1. Controller and contact details
The data controller is BoopStudio di Francois Lampasona, Via Giacomo Matteotti 56, 91018 Salemi (TP), Sicily, Italy. For questions or requests about your data, write to lampasonafrancois@gmail.com.
2. Data and features
- Website. Servers receive technical connection data, such as your IP address, browser and request time. We have not added advertising or profiling tools. Fonts are hosted with the website.
- App without an account. Ideas, checklists and attachments stay on your device. The app may still contact update services and, if an error occurs, send the essential diagnostics described below.
- Account and cloud. We process email addresses, credentials managed by the authentication service, account identifiers, profiles, ideas, tasks, attachments, workspaces, roles and notifications. When you first sign in, you choose which local ideas to import into the cloud. We record the version of the Terms you accepted and the privacy notice you read, together with the registration date.
- Photos and camera. These are used when you choose to add an image or change an avatar or cover. You can deny or revoke permissions in your device settings. We do not request microphone access.
- Push notifications. If enabled, we use your device token to deliver updates. Notification text may appear on your lock screen: you can limit previews in your system settings.
- Diagnostics. If a failure occurs, the app sends the error type and identifiers for the app version and update. The current version does not send idea text, passwords, raw error messages or stacks. The server also receives normal technical connection data.
- Support. When you write to us, we receive your email address and message content. Send only necessary information and hide personal data in screenshots.
3. Purposes and legal bases
Accounts, cloud storage, collaboration and requested support are used to provide the service and rely on performance of a contract or steps you request before entering a contract (Article 6(1)(b) GDPR). Security and essential diagnostics rely on our legitimate interest in protecting and maintaining the service (Article 6(1)(f)), while respecting your rights. Mandatory compliance activities rely on Article 6(1)(c).
We do not perform automated marketing or profiling, or make solely automated decisions that produce legal effects concerning a person. Reading this notice and accepting the Terms does not constitute consent to advertising purposes. Account data is required only if you choose cloud features; other profile and content data is optional.
4. Protection and sharing
The local ideas database is encrypted and its key is stored in the device keychain. Transfers to services use encrypted connections. Cloud attachments are stored privately, with authorised access and temporary links. Local encryption is not the same as end-to-end encryption of the cloud service; exported files and local images also depend on device protections.
Workspace members see shared content according to their role and participants’ profile data, which may include email addresses. A registered user who knows your exact email address or username can find your name and avatar to invite you; search does not return your email address. Content is not published on the website. If you export a document to another service, you choose the recipient and its privacy notice also applies. Exporting for an AI chat does not automatically send content to a model. Links are saved without automatically loading external websites or preview images.
5. Retention and deletion
Content remains available for as long as you keep it in the service. You can delete ideas and attachments, export content and request account deletion from Settings. Local-only ideas remain on your phone until you delete them or remove the app’s data; signing out removes the local copy of cloud data.
Account deletion removes your profile, registered devices, notifications and personal content. Workspaces you own are removed: ideas written by other members become personal to their authors. Tasks you added to other people’s ideas may remain without a reference to your account. To keep a workspace, you can transfer ownership first. Files you uploaded, including covers in other people’s workspaces, are removed with your account.
Technical deletion identifiers, without idea text, allow offline devices to catch up within a 180-day sync window. Technical logs follow providers’ retention windows and are not copied into a permanent application archive. Support requests are retained to handle them and for as long as necessary to meet legal obligations or defend a legal right. Backups and retention obligations may involve additional technical time after removal from active data.
6. Service providers
Our infrastructure uses Supabase for authentication, databases and files; Railway for APIs and diagnostics; Vercel for the website; Expo and Apple or Google services for distribution, updates and device notifications. Support email uses Gmail. Each provider receives the data needed for its function, according to its role and applicable terms. People you share a workspace with receive the content you make accessible to them.
7. International transfers
The project’s Supabase database is configured in the Ireland region. Some providers and subprocessors also operate outside the European Economic Area: the database region does not guarantee that all processing takes place exclusively in the EU. Transfers require the safeguards provided by Articles 44–49 GDPR, such as adequacy decisions or standard contractual clauses, depending on the service involved. You can request information about recipients and applicable safeguards by writing to the controller.
8. Cookies and preferences
The website uses the language in the page address and, on your first visit, your browser preference, without storing language cookies. In the app, we save your choice of Italian, English or the system language on your device. When you sign in, we also save the current language in your authentication profile to deliver notifications in that language. You can change it in Settings.
The website does not set advertising or profiling cookies. It stores your light/dark preference in the browser to remember your choice. Password recovery manages the temporary session needed for the operation. Details about purposes, duration and removal are available on the Cookies and browser data page. If non-essential tools are added, the required consent choices will be introduced beforehand.
9. Your rights
Where Articles 15–22 GDPR apply, you may request access, rectification, erasure, restriction and portability of your data, or object to processing based on legitimate interests. Write to lampasonafrancois@gmail.com. We will respond within the time limits of Article 12 GDPR, normally within one month; if a complex request requires a legally permitted extension, we will explain why. We will ask only for information needed to verify your identity.
You may lodge a complaint with the Italian Data Protection Authority or the competent authority in your country, without prejudice to other remedies available by law.
10. Updates
The date and version at the top identify this document. If processing changes substantially, we will update this notice and provide the required communications. You can contact us at any time for clarification.