MilkStorage · RGPD baseline · v2026-07-19
Privacy notice
MilkStorage processes a small amount of personal data to authenticate your account, manage milk storage records, and deliver optional reminders. This page describes the concrete technical measures currently implemented. It is not a legal certification.
MilkStorage is not a medical service. Label every bag with the pumping date and time. Always check the storage conditions and storage duration yourself before using the milk. MilkStorage is a tracking aid: its calculations and reminders do not replace your own checks and may be delayed or unavailable.
Data controller
Publisher and data controller: Florent LAGOUTTE, Entrepreneur individuel (EI), exploitant l'application MilkStorage. MilkStorage is the commercial name of the application and is not a separate legal entity.
Legal status: Entrepreneur individuel exerçant sous le régime de la micro-entreprise. Country: France.
Postal address: 246 Chemin de Loyse, 71570 LA CHAPELLE-DE-GUINCHAY, France.
Registration: SIREN 829 402 007, SIRET 829 402 007 00027. Entreprise immatriculée au Registre national des entreprises (RNE).
VAT: Aucun numéro de TVA intracommunautaire attribué. Franchise en base de TVA - TVA non applicable, article 293 B du Code général des impôts..
Privacy contact: contact@milkstorage.eu. No data protection officer has been appointed.
Data processed
Account data: Google account identifier when Google sign-in is used, email address, display name, profile picture, language, and preferred unit.
Authentication and security data: session cookies, verification tokens, password-reset tokens, and limited technical logs.
Application data: milk storage records, storage locations, timestamps, notes, expiration dates, household memberships, notification preferences, reminder rules, push subscription metadata, and notification jobs.
Purposes and legal bases
Account creation and authentication are processed because they are necessary to provide the service requested by the user.
Milk storage records may reveal health-related information. MilkStorage therefore asks for explicit consent before the first creation of milk-related data.
Security, abuse prevention, and limited debugging rely on legitimate interest in securing and maintaining the service.
Push notifications are optional and only used when the user enables them. Browser permission alone is not treated as consent for every processing activity.
Processors and recipients
Hosting and deployment: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, États-Unis.
Database: Neon, LLC, service Neon Postgres.
Transactional email: OVHcloud, service de messagerie Zimbra et serveurs SMTP, used for invitations, account messages, password resets, alerts, and other application notifications.
Google receives the data required for Google OAuth only when the user chooses Google sign-in.
Web Push delivery also depends on the user's browser or platform push service.
Hosting and processing regions
Neon/PostgreSQL: AWS Europe - Francfort, Allemagne (aws-eu-central-1).
Vercel: États-Unis et autres pays dans lesquels Vercel ou ses sous-traitants exploitent des infrastructures.
Google OAuth: Espace économique européen et autres pays dans lesquels Google exploite ses services.
OVHcloud/Zimbra: France, au sein de l'Union européenne.
Retention
Account and milk-management data are kept while the account is active.
Deleting the account removes user-owned milk records, push subscriptions, notification preferences, reminder rules, household memberships, and other directly linked application data.
Invalid push subscriptions are removed or revoked. Completed, failed, and cancelled notification jobs are pruned after a limited retention period.
Avec le forfait Neon Free, un historique des modifications est conservé pendant une durée maximale de six heures, dans la limite de 1 Go de modifications. This point-in-time restore feature is not an independent full backup. MilkStorage does not currently maintain an additional independent backup.
Technical backup retention for Vercel, OVHcloud, and Google depends on those providers' own policies.
Your rights
You can request access, rectification, deletion, export/portability, withdrawal of sensitive-data consent, restriction, or objection where applicable.
MilkStorage currently provides in-app self-service controls for JSON export, account deletion, and withdrawal of milk-data consent.
Requests may also be sent to contact@milkstorage.eu. They should normally be handled within the legally applicable period.
Safety and use of reminders
MilkStorage is an organizational tool and does not provide medical advice or medical expertise. For breast milk handling, storage, expiry, feeding, or health questions, consult a qualified healthcare professional and follow the guidance applicable where you live.
Write the pumping date and time on every bag or container. You remain responsible for checking labels, actual storage conditions, storage duration, and expiry. Reminders, calculations, and push notifications are optional convenience features and may be delayed, unavailable, or incorrect.
Cookies, local storage, advertising, and optional tracking
MilkStorage uses cookies and browser storage for authentication, language preference, push/PWA operation, and UI convenience features such as the floating add button position.
As of this privacy version, no non-essential advertising, analytics, or tracking technology is active in production: no active ad network, no active Google AdSense or Google AdMob service, no confirmed non-essential audience analytics, no advertising profiling, no advertising cookie or identifier, and any in-app ad placements are disabled.
Google authentication is used only as a sign-in feature.
Future activation of advertising, analytics, or tracking after Google Play publication will require an update to this privacy notice, Play Console declarations, and a consent mechanism whenever required.