Skip to content
  • Pricing
↑↓ to move ↵ to open esc to close
Join the waitlistWaitlist
  • Search everything
    Features All the bells, and some whistles
  • Savepad has opinions.
    1. 1No AI.
    2. 2Personal, on purpose
    3. 3You sort it
    4. 4Leaving must be easy
    Philosophy Savepad is quite opinionated
  • Docs / Capture Save from your phone
    1. 1
    2. 2
    3. 3
    Docs How to save, sort, and find things.
  • Considering
    In progress
    Done
    Roadmap What I'm working on
    • Sep 26, 2026Website A new savepad.app
    • Jan 14, 2025Old beta Savepad is live in beta
    Changelog All the product updates

Jump to

  • Spaces and folders
  • Views
  • Search and OCR
  • Public pages
  • Capture
  • Integrations
  • Security
  • Recipes
All of them →
  • 50% off
    Sneakers for puddles
    Swipe file Ads, pages, and emails worth stealing from.
  • Aa
    Moodboards UI, type, colour, and motion, easily findable.
    • stripe.com/pricing
    • linear.app/method
    • arc.net/max
    • vercel.com/blog
    Bookmark manager Oh look, another bookmark manager. Or is it?
  • 4 min read Not everything is “performative”
    Read later Give some TLC to that reading list you never got to
  • coldco.comCold brew, canned
    vs
    northbrew.coBrewed cold, 18 hours
    Competitor research Pricing pages, flows, changelogs, whatever you're stalking
  • brand voice⌘K
    • PDFBrand guidelines, brand voice
    • DocTone of voice notes
    • NoteWords we never use
    Knowledge base PDFs, docs, notes, and links in one search box.
All use cases →
  • oddsocks.co/summer
    The summer dropShop now
    PageReaderSnapshot
    Web pages Snapshot, reader, and SEO
  • 2880 × 1800
    Images and screenshots Text and colours pulled out
  • You left something behind
    Finish checkout
    0212 ·
    Emails Forwarded, trackers blocked
  • Launch film · 0:32
    0078 ·
    Video Links and files, with a frame
  • Brand guidelines 2026
    p. 4 / 38
    0164 ·
    PDFs Every page searchable
  • saves.ts
    type Save = { url: string }const find = (q: string) => db.search<Save>(q, { tag: 'ugc' })
    Code Highlighted, one click to copy
  • Onboarding ideas to steal
    • Progress bar from step one
    • Ask what they save first
    • Day 3 email, one tip
    Notes Checklists that link to saves
  • Aa Fraunces
    0433 ·
    Fonts Opens as a type tester
  • Ink#1B0F3A
    Accent#7A4AFB
    Soft#C9B8FF
    Pop#FFDD4A
    Colours and palettes Hex, RGB, and OKLCH
  • Billboard, Callao
    0255 ·
    Places Pins you can find on a map
All 17 save types →
  • northwindSponsored
    Run further. Hurt less.
    Shop now›
    Marketers Ads, landing pages, emails, onboarding flows, everything you want to steal
  • Aa Fraunces
    0433 ·
    Designers UI, typefaces, colours, animations, everything that made your eyes go wide
  • Step 2 of 3 What are you saving first?
    0461 ·
    Product managers Competitor info, pricing, flows, user research, everything you need for your retro
  • saves.ts
    type Save = { url: string }const find = (q: string) => db.search<Save>(q, { tag: 'ugc' })
    Developers Snippets, docs, repos, quirks, everything you need, keyboard first
  • T TidepoolWater, sorted. 412
    Launching todaySaaSDev tools
    Makers Launches, pricing pages, snippets, everything for the thing you're shipping
  • Cacio e pepe
    Cook mode
    0620 ·
    You Recipes, trips, furniture, whatever. See it, save it.
Is Savepad for you? →
  • What is a swipe file? Swipe filesMarketing
    Blog Swipe files, references, and taste.
  • UTM builder sourcenewslettermediumemailcampaignsummer-dropoddsocks.co/?utm_source=newsletter&utm_medium=emailCopy
    Free tools Nifty tools you probably search for anyways
  • SavepadOthers
    ✓✓
    ✓✕
    ✕✓
    ✓✓
    ✓✕
    Compare See how Savepad stacks up
  • savepad.app
    /features
    /blog
    /docs
    Sitemap All the pages on this website
  • New message
    To[email protected] SubjectAn idea for Savepad
    Send
    Say hello 👋 Ideas, bugs, feedback, whatever

Savepad vs

  • Foreplay
  • Swipewell
  • mymind
  • Raindrop.io
  • Notion
  • Milanote
  • Are.na
  • Savee
All of them →
Product
  • Features
  • Philosophy
  • Docs
  • Roadmap
  • Changelog
Use cases
  • Swipe file
  • Moodboards
  • Bookmark manager
  • Read later
  • Competitor research
  • Knowledge base
  • All use cases →
Save types
  • Web pages
  • Images and screenshots
  • Emails
  • Video
  • PDFs
  • Code
  • Notes
  • Fonts
  • Colours and palettes
  • Places
  • All 17 save types →
Who it's for
  • Marketers
  • Designers
  • Product managers
  • Developers
  • Makers
  • You
  • Is Savepad for you? →
Resources
  • Blog
  • Free tools
  • Compare
  • Sitemap
  • Say hello 👋
Pricing
Join the waitlist

Privacy policy

Last updated 1 October 2026

This policy sets out how Otlo UG (haftungsbeschränkt) processes personal data in connection with Savepad, being the website at savepad.app, the application at my.savepad.app, public pages at my.savepad.app/@username, email capture at in.savepad.app, the API, and the MCP server. It provides the information required by Arts. 13 and 14 GDPR. The terms of use govern the use of Savepad. The imprint identifies the operator.

Some sections are preceded by a summary in plain English. The summary is a reading aid. The section is the policy.

Contents

  1. 01Controller
  2. 02Our role, and personal data in your saves
  3. 03Categories of data and processing
  4. 04Legal bases
  5. 05Recipients
  6. 06Configuration of analytics and error reporting
  7. 07Retention
  8. 08Your rights
  9. 09Cookies and local storage
  10. 10Security
  11. 11Children
  12. 12California and other US state laws
  13. 13Changes to this policy

01Controller

The controller within the meaning of Art. 4 (7) GDPR is Otlo UG (haftungsbeschränkt), Lehmbruckstr. 23, 10245 Berlin, Germany, registered with the Amtsgericht Charlottenburg under HRB 291932 B, represented by its managing director Ronak Rajesh Ganatra.

Requests and questions concerning data protection: [email protected]. Correspondence is conducted in English or German.

No data protection officer has been appointed. None is required: the conditions of Art. 37 (1) GDPR are not met, and § 38 (1) BDSG requires an appointment only where as a rule at least 20 persons are constantly engaged in the automated processing of personal data, or where processing is subject to a data protection impact assessment under Art. 35 GDPR. Neither applies.

02Our role, and personal data in your saves

In plain English

Savepad is for references: ads, pages, emails, screenshots, ideas. It's not a place for anyone's personal data. No IDs, no bank details, no contracts, no medical stuff, no client files with people's details in them.

If you save that kind of thing anyway, that's on you. We don't sign data processing agreements, because Savepad isn't built for it.

We are the controller for the processing of data relating to your account, your use of the website and the application, payments, support, and reports.

Savepad is intended for storing references, such as advertisements, web pages, newsletters, screenshots, and notes. It is not intended for storing personal data of third parties, and the terms of use prohibit storing personal data of third parties beyond what is incidental to a reference, as well as any special categories of personal data. In particular, Savepad must not be used to store identity documents, banking or payment information, legal documents such as contracts or court papers, medical or health records, passwords or other credentials, or files containing personal data of customers, clients, or employees.

We do not conclude data processing agreements under Art. 28 GDPR, and Savepad must not be used to process personal data on behalf of another controller. Where you nevertheless store personal data of third parties, you do so on your own responsibility, and you are responsible for the lawfulness of that storage.

Saved content may incidentally contain personal data of third parties, for example a name in a screenshot of an advertisement or the sender of a forwarded newsletter. We process saved content solely to provide Savepad to you and in accordance with your instructions, and not for any purpose of our own. Where you save content in the course of a purely personal or household activity, the GDPR does not apply to your own processing of it (Art. 2 (2)(c) GDPR).

Personal data of third parties contained in saved content originates from the user who saved it. Informing each such person individually is impossible or would involve a disproportionate effort, so Art. 14 (5)(b) GDPR applies. This policy is published so that the information is available to them.

03Categories of data and processing

In plain English

Your email, your username, and whatever you put on your profile. Everything you save, plus what we work out from it: the text, the colours, the words in your screenshots.

Save a link and our server goes and gets the page, so the site sees us, not you.

Email something to your Savepad address and we keep it the way it arrived. The images get copied once, so the sender's tracking pixel never finds out you opened it again.

Analytics only if you hit Allow, and even then every word on screen is blacked out. Crash reports never include your stuff.

People visiting your public page get counted as daily totals. Nobody gets tracked.

Website visits

When you access the website, our hosting provider processes your IP address, browser identification, the address requested, and the time of the request, in order to deliver the page and secure the service. Server logs are retained as set out in section 7. Analytics is subject to section 3, Analytics.

Waitlist

Your email address and the form used. Cloudflare Turnstile is used to distinguish persons from automated requests and is loaded only once you interact with the form. To prevent automated mass submissions, a keyed hash of your IP address is stored for no longer than one day. The IP address itself is not stored.

Account

  • email address, username, and the date of registration,
  • your confirmation that you are at least 16 years old, and your acceptance of the terms of use, each with the version and time,
  • profile information you choose to provide: display name, profile picture, biography, website, and links to social media profiles. This information is displayed on your public page, if you have one. Profile pictures are stored at a publicly accessible address,
  • sign-in sessions: browser and device type, and the time of last use, so that you can review and end sessions in Settings,
  • settings, plan, and storage used.

Sign-in takes place by means of a one-time link sent to your email address. No passwords are stored.

Saved content

Links, web pages, images, screenshots, videos, PDF files, documents, emails, notes, code, colours, places, routes, and other content you add, together with the folders, tags, notes, and custom properties you assign to it.

The following is derived from saved content by automated means, without the use of any artificial intelligence model: the title, description, and preview image of a web page; a readable copy of the text of a web page; the colours of an image; the text of a PDF file; text contained in images and in scanned PDF pages (section 3, Text recognition); the coordinates of places and routes; and the sender, subject, and date of an email.

Saved content is not sold, is not used to train artificial intelligence models, and is not used for advertising.

Retrieval of web pages

When you save a link, our server retrieves the page under the user agent SavepadBot in order to create a preview. The website concerned receives the IP address of our server, not yours. Where a website refuses retrieval, we may request an archived copy from the Internet Archive. Site icons are requested by our server from Google's favicon service, which receives the domain of the website concerned and no data relating to you.

On the Pro plan, pages you choose to watch are retrieved again once a month, and a new version is stored where the text of the page has changed. Screenshots of such versions are produced by Cloudflare Browser Rendering.

Images contained in saved web pages are retrieved by our server and delivered to you through our own image proxy. Viewing a save does not cause your browser to contact the server hosting the image.

Text recognition

Text contained in images and scanned PDF pages is recognised with Tesseract, open-source software operated on our own infrastructure. Images are not transmitted to any third party for this purpose, no artificial intelligence model is used, and the recognised text is used solely to make your saves searchable.

Email capture

You may create a private email address at in.savepad.app. When you send or forward an email to that address, we receive the entire message, including its headers, sender, recipients, subject, body, and attachments. The message is then processed as follows:

  • a message consisting only of links is saved as those links, and the message is not retained,
  • a message consisting only of images or PDF files is saved as those files, and the message is not retained,
  • any other message is saved as an email, comprising the original message file, a sanitised copy of its HTML for display, and its text for search.

Where a message is saved as an email, its remote images are retrieved once by our server upon receipt and stored with the save. The sender's tracking mechanisms therefore register a single retrieval by our server at that time, and no further retrieval when you later open the save.

During processing, messages are held in temporary storage, which is cleared upon completion and no later than one day after receipt.

Any person who knows your address can submit content to your account. You may replace the address in Settings at any time, whereupon the previous address ceases to function.

Sharing to the installed application

Content you share from another application on Android to the installed Savepad application is uploaded to your account in the same way as a file you add directly. No other data is read from your device.

Public pages

Content is private unless and until you make it public. When you make a space, folder, or tag public, its saves become accessible to anyone at my.savepad.app/@username, including their titles, links, images, tags, and folders. Notes attached to a save are shown only where you have enabled Show my note. A save that consists only of a note is shown with its text, as that text is its content. Your profile information is shown on the same page.

Public pages may be indexed by search engines and read by artificial intelligence assistants, including through plain-text versions, an llms.txt file, and a sitemap. If you enable Keep out of search engines, search engines are instructed not to index your public pages, and the plain-text versions, the llms.txt file, and the sitemap are disabled.

Visit statistics. When a public page is viewed, our server increments a daily total for that page, broken down by country, referring website, and device class (desktop, mobile, or tablet). To avoid counting the same visitor more than once within an hour, the server forms a keyed hash of the visitor's IP address and browser identification, retains it for no longer than one day, and does not store it with the totals. No cookie is set and no script is executed in the visitor's browser. The totals are visible only to the owner of the page.

Private links

A private link makes a single save or folder accessible to anyone who has the link. We store the link only as a hash, any password only as a salted hash, the expiry date you set, and the number of times the link was opened.

API and assistants (MCP)

You may create personal access tokens in Settings to use the API or to connect an artificial intelligence assistant via the MCP server. Each token is stored only as a hash, together with its name, permissions, expiry date, and time of last use.

When you connect an assistant, it reads and modifies your saves within the permissions of the token. The processing of that data by the assistant is governed by your agreement with its provider. We are not the controller of that transmission. Savepad itself does not transmit your content to any artificial intelligence model.

Maps

When you open a map in the application, your browser loads map tiles from OpenFreeMap. OpenFreeMap receives your IP address and the map area displayed, and no information about your saves.

Support, feedback, and reports

When you contact us, including through the feedback form in the application, we process your message, your email address, and your username. When you submit a report concerning content, we process the information you provide, the content concerned, and your email address.

Payment

Paid plans are sold by Paddle as merchant of record (section 5). We receive your plan, its status and renewal date, your country, and a Paddle customer reference. We do not receive payment card or bank account details.

Analytics

The data processed depends on your response to the consent request.

If you select Allow, PostHog processes a random identifier stored in a first-party cookie; an approximate location derived from your IP address (country, region, and city); the referring website; pages viewed; interactions with our own controls; a limited number of named events, such as the creation of a save and its type; and, once you are signed in, your account identifier. The IP address is used only to derive the location and is then discarded.

With your consent, PostHog also records how the application responds to your use of it, in order to identify faults and usability problems. All text is masked, and all images, videos, and embedded frames are blocked, before a recording leaves your browser. A recording shows the layout of the screen and not the content of your saves, their titles, or anything you type.

If you select No thanks or do not respond, no information is stored on or read from your device, and no recording is made. Page views are counted without a cookie, PostHog does not store your IP address, and visits cannot be linked across days.

In either case, addresses transmitted to PostHog are first stripped of private links, tokens, signed file addresses, search terms, and shared content. PostHog does not receive saved links, their titles, or search queries.

Error reports

When an error occurs, Sentry receives the error, the location in our code, the browser and operating system version, and the page, stripped as described under Analytics. Request contents, cookies, IP addresses, and the content of saves are not transmitted.

Security and prevention of abuse

To prevent abuse, requests are counted per account and per keyed hash of an IP address, for no longer than one day. Registration and sign-in are protected by Cloudflare Turnstile. Links to known malware, phishing, and pornographic websites are refused when saved.

Processing that does not take place

We do not acquire personal data from data brokers, enrich email addresses from other sources, conduct advertising, or sell or rent personal data. No decision producing legal effects or similarly significant effects is based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.

04Legal bases

In plain English

Mostly: you signed up, so we run the thing you signed up for. Security, and counting visitors to your public page, are what the law calls our legitimate interest. Analytics and the waitlist only happen because you said yes, and you can take that back whenever.

  • Account, saved content and derived data, email capture, public pages, private links, tokens, sessions, support relating to your account, and payment: Art. 6 (1)(b) GDPR, performance of the contract with you.
  • Security, rate limiting, Turnstile, refusal of harmful links, error reports, server logs, and retrieval of web pages through our server: Art. 6 (1)(f) GDPR. Our legitimate interest lies in operating a secure and functioning service and in protecting you from tracking by the websites you save.
  • Visit statistics for public pages: Art. 6 (1)(f) GDPR. The legitimate interest, ours and that of the page owner, lies in knowing how a public page is used, measured by the least intrusive means available: daily totals, without cookies and without storing IP addresses.
  • Retaining a closed account (section 7): Art. 6 (1)(f) GDPR. The legitimate interest, ours and yours, lies in allowing you to restore your account. You may object at any time (section 8) or request erasure.
  • Handling reports concerning content: Art. 6 (1)(c) GDPR in conjunction with Arts. 16 to 18 of Regulation (EU) 2022/2065 (Digital Services Act), and Art. 6 (1)(f) GDPR.
  • Analytics and recordings after you select Allow: Art. 6 (1)(a) GDPR and § 25 (1) TDDDG, consent.
  • Counting page views where you select No thanks or do not respond: no information is stored on or read from your device, so § 25 TDDDG does not apply. To the extent the resulting count constitutes personal data, Art. 6 (1)(f) GDPR, our legitimate interest in knowing how many people visit.
  • The cookie recording your response, and the sign-in cookies: § 25 (2) no. 2 TDDDG, strictly necessary.
  • Waitlist: Art. 6 (1)(a) GDPR, consent given by submitting the form. Every email contains an unsubscribe link.
  • Retention of payment and accounting records: Art. 6 (1)(c) GDPR, statutory retention obligations under German tax and commercial law.

Consent may be withdrawn at any time with effect for the future (section 9). Withdrawal does not affect the lawfulness of processing carried out before it.

Providing your email address is necessary to conclude the contract. There is no statutory obligation to provide it. Without it, we cannot provide Savepad to you.

05Recipients

In plain English

Your library lives in Frankfurt, your files in Cloudflare's EU storage. Everyone else on this list hosts, sends, counts, or checks things for us.

Paddle and OpenFreeMap don't work for us. They deal with you directly.

A few of these are American companies, so some technical data (an IP address, say) can leave the EU. That's covered by the EU-US Data Privacy Framework or EU standard contract clauses.

The following recipients act as our processors under Art. 28 GDPR, on the basis of data processing agreements, unless stated otherwise.

Supabase
Database, authentication, and storage of profile pictures. Account data and saved content, other than files. AWS region eu-central-1, Frankfurt, Germany.
Vercel
Hosting of the website and the application. IP address, browser identification, and the address requested. Server functions are executed in Frankfurt (fra1). Static files are delivered through Vercel's global network.
Cloudflare
File storage (R2, EU jurisdiction), receipt of email for in.savepad.app (Email Routing and Workers), screenshots of web pages (Browser Rendering), and Turnstile. Files, emails sent to your address, and, for Turnstile, IP address and browser identification.
Resend
Delivery of sign-in and account emails, and forwarding of feedback to our inbox. Email address and message content. EU region.
MailerLite
Waitlist and its emails. Email address. Lithuania, EU.
PostHog
Analytics and masked recordings, as described in section 3. EU region, Frankfurt.
Sentry
Error reports, as described in section 3. EU region, Frankfurt.
Paddle (independent controller)
Paddle.com Market Limited sells paid plans to you as merchant of record and processes payment, taxation, and invoicing in its own name under its own privacy policy. Paddle is not our processor in respect of that data.
OpenFreeMap (independent controller)
Map tiles, loaded directly by your browser when you open a map. OpenFreeMap receives your IP address under its own terms.

In addition, our server requests site icons from Google's favicon service and archived pages from the Internet Archive. These recipients receive web addresses from our server and no data relating to you.

Personal data is disclosed to public authorities only where we are legally obliged to do so.

Transfers to third countries

Account data and saved content are stored in the European Union. Some of the recipients listed above are companies based in the United States operating global networks, so technical data such as IP addresses or error reports may be processed outside the European Economic Area. Such transfers are based on the adequacy decision of the European Commission for the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified under it, and otherwise on standard contractual clauses (Art. 46 (2)(c) GDPR). A copy may be requested at [email protected].

06Configuration of analytics and error reporting

In plain English

Out of the box, these tools grab everything. In a swipe file, "everything" is your swipe file. So we switched all of that off, on purpose, and there are tests that check it stays off.

By default, analytics and error reporting tools may collect request contents, values held in memory at the time of an error, cookies, headers, console output, and full-page recordings. In Savepad, each of these could contain saved content. The tools are therefore configured as follows:

  • error reports contain no request contents, cookies, headers, IP addresses, variable values, or console output,
  • no recordings are made by the error reporting tool,
  • recordings made by the analytics tool mask all text and block all images, videos, and embedded frames. Masking is configured for all elements rather than for a list of elements, so that no screen is recorded unmasked by omission,
  • addresses transmitted to either tool are stripped of private links, tokens, signed addresses, and search terms,
  • events identify an action and its type, and never a saved link, title, note, or search query.

07Retention

In plain English

Your saves stay until you delete them. Deleted stuff sits in the bin for 30 days, then it's gone, and the files go from storage within a week after that.

Close your account and your library goes the same way. We hang on to the closed account itself (your email, username, and settings) so you can come back. Want that gone too? Email us and we wipe the lot.

  • Saved content. Until you delete it. Deleted content remains in the bin for 30 days and is then deleted. Associated files are deleted from storage within a further 7 days.
  • Page versions (Pro plan). 24 months. The most recent version of each watched page is retained.
  • Closing your account. Upon closure, your public pages are taken offline, sign-in is blocked, and all tokens are revoked. Your saved content is moved to the bin and deleted after 30 days as described above. Your account record (email address, username, profile, settings, and plan history) is retained in closed form so that you can restore your account, until you request its erasure. Your username remains reserved for you for 90 days and is then released.
  • Erasure on request. On request to [email protected] from the email address of the account, we erase the account record and all associated data without undue delay and in any event within one month (Arts. 12 (3) and 17 GDPR), except data we are legally obliged to retain.
  • Emails in processing. Deleted upon completion of processing, and no later than one day after receipt.
  • Visit statistics. 25 months, to allow comparison with the same period of the previous year. The hash used to prevent double counting: no longer than one day.
  • Rate-limit counters. No longer than one day.
  • Sessions. Until you sign out or end the session, or until it expires.
  • Tokens and private links. Until you revoke or delete them. Revoked tokens are retained as a hash, which prevents their reuse, until your account is erased.
  • Waitlist. Until the launch email has been sent, or until you unsubscribe.
  • Support, feedback, and reports. Until the matter is concluded, and no longer than 3 years from the end of the year in which it was concluded, corresponding to the regular limitation period under §§ 195 and 199 BGB.
  • Payment and accounting records. 8 years, as required by § 147 AO, held by Paddle and by us.
  • Analytics recordings. 30 days. Analytics events: deleted by PostHog in accordance with the retention period of our plan, no longer than 7 years.
  • Error reports. 90 days.
  • Server logs. Retained by the hosting provider for no longer than 30 days.
  • Backups. Database backups are overwritten on a rolling basis within 7 days. Deleted data is removed from backups within 7 days of its deletion.

08Your rights

In plain English

Export and delete are buttons in Settings, no need to ask. For anything else, email us and we'll sort it within a month.

Not happy with us? You can complain to the Berlin data protection authority, or the one where you live.

You have the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), to data portability (Art. 20 GDPR), to object (Art. 21 GDPR), and to withdraw consent at any time (Art. 7 (3) GDPR).

Several of these rights can be exercised directly in the application: you can export all saved content at any time in open formats, including as a ZIP archive containing every file; edit or delete any save; edit your profile; end sessions; revoke tokens; and close your account.

All other requests may be sent to [email protected]. We respond within one month (Art. 12 (3) GDPR). We may request confirmation of a request from the email address registered to the account in order to verify your identity.

Right to object under Art. 21 GDPR. Where we process your personal data on the basis of Art. 6 (1)(f) GDPR (section 4), you have the right to object to that processing at any time on grounds relating to your particular situation. We will then cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims. The objection may be sent to [email protected].

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, datenschutz-berlin.de. You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.

09Cookies and local storage

In plain English

Exactly one cookie is optional: the analytics one, set only if you hit Allow, and it lasts six months. Everything else just keeps you signed in and remembers what you picked.

  • Sign-in. Session cookies on my.savepad.app that keep you signed in. Strictly necessary.
  • Consent response. savepad_consent, on savepad.app and its subdomains, for six months, so that your response applies across Savepad. Strictly necessary.
  • Analytics. A first-party cookie containing a random identifier, set only if you select Allow, for six months.
  • Preferences. Interface settings such as the width of the sidebar, your list view, and your triage keys, stored in your browser's local storage. These are not transmitted to us.
  • Installed application. If you install Savepad, a service worker receives content you share to it. It does not cache content.
  • Turnstile. Cloudflare may store a short-lived token to confirm that you are a person. It is not used for tracking.

Savepad uses no advertising cookies and no third-party tracking, and does not track you across websites.

Changing your response

deletes your recorded response. You will be asked again on your next visit to the application. Selecting No thanks deletes the analytics cookie immediately. Deleting your browser's cookies has the same effect.

Your response has been deleted.

10Security

Data is encrypted in transit using TLS and encrypted at rest. Each record in the database is assigned to one account, and row-level security policies separate the data of different accounts. Files are stored under keys that can be accessed only through addresses signed by our server. Saved web pages and emails are displayed in sandboxed frames that cannot execute scripts, under a restrictive Content Security Policy.

Savepad does not use end-to-end encryption. Saved content is processed on our servers in order to create previews, extract text, and make it searchable. Access to it is restricted as described in section 6.

Security vulnerabilities may be reported to [email protected].

11Children

Savepad is not directed at children. Registration requires a minimum age of 16, which you confirm when you register. If you believe that a person under 16 has provided us with personal data, please notify us at [email protected], and we will delete it.

12California and other US state laws

In plain English

California's privacy law is for businesses way bigger than us. The parts people actually care about are true anyway: we don't sell your data, we don't share it for ads, and the rights in section 8 work for everyone, wherever you live.

Savepad is operated from Germany, and this policy is drafted under the GDPR. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), applies to a business that meets at least one of the following thresholds: annual gross revenue exceeding the inflation-adjusted amount (USD 26,625,000 as of 2025); annually buying, selling, or sharing the personal information of 100,000 or more California consumers or households; or deriving 50% or more of its annual revenue from selling or sharing personal information. Otlo UG (haftungsbeschränkt) meets none of these thresholds, nor the comparable thresholds of the consumer privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, and Oregon.

Irrespective of whether any of those laws applies:

  • we do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA,
  • we do not process personal information for targeted advertising and do not conduct advertising,
  • we do not use sensitive personal information to infer characteristics about you,
  • we do not knowingly collect personal information from persons under 16,
  • the rights described in section 8 are available to every person, regardless of place of residence, and exercising them does not result in any less favourable treatment.

Analytics is disabled unless you select Allow. No opt-out is therefore required.

13Changes to this policy

New processors are added to section 5 before they begin processing personal data. Where a change materially affects the processing of your personal data, we notify account holders by email before the change takes effect. The date below indicates when the current version was published.

The personal swipe file for marketers, designers, devs, and makers.

Join the waitlist →

Product

  • Features
  • Save types
  • Pricing
  • Philosophy
  • Docs
  • Roadmap
  • Changelog

Who it's for

  • Marketers
  • Designers
  • Product managers
  • Developers
  • Makers
  • Just you
  • Is it for you?

Use cases

  • Swipe file
  • Moodboards
  • Bookmark manager
  • Read later
  • Competitor research
  • Knowledge base
  • All use cases

Savepad

  • Blog
  • Free tools
  • Contact
  • Sitemap

© 2026 Otlo UG, made out of frustration and 🍺 in Berlin.

  • Privacy
  • Terms
  • Imprint