save4me keeps the links you save. This page explains which data reaches our servers, why, how long it stays, and how to take it away or delete it. It is written to be read, not filed.
The data controller is asaconsult di Antonio Saponara, Piazza Card. Carlo Maria Martini 5, 20013 Magenta (MI), Italy — VAT IT 07281210968.
For anything about this policy, or to exercise your rights: asaponara@asaconsult.com.
No Data Protection Officer has been appointed: this processing does not fall within the cases where the GDPR requires one.
Cloud sync is on by default. On first launch the app creates an account by itself — without asking you anything, because no email and no password are needed — and from that moment the data described below reaches us. We would rather say it plainly: this is not a feature you switch on, it is one you can switch off.
It exists so you can find your links on another device, and not lose them if you lose this one. If you would rather not, turn it off under Account and privacy: with it off, your links stay on your device and nothing leaves your phone. The same screen also lets you delete the account, erasing what has already arrived.
One exception: preview resolution, described further down, may contact our servers before that, because its whole job is to show you the image of the link you are saving.
Every row of this table matches something that actually exists in our database. We collect nothing else.
| Data | What it is for | Legal basis |
|---|---|---|
| Account identifier | A random number generated by the server, with no link to your identity. It is what holds your links together. | Performance of a contract (art. 6(1)(b)) |
| iCloud identifier | Apple only. A code provided by iCloud that lets your devices recognise the same account without asking you to sign in. It is not your Apple ID and carries no name or email. | Performance of a contract (art. 6(1)(b)) |
| Recovery anchors | If you choose to protect your links with Apple or Google, we keep the name of that service and the technical identifier it returns to us. It is what finds your account again on a new phone. We neither receive nor store your name or your email. | Performance of a contract (art. 6(1)(b)) |
| Links and folders | Address, title, tags, notes, preview image address and dates. This is the content you asked us to keep: it is yours, not ours. | Performance of a contract (art. 6(1)(b)) |
| Connected devices | A device identifier, the platform and operating system version, the date of last access, and the outcome of the app authenticity check. It is what makes syncing work and stops anyone from impersonating the app. | Contract (art. 6(1)(b)) and legitimate interest in security (art. 6(1)(f)) |
| Access tokens | One credential per device, keeping the app signed in without a password from you. Deleting your account revokes them all. | Performance of a contract (art. 6(1)(b)) |
| Pairing codes | The six-digit codes that connect two devices. They expire after two minutes and work once. | Performance of a contract (art. 6(1)(b)) |
| Server technical logs | Like every web server, we record IP address, date, time and the request made. They serve to diagnose faults and to recognise abuse. | Legitimate interest in security (art. 6(1)(f)) |
| Waiting-list signup | On this website only, and only if you sign up: email, the platform you care about, where the visit came from, IP address and browser. It is what lets us tell you when the app ships. | Consent (art. 6(1)(a)), withdrawable at any time |
What "a link" really means. A saved address can reveal a great deal about the person who saved it, and the notes you attach reveal more. We treat this content as personal data in full — but it is worth knowing: if you save something you would rather not entrust to anyone, syncing can stay off.
When you save a link, our server may visit that address on your behalf to fetch its image. That is a technical choice with a consequence worth knowing: the destination site sees a request coming from our server, not from your device, and therefore does not see your IP address. For YouTube and TikTok we use their public endpoints instead.
We neither copy nor keep those images on our servers: we return only their address, and the copy of the image stays on your device. The address of the link being saved is used for that request and not separately retained in application logs.
Your links and your account live on Oracle Cloud Infrastructure servers in the Milan region (eu-milan-1), in Italy. We do not move them outside the European Union.
We rely on these providers, each for one precise job:
| Provider | What it does for us | Where |
|---|---|---|
| Oracle Cloud Infrastructure | Hosts the application and the database. | Milan, Italy |
| Cloudflare | Protects and encrypts traffic to the site and the API. It processes technical connection data, including the IP address. | Global network, including outside the EU, under the transfer safeguards the GDPR requires |
| Apple | Verifies that requests come from the genuine iOS app (App Attest) and, if you choose it, provides the recovery identity (Sign in with Apple). | Per Apple’s own policy |
| The equivalent functions on Android (Play Integrity and Google sign-in), once the Android app ships. | Per Google’s own policy |
None of these providers receives your links for purposes of their own. Cloudflare, Apple and Google process technical data under their respective policies, over which we have no control.
You do not need to write to us for the two rights people exercise most: they are inside the app, under Account and privacy.
Deletion covers our servers. The links still on your device remain: they are yours, and you remove them by deleting them in the app or uninstalling it.
The exact steps, and what to do if you no longer have the device, are on the Deleting your account page.
The GDPR gives you the right to access your data, correct it, erase it, restrict its processing, object to processing based on legitimate interest, and receive it in a portable format. Where we asked for your consent, you may withdraw it at any time without affecting the lawfulness of what came before.
To exercise them, write to asaponara@asaconsult.com. We answer within one month, as art. 12 requires.
One honest caveat: because we ask for no email and no password, we usually cannot connect a request sent by email to an account. That is precisely why export and deletion live inside the app, where the device proves for itself that it is authorised. If you do write to us, we may have to ask you to use those functions.
If you believe the processing breaches the GDPR, you may lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or with the authority of the country where you live.
For completeness: the data is not individually encrypted in the database beyond the storage-level encryption the infrastructure provides. Whoever administers the system can therefore technically reach it. We write this down because an end-to-end encryption promise that was not true would be worse than saying nothing.
The app uses no cookies. This website uses the bare minimum it needs to work — all technical, none for advertising, and none requiring a consent banner under the law:
save4me is not intended for children under 14, the age Italian law sets for digital consent. We do not knowingly collect their data; if we find that we have, we delete it.
When the product changes, this page changes with it: it lives in the same repository as the code it describes, precisely so it cannot drift. The date at the top is the last update. Should a change materially affect the processing, we will say so inside the app.