Privacy Policy

Last updated: June 2026

This Privacy Policy explains how MicroSigns collects, uses, stores, shares, protects, and deletes personal data when you access our website, create an account, use our training platform, purchase paid access, contact us, or otherwise interact with the Service.

MicroSigns is an educational platform designed to help users learn how to recognize facial expressions and micro-expressions. MicroSigns does not use your camera, does not analyze your face, does not identify you through facial recognition, and does not infer your emotions from biometric data unless we explicitly introduce such a feature in the future and provide a separate privacy notice and legal basis.

1. Who We Are

MicroSigns is operated by NON | NÉGOCIABLE, a French company.

Legal name: NON | NÉGOCIABLE
Legal form: SASU
Registered office: 38 rue des Aqueducs 69005 Lyon - FRANCE
Registration number: 989 325 725
VAT number: FR93989325725
Contact email: legal@micro-signs.com

For the purposes of the General Data Protection Regulation, MicroSigns acts as the data controller for the personal data described in this Privacy Policy, unless otherwise stated.

We have not appointed a Data Protection Officer at this stage. You may contact us about privacy matters at privacy@micro-signs.com.

2. Scope of This Privacy Policy

This Privacy Policy applies to:

  • the MicroSigns website, including micro-signs.com and related subdomains;
  • user accounts and authentication flows;
  • free and premium training features;
  • payment and checkout flows;
  • support, legal, and customer communications;
  • technical logs, security logs, and usage analytics; and
  • cookies and similar technologies used on the Service.

This Privacy Policy does not apply to third-party websites, services, platforms, or applications that we do not control, even if they are linked from MicroSigns.

3. Personal Data We Collect

We collect different categories of personal data depending on how you use MicroSigns.

CategoryExamplesSource
Account dataEmail address, user ID, authentication method, account status, access levelYou / authentication provider
Profile and onboarding dataName or display name if provided, country, professional role, learning context, preferencesYou
Training and usage dataGame attempts, selected difficulty, answers, scores, progression, unlocked features, session activity, timestampsYour use of the Service
Payment and billing dataPurchase status, product purchased, transaction ID, billing country, tax information, invoice information, payment confirmationYou / payment provider
Technical dataIP address, device type, browser, operating system, language, approximate location, pages visited, error logs, security logsYour device / hosting and infrastructure providers
Support and communication dataEmails, support requests, refund requests, legal requests, feedback, messages and related metadataYou
Cookie and tracker dataCookie IDs, consent choices, session cookies, analytics events if enabledYour browser / consent management tools

4. Data We Do Not Intentionally Collect

MicroSigns does not intentionally collect special categories of personal data such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, health data, sex life, sexual orientation, or biometric data for identification purposes.

MicroSigns does not require you to upload images of yourself, activate your camera, provide video recordings, or submit biometric identifiers to use the current version of the Service.

The facial expression images used in MicroSigns training exercises are part of our educational dataset. They are not used to identify you and are not generated from your own face.

Please do not submit sensitive personal data through support emails, feedback forms, or other free-text fields unless strictly necessary.

5. How We Use Personal Data

We use personal data for the following purposes:

  • to provide access to the MicroSigns website and training platform;
  • to create, authenticate, manage, and secure user accounts;
  • to provide free and premium features according to your access level;
  • to process payments, confirm purchases, prevent fraud, and manage billing records;
  • to save your progression, preferences, scores, and training history where applicable;
  • to improve the Service, debug errors, monitor performance, and understand feature usage;
  • to protect the Service, users, infrastructure, intellectual property, and dataset;
  • to detect abuse, scraping, fraud, unauthorized access, and security incidents;
  • to provide customer support and respond to your requests;
  • to send transactional emails, such as login links, account notifications, purchase confirmations, and security notices;
  • to send marketing communications only where permitted by law and with any required consent;
  • to comply with accounting, tax, legal, regulatory, and consumer protection obligations; and
  • to establish, exercise, or defend legal claims.

6. Legal Bases Under the GDPR

If you are located in the European Union, the European Economic Area, the United Kingdom, or another jurisdiction requiring a legal basis for processing, we rely on the following legal bases:

PurposeLegal Basis
Providing the Service and managing accountsPerformance of a contract
Processing purchases and premium accessPerformance of a contract
Invoices, accounting, tax and compliance recordsLegal obligation
Security, fraud prevention, abuse detection and dataset protectionLegitimate interests and, where applicable, legal obligation
Product improvement and internal analyticsLegitimate interests or consent, depending on the technology used
Non-essential cookies and marketing analyticsConsent, where required
Customer support and legal requestsPerformance of a contract, legitimate interests, or legal obligation
Direct marketingConsent or legitimate interests, depending on applicable law

7. Account Authentication

MicroSigns may use email authentication, magic links, password-based authentication, or third-party login providers such as Google Sign-In.

If you choose to sign in with a third-party provider, we may receive basic account information such as your email address, name or display name, profile image if provided by the provider, and authentication identifiers. We use this information only to create, secure, and manage your MicroSigns account.

Your use of third-party login providers may also be subject to their own privacy policies and account settings.

8. Payments and Stripe

Payments are processed by third-party payment providers such as Stripe. We do not store your full payment card number, card security code, or full payment credentials on our own servers.

We may receive payment-related information from the payment provider, such as your payment status, transaction ID, product purchased, billing country, tax calculation, invoice status, refund status, and limited billing details.

Payment providers may process your data as independent controllers for certain purposes, such as fraud prevention, regulatory compliance, payment network rules, and anti-money laundering obligations.

9. Cookies and Similar Technologies

MicroSigns may use cookies, local storage, pixels, SDKs, and similar technologies to operate, secure, personalize, measure, and improve the Service.

We may use the following categories of cookies and similar technologies:

  • Strictly necessary cookies: required for authentication, security, session management, payment flow, consent storage, and core website functionality.
  • Preference cookies: used to remember settings such as language, display preferences, or interface choices.
  • Analytics cookies: used to understand how users interact with the Service, measure performance, and improve the product.
  • Marketing cookies: used only if enabled, for campaign measurement, retargeting, or advertising attribution.

Where required by law, we will ask for your consent before placing non-essential cookies or similar trackers on your device. You can change or withdraw your cookie choices through Cookie Policy.

You can also configure your browser to block or delete cookies. Blocking strictly necessary cookies may prevent parts of the Service from working properly.

10. Analytics

We may use privacy-conscious analytics to understand aggregate usage patterns, identify bugs, improve learning flows, and monitor the performance of the Service.

Where analytics involves non-essential cookies or similar technologies, we will obtain consent where required by applicable law.

We do not use analytics data to make automated decisions that produce legal or similarly significant effects concerning you.

11. Emails and Communications

We may send you transactional emails necessary for the Service, including login links, account security notices, payment confirmations, receipts, refund updates, support replies, and important legal or service notices.

We may send marketing emails only where permitted by applicable law. You can unsubscribe from marketing emails at any time by using the unsubscribe link or contacting us.

You cannot opt out of strictly necessary transactional or legal communications unless you stop using the Service and close your account.

12. How We Share Personal Data

We do not sell your personal data in the ordinary meaning of selling it for money.

We may share personal data with the following categories of recipients:

  • hosting, infrastructure, database, and storage providers;
  • authentication providers;
  • payment processors and billing providers;
  • email delivery and communication providers;
  • analytics and monitoring providers, if enabled;
  • security, anti-fraud, and abuse-prevention providers;
  • professional advisors, such as lawyers, accountants, and auditors;
  • public authorities, regulators, courts, or law enforcement where legally required; and
  • successors or potential successors in connection with a merger, acquisition, restructuring, financing, or sale of assets.

We require service providers acting on our behalf to process personal data only under appropriate contractual, confidentiality, security, and data protection obligations.

13. International Data Transfers

MicroSigns is operated from France. Some of our service providers may process personal data in countries outside your country of residence, including outside the European Union or European Economic Area.

When we transfer personal data internationally, we use appropriate safeguards where required by law. These safeguards may include adequacy decisions, the EU-U.S. Data Privacy Framework for certified U.S. organizations, Standard Contractual Clauses, data processing agreements, technical protections, or other lawful transfer mechanisms.

You may contact us if you want more information about the safeguards used for international data transfers.

14. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Data CategoryTypical Retention Period
Account dataFor as long as your account remains active, then deleted or anonymized within a reasonable period unless retention is required by law or legitimate security reasons.
Training and progression dataFor as long as needed to provide your account features, unless you request deletion or we anonymize the data for product analytics.
Payment and invoice recordsKept for the period required by accounting, tax, payment, and legal obligations, which may be up to 10 years depending on applicable law.
Security and technical logsKept for a limited period appropriate for security, troubleshooting, abuse prevention, and audit purposes, unless longer retention is needed for investigation or legal claims.
Support communicationsKept as long as needed to handle your request, maintain records of our response, and defend legal claims.
Cookie consent recordsKept for the period necessary to remember and document your consent choices.

We may retain anonymized or aggregated data that no longer identifies you.

15. Security

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction.

These measures may include access controls, authentication protections, private storage, temporary signed URLs for protected assets, encryption in transit, provider-level security controls, logging, monitoring, backups, and internal access restrictions.

No online service can be guaranteed to be completely secure. You are responsible for keeping your login credentials, email account, devices, and authentication methods secure.

16. Data Breaches

If we become aware of a personal data breach affecting your personal data, we will assess the incident and take appropriate measures.

Where required by applicable law, we will notify the relevant supervisory authority and affected users within the legally required timeframe.

17. Your Rights Under the GDPR

If you are located in the European Union, the European Economic Area, the United Kingdom, or another jurisdiction with similar rights, you may have the following rights:

  • Access: request a copy of the personal data we hold about you;
  • Rectification: ask us to correct inaccurate or incomplete personal data;
  • Erasure: ask us to delete your personal data in certain circumstances;
  • Restriction: ask us to restrict certain processing activities;
  • Objection: object to processing based on legitimate interests or direct marketing;
  • Portability: request a copy of certain data in a structured, commonly used, machine-readable format;
  • Withdrawal of consent: withdraw consent at any time where processing is based on consent;
  • Complaint: lodge a complaint with a data protection authority.

In France, you may contact the Commission Nationale de l’Informatique et des Libertés (CNIL) if you believe your rights have not been respected.

To exercise your rights, contact us at privacy@micro-signs.com. We may need to verify your identity before responding.

18. California Privacy Notice

This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to MicroSigns.

In the past 12 months, we may have collected the following categories of personal information:

  • Identifiers: email address, account ID, IP address, authentication identifiers;
  • Commercial information: purchases, premium access status, transaction records;
  • Internet or network activity: pages viewed, device information, logs, usage events;
  • Geolocation data: approximate location inferred from IP address or billing country;
  • Inferences: limited product preferences or learning context inferred from your usage or onboarding answers;
  • Customer support information: messages and requests you send to us.

We collect and use this information for the business and commercial purposes described in this Privacy Policy, including providing the Service, processing payments, securing accounts, preventing fraud, improving the product, and complying with legal obligations.

We disclose personal information to service providers and contractors for the purposes described in this Privacy Policy.

We do not knowingly sell personal information. We do not knowingly share personal information for cross-context behavioral advertising unless we clearly disclose that practice and provide any required opt-out mechanism.

We do not knowingly sell or share personal information of users under 16.

California residents may have the right to:

  • know what personal information we collect, use, disclose, sell, or share;
  • request access to specific pieces of personal information;
  • request deletion of personal information;
  • request correction of inaccurate personal information;
  • opt out of sale or sharing of personal information, where applicable;
  • limit the use and disclosure of sensitive personal information, where applicable; and
  • not be discriminated against for exercising privacy rights.

To exercise your California privacy rights, contact us at privacy@micro-signs.com.

Where legally required, we will honor browser-based opt-out preference signals such as Global Privacy Control for sale or sharing opt-outs.

19. Other U.S. State Privacy Rights

Depending on your U.S. state of residence and whether the relevant law applies to MicroSigns, you may have additional rights, including rights to access, correct, delete, obtain a portable copy of your data, opt out of targeted advertising, opt out of sale of personal data, or appeal a privacy request decision.

You may submit a privacy request by contacting us at privacy@micro-signs.com. If an appeal right applies and we deny your request, we will explain how you may appeal.

20. Children’s Privacy

MicroSigns is not directed to children under 13 and we do not knowingly collect personal information from children under 13.

If you are under 13, you must not use MicroSigns, create an account, or provide personal information to us.

If we learn that we have collected personal information from a child under 13 without appropriate parental consent, we will take reasonable steps to delete that information.

Users between 13 and 16 should use MicroSigns only with permission from a parent or legal guardian where required by applicable law.

21. Automated Decision-Making

MicroSigns may automatically calculate scores, progression, access level, training history, or feature availability based on your activity and purchase status.

We do not use automated decision-making that produces legal or similarly significant effects concerning you, such as employment decisions, credit decisions, education admissions, insurance decisions, law enforcement decisions, or healthcare decisions.

22. AI, Facial Expressions and Biometric Data

MicroSigns teaches users to recognize facial expressions using educational content and a curated training dataset.

The current version of MicroSigns does not:

  • use facial recognition to identify users;
  • collect facial geometry from users;
  • analyze users’ faces through a camera or uploaded image;
  • infer users’ emotions from their biometric data;
  • create biometric templates of users;
  • make decisions about users based on emotional state; or
  • provide emotion recognition services for employers, schools, law enforcement, or surveillance purposes.

If we introduce features involving camera input, user-uploaded facial images, biometric processing, or emotion inference about users, we will update this Privacy Policy and implement additional consent, transparency, security, and compliance measures before such processing begins.

23. Do Not Track and Global Privacy Control

Some browsers provide “Do Not Track” signals. Because there is no single universally accepted standard for Do Not Track signals, we may not respond to them unless required by law.

Where required by applicable privacy law, we will recognize legally valid opt-out preference signals, such as Global Privacy Control, for applicable opt-out rights.

24. How to Exercise Your Rights

You can exercise your privacy rights by contacting us at:

Email: privacy@micro-signs.com
Postal address: 38 rue des Aqueducs 69005 Lyon - FRANCE

Please include enough information for us to identify your account and understand your request. We may ask for additional information to verify your identity, protect your account, and prevent unauthorized disclosure or deletion.

We will respond within the timeframe required by applicable law. If we cannot fulfill your request, we will explain why, unless legally prohibited.

25. Account Deletion

You may request deletion of your MicroSigns account by contacting us at privacy@micro-signs.com.

Deleting your account may delete or anonymize your profile, training history, preferences, and account access data, subject to technical constraints and legal retention obligations.

Some information may be retained after account deletion where necessary for legal compliance, payment records, fraud prevention, security, dispute resolution, backup integrity, or enforcement of our Terms & Conditions.

26. Backup Copies

Personal data may remain in encrypted or protected backups for a limited period after deletion from active systems.

Backup data is retained for security, resilience, and disaster recovery purposes and is not used for ordinary business operations unless restoration is necessary.

27. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our data practices, legal requirements, providers, cookies, or security measures.

The updated version will be posted on this page with a revised “Last updated” date. If changes are material, we will take reasonable steps to notify users, for example through the website, account interface, or email.

Your continued use of the Service after the updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy.

28. Contact

For any privacy question, request, complaint, or concern, contact us at:

MicroSigns / NON | NÉGOCIABLE
Email: support@micro-signs.com
Legal email: legal@micro-signs.com
Postal address: 38 rue des Aqueducs 69005 Lyon - FRANCE