noweb

Privacy Policy

Last updated: August 4, 2026

1. Controller

Corinna Kimmerle-Muffler, trading as noweb
Schwabenstraße 26
72768 Reutlingen, Germany
Email: team@noweb.app

2. Visiting Noweb and server operation

When you access Noweb, the server necessarily processes connection data such as your IP address, requested URL, time of access, response status, browser information and referring page. This is necessary to deliver the service, maintain security and investigate faults. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure and reliable operation of Noweb.

The application, PostgreSQL database, object storage and published websites are operated by us on our own server in Germany. Technical log data is not used for advertising or analytics and is retained only for as long as needed for operation, security or the investigation of a specific incident, after which it is deleted or overwritten through system rotation.

3. Accounts and authentication

To create and operate an account, we process your name, email address, profile image if supplied, password hash, email-verification records, account identifiers, login methods, session data and security information. We never store your plain-text password. Processing is necessary to provide your account and the requested service under Article 6(1)(b) GDPR and to protect accounts under Article 6(1)(f) GDPR.

If you choose Google or GitHub sign-in, the selected provider sends us the account information required for authentication, normally an identifier, name, email address, profile image, verification status and authentication tokens needed to maintain the connection. Your use of the provider is also governed by its own privacy terms. The transfer is initiated only when you select that sign-in method.

Google privacy information: policies.google.com/privacy. GitHub privacy information: GitHub General Privacy Statement.

4. Transactional email

We use Resend to send verification and other service-related emails. We transmit the recipient address and the content necessary for the particular message. The legal basis is Article 6(1)(b) GDPR. For security or legally required notices, Article 6(1)(c) or (f) GDPR may also apply. Resend's privacy information is available at resend.com/legal/privacy-policy.

If you use the electronic withdrawal function, we process your name, email address, contract reference, declaration and submission time to receive, confirm and process the withdrawal and forward it to Polar as the merchant of record. The legal basis is Article 6(1)(b) and (c) GDPR.

5. Projects, templates, uploads and publishing

We process project and template names, source code, customizations, domains, publication status, uploaded files and related account identifiers to provide the editor, moderation, storage and hosting functions. The legal basis is Article 6(1)(b) GDPR.

Content that you publish, including approved community templates, websites, domains and uploaded images, is publicly accessible. Do not upload personal data or images of another person unless you have a lawful basis and all necessary rights.

Account and content data is kept while your account exists and while it is needed to provide the service. You can delete individual projects and templates in the service where that function is available. To request account deletion, email team@noweb.app. Approved community templates and the minimum associated account reference may be retained where necessary to preserve licenses already granted to other users, comply with law or establish, exercise or defend legal claims.

6. AI assistant

When you use the AI assistant, we send your prompt and the editable project content needed to generate suggestions to OpenAI Ireland Ltd. The legal basis is Article 6(1)(b) GDPR. OpenAI processes this data on our behalf under a data-processing agreement. API data is not used to train OpenAI models by default. Depending on our account settings, content may be retained in abuse-monitoring logs for up to 30 days. Do not submit sensitive personal data.

7. Payments and subscriptions

Paid subscriptions are sold and billed by Polar Software, Inc. as merchant of record. When you start checkout, we send Polar the account identifier, email address and selected product information necessary to create and manage the order. Polar independently processes payment, billing, tax, invoice and subscription data under its own terms and privacy policy. We receive subscription status and identifiers needed to provide paid access. The legal basis is Article 6(1)(b) GDPR.

Polar's privacy policy is available at polar.sh/legal/privacy-policy.

8. Illegal-content reports and support

If you contact us or submit an illegal-content report, we process the information you provide, contact details, affected URL, report text, supporting information and our handling of the matter. Processing is based on Article 6(1)(c) GDPR where required by the Digital Services Act and otherwise on Article 6(1)(f) GDPR. Our legitimate interests are responding to requests, enforcing our rules and protecting legal rights. Reports are retained for the duration of the review and as long as necessary for statutory duties or legal claims.

9. Cookies and local browser storage

Noweb uses authentication cookies required to keep you signed in and protect sessions. We also store your selected color-theme preference locally in your browser. These technologies are necessary to provide functions you request. We do not currently use advertising cookies, marketing pixels or analytics cookies.

10. International transfers

Google, GitHub, Resend, OpenAI and Polar are based in or may process data in the United States. Where personal data is transferred outside the European Economic Area, the relevant provider and transfer are covered by an applicable adequacy decision, including the EU-US Data Privacy Framework where available, or safeguards under Article 46 GDPR such as the European Commission's Standard Contractual Clauses. Further information and copies of applicable safeguards can be requested from us. Relevant safeguards are incorporated into the Resend DPA, the OpenAI DPA and the Polar DPA.

11. Your rights

Subject to the legal requirements, you have the right to access, rectify or erase your data, restrict processing, receive data you provided in a portable format and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time for the future. You also have the right to lodge a complaint with a data-protection authority.

The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg. You can find its contact details at baden-wuerttemberg.datenschutz.de. You may exercise your rights by emailing team@noweb.app.

12. Changes to this policy

We update this policy when our processing or legal obligations change. The current version is always available on this page.

For contractual rules, please see the Terms of Service.