shield_person Privacy policy
Last updated: August 13, 2026
1. Who we are
Floatee is published by BIG et Nouf, a French SARL registered at 17 Boulevard de Strasbourg, 62000 Arras, France (RCS Arras 978 428 506, VAT FR55 978 428 506). For any privacy-related question, contact us at contact@bigetnouf.fr.
2. Data we collect
We collect only what the service needs to operate:
- Account data: email address, display name, avatar URL, and the OAuth subject identifier returned by your sign-in provider (GitHub or Codeberg).
- Workspace content: workspaces, projects, items (todos, ideas, notes), their comments and attachments, and the API tokens you create in the app.
- Technical logs: timestamp, IP and HTTP status of each API request, kept for rate-limiting and abuse detection.
- Billing identifiers: a Paddle customer reference once you subscribe to a paid plan. We never see or store card data.
3. Why we process it
- Operate the service: store and organize your items, run search, and sync across your devices.
- Authenticate you and prevent unauthorized access to your workspaces.
- Bill your subscription (paid plans only) via Paddle.
- Detect and block abuse (rate-limit, request logs).
- Communicate service-critical messages (security alerts, invoices, account changes).
We never sell your data and never use your content for advertising or profiling. If you connect your own AI agent or script to the API, the content it reads is transmitted to that third-party service, which you choose and control; we are not responsible for how that service processes it.
4. How long we keep it
- Your content (items, comments, attachments): kept while your account is active. Items you delete are soft-deleted and stay in your history and search until you permanently remove them or close your account.
- Account data: kept while your account is active and deleted when you close it. A short audit window (logs of authentication and billing events) may be retained up to 12 months for security and legal compliance.
- Billing records: invoices and the underlying transaction trail are retained for the period required by French accounting law (10 years).
5. Sub-processors
Operating the service relies on a small number of vetted third parties:
- o2switch (France): hosting and storage. Data resides in their Clermont-Ferrand datacenter.
- GitHub / Codeberg: OAuth sign-in.
- Paddle.com Market Ltd (UK): Merchant of Record handling subscription billing, tax collection and customer payment data on our behalf.
We sign Data Processing Agreements with these sub-processors where applicable.
6. International transfers
Service data is stored within the European Union (o2switch, France). Some sub-processors (Paddle, GitHub) may process limited account or billing data outside the EU under standard contractual clauses or adequacy decisions.
7. Your rights
Under the GDPR you can access, rectify, port, restrict or erase your personal data, and object to its processing. You can act on most of these rights directly from your account (Settings → Account), or contact us at contact@bigetnouf.fr. You may also lodge a complaint with the CNIL (French data protection authority).
8. Security
We use HTTPS for every connection, hash credentials with strong algorithms, sign session tokens, and keep databases on encrypted volumes provided by our host. No system is perfectly secure: if you spot a vulnerability please email contact@bigetnouf.fr.
9. Cookies
Floatee uses a single first-party session cookie to keep you signed in. We do not use advertising, analytics or third-party tracking cookies.
10. Audience measurement
Floatee measures its audience with Matomo, hosted on our own servers: without cookies, with an anonymised IP address, and a retention limited to 180 days. No item content, no token and no account data is ever transmitted. This is why you are not asked to accept anything.
What we record is a page view, along with your interface language, your theme, and whether you opened Floatee as an installed app or in a browser tab. Identifiers in the address bar are replaced by :id before anything is sent, and four areas are excluded from measurement entirely: invitation links, which carry an access secret; the administration pages; the capture screen, which receives whatever you shared from another app; and every item page (/i/…), whose address contains the name of your workspace.
On top of that, the following events count an action. Each one carries a type, never a value you typed. Open your browser's network tab and check for yourself:
| Event | When | What is transmitted |
|---|---|---|
| floatee / signup / github | You create an account | The sign-in provider, never your name or email |
| floatee / login / github | You sign back in | The sign-in provider, never who you are |
| floatee / item / todo | You capture a todo, an idea or a note | Which of the three, never the title, the body, the tags nor the attachments |
| floatee / item / view | You open an item | Nothing else, never which item nor where it lives |
| floatee / capture / quick-add | A capture comes in through the quick-add bar, the system share sheet, or the offline queue | Which of the three entry points, never what was captured |
| floatee / workspace / create | You create a workspace | Nothing else, never its name |
| floatee / project / create | You create or delete a project | Which of the two, never the project name |
| floatee / member / invite | You invite someone to a workspace | Nothing else, never their email or the invitation code |
| floatee / token / create | You create or revoke an agent token | Which of the two, never the label nor the token |
| floatee / push / enable | You turn on browser notifications | Nothing else, never your push endpoint |
| floatee / checkout / pro | A payment overlay opens | The plan, never an amount or a customer reference |
| floatee / subscribed / pro | A subscription is confirmed | The plan, never an amount or a customer reference |
What your agent does through the API is not measured this way at all: it happens server-side and never reaches Matomo. And we deliberately do not attach your account to these measurements, so they count usage, not people.
11. Changes
We may update this policy as the service evolves. Material changes will be announced in the in-app changelog and, when required, by email.