Service (a Mistral model hosted in Switzerland/EU). The email text is used only to perform the extraction and is not retained by us after extraction: we keep the structured trip fields, not the message bodies.

OAuth tokens

To run scheduled scans we store the OAuth access and refresh tokens issued by Google. They are stored encrypted and are deleted when you disconnect Gmail or delete your account.

Trip and usage data

  • Extracted trip fields: destination, departure and return dates, booking type, confirmation number, carrier, amount and currency where available.
  • Gmail message identifiers, kept only to avoid creating the same trip twice (we do not keep the message body).
  • Your settings: scan frequency, scan on/off, nationality (used for visa advice) and scan history.

3. Why we process your data and on what legal basis

  • To provide the service (account, trip detection, visa information): performance of our Terms of Service (Art. 6(1)(b) GDPR).
  • To scan your Gmail and run automatic background scans: your explicit consent, given through the Google authorization screen and revocable at any time (Art. 6(1)(a) GDPR).
  • To secure the service and prevent abuse (e.g. rate limiting): our legitimate interest (Art. 6(1)(f) GDPR).
  • To comply with our legal obligations (Art. 6(1)(c) GDPR).

4. Google API limited use

Visamundi Vision's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, we do not sell it, and humans do not read it except where strictly necessary for security, to comply with the law, or with your explicit consent for support.

5. Who processes data on our behalf

We rely on a small number of carefully chosen subprocessors, bound by contract to protect your data:

  • Netlify — application hosting.
  • Supabase — database and authentication (where your account, tokens and trips are stored).
  • Upstash — rate limiting / abuse prevention.
  • Google — sign-in and Gmail API access.
  • Infomaniak AI Service — AI extraction (Mistral model, hosted in Switzerland/EU); receives the processed email text only during extraction.
  • Visamundi API — visa requirement lookups (receives destination and nationality, not your emails).

6. International transfers

Some of these providers are established outside the European Union. Where that is the case, transfers are governed by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework.

7. How long we keep your data

  • Account, trips and settings: for as long as your account exists. Deleted when you delete your account.
  • OAuth tokens: deleted as soon as you disconnect Gmail or delete your account.
  • Email bodies sent for extraction: not retained after the extraction completes.
  • Technical and security logs: kept for a limited period proportionate to their purpose.

8. Your rights

Under the GDPR you have the right to access, rectify, erase and port your data, to restrict or object to its processing, and to withdraw your consent at any time (which does not affect processing carried out before withdrawal). You can exercise these rights, and disconnect Gmail or delete all your data, from your settings or by contacting contact@visamundi.co.

You also have the right to lodge a complaint with the French supervisory authority, the CNIL (www.cnil.fr).

9. Security

Data is encrypted in transit and at rest, access is restricted, and the database enforces row-level security so that each user can only ever reach their own data. No system is perfectly secure, but we design for the principle that the less we hold, the less is ever at risk.

10. Children

The service is not intended for anyone under 16. We do not knowingly collect data from children under that age.

11. Changes to this policy

We may update this policy to reflect changes to the service or the law. We will update the date above and, for material changes, take reasonable steps to inform you.