Legal notice

Privacy Policy

What we collect, why we collect it, who processes it on our behalf, and what you can ask us to do about it. Written to be read, not to be skipped.

Effective August 9, 2026 Last updated August 9, 2026 Version 2.0
In one paragraph

We collect your first name and email address when you ask for a guide or subscribe, plus the information needed to process a purchase. We use it to send you what you asked for and to run the business. We do not sell your personal information and we never have. You can access, correct or delete your data at any time by writing to hello@chronobiohacker.com, and you can unsubscribe from every email with one click.

01

Who is responsible for your data

ChronoBiohacker is a science-based longevity and biohacking publication covering metabolic health, circadian biology, longevity protocols and consumer health technology.

Data controllerChronoBiohacker — sole trader under the French micro-entreprise regime
SIREN514 290 410
Registered address6 rue d’Armaillé, 75017 Paris, France
Governing lawFrench data protection law and the EU General Data Protection Regulation (Regulation 2016/679), together with the US state privacy laws described in section 09

We are not required to appoint a Data Protection Officer, and we have not appointed one. Privacy requests are handled directly at the address above.

02

Newsletter and free guides

When you request a free guide or subscribe to the ChronoBriefing, we collect your first name and email address, and we record which form you used and when.

PurposeDelivering the guide you requested and sending the educational email sequence you signed up for
Legal basisYour consent — Article 6(1)(a) GDPR
ProcessorBrevo (Sendinblue SAS, France) — email delivery and automation
RetentionUntil you unsubscribe, then deleted within 30 days except where we must keep a suppression record to honor your unsubscribe

We record which of our four subject areas you told us you were interested in — metabolic health, circadian rhythm, longevity protocols or health technology — so that we send you relevant emails rather than all of them. We treat that preference carefully: it is used only to choose which emails you receive, it is never used to infer that you have any medical condition, and it is never disclosed to anyone.

Every email carries a one-click unsubscribe link. It works immediately, you are never asked why, and you never have to log in.

03

Purchases

When you buy a digital product we collect the data needed to process the order and deliver the product: your name, your email address, your billing country and the transaction record.

PurposeProcessing your order, delivering your product, customer support, accounting and tax compliance
Legal basisPerformance of a contract — Article 6(1)(b) — and legal obligation — Article 6(1)(c) GDPR
ProcessorsStripe and PayPal — payment processing and fraud prevention
Retention10 years for accounting records, as required by article L123-22 of the French Commercial Code

We never see, receive or store your card number. Card details are captured directly by Stripe or PayPal under their own terms and security standards. Each of them acts as an independent controller for its own fraud prevention and regulatory obligations.

04

Contact form and correspondence

If you write to us through the contact form or by email, we keep your message and our reply for as long as needed to deal with your request and for a reasonable period afterwards — normally three years — so that we have a record if you write again about the same thing.

Legal basis: our legitimate interest in answering you — Article 6(1)(f) GDPR. Form submissions are stored on our hosting and delivered by email through Brevo. The form uses Google reCAPTCHA to block automated spam, which involves Google receiving your IP address and interaction data under its own privacy policy.

Please do not send us medical information about yourself. We are not able to advise on it, and we would rather you did not entrust it to an inbox.

05

Technical processing that happens automatically

Some data is processed simply because the site has to work.

  • Hosting — IONOS stores the site and keeps server logs including IP addresses, for security and troubleshooting. Legal basis: legitimate interest in operating and securing the site.
  • Web fonts — our typefaces are hosted on our own server. No font request is sent to Google or to any other third party.
  • Security — connections are encrypted over HTTPS, and we keep limited logs of failed access attempts.
06

Cookies and analytics

We use strictly necessary cookies to make the site work — these do not require consent and cannot be switched off without breaking the site. We do not use reCAPTCHA anywhere on the site; spam protection on our forms works without setting any Google cookie or loading any Google script.

  • Analytics cookies — Google Analytics, used to understand which content is read and where readers struggle. Loaded only after you consent, and never used to identify you personally. Retention: 26 months.
  • Advertising cookies — none at present. We do not currently run the Meta pixel or any other advertising or retargeting tool. If that changes, we will update this policy and our consent banner before any such tool goes live, not after.

Cookie consent is managed through the banner shown on your first visit, built with Complianz. You can change or withdraw your choice at any time by reopening your cookie preferences from the link in the site footer, or through your browser settings. Withdrawing consent does not affect processing already carried out lawfully before you withdrew it.

07

Who processes data on our behalf

BrevoEmail delivery, automation, form handling — France (EU)
IONOSWebsite hosting and server logs — Germany (EU)
StripePayment processing — Ireland and United States
PayPalPayment processing — Luxembourg and United States
GoogleWeb fonts, reCAPTCHA, and analytics where enabled — United States
MetaAdvertising measurement where enabled — United States

We do not sell personal information, we do not rent mailing lists, and we do not disclose your data to anyone except the processors above, or where the law requires it.

08

International transfers

Some of our processors are established in, or transfer data to, the United States. Where that happens we rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, and on Standard Contractual Clauses together with supplementary measures where it is not.

You may request a copy of the transfer safeguards applicable to any specific processor by writing to us.

09

Your rights if you are in the United States

Most of our readers are in the United States. California residents have rights under the CCPA as amended by the CPRA, and residents of a growing number of other states — including Colorado, Connecticut, Virginia, Texas, Oregon and others — have comparable rights under their own laws. We apply the following to every US resident, regardless of state, because operating two standards would be worse for everyone.

What we collect, and from where

  • Identifiers — first name, email address, IP address. Collected directly from you, or automatically from your device.
  • Commercial information — records of products purchased. Collected directly from you.
  • Internet activity — pages viewed, emails opened, links clicked. Collected automatically.
  • Approximate location — country or region, derived from IP address. Collected automatically.
  • Inferences — which of our four subject areas appears to interest you, used solely to choose which emails to send you.

What we do not do

We do not sell personal information, and we have not sold any in the preceding twelve months. We do not knowingly collect sensitive personal information as California law defines it, and we do not use or disclose personal information for purposes beyond those described in this policy. We honor Global Privacy Control signals sent by your browser as a valid opt-out request.

Your rights

  • Right to know — what we have collected about you, where it came from, why we collected it and who received it
  • Right to delete — subject to exceptions where we must retain records, such as transaction records for tax purposes
  • Right to correct — inaccurate personal information
  • Right to opt out — of any sale or sharing of personal information, and of targeted advertising
  • Right to limit — the use of sensitive personal information
  • Right to non-discrimination — exercising any of these rights never affects the price you pay, the products you can buy, or the content you can read
  • Right to appeal — if we decline a request, you may appeal by replying to our decision, and several state laws require us to explain our reasoning

Write to hello@chronobiohacker.com to exercise any of these. We respond within 45 days and will tell you if we need the further 45 days that state law allows. You may use an authorized agent; we will ask for proof of their authority. We verify requests by confirming control of the email address concerned, and we ask for nothing more than that.

10

Your rights under the GDPR

If you are in the European Economic Area or the United Kingdom, you have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to receive it in a portable format, to object to processing based on legitimate interest or to direct marketing, and to withdraw consent at any time without affecting the lawfulness of what came before.

Write to hello@chronobiohacker.com. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

If you are not satisfied with how we have handled your request, you may lodge a complaint with the French supervisory authority:

AuthorityCommission Nationale de l’Informatique et des Libertés (CNIL)
Address3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France

You may also complain to the supervisory authority of your own country of residence within the EEA.

11

Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. Our email automation decides which message to send you next based on which guide you requested and which subject area you selected — that is all it does, and you can leave it at any time.

12

Affiliate links

Some pages contain affiliate links to third-party products. If you follow one and buy something, we may earn a commission at no additional cost to you, and this is disclosed clearly next to the link.

Following an affiliate link takes you to a site we do not control, which may set its own cookies and collect data under its own privacy policy. We have no control over and accept no responsibility for the privacy practices of third parties. Commercial relationships never influence which products we recommend or how we describe the evidence behind them.

13

Security and data breaches

We use encrypted connections, restricted access to accounts holding personal data, multi-factor authentication where our providers support it, and we review the security posture of our processors.

No transmission over the internet is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify the CNIL within 72 hours as required by the GDPR, and we will notify you directly where the risk is high — and where US state law requires notification, we will comply with that as well.

14

Children

This site is intended for adults, and our terms require purchasers to be at least 18. We do not knowingly collect personal information from anyone under 16 in the European Economic Area, or under 13 in the United States as defined by COPPA.

If you believe a child has given us personal information, write to us and we will delete it promptly.

15

Changes to this policy

We update this policy when our practices, our processors or our legal obligations change. The effective date at the top of the page always reflects the current version, and we keep previous versions available on request.

Where a change materially affects how we use data you have already given us, we will tell you by email rather than relying on you noticing a date change.

Privacy requests

Access, correction, deletion, opt-out, or any question about this policy: hello@chronobiohacker.com. A real person reads every message, and you never need an account to exercise a right.