Privacy Policy - MyTwin Lab

Last updated: October 9, 2026

This policy explains how We Are One processes your personal data when you visit or take part in MyTwin Lab (https://mytwinlab.care), and how you can exercise your rights. It does not cover the MyTwin application, whose own policy is available at https://mytwin.care/en/privacy-policy.

1. Key points

  • We only process the data needed to run the Lab. We do not sell it, do not use it for advertising, and use no analytics or advertising trackers.
  • The Lab is open by design: your display name, profile picture, GitHub username, contributions and contribution points are public. Your email address is not.
  • Part of the evaluation of contributions is done by AI. You can always ask for a human review.
  • If you join the Lab community, we send you its news by email. You can unsubscribe at any time, from the link in each newsletter.
  • The Lab is not designed for health data: never upload data about a patient. The only exception is the health story you may choose to share about yourself, with your explicit consent (§ 4.7).
  • You can access, correct or delete your data, and object to some processing, by writing to contact@my-twin.io.

2. Who is responsible for your data

The data controller is We Are One, a French SAS registered with the Trade and Companies Register under number 953 111 960, whose registered office is located at 10 Rue de Penthièvre, 75008 Paris, France, represented by Rubens Valcy.

For any question about your data, contact us at contact@my-twin.io.

3. No health data in the Lab

MyTwin Lab is a research and development platform, not a medical service. It is not hosted by a certified health data host (HDS) and is not designed to process health data.

Our Terms of Use prohibit uploading personal health data or any data about an identifiable patient: challenges rely on public, anonymized or synthetic data. If you notice personal health data in the Lab, report it to us so that we can remove it.

The one exception is the health story a member of the community may choose to share on the Lab (§ 4.7). It is sent directly to the MyTwin contact database, is never published, and is never placed in a challenge.

4. What we process, why, and for how long

4.1 Your account

  • Data: your name, email address and Google account identifier, received when you sign in with Google (we never receive your Google password and do not keep the access tokens Google issues); your display name, GitHub username, profile picture and, where applicable, a short bio; your role in the Lab.
  • Purpose: creating and managing your account, signing you in, displaying your profile.
  • Legal basis: performance of the contract formed by our Terms of Use.
  • Retention: as long as your account exists. An account with no sign-in for 3 years is deleted.

4.2 Taking part in challenges and the Sandbox

  • Data: the challenges and groups you join, your personal task board and workspace information (branch name, repository links); your contributions (titles, descriptions, links to repositories, datasets, models or deployed applications) and the content of the repositories evaluated, including the author and title of commits and pull requests; the Sandbox projects you launch and the projects you star; the reference cases, observations, verdicts, comments and test results you submit in validation challenges; your requests for temporary GPU instances; in-app notifications such as group invitations.
  • Purpose: running challenges, the Sandbox, validation challenges and compute resources.
  • Legal basis: performance of the contract.
  • Retention: as long as your account exists. Files submitted to validation challenges and the responses collected during tests are deleted 12 months after the challenge is completed. The access details of a GPU instance are erased when the instance expires.

4.3 Evaluation, contribution points and leaderboard

  • Data: evaluation reports, scores, contribution points (CP) and ranking.
  • Purpose: evaluating and crediting contributions, and publishing the leaderboard.
  • Legal basis: performance of the contract, and our legitimate interest in recognizing every contribution fairly and transparently.
  • Retention: as long as your account exists.

How the automated part of this evaluation works is described in § 6.

4.4 Challenge discussions and meetings

This processing only takes place on challenges where it is enabled, and team members are informed of it in the challenge.

  • Slack discussions — data: the top-level messages posted by challenge participants in the Slack channel linked to the challenge, with their author's name, read once a day; the author's email address is used only to match them to their Lab account. When a message leads to a reward, we keep an excerpt of 200 characters at most and the reason given by the analysis.
  • Meetings — data: meeting invitations are sent to team members' email addresses through Google Calendar. After a meeting, we retrieve the list of participants (Google identifier and display name) and the transcript from Google Meet, and produce a summary, the decisions taken, the actions agreed and the contributions mentioned. The transcript itself is not stored, and recordings are not retrieved.
  • Purpose: recognizing contributions that are not code, and helping teams coordinate.
  • Legal basis: our legitimate interest in crediting all forms of contribution. You can object to it at any time (§ 11); your messages and meetings will then no longer be analyzed.
  • Retention: reward excerpts, as long as your account exists; meeting summaries and participant lists, 12 months after the challenge is completed.

4.5 Security, abuse prevention and operation

  • Data: server logs and performance traces (pages and routes requested, time, errors, IP address); if you star a Sandbox project without an account, a random identifier stored in a cookie and a keyed hash of your IP address (never the address itself).
  • Purpose: keeping the Lab secure and available, preventing abuse such as coordinated starring, and fixing bugs.
  • Legal basis: our legitimate interest in operating a reliable and fair service.
  • Retention: hashed IP addresses, 30 days; the anonymous identifier, as long as the star it is attached to; logs and traces, 12 months at most.

4.6 Joining the Lab community

When you click « Join the Lab » and leave your email address.

  • Data: your email address; if you choose to give it, who you are (patient or caregiver, clinician, researcher, developer, other); the date of your sign-up, the version of the consent text you accepted, and the page that led you there.
  • Purpose: sending you the Lab's news by email (new challenges, research progress, community life), starting with a welcome email; knowing who joins the Lab, so that what we send is relevant to you.
  • Legal basis: your consent, given by signing up. You can withdraw it at any time, from the unsubscribe link in each newsletter or by writing to contact@my-twin.io; withdrawing it does not affect what was done before.
  • Retention: news is sent until you unsubscribe. Your contact details are deleted 3 years after your last contact with us.

Your sign-up is recorded in the contact database that MyTwin uses for all its websites. If you have also contacted MyTwin elsewhere (for example on mytwin.care) with the same email address, we keep a single record of you.

4.7 Your health story

When, as a member of the community, you share a health experience on the Lab.

  • Data: the text you write, which may contain information about your health or a relative's health; the version of the consent text you accepted; the date. The story is attached to your contact record, so that we can delete it at your request.
  • Purpose: understanding real care journeys, to decide where the human digital twin should help first and to improve MyTwin's services. Stories are read by the MyTwin team only. They are never published and never shared with other members or with third parties; if we quote a story, it is only after removing anything that could identify you.
  • Legal basis: your explicit consent, given by ticking the box under the form. You can withdraw it and have your story deleted at any time by writing to contact@my-twin.io.
  • Retention: as long as your contact record is kept (§ 4.6), unless you ask us to delete it sooner.

Please do not write anything about another person that would allow them to be identified.

4.8 Booking a call

When you book a call with the MyTwin Lab team.

  • Data: your first name and email address, and the reason for the call (creating a twin, a Sandbox project, the scientific committee, or a general request); then, on Lemcal, the time slot you choose.
  • Purpose: organizing the call and following up on your request.
  • Legal basis: steps taken at your request before any agreement, and our legitimate interest in answering you.
  • Retention: 3 years after your last contact with us.

Your first name and email are recorded in the MyTwin contact database (§ 4.6), then sent to Lemcal, where you pick the slot. The booking page itself loads nothing from Lemcal: your browser only contacts Lemcal when you click to choose a time.

4.9 Your requests and our legal obligations

  • Data: your messages and the details of your requests (for example a request to exercise your rights or a content report).
  • Purpose: answering you and complying with our legal obligations.
  • Legal basis: legal obligation.
  • Retention: the time needed to handle the request, then 5 years as evidence.

5. Where the data comes from

Most data comes from you: your profile, your contributions, your messages, your sign-up to the community, your health story, your booking requests. Some comes from other sources:

  • Google, for your identity when you sign in, and for meeting participants and transcripts on challenges where meetings are enabled;
  • GitHub, for the content and history of the repositories linked to a challenge or a Sandbox project;
  • Slack, for the discussions of challenges where it is enabled;
  • Kaggle, for the metadata and metrics of public datasets and models;
  • other members, for example when they invite you to a group or give a verdict on a deliverable you built.

Signing in with Google is required to take part in challenges and the Sandbox; it is not required to join the community, share a health story or book a call. The rest depends on how you choose to take part.

6. Automated evaluation

Part of the evaluation of contributions is automated:

  • code and datasets are scored by AI agents against the evaluation grid published for each challenge;
  • machine-learning models are scored on the metric the challenge defines;
  • discussion messages are analyzed by AI to detect contributions such as ideas, help or reviews;
  • Sandbox projects earn points when they reach star milestones.

The result is converted into contribution points without prior human review. Contribution points and rankings have no legal or financial effect: they have no monetary value and give no right to payment.

You can nonetheless ask for a human review of any evaluation concerning you, explain your point of view and contest the result, by writing to contact@my-twin.io.

The content sent to the AI provider for evaluation is the content of the contribution. The email addresses of commit authors and message authors are not sent.

7. What is visible to others

MyTwin Lab is an open platform. Anyone, including visitors who are not signed in, can see:

  • your display name, profile picture and GitHub username;
  • your contribution points, rank and the date you started contributing;
  • your contributions to public challenges (titles, descriptions, points and dates) and the challenges whose team you belong to;
  • the activity of public challenge repositories, including the author and title of commits and pull requests;
  • the Sandbox projects you launch.

Contributor profile pages ask search engines not to index them.

Members of the same challenge can see what they need to work together, such as the team's progress, meeting summaries and participants. Your email address is never shown to other members. Administrators, and project managers for the challenges they manage, access the data needed to run and moderate the Lab.

8. Service providers and transfers

We rely on the following providers, bound by contractual commitments ensuring the confidentiality and security of your data:

  • Scalingo (France): hosting of the platform and its database.
  • OpenAI (United States): AI evaluation of contributions, analysis of discussions and meeting transcripts. Data sent through the OpenAI API is not used to train OpenAI's models.
  • Google (Ireland / United States): sign-in, Google Calendar and Google Meet.
  • GitHub (United States): challenge repositories and contributors' access to them.
  • Slack (United States): discussion channels of challenges, where enabled.
  • Kaggle (United States): dataset and model metadata and metrics.
  • Scaleway (France): temporary GPU instances.
  • Grafana Labs (European Union region): monitoring and performance traces.
  • Resend (United States): sending the welcome email and the Lab's news.
  • Lemcal, operated by lemlist (France): choosing the slot of a call you book, and its confirmation.

When data is transferred outside the European Union, the transfer relies on the EU-U.S. Data Privacy Framework where the provider is certified under it, or on the Standard Contractual Clauses adopted by the European Commission.

Data may also be disclosed to public authorities when the law requires it.

9. Cookies

MyTwin Lab only uses cookies that are strictly necessary for the service you request. They are exempt from consent, which is why no cookie banner is displayed.

  • access_token — keeps you signed in (15 minutes).
  • refresh_token — renews your session without asking you to sign in again (7 days).
  • sb_anon — remembers the stars you give without an account (1 year). Only set when you star a project while signed out.
  • lab_member — remembers that you joined the community, with your email address and the first steps you completed, so that your welcome page and your health story reach you (1 year). Only set when you join the Lab community; it cannot be read by the page's scripts.
  • g_oauth_state — protects your sign-in with Google against request forgery (10 minutes).
  • gh_oauth_state — protects the connection of a GitHub account by an administrator (10 minutes).

Embedded videos. The episodes of MyTwin Inside shown on the Lab are hosted on YouTube. A video is loaded, in YouTube's privacy-enhanced mode (youtube-nocookie.com), only when you press play: until then, your browser sends nothing to YouTube. Once you start a video, YouTube, operated by Google Ireland Limited, receives your IP address and may store information on your device, under its own privacy policy: https://policies.google.com/privacy.

10. Security

We implement technical and organizational measures suited to the risks, including:

  • HTTPS/TLS encryption of all communications;
  • session cookies that scripts cannot read (httpOnly);
  • encryption of the credentials used to connect third-party services;
  • hashing of the IP addresses of anonymous visitors;
  • access to personal data restricted by role to the people who need it.

11. Your rights

Under the GDPR and the French Data Protection Act, you have the right to:

  • access your data and receive a copy of it;
  • rectify inaccurate data;
  • erase your data, including by closing your account;
  • restrict processing;
  • object to processing based on our legitimate interest, in particular the analysis of discussions and meetings;
  • withdraw your consent at any time, for the news and for your health story, without affecting what was done before;
  • data portability, for the data you provided;
  • define directives on what happens to your data after your death.

To exercise these rights, write to contact@my-twin.io. We answer within one month; this period may be extended by two months for complex requests, in which case we will tell you why. We may ask you to prove your identity if there is a reasonable doubt.

If you believe your rights are not respected, you can lodge a complaint with the CNIL — Commission Nationale de l'Informatique et des Libertés, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.

12. Minors

MyTwin Lab is intended for people aged 18 and over. We do not knowingly collect data from minors. If such data is brought to our attention, it is deleted.

13. Changes to this policy

We may update this policy, in particular when the Lab or the law changes. Members are informed of any substantial change on the Lab or by email before it takes effect. The date of the last update appears at the top of this page.