Privacy Policy
Last updated: September 29, 2026
Gustave's legal documents are published in English and in French, with the same content. For consumers residing in France, the French version prevails in case of discrepancy; in all cases, any ambiguity is interpreted in the way most favourable to you.
This policy explains how 3h53 SAS ("we", "us") processes your personal data when you use the Gustave browser extension (the "Extension") and the meetgustave.app website (the "Website"). Terms defined in the Terms of Service have the same meaning here.
Key points
- The text of your conversations does not leave your browser. The Extension estimates tokens on your device and only sends us numbers and technical data. The single exception is Verified mode, which you turn on yourself: the text then passes through our server for the count only and is not kept.
- No advertising, no analytics, no sale of your data, and no training of artificial intelligence models. The Website only uses essential cookies.
- Your page is private by default: it becomes public (shareable page, leaderboards) only if you switch it on, and you can switch it off at any time.
- You stay in control: counting can be turned off site by site, you can delete your account and exercise your rights.
1. Data controller
The data controller is 3h53 SAS, 16 A rue du Pré d'Avril, 74940 Annecy, France. For any question about your data: hello@meetgustave.app.
We have not appointed a data protection officer, as this is not mandatory for our activity.
2. The browser Extension
2.1 What the Extension reads, only on your device
The Extension only runs on chatgpt.com (and chat.openai.com), claude.ai and gemini.google.com. On these pages, it reads the network responses and the displayed text of your conversations to estimate, on your device, the number of tokens of each new message. This text is processed in memory: the Extension does not store it and does not send it to us, except in Verified mode. It does not read other websites or your browsing history. These reads are strictly necessary for the service you requested by installing the Extension.
2.2 What the Extension sends us
Only while you are signed in, the Extension sends us, for each counted message:
- the estimated number of tokens, the site concerned (chatgpt, claude or gemini), the role of the message (yours or the assistant's reply) and the estimation method used;
- the date and time of the message;
- an idempotency key: the one-way SHA-256 hash of the conversation and message identifiers, which ensures each message is counted only once. We never receive these identifiers, nor the content of the message.
It also sends the Extension's version, your session information (to authenticate you) and the choices you make from your new tab (outfit, content, photo). If you are not signed in, nothing is sent to us: counts wait in your browser and only reach us after you sign in, if they are still recent.
2.3 Verified mode (optional)
For claude.ai and gemini.google.com, you can save your own API key to get an exact count. Your key is stored only in your browser, never on our servers. For each new message on the site concerned, the Extension sends the message text and your key, encrypted in transit, to our server function, which queries the provider's official token-counting endpoint (Anthropic for claude.ai, Google for gemini.google.com) and records only the resulting number of tokens. We neither store nor log the text or the key.
The provider concerned receives the text and your key under the contract between you and that provider for your API account; its own privacy policy applies. Your messages may contain personal, even sensitive, information: only turn this mode on if you accept this. You can turn it off at any time by removing your key; counting then goes back to local estimates.
2.4 Data stored in your browser
The Extension keeps in its local storage: your settings (language, tracked sites, Verified mode), any API keys, the queue of counts waiting to be sent, the hashes of messages already counted (to avoid duplicates), your daily statistics, a copy of your profile (balance, inventory, scene) and your session with the associated email address. This data stays on your device and is erased when you uninstall the Extension.
2.5 Permissions requested
- storage: save this data on your device;
- alarms: schedule the periodic synchronisation of your counts;
- access to chatgpt.com, chat.openai.com, claude.ai and gemini.google.com: estimate tokens on these sites only;
- communication with our servers: synchronise your counts and your account.
The Extension also replaces your browser's New Tab page with Gustave's.
2.6 Limited Use commitment (Chrome Web Store)
The use of information received by the Gustave Extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. In particular:
- we only use this data to provide and improve the Extension's single purpose: turning your use of the AI Services into gems and displaying your Gustave;
- we only transfer it as necessary for this purpose (to our processors), to comply with the law, to protect against malware, spam, phishing, fraud or abuse, or as part of a merger, acquisition or sale of assets, with your prior explicit consent;
- we never sell it, never use or transfer it for personalised advertising, never pass it on to data brokers, and never use it to determine creditworthiness or for lending purposes;
- nobody reads it, except with your explicit consent for specific data (for example in a support request), for security purposes (for example to investigate abuse), to comply with the law, or once aggregated and anonymised for our internal operations.
The same commitments apply to the Firefox version of the Extension.
3. The Website and your account
3.1 Data we process
- Account: email address, username, display name, language, creation date, sign-in data (one-time codes and links, sign-in dates).
- Game: estimated and verified tokens, level, gem balance and history of gem movements, inventory (items and edition numbers), outfit, new tab settings (greeting name, widgets), public or private status of your profile, promotional codes redeemed.
- Your content: sign message, web panel website, frame photo, banner text, links, and the preview image of your scene, drawn in your browser.
- Market: listings, sales and purchases (item, price, date, counterparty).
- Moderation and anti-cheat: reports you send or that concern you, decisions, complaints, capped or flagged counts and their reasons, adjustments.
- Purchases: order (item, amount, currency, status, date) and payment identifiers at Stripe. We never receive your bank card details.
- Exchanges with us: your messages and our replies.
- Technical data: IP address, browser type, date and time of requests, error logs, kept by our hosting providers to run and secure the Service.
Signing in with Google is optional. If you choose it, Google (Google Ireland Limited if you live in the European Economic Area or Switzerland) authenticates you and sends us your email address, as well as your name and the address (URL) of your profile picture, as provided by Google. Our authentication provider, Supabase, stores them with your account. We only use your email address, to identify your account: your name and picture are not displayed on the Service. The legal basis is the performance of the contract (your account). Google processes this sign-in under its own privacy policy (https://policies.google.com/privacy).
3.2 What is public
Unless your profile is private, the following are visible to everyone:
- your public page: username, display name, level, estimated and verified tokens, rank, sign-up date, scene, collection with edition numbers, and your content;
- the leaderboards: username, display name, level, tokens and outfit;
- the Market: your listings, sales and purchases, with your username.
Your profile is private by default: it becomes public only if you switch it on. If you make it private again, your page is no longer accessible, you leave the leaderboards and the Market shows you as "a player". The frame photo and the preview image are stored in public file storage: anyone who knows their address can display them until they are deleted. Pages and images already shared may also remain in the caches of third-party services (social networks, search engines).
3.3 Emails
We only send you emails related to the Service: sign-in, purchases, security, moderation and important changes to our terms. We do not send newsletters; if we ever offered one, it would require your prior consent.
4. Cookies and trackers
The Website only uses strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
sb-…-auth-token |
Sign-in session and security of authentication | Up to 400 days, or until you sign out |
NEXT_LOCALE |
Remembers your choice of language | 12 months |
Cloudflare security cookies (for example __cf_bm), where applicable |
Protects the Website against bots and attacks | Short duration set by Cloudflare (30 minutes for __cf_bm) |
These cookies are exempt from consent (Article 82 of the French Data Protection Act and the guidelines of the CNIL, the French data protection authority): this is why the Website shows no cookie banner. We use no analytics tool, no advertising tracker and no social network plug-in. The share buttons are simple links: nothing is sent to the social network concerned until you click. The Extension does not use cookies; it uses the storage described in section 2.4.
When a public page shows a web panel, the website chosen by the player is loaded from that website's own servers, in an isolated frame. That website may receive technical data such as your IP address and remains responsible for its own processing. We do not pass on any data from your account to it.
5. Purposes and legal bases
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Creating and managing your account, signing you in | Performance of the contract (Terms of Service) |
| Estimating tokens, crediting gems, managing levels, items, outfit and public page | Performance of the contract |
| Verified mode | Consent, which you can withdraw at any time |
| Leaderboards and public Market history | Performance of the contract and legitimate interest (transparency and friendly competition between players) |
| Fighting cheating and fraud, security of the Service | Legitimate interest (integrity of the game and security) |
| Reports, moderation and complaints | Legal obligation (EU Digital Services Act, French LCEN) and legitimate interest |
| Sale of Premium Items and invoicing | Performance of the contract |
| Accounting and retention of orders | Legal obligation |
| Retention of data identifying the authors of content | Legal obligation (French LCEN and Decree No. 2021-1362 of 20 October 2021) |
| Answering your requests and handling your rights | Legal obligation and legitimate interest |
| Establishing, exercising or defending our rights | Legitimate interest |
We take no decision producing legal effects concerning you or similarly significantly affecting you based solely on automated processing (Article 22 GDPR). Anti-cheat caps apply in the same way to everyone, and automatic hiding (from leaderboards, of reported content) is temporary and followed by human review before any sanction.
6. Recipients and processors
Your data is only accessible to authorised members of our team, within the limits of their tasks (support, moderation, anti-cheat), and to our processors:
| Provider | Role | Location |
|---|---|---|
| Supabase Pte. Ltd. | Database, authentication, file storage, server functions, sending of sign-in emails | Data hosted in the EU (Paris, AWS eu-west-3); company established in Singapore |
| Cloudflare, Inc. | Website hosting, content delivery network, security | Global network; company established in the United States |
| Stripe Payments Europe, Limited | Payments and tax calculation | Ireland; possible transfers within the Stripe group, in particular to the United States |
Stripe acts as our processor for payment processing and as an independent controller for its own obligations, in particular fraud prevention and anti-money laundering (see stripe.com/privacy).
If you sign in with Google, Google (Google Ireland Limited if you live in the European Economic Area or Switzerland) authenticates you as an independent controller, under its own privacy policy, and sends us the data described in section 3.1; it is not our processor.
Your data may also be disclosed: in Verified mode, to the provider of the service concerned, at your request (section 2.3); to the public, for the information described in section 3.2; to administrative or judicial authorities, where the law requires it; to our advisers (lawyer, accountant), who are bound by professional secrecy; to an acquirer in the event of a merger, acquisition or sale of assets, in compliance with this policy and, for data coming from the Extension, with your prior consent. We never sell your data.
7. Transfers outside the European Union
Our database is hosted in the European Union. However, some providers are established outside the EU or may access data from abroad (Supabase in Singapore, Cloudflare and the Stripe group in the United States), and some technical processing, such as Cloudflare's network or server functions, may run in data centres located outside the EU. These transfers are governed by the European Commission's standard contractual clauses and, for certified US companies, by the EU–US Data Privacy Framework. In Verified mode, the provider of the service you chose may process the text outside the EU, under its own terms. You can obtain a copy of the applicable safeguards at hello@meetgustave.app.
8. Retention periods
| Data | Retention period |
|---|---|
| Account, game data and content | Until your account is deleted (within 30 days if you request deletion by email), then erased from backups within 7 days |
| Detailed counts (message by message) and anti-cheat signals | 13 months, then aggregated: only totals are kept |
| Reports, moderation decisions and complaints | 1 year after the case is closed |
| Market history | As long as the accounts concerned exist; once your account is deleted, your username no longer appears in it |
| Orders and accounting records | 10 years (Article L123-22 of the French Commercial Code), no longer linked to your account once it is deleted |
| Technical logs | 30 days |
| Data identifying the authors of content, to the extent we collect it | Periods set by Decree No. 2021-1362: up to 1 year for account and connection data, 5 years after the account is closed for identity data such as the email address; access restricted to requests from the authorities |
| Exchanges with us | 3 years after the last exchange |
| Text and API key in Verified mode | Not kept: only for the duration of the request |
| Extension data | On your device, until you uninstall the Extension |
9. Security
We implement appropriate technical and organisational measures, including: encryption of communications (HTTPS enforced across the Website); strict database access rules, each player accessing only their own data and sensitive operations (gems, inventory, Market, purchases) going through controlled server-side functions; administrative access limited to authorised people; data minimisation (no storage of conversation text, message identifiers replaced by a hash, API keys kept on your device); payments entrusted to Stripe, which is PCI DSS certified. If a personal data breach poses a risk to your rights, we notify the CNIL and, where the law requires it, the people concerned.
10. Your rights
You have the rights of access, rectification, erasure, restriction, objection (to processing based on our legitimate interest) and portability (for the data you provided to us, processed on the basis of the contract or your consent). You can withdraw your consent at any time, without affecting processing already carried out, and give instructions on what happens to your data after your death (Article 85 of the French Data Protection Act).
Several actions are available directly in the Service: changing your username or content, making your profile private, deleting your account, turning off counting for a site. For anything else, write to hello@meetgustave.app from your account's email address. We answer within one month, which may be extended by two months for complex requests, and may ask you to prove your identity if we have reasonable doubts.
If you believe your rights are not respected, you can lodge a complaint with the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France; www.cnil.fr) or with the data protection authority of your country of residence.
11. Minors
The Service is not intended for children under 15. If you hold parental authority and believe that a child under 15 has created an account, write to us at hello@meetgustave.app: we will delete it.
12. Changes
We may update this policy. For any significant change, we will notify you by email or in the Service before it takes effect. The date of the last update appears at the top of this page.
13. Contact
hello@meetgustave.app — 3h53 SAS, 16 A rue du Pré d'Avril, 74940 Annecy, France. See also the Legal Notice.