This policy describes WebPion’s actual data flows: local file processing, Contact, GPTO administration, aggregate measurement, browser storage and infrastructure limits.
WebPion 4.7.6Updated: 1 September 2026
Operator and privacy contact
WebPion is operated by Koperateur Consulting®, Pau (64000), France, SIREN 828 995 399. Mehdi Kachouri is service manager and publication director.
Privacy and rights requests are routed through the secure Contact form rather than a publicly exposed email address.
For an operation explicitly marked local, file content is processed in the browser on the device and WebPion does not receive that content to perform the operation.
Page/resource loading is distinct from file-content processing and exact capabilities depend on the tool and browser.
Data not intentionally stored by application telemetry
WebPion application statistics are not designed to store file names, local paths, file content, IP addresses in the statistics database, full user-agent strings, fingerprints or public-account identifiers.
This does not mean no technical logs can exist at server, proxy or hosting level for operation and security.
Aggregate operational measurement
First-party operational telemetry may include tool/operation categories, broad file family, input/output bytes, accepted/success/error state, processing duration, UI language and a broad browser family when supplied.
Its purpose is service operation and error understanding, not advertising profiling or cross-site tracking. Public counters are separated from encrypted administrative detail.
Submitting Contact intentionally transmits name or pseudonym, email address, message and selected language to WebPion for reply and administrative follow-up.
This is not local file processing. Correctly configured HTTPS protects transport with TLS. The sensitive application payload is encrypted at rest in GPTO using the existing authenticated-encryption mechanism; persistence must fail closed if mandatory encryption is unavailable.
GPTO is WebPion’s restricted administration area, using a short-lived one-time link and hardened server session without a permanent public user account.
Sensitive contact payloads and detailed administrative statistics are encrypted at rest where implemented. Encryption keys must remain outside public code and the web root.
Cookies and browser storage
Public pages set no advertising or profiling cookie. GPTO uses a separate administrator session cookie containing a random session identifier, not contact content or statistics.
localStorage and IndexedDB are documented separately and are not described as cookies. The 4.7.4 code audit found no application feature relying on sessionStorage.
WebPion is hosted by Infomaniak Network SA in Switzerland. Hosting infrastructure may create technical logs needed for operation, abuse prevention, diagnostics or security.
The lack of IP storage in the WebPion application statistics database is not presented as proof that infrastructure cannot process technical connection data.
Retention and deletion
Contact and operational data are retained only as long as needed for operational, security, request-follow-up or applicable legal needs. Exact periods must follow configured GPTO procedures when defined.
WebPion does not publish an invented universal retention period that is not enforced by code or policy.
Data rights and requests
Depending on the processing and applicable law, rights may include access, rectification, erasure, restriction, objection or portability.
Requests should use Contact and provide enough information to identify the request without collecting unnecessary additional data.