Privacy policy
This policy sets out how Otlo UG (haftungsbeschränkt) processes personal data in connection with Savepad, being the website at savepad.app, the application at my.savepad.app, public pages at my.savepad.app/@username, email capture at in.savepad.app, the API, and the MCP server. It provides the information required by Arts. 13 and 14 GDPR. The terms of use govern the use of Savepad. The imprint identifies the operator.
Some sections are preceded by a summary in plain English. The summary is a reading aid. The section is the policy.
Controller
The controller within the meaning of Art. 4 (7) GDPR is Otlo UG (haftungsbeschränkt), Lehmbruckstr. 23, 10245 Berlin, Germany, registered with the Amtsgericht Charlottenburg under HRB 291932 B, represented by its managing director Ronak Rajesh Ganatra.
Requests and questions concerning data protection: [email protected]. Correspondence is conducted in English or German.
No data protection officer has been appointed. None is required: the conditions of Art. 37 (1) GDPR are not met, and § 38 (1) BDSG requires an appointment only where as a rule at least 20 persons are constantly engaged in the automated processing of personal data, or where processing is subject to a data protection impact assessment under Art. 35 GDPR. Neither applies.
Our role, and personal data in your saves
We are the controller for the processing of data relating to your account, your use of the website and the application, payments, support, and reports.
Savepad is intended for storing references, such as advertisements, web pages, newsletters, screenshots, and notes. It is not intended for storing personal data of third parties, and the terms of use prohibit storing personal data of third parties beyond what is incidental to a reference, as well as any special categories of personal data. In particular, Savepad must not be used to store identity documents, banking or payment information, legal documents such as contracts or court papers, medical or health records, passwords or other credentials, or files containing personal data of customers, clients, or employees.
We do not conclude data processing agreements under Art. 28 GDPR, and Savepad must not be used to process personal data on behalf of another controller. Where you nevertheless store personal data of third parties, you do so on your own responsibility, and you are responsible for the lawfulness of that storage.
Saved content may incidentally contain personal data of third parties, for example a name in a screenshot of an advertisement or the sender of a forwarded newsletter. We process saved content solely to provide Savepad to you and in accordance with your instructions, and not for any purpose of our own. Where you save content in the course of a purely personal or household activity, the GDPR does not apply to your own processing of it (Art. 2 (2)(c) GDPR).
Personal data of third parties contained in saved content originates from the user who saved it. Informing each such person individually is impossible or would involve a disproportionate effort, so Art. 14 (5)(b) GDPR applies. This policy is published so that the information is available to them.
Categories of data and processing
Website visits
When you access the website, our hosting provider processes your IP address, browser identification, the address requested, and the time of the request, in order to deliver the page and secure the service. Server logs are retained as set out in section 7. Analytics is subject to section 3, Analytics.
Waitlist
Your email address and the form used. Cloudflare Turnstile is used to distinguish persons from automated requests and is loaded only once you interact with the form. To prevent automated mass submissions, a keyed hash of your IP address is stored for no longer than one day. The IP address itself is not stored.
Account
- email address, username, and the date of registration,
- your confirmation that you are at least 16 years old, and your acceptance of the terms of use, each with the version and time,
- profile information you choose to provide: display name, profile picture, biography, website, and links to social media profiles. This information is displayed on your public page, if you have one. Profile pictures are stored at a publicly accessible address,
- sign-in sessions: browser and device type, and the time of last use, so that you can review and end sessions in Settings,
- settings, plan, and storage used.
Sign-in takes place by means of a one-time link sent to your email address. No passwords are stored.
Saved content
Links, web pages, images, screenshots, videos, PDF files, documents, emails, notes, code, colours, places, routes, and other content you add, together with the folders, tags, notes, and custom properties you assign to it.
The following is derived from saved content by automated means, without the use of any artificial intelligence model: the title, description, and preview image of a web page; a readable copy of the text of a web page; the colours of an image; the text of a PDF file; text contained in images and in scanned PDF pages (section 3, Text recognition); the coordinates of places and routes; and the sender, subject, and date of an email.
Saved content is not sold, is not used to train artificial intelligence models, and is not used for advertising.
Retrieval of web pages
When you save a link, our server retrieves the page under the user agent SavepadBot in order to create a preview. The website concerned receives the IP address of our server, not yours. Where a website refuses retrieval, we may request an archived copy from the Internet Archive. Site icons are requested by our server from Google's favicon service, which receives the domain of the website concerned and no data relating to you.
On the Pro plan, pages you choose to watch are retrieved again once a month, and a new version is stored where the text of the page has changed. Screenshots of such versions are produced by Cloudflare Browser Rendering.
Images contained in saved web pages are retrieved by our server and delivered to you through our own image proxy. Viewing a save does not cause your browser to contact the server hosting the image.
Text recognition
Text contained in images and scanned PDF pages is recognised with Tesseract, open-source software operated on our own infrastructure. Images are not transmitted to any third party for this purpose, no artificial intelligence model is used, and the recognised text is used solely to make your saves searchable.
Email capture
You may create a private email address at in.savepad.app. When you send or forward an email to that address, we receive the entire message, including its headers, sender, recipients, subject, body, and attachments. The message is then processed as follows:
- a message consisting only of links is saved as those links, and the message is not retained,
- a message consisting only of images or PDF files is saved as those files, and the message is not retained,
- any other message is saved as an email, comprising the original message file, a sanitised copy of its HTML for display, and its text for search.
Where a message is saved as an email, its remote images are retrieved once by our server upon receipt and stored with the save. The sender's tracking mechanisms therefore register a single retrieval by our server at that time, and no further retrieval when you later open the save.
During processing, messages are held in temporary storage, which is cleared upon completion and no later than one day after receipt.
Any person who knows your address can submit content to your account. You may replace the address in Settings at any time, whereupon the previous address ceases to function.
Sharing to the installed application
Content you share from another application on Android to the installed Savepad application is uploaded to your account in the same way as a file you add directly. No other data is read from your device.
Public pages
Content is private unless and until you make it public. When you make a space, folder, or tag public, its saves become accessible to anyone at my.savepad.app/@username, including their titles, links, images, tags, and folders. Notes attached to a save are shown only where you have enabled Show my note. A save that consists only of a note is shown with its text, as that text is its content. Your profile information is shown on the same page.
Public pages may be indexed by search engines and read by artificial intelligence assistants, including through plain-text versions, an llms.txt file, and a sitemap. If you enable Keep out of search engines, search engines are instructed not to index your public pages, and the plain-text versions, the llms.txt file, and the sitemap are disabled.
Visit statistics. When a public page is viewed, our server increments a daily total for that page, broken down by country, referring website, and device class (desktop, mobile, or tablet). To avoid counting the same visitor more than once within an hour, the server forms a keyed hash of the visitor's IP address and browser identification, retains it for no longer than one day, and does not store it with the totals. No cookie is set and no script is executed in the visitor's browser. The totals are visible only to the owner of the page.
Private links
A private link makes a single save or folder accessible to anyone who has the link. We store the link only as a hash, any password only as a salted hash, the expiry date you set, and the number of times the link was opened.
API and assistants (MCP)
You may create personal access tokens in Settings to use the API or to connect an artificial intelligence assistant via the MCP server. Each token is stored only as a hash, together with its name, permissions, expiry date, and time of last use.
When you connect an assistant, it reads and modifies your saves within the permissions of the token. The processing of that data by the assistant is governed by your agreement with its provider. We are not the controller of that transmission. Savepad itself does not transmit your content to any artificial intelligence model.
Maps
When you open a map in the application, your browser loads map tiles from OpenFreeMap. OpenFreeMap receives your IP address and the map area displayed, and no information about your saves.
Support, feedback, and reports
When you contact us, including through the feedback form in the application, we process your message, your email address, and your username. When you submit a report concerning content, we process the information you provide, the content concerned, and your email address.
Payment
Paid plans are sold by Paddle as merchant of record (section 5). We receive your plan, its status and renewal date, your country, and a Paddle customer reference. We do not receive payment card or bank account details.
Analytics
The data processed depends on your response to the consent request.
If you select Allow, PostHog processes a random identifier stored in a first-party cookie; an approximate location derived from your IP address (country, region, and city); the referring website; pages viewed; interactions with our own controls; a limited number of named events, such as the creation of a save and its type; and, once you are signed in, your account identifier. The IP address is used only to derive the location and is then discarded.
With your consent, PostHog also records how the application responds to your use of it, in order to identify faults and usability problems. All text is masked, and all images, videos, and embedded frames are blocked, before a recording leaves your browser. A recording shows the layout of the screen and not the content of your saves, their titles, or anything you type.
If you select No thanks or do not respond, no information is stored on or read from your device, and no recording is made. Page views are counted without a cookie, PostHog does not store your IP address, and visits cannot be linked across days.
In either case, addresses transmitted to PostHog are first stripped of private links, tokens, signed file addresses, search terms, and shared content. PostHog does not receive saved links, their titles, or search queries.
Error reports
When an error occurs, Sentry receives the error, the location in our code, the browser and operating system version, and the page, stripped as described under Analytics. Request contents, cookies, IP addresses, and the content of saves are not transmitted.
Security and prevention of abuse
To prevent abuse, requests are counted per account and per keyed hash of an IP address, for no longer than one day. Registration and sign-in are protected by Cloudflare Turnstile. Links to known malware, phishing, and pornographic websites are refused when saved.
Processing that does not take place
We do not acquire personal data from data brokers, enrich email addresses from other sources, conduct advertising, or sell or rent personal data. No decision producing legal effects or similarly significant effects is based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
Legal bases
- Account, saved content and derived data, email capture, public pages, private links, tokens, sessions, support relating to your account, and payment: Art. 6 (1)(b) GDPR, performance of the contract with you.
- Security, rate limiting, Turnstile, refusal of harmful links, error reports, server logs, and retrieval of web pages through our server: Art. 6 (1)(f) GDPR. Our legitimate interest lies in operating a secure and functioning service and in protecting you from tracking by the websites you save.
- Visit statistics for public pages: Art. 6 (1)(f) GDPR. The legitimate interest, ours and that of the page owner, lies in knowing how a public page is used, measured by the least intrusive means available: daily totals, without cookies and without storing IP addresses.
- Retaining a closed account (section 7): Art. 6 (1)(f) GDPR. The legitimate interest, ours and yours, lies in allowing you to restore your account. You may object at any time (section 8) or request erasure.
- Handling reports concerning content: Art. 6 (1)(c) GDPR in conjunction with Arts. 16 to 18 of Regulation (EU) 2022/2065 (Digital Services Act), and Art. 6 (1)(f) GDPR.
- Analytics and recordings after you select Allow: Art. 6 (1)(a) GDPR and § 25 (1) TDDDG, consent.
- Counting page views where you select No thanks or do not respond: no information is stored on or read from your device, so § 25 TDDDG does not apply. To the extent the resulting count constitutes personal data, Art. 6 (1)(f) GDPR, our legitimate interest in knowing how many people visit.
- The cookie recording your response, and the sign-in cookies: § 25 (2) no. 2 TDDDG, strictly necessary.
- Waitlist: Art. 6 (1)(a) GDPR, consent given by submitting the form. Every email contains an unsubscribe link.
- Retention of payment and accounting records: Art. 6 (1)(c) GDPR, statutory retention obligations under German tax and commercial law.
Consent may be withdrawn at any time with effect for the future (section 9). Withdrawal does not affect the lawfulness of processing carried out before it.
Providing your email address is necessary to conclude the contract. There is no statutory obligation to provide it. Without it, we cannot provide Savepad to you.
Recipients
The following recipients act as our processors under Art. 28 GDPR, on the basis of data processing agreements, unless stated otherwise.
- Supabase
- Database, authentication, and storage of profile pictures. Account data and saved content, other than files. AWS region
eu-central-1, Frankfurt, Germany. - Vercel
- Hosting of the website and the application. IP address, browser identification, and the address requested. Server functions are executed in Frankfurt (
fra1). Static files are delivered through Vercel's global network. - Cloudflare
- File storage (R2, EU jurisdiction), receipt of email for in.savepad.app (Email Routing and Workers), screenshots of web pages (Browser Rendering), and Turnstile. Files, emails sent to your address, and, for Turnstile, IP address and browser identification.
- Resend
- Delivery of sign-in and account emails, and forwarding of feedback to our inbox. Email address and message content. EU region.
- MailerLite
- Waitlist and its emails. Email address. Lithuania, EU.
- PostHog
- Analytics and masked recordings, as described in section 3. EU region, Frankfurt.
- Sentry
- Error reports, as described in section 3. EU region, Frankfurt.
- Paddle (independent controller)
- Paddle.com Market Limited sells paid plans to you as merchant of record and processes payment, taxation, and invoicing in its own name under its own privacy policy. Paddle is not our processor in respect of that data.
- OpenFreeMap (independent controller)
- Map tiles, loaded directly by your browser when you open a map. OpenFreeMap receives your IP address under its own terms.
In addition, our server requests site icons from Google's favicon service and archived pages from the Internet Archive. These recipients receive web addresses from our server and no data relating to you.
Personal data is disclosed to public authorities only where we are legally obliged to do so.
Transfers to third countries
Account data and saved content are stored in the European Union. Some of the recipients listed above are companies based in the United States operating global networks, so technical data such as IP addresses or error reports may be processed outside the European Economic Area. Such transfers are based on the adequacy decision of the European Commission for the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified under it, and otherwise on standard contractual clauses (Art. 46 (2)(c) GDPR). A copy may be requested at [email protected].
Configuration of analytics and error reporting
By default, analytics and error reporting tools may collect request contents, values held in memory at the time of an error, cookies, headers, console output, and full-page recordings. In Savepad, each of these could contain saved content. The tools are therefore configured as follows:
- error reports contain no request contents, cookies, headers, IP addresses, variable values, or console output,
- no recordings are made by the error reporting tool,
- recordings made by the analytics tool mask all text and block all images, videos, and embedded frames. Masking is configured for all elements rather than for a list of elements, so that no screen is recorded unmasked by omission,
- addresses transmitted to either tool are stripped of private links, tokens, signed addresses, and search terms,
- events identify an action and its type, and never a saved link, title, note, or search query.
Retention
- Saved content. Until you delete it. Deleted content remains in the bin for 30 days and is then deleted. Associated files are deleted from storage within a further 7 days.
- Page versions (Pro plan). 24 months. The most recent version of each watched page is retained.
- Closing your account. Upon closure, your public pages are taken offline, sign-in is blocked, and all tokens are revoked. Your saved content is moved to the bin and deleted after 30 days as described above. Your account record (email address, username, profile, settings, and plan history) is retained in closed form so that you can restore your account, until you request its erasure. Your username remains reserved for you for 90 days and is then released.
- Erasure on request. On request to [email protected] from the email address of the account, we erase the account record and all associated data without undue delay and in any event within one month (Arts. 12 (3) and 17 GDPR), except data we are legally obliged to retain.
- Emails in processing. Deleted upon completion of processing, and no later than one day after receipt.
- Visit statistics. 25 months, to allow comparison with the same period of the previous year. The hash used to prevent double counting: no longer than one day.
- Rate-limit counters. No longer than one day.
- Sessions. Until you sign out or end the session, or until it expires.
- Tokens and private links. Until you revoke or delete them. Revoked tokens are retained as a hash, which prevents their reuse, until your account is erased.
- Waitlist. Until the launch email has been sent, or until you unsubscribe.
- Support, feedback, and reports. Until the matter is concluded, and no longer than 3 years from the end of the year in which it was concluded, corresponding to the regular limitation period under §§ 195 and 199 BGB.
- Payment and accounting records. 8 years, as required by § 147 AO, held by Paddle and by us.
- Analytics recordings. 30 days. Analytics events: deleted by PostHog in accordance with the retention period of our plan, no longer than 7 years.
- Error reports. 90 days.
- Server logs. Retained by the hosting provider for no longer than 30 days.
- Backups. Database backups are overwritten on a rolling basis within 7 days. Deleted data is removed from backups within 7 days of its deletion.
Your rights
You have the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), to data portability (Art. 20 GDPR), to object (Art. 21 GDPR), and to withdraw consent at any time (Art. 7 (3) GDPR).
Several of these rights can be exercised directly in the application: you can export all saved content at any time in open formats, including as a ZIP archive containing every file; edit or delete any save; edit your profile; end sessions; revoke tokens; and close your account.
All other requests may be sent to [email protected]. We respond within one month (Art. 12 (3) GDPR). We may request confirmation of a request from the email address registered to the account in order to verify your identity.
Right to object under Art. 21 GDPR. Where we process your personal data on the basis of Art. 6 (1)(f) GDPR (section 4), you have the right to object to that processing at any time on grounds relating to your particular situation. We will then cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims. The objection may be sent to [email protected].
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, datenschutz-berlin.de. You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.
Cookies and local storage
- Sign-in. Session cookies on my.savepad.app that keep you signed in. Strictly necessary.
- Consent response.
savepad_consent, on savepad.app and its subdomains, for six months, so that your response applies across Savepad. Strictly necessary. - Analytics. A first-party cookie containing a random identifier, set only if you select Allow, for six months.
- Preferences. Interface settings such as the width of the sidebar, your list view, and your triage keys, stored in your browser's local storage. These are not transmitted to us.
- Installed application. If you install Savepad, a service worker receives content you share to it. It does not cache content.
- Turnstile. Cloudflare may store a short-lived token to confirm that you are a person. It is not used for tracking.
Savepad uses no advertising cookies and no third-party tracking, and does not track you across websites.
Changing your response
deletes your recorded response. You will be asked again on your next visit to the application. Selecting No thanks deletes the analytics cookie immediately. Deleting your browser's cookies has the same effect.
Security
Data is encrypted in transit using TLS and encrypted at rest. Each record in the database is assigned to one account, and row-level security policies separate the data of different accounts. Files are stored under keys that can be accessed only through addresses signed by our server. Saved web pages and emails are displayed in sandboxed frames that cannot execute scripts, under a restrictive Content Security Policy.
Savepad does not use end-to-end encryption. Saved content is processed on our servers in order to create previews, extract text, and make it searchable. Access to it is restricted as described in section 6.
Security vulnerabilities may be reported to [email protected].
Children
Savepad is not directed at children. Registration requires a minimum age of 16, which you confirm when you register. If you believe that a person under 16 has provided us with personal data, please notify us at [email protected], and we will delete it.
California and other US state laws
Savepad is operated from Germany, and this policy is drafted under the GDPR. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), applies to a business that meets at least one of the following thresholds: annual gross revenue exceeding the inflation-adjusted amount (USD 26,625,000 as of 2025); annually buying, selling, or sharing the personal information of 100,000 or more California consumers or households; or deriving 50% or more of its annual revenue from selling or sharing personal information. Otlo UG (haftungsbeschränkt) meets none of these thresholds, nor the comparable thresholds of the consumer privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, and Oregon.
Irrespective of whether any of those laws applies:
- we do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA,
- we do not process personal information for targeted advertising and do not conduct advertising,
- we do not use sensitive personal information to infer characteristics about you,
- we do not knowingly collect personal information from persons under 16,
- the rights described in section 8 are available to every person, regardless of place of residence, and exercising them does not result in any less favourable treatment.
Analytics is disabled unless you select Allow. No opt-out is therefore required.
Changes to this policy
New processors are added to section 5 before they begin processing personal data. Where a change materially affects the processing of your personal data, we notify account holders by email before the change takes effect. The date below indicates when the current version was published.