Privacy Policy
Last updated: September 2026
Who we are
Seeds is operated by Emanuele Forlano. For any question about this policy, or to exercise any of the rights described below, write to hello@useseeds.app.
What we collect, and why
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address and password (stored hashed) | To create and secure your account | Performance of a contract |
| Email address, if you join the waitlist | To send you an invitation when a place opens up | Consent |
| The URLs you save, and the article content our servers retrieve from them | To build and display your reading library | Performance of a contract |
| Archive, favourite and tag actions, timestamps, reading progress | To make the library work and keep it in sync across your devices | Performance of a contract |
| Server logs: IP address, time of request, browser user agent | Security, abuse prevention and debugging | Legitimate interest |
We use no third-party analytics, no advertising, and no behavioural profiling. We do not build a profile of you. Our email provider records aggregate open and click counts — not linked to you individually — solely to monitor deliverability.
How we use it
We use your data only to operate and secure Seeds. We do not sell it, and we do not disclose it to anyone for their own purposes.
We do not read or analyse the articles you save — they are stored so that they can be shown back to you. When you save a page, our servers are the ones that fetch it: the source website sees a request from Seeds, not from you.
Who processes it for us
We rely on a small number of providers who process data on our behalf, under written data processing agreements. Our current providers are:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and storage for the website, the app and the database | Germany |
| Brevo (Sendinblue) | Sending account and waitlist emails | France (EU) |
| Cloudflare, Inc. | Bot and abuse protection on our public forms (Turnstile) | USA |
If we change provider, we will update this policy.
Where your data is stored
Your account data and the articles you save are stored and processed within the European Union. The only personal data that leaves the EEA is the IP address seen by Cloudflare when the anti-bot check (Turnstile) runs on a public form; this transfer is covered by appropriate safeguards (Standard Contractual Clauses).
How long we keep it
Your account and your saved articles are kept for as long as your account exists. If you delete your account, or ask us to, we erase your personal data — including from backups — within 30 days.
Waitlist emails are kept until you receive your invitation, and in any case no longer than 12 months. You can ask to be removed at any time.
Server logs are kept for 30 days. Session tokens expire after 30 days without use.
Your rights
You have the right to access the personal data we hold about you, to have it corrected, to have it erased, to receive a copy of it in a portable format, to restrict or object to how we process it, and to withdraw your consent where our processing is based on it.
Write to hello@useseeds.app and we will respond within 30 days. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.gpdp.it).
Security
Data is stored on servers in Germany and encrypted in transit. Passwords are stored hashed and are never readable by us. Access to production systems is limited to the founder, Emanuele Forlano.
Cookies
Seeds does not use cookies. We keep you signed in using your browser's local storage, a technical mechanism strictly necessary to provide the service. We use no profiling or advertising cookies and no trackers, which is why you are not asked to accept a cookie banner.
Children
Seeds is not intended for anyone under 16, and we do not knowingly collect data from children.
Browser extension
The Seeds browser extension lets you save the page you are currently viewing to your library. It is operated by us, and the whole of this policy applies to it.
What it sends. When you click the extension icon and choose to save, the extension sends the address of that page to our servers, together with your session token. It sends nothing else: not the title, not the page content, not your browsing history. Our servers then retrieve the article from that address, exactly as they would if you had pasted the URL into the app.
Signing in. Signing in happens on app.useseeds.app, in a normal browser tab. The extension never asks for your password. It stores the resulting session token in your browser's local extension storage (chrome.storage.local) so that you stay signed in. The token is deleted when you sign out, and expires automatically after 30 days without use.
Permissions we request. Access to the address of the active tab, granted only at the moment you click the icon; local extension storage, to keep you signed in; and network access to app.useseeds.app. We request nothing else. The extension runs no code on the pages you browse: it includes a single small script that runs only on app.useseeds.app, and only during a sign-in you have started from the extension, for the sole purpose of reading your session token from that page after you log in.
No analytics, no third-party code. The extension communicates only with Seeds' own backend. It contains no analytics, no advertising and no third-party libraries that send data anywhere.
Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect how we handle your data, we will notify you by email before they take effect.