Legal
Privacy Policy
1. Who We Are
Webnotes ("we", "us") operates webnotes.work, a spatial note-taking application. This policy explains what personal data we collect, why we collect it, and your rights under the EU General Data Protection Regulation (GDPR) and other applicable laws.
2. Data We Collect
- Account data: email address, username, display name, and avatar when you register.
- Content you create: notes, workspaces, connections, attachments, and messages you create or upload.
- Authentication data: when you sign in with Google or GitHub, we receive your identifier from those providers.
- Usage data: technical information such as IP address, browser type, and access times, used for security and troubleshooting.
- Local data: preferences (theme, settings) stored in your browser's local storage.
3. How We Use Your Data
- To provide, operate, and improve the Service
- To authenticate you and keep your account secure
- To send transactional emails (password resets, notifications)
- To prevent abuse, fraud, and violations of our Terms
- To comply with legal obligations
4. Legal Basis (GDPR)
We process your personal data on the following legal bases:
- Performance of a contract — providing the Service you signed up for (Art. 6(1)(b) GDPR)
- Legitimate interests — security, abuse prevention, service improvement (Art. 6(1)(f) GDPR)
- Consent — where you opt in to non-essential processing (Art. 6(1)(a) GDPR)
5. Where Data Is Stored
Your data is stored on servers operated by us, including a self-hosted Supabase database. Data is processed within the European Economic Area (EEA).
6. Third Parties
- Brevo — transactional email delivery (password resets, notifications).
- Google / GitHub — OAuth sign-in, if you choose those methods.
- Cloudflare — network infrastructure and security (DNS, tunneling).
- Google AdSense — may serve ads; AdSense uses cookies for personalization. See Google's Advertising Policies for details.
We do not sell your personal data to third parties.
7. Cookies and Local Storage
The Service uses minimal cookies and browser local storage to keep you signed in and remember your preferences (theme, settings). These are strictly necessary for the Service to function. Third-party services (e.g. AdSense, OAuth providers) may set their own cookies governed by their policies.
8. Data Retention
We retain your data for as long as your account exists. If you delete your account, your data is deleted within 30 days, except where retention is required by law.
9. Your Rights (GDPR)
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict or object to processing
- Data portability (export your data in a machine-readable format)
- Withdraw consent at any time
To exercise any right, contact us at [email protected]. You may also lodge a complaint with your local data protection authority.
10. Security
We use reasonable technical and organizational measures to protect your data, including encrypted connections (TLS) and access controls. No system is 100% secure — you are responsible for keeping your password safe.
11. Children
The Service is not intended for children under 13. We do not knowingly collect data from children under 13.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be announced on the Service.
13. Contact
For privacy questions or requests, contact us at [email protected].
Last updated: August 14, 2026
