seeds

Privacy Policy

Last updated: September 2026

Who we are

Seeds is operated by Emanuele Forlano. For any question about this policy, or to exercise any of the rights described below, write to hello@useseeds.app.

What we collect, and why

Data Why we collect it Legal basis
Email address and password (stored hashed) To create and secure your account Performance of a contract
Email address, if you join the waitlist To send you an invitation when a place opens up Consent
The URLs you save, and the article content our servers retrieve from them To build and display your reading library Performance of a contract
Archive, favourite and tag actions, timestamps, reading progress To make the library work and keep it in sync across your devices Performance of a contract
Server logs: IP address, time of request, browser user agent Security, abuse prevention and debugging Legitimate interest

We use no third-party analytics, no advertising, and no behavioural profiling. We do not build a profile of you. Our email provider records aggregate open and click counts — not linked to you individually — solely to monitor deliverability.

How we use it

We use your data only to operate and secure Seeds. We do not sell it, and we do not disclose it to anyone for their own purposes.

We do not read or analyse the articles you save — they are stored so that they can be shown back to you. When you save a page, our servers are the ones that fetch it: the source website sees a request from Seeds, not from you.

Who processes it for us

We rely on a small number of providers who process data on our behalf, under written data processing agreements. Our current providers are:

Provider Purpose Location
Hetzner Online GmbH Hosting and storage for the website, the app and the database Germany
Brevo (Sendinblue) Sending account and waitlist emails France (EU)
Cloudflare, Inc. Bot and abuse protection on our public forms (Turnstile) USA

If we change provider, we will update this policy.

Where your data is stored

Your account data and the articles you save are stored and processed within the European Union. The only personal data that leaves the EEA is the IP address seen by Cloudflare when the anti-bot check (Turnstile) runs on a public form; this transfer is covered by appropriate safeguards (Standard Contractual Clauses).

How long we keep it

Your account and your saved articles are kept for as long as your account exists. If you delete your account, or ask us to, we erase your personal data — including from backups — within 30 days.

Waitlist emails are kept until you receive your invitation, and in any case no longer than 12 months. You can ask to be removed at any time.

Server logs are kept for 30 days. Session tokens expire after 30 days without use.

Your rights

You have the right to access the personal data we hold about you, to have it corrected, to have it erased, to receive a copy of it in a portable format, to restrict or object to how we process it, and to withdraw your consent where our processing is based on it.

Write to hello@useseeds.app and we will respond within 30 days. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.gpdp.it).

Security

Data is stored on servers in Germany and encrypted in transit. Passwords are stored hashed and are never readable by us. Access to production systems is limited to the founder, Emanuele Forlano.

Cookies

Seeds does not use cookies. We keep you signed in using your browser's local storage, a technical mechanism strictly necessary to provide the service. We use no profiling or advertising cookies and no trackers, which is why you are not asked to accept a cookie banner.

Children

Seeds is not intended for anyone under 16, and we do not knowingly collect data from children.

Browser extension

The Seeds browser extension lets you save the page you are currently viewing to your library. It is operated by us, and the whole of this policy applies to it.

What it sends. When you click the extension icon and choose to save, the extension sends the address of that page to our servers, together with your session token. It sends nothing else: not the title, not the page content, not your browsing history. Our servers then retrieve the article from that address, exactly as they would if you had pasted the URL into the app.

Signing in. Signing in happens on app.useseeds.app, in a normal browser tab. The extension never asks for your password. It stores the resulting session token in your browser's local extension storage (chrome.storage.local) so that you stay signed in. The token is deleted when you sign out, and expires automatically after 30 days without use.

Permissions we request. Access to the address of the active tab, granted only at the moment you click the icon; local extension storage, to keep you signed in; and network access to app.useseeds.app. We request nothing else. The extension runs no code on the pages you browse: it includes a single small script that runs only on app.useseeds.app, and only during a sign-in you have started from the extension, for the sole purpose of reading your session token from that page after you log in.

No analytics, no third-party code. The extension communicates only with Seeds' own backend. It contains no analytics, no advertising and no third-party libraries that send data anywhere.

Changes to this policy

If we change this policy we will update the date at the top. For changes that materially affect how we handle your data, we will notify you by email before they take effect.