Floatee

shield_person Privacy policy

Last updated: August 13, 2026

1. Who we are

Floatee is published by BIG et Nouf, a French SARL registered at 17 Boulevard de Strasbourg, 62000 Arras, France (RCS Arras 978 428 506, VAT FR55 978 428 506). For any privacy-related question, contact us at contact@bigetnouf.fr.

2. Data we collect

We collect only what the service needs to operate:

  • Account data: email address, display name, avatar URL, and the OAuth subject identifier returned by your sign-in provider (GitHub or Codeberg).
  • Workspace content: workspaces, projects, items (todos, ideas, notes), their comments and attachments, and the API tokens you create in the app.
  • Technical logs: timestamp, IP and HTTP status of each API request, kept for rate-limiting and abuse detection.
  • Billing identifiers: a Paddle customer reference once you subscribe to a paid plan. We never see or store card data.

3. Why we process it

  • Operate the service: store and organize your items, run search, and sync across your devices.
  • Authenticate you and prevent unauthorized access to your workspaces.
  • Bill your subscription (paid plans only) via Paddle.
  • Detect and block abuse (rate-limit, request logs).
  • Communicate service-critical messages (security alerts, invoices, account changes).

We never sell your data and never use your content for advertising or profiling. If you connect your own AI agent or script to the API, the content it reads is transmitted to that third-party service, which you choose and control; we are not responsible for how that service processes it.

4. How long we keep it

  • Your content (items, comments, attachments): kept while your account is active. Items you delete are soft-deleted and stay in your history and search until you permanently remove them or close your account.
  • Account data: kept while your account is active and deleted when you close it. A short audit window (logs of authentication and billing events) may be retained up to 12 months for security and legal compliance.
  • Billing records: invoices and the underlying transaction trail are retained for the period required by French accounting law (10 years).

5. Sub-processors

Operating the service relies on a small number of vetted third parties:

  • o2switch (France): hosting and storage. Data resides in their Clermont-Ferrand datacenter.
  • GitHub / Codeberg: OAuth sign-in.
  • Paddle.com Market Ltd (UK): Merchant of Record handling subscription billing, tax collection and customer payment data on our behalf.

We sign Data Processing Agreements with these sub-processors where applicable.

6. International transfers

Service data is stored within the European Union (o2switch, France). Some sub-processors (Paddle, GitHub) may process limited account or billing data outside the EU under standard contractual clauses or adequacy decisions.

7. Your rights

Under the GDPR you can access, rectify, port, restrict or erase your personal data, and object to its processing. You can act on most of these rights directly from your account (Settings → Account), or contact us at contact@bigetnouf.fr. You may also lodge a complaint with the CNIL (French data protection authority).

8. Security

We use HTTPS for every connection, hash credentials with strong algorithms, sign session tokens, and keep databases on encrypted volumes provided by our host. No system is perfectly secure: if you spot a vulnerability please email contact@bigetnouf.fr.

9. Cookies

Floatee uses a single first-party session cookie to keep you signed in. We do not use advertising, analytics or third-party tracking cookies.

10. Audience measurement

Floatee measures its audience with Matomo, hosted on our own servers: without cookies, with an anonymised IP address, and a retention limited to 180 days. No item content, no token and no account data is ever transmitted. This is why you are not asked to accept anything.

What we record is a page view, along with your interface language, your theme, and whether you opened Floatee as an installed app or in a browser tab. Identifiers in the address bar are replaced by :id before anything is sent, and four areas are excluded from measurement entirely: invitation links, which carry an access secret; the administration pages; the capture screen, which receives whatever you shared from another app; and every item page (/i/…), whose address contains the name of your workspace.

On top of that, the following events count an action. Each one carries a type, never a value you typed. Open your browser's network tab and check for yourself:

EventWhenWhat is transmitted
floatee / signup / githubYou create an accountThe sign-in provider, never your name or email
floatee / login / githubYou sign back inThe sign-in provider, never who you are
floatee / item / todoYou capture a todo, an idea or a noteWhich of the three, never the title, the body, the tags nor the attachments
floatee / item / viewYou open an itemNothing else, never which item nor where it lives
floatee / capture / quick-addA capture comes in through the quick-add bar, the system share sheet, or the offline queueWhich of the three entry points, never what was captured
floatee / workspace / createYou create a workspaceNothing else, never its name
floatee / project / createYou create or delete a projectWhich of the two, never the project name
floatee / member / inviteYou invite someone to a workspaceNothing else, never their email or the invitation code
floatee / token / createYou create or revoke an agent tokenWhich of the two, never the label nor the token
floatee / push / enableYou turn on browser notificationsNothing else, never your push endpoint
floatee / checkout / proA payment overlay opensThe plan, never an amount or a customer reference
floatee / subscribed / proA subscription is confirmedThe plan, never an amount or a customer reference

What your agent does through the API is not measured this way at all: it happens server-side and never reaches Matomo. And we deliberately do not attach your account to these measurements, so they count usage, not people.

11. Changes

We may update this policy as the service evolves. Material changes will be announced in the in-app changelog and, when required, by email.