legal
Privacy policy
Last updated: September 6, 2026
This English version is provided for convenience. The legally binding version is the German Datenschutzerklärung.
favowe is deliberately built to be data-minimal: no ad trackers, no third-party analytics, no third-party cookies during normal operation (the only exception is the payment process, section 11), no selling of data. This policy fully describes what data we process and for what purpose.
1. The essentials at a glance
- Your bookmarks, notes and documents are stored in Frankfurt (EU) and strictly restricted to your account by database-level access rules (Row Level Security).
- While you use the app, your browser makes no connections to advertising or analytics third parties. Fonts are self-hosted.
- We use no cookies for tracking purposes — only technically necessary storage in your browser's local storage (§ 25 (2) TDDDG): your login session, app settings, the site's language choice, a local cache of your bookmarks for fast loading, and the locally kept search vectors of the semantic search; the browser extension stores its session locally (section 8).
- You can export your content at any time (several open formats, scope in section 13) and delete your account yourself (Settings → Account) — deletion removes all your content after a 14-day grace period during which you can still abort it (a few legally justified billing records remain: section 11; for the backup tail: section 10).
2. Hosting and delivery of the app (Cloudflare)
The web app is delivered via Cloudflare (Cloudflare, Inc., USA — for EU users: Cloudflare Germany GmbH as the EU establishment) (Pages, DNS proxy). In doing so, Cloudflare processes technically necessary connection data (IP address, user agent, timestamp) in short-lived server logs.
Purpose: delivery, stability and protection of the website (including DDoS protection). Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure, performant operation). A data processing agreement with EU standard contractual clauses is in place with Cloudflare; Cloudflare is also certified under the EU-U.S. Data Privacy Framework.
3. Registration and login
An account is required to use favowe. We process: email address, chosen login method (email or OAuth via Google or GitHub), login timestamps and session tokens. Providing an email address is required to create an account — without it, favowe cannot be used; all further content you add is provided voluntarily.
When you sign in via Google (Google Ireland Ltd.) or GitHub (GitHub, Inc.), we receive your email address and an account identifier from the respective provider; what data the provider itself processes is set out in its own privacy policy. Account emails (e.g. sign-up confirmation and password-reset emails) are sent via our email delivery processor Resend (Resend, Inc., USA); sending takes place from an EU region (Ireland). Resend processes your email address and the message content solely for delivery.
Storage location: Supabase (Supabase, Inc.) on AWS infrastructure in Frankfurt (eu-central-1). Legal basis: Art. 6 (1) (b) GDPR (performance of contract). Retention: until you delete your account.
Product news (optional): when creating your account — or later under Settings → Account — you can consent to receiving occasional emails about new favowe features. The checkbox is never pre-ticked. We record your consent (timestamp, method, text version and your app language, so news can reach you in your language) and manage the recipient list with our processor Resend. Every such email contains an unsubscribe link, and you can also withdraw your consent at any time under Settings → Account → “Product news” — with effect for the future; account emails such as password resets are unaffected. Legal basis: Art. 6 (1) (a) GDPR (consent). Retention: the consent record is kept until account deletion; on withdrawal you are removed from the recipient list immediately.
4. Your bookmarks, notes and documents (core product)
We store the content you create in favowe: URLs, titles, personal notes, tags, your organizational structure (boards, collections, folders), timestamps and — for full-text search — extracted page text of saved links.
We are aware that saved URLs and notes can reveal interests and personal circumstances. We therefore treat this data as confidential: access is restricted to your account at the database level (Row Level Security); there is no access to content by us in regular operation, no analysis, no disclosure.
Storage location: Supabase, Frankfurt. Documents you upload (HTML, PDF, images) are stored in Cloudflare R2 with EU jurisdiction (storage within the EU); Markdown documents are stored in the database (Frankfurt). Legal basis: Art. 6 (1) (b) GDPR. Retention: deleted items first move to the trash for 30 days (restorable) and are then permanently removed; account deletion removes all content after the 14-day grace period (section 1).
Viewing uploaded HTML documents: if an HTML document you upload references external libraries or fonts (e.g. CDN services or Google Fonts), your browser loads them directly from those providers when you view the document — transmitting your IP address to them. This only concerns content your own document embeds; the document itself cannot send any data to the outside (network access from within the document is technically blocked).
5. Automatic enrichment of saved links
When you save a link, our server fetches the target page once and extracts title, description, favicon and, where available, a preview image. The assets are stored in our own storage (Frankfurt) — your browser does not contact any third parties for this.
Exception: if a target page provides no favicon (e.g. login-protected pages), our server queries the favicon service of Google LLC as a last resort; this transmits the saved URL to Google. The result is cached on our side, and your browser still never communicates with Google. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in usable link previews); transfer to the USA on the basis of the EU-U.S. Data Privacy Framework (Google is certified).
YouTube links: when you save a YouTube link, our server retrieves the title, channel name, description and thumbnail via Google/YouTube interfaces (YouTube Data API, oEmbed, thumbnail servers); this transmits the video or channel identifier of the saved link to Google. This, too, happens exclusively server-side — your browser never communicates with Google or YouTube for this. Legal basis: Art. 6 (1) (f) GDPR; transfer to the USA on the basis of the EU-U.S. Data Privacy Framework. favowe uses YouTube API Services for this; the YouTube Terms of Service also apply in this respect, and how Google processes data is described in the Google Privacy Policy.
YouTube transcripts: in addition, when you save a YouTube video our server retrieves its publicly available transcript (subtitles) through the specialized service Supadata (EU-based provider), so that full-text search also covers the spoken content. Only the video identifier of the saved link is transmitted to Supadata — never your IP address or any account data; your browser never communicates with Supadata. The transcript is stored on our side (Frankfurt) and follows the link’s lifecycle. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in searchable saved content).
6. Search (full-text and semantic)
Full-text search runs entirely in our database (Frankfurt). For the semantic search, the title, tags, description, note and a short excerpt of the stored page text of a link — and, when you search, your search query — are briefly processed by an AI service of our processor Cloudflare in order to find and rank matching results. All of this processing is transient — nothing is stored at Cloudflare; the results stay in your browser. A processing location within the EU is not guaranteed (safeguard: Cloudflare data processing agreement with standard contractual clauses).
Legal basis: Art. 6 (1) (b) GDPR. In the settings (“Search by meaning”) you can hide these results from search; your search queries are then no longer processed for this, while saved links continue to be indexed.
7. AI agent connection (optional)
You can connect your own AI assistants (e.g. claude.ai) to your account via an MCP interface. In doing so, we process: OAuth access tokens (encrypted in Cloudflare KV, globally replicated), the name of the connected client, timestamps and an activity log of agent actions (which may contain compact before-snapshots of changed entries so you can review and undo changes; the contents of uploaded documents are never logged).
What data your AI provider itself processes when your agent reads your bookmarks is its own responsibility — only connect services you trust. Legal basis: Art. 6 (1) (b) GDPR (a feature you actively set up). Retention: activity log 90 days; tokens until you disconnect.
8. Browser extension and app installation (PWA)
The optional browser extension stores your session locally in your browser (chrome.storage). For the “already saved?” checkmark it transmits, while connected to your account, a normalized form of the address of the page you are viewing (host and path, without query parameters) to our server on each page visit — only to us, to no third party — and matches it against your saved links; the result is only shown locally, and the addresses are not stored in our database. The extension contains no telemetry. The installable web app (PWA) uses no service workers and collects no additional data.
Optional page text capture: if you enable “Also capture the page text” in the extension settings (off by default), the visible text of a page is captured at the moment you click save — from the page as your browser renders it, which can include content behind your own logins — and stored in your private search index (Supabase, Frankfurt) so you can find pages by their content. On YouTube, the video’s transcript is captured too when one is available; it is loaded through the page’s own transcript panel, which may briefly open. This happens only on your explicit save click, never in the background, never in incognito/private windows, and never on banking or webmail sites (built-in exclusion list of several thousand domains, extendable by you). Form input is never read, and the amount of text per page is capped. You can switch capture off for an individual save, exclude a site permanently (“never on this site”), and remove a page’s captured text at any time in the app (edit link → “Remove saved page text”) — once removed, it is never re-added automatically.
Captured page text is part of your library: like all your stored content, it can be read by AI agents you choose to connect (section 7). Legal basis: Art. 6 (1) (a) GDPR (consent, given by enabling the feature in the extension settings; revocable there at any time without affecting the lawfulness of processing carried out before the withdrawal — already captured text stays until you remove it). Retention: until you remove the text or delete the link.
9. Error, performance and usage diagnostics plus in-app feedback (self-hosted)
For debugging and product improvement we record — without third parties, in our own database (Frankfurt) — three kinds of technical events:
- Error reports: error type and masked error message (IDs/numbers removed), affected page path without query parameters, app version, account reference. Retention: 90 days.
- Performance measurements (Web Vitals): loading-time metrics from your browser. Retention: 60 days.
- Usage events: only the name of an action (e.g. “link opened”, “search opened”) with a timestamp — no URLs, no content, no link reference. Retention: 90 days.
Only aggregates are evaluated. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a stable, error-free service). Long-term statistics are kept only as anonymous totals without any personal reference. To protect against abuse and to enforce plan quotas we also keep short-lived technical counters and protection logs (e.g. rate limits, quota usage); they contain no content and are deleted automatically.
In-app feedback: via the feedback form in the app you can voluntarily send us comments (free text and a category). If you would like a reply, you can consent via a checkbox to us contacting you at your account email address — only then is your email address shown to us alongside the feedback. You can revoke this consent at any time with effect for the future (informally, to support@favowe.com). Legal basis: for contacting you, Art. 6 (1) (a) GDPR (consent); otherwise (f) (product improvement). Retention: we keep feedback indefinitely as product insight; the personal reference ends when your account is deleted.
Exit survey: when deleting your account you can voluntarily answer a short survey (reason, optional free text) — it can always be skipped and is never a precondition for deletion. The answer is stored anonymously, without any account reference; it therefore persists — without any personal reference — after your account is deleted. Legal basis: Art. 6 (1) (f) GDPR.
10. Backups
To protect against data loss (Art. 32 GDPR) we create nightly, encrypted database backups (retention: 14 days, stored in Cloudflare R2 with EU jurisdiction; the decryption key is kept exclusively offline by the controller) as well as a backup copy of uploaded documents. As a result, permanently deleted content may persist in backup copies for up to approx. 90 days after deletion before it is automatically removed there as well.
Backup transport runs via infrastructure of our processor GitHub (GitHub, Inc. / Microsoft, USA); this is based on the GitHub data processing agreement with standard contractual clauses and the EU-U.S. Data Privacy Framework.
11. Payment (pro plan)
You purchase the paid pro plan via our payment provider Paddle (Paddle.com Market Ltd., London, United Kingdom; for certain regions Paddle.com, Inc., USA). Paddle acts as merchant of record: the purchase contract for the subscription is concluded with Paddle, and Paddle is an independent controller for the payment processing — in this respect Paddle’s privacy policy applies.
When you buy, Paddle’s checkout opens (as an embedded window); you enter your payment and billing details directly with Paddle — we never receive or store payment data. From Paddle we only receive the status of your subscription (e.g. active, cancelled) and a customer identifier that we link to your account in order to activate the pro plan. Paddle’s scripts are only loaded when you open the upgrade dialog — not on normal app start.
In the checkout, Paddle sets technically necessary cookies (e.g. for fraud prevention); details are in Paddle’s privacy notices. If you use our public cancellation or withdrawal page, we process the email address you enter and your declaration in order to execute it and confirm receipt.
Legal basis: Art. 6 (1) (b) GDPR (performance of contract). Retention: subscription status until account deletion; statutory retention obligations (e.g. tax and invoice data) rest with Paddle as the seller. We retain records of subscription management even after account deletion: cancellation and withdrawal declarations, and the record that your subscription was cancelled upon account deletion, for three years (regular limitation period; legal basis in this respect Art. 6 (1) (f) GDPR — proof of proper contract termination), plus a log of billing events with Paddle identifiers (no payment data, no email address) as a billing record; the link to your account is removed upon deletion. An EU Commission adequacy decision is in place for the United Kingdom; any transfer to the USA is safeguarded by Paddle via EU standard contractual clauses.
12. Recipients and processors
We use the following processors (each under a contract pursuant to Art. 28 GDPR including EU standard contractual clauses):
| Provider | Service | Data location |
|---|---|---|
| Supabase, Inc. | Database, login, file storage | Frankfurt (EU); serverless functions may execute transiently worldwide |
| Cloudflare, Inc. | App delivery, document storage (R2), AI processing | Storage EU (R2 EU jurisdiction); edge processing transient, global |
| GitHub, Inc. / Microsoft | Backup automation | USA (transient transport only) |
| Resend, Inc. | Email delivery (account emails, product news) | Sending from the EU (Ireland); US provider |
Independent third-party recipients: Google LLC (favicon fallback and YouTube retrieval, section 5), Paddle as payment provider and merchant of record (section 11), your chosen OAuth login provider (section 3) and, where applicable, your AI provider (section 7). Transfers to third countries (USA) occur only in the cases mentioned and are safeguarded by standard contractual clauses or the EU-U.S. Data Privacy Framework. There is no selling and no advertising-related sharing of data. The EU standard contractual clauses are available on the European Commission’s website, the DPF certifications at www.dataprivacyframework.gov; on request to support@favowe.com we provide copies of the respective safeguards.
13. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20 GDPR). To exercise these rights, contact support@favowe.com.
Right to object (Art. 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (in particular sections 2, 5, 9, 11 and 14).
Much of this is fastest directly in the app: an export of your content in open formats (Settings → Export) and self-deletion of your account (Settings → Account) are available at any time — in every plan, free of charge. The export contains your bookmarks, notes, tags, uploaded documents and saved prompts. Not included are the page texts and YouTube transcripts favowe fetches automatically from the web to make your links searchable — they are not data you entered and can be fetched again at any time.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.
14. Contacting us
If you contact us by email (e.g. with a support request), we process your email address and the content of your message in order to handle the request. Legal basis: Art. 6 (1) (b) GDPR (requests related to your account) or (f) (other requests). Retention: until the request has been fully handled; statutory retention obligations remain unaffected.
15. No automated decision-making, no profiling
No automated decisions within the meaning of Art. 22 GDPR and no profiling take place.
16. Changes to this policy
We update this privacy policy when the service or the legal situation changes. The current version is always available at favowe.com; the effective date is shown at the top.
17. Controller
The controller within the meaning of the GDPR is:
Ahmet Altuntas Softwareentwicklung & IT-Dienstleistungen (favowe.com)
c/o Online-Impressum #9449, Europaring 90, 53757 Sankt Augustin, Germany
Email: support@favowe.com — see also the imprint.
A data protection officer has not been appointed, as the legal requirements (Art. 37 GDPR, § 38 BDSG) do not apply.