SecondBrain LogoSecondBrain

Privacy Policy

Last updated: 21 May 2026

This Privacy Policy explains how your personal data is collected and processed when you use SecondBrain (the "Service"), in accordance with Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 (the "Privacy Code"). Please read it together with our Cookie Policy and Terms of Service.

1. Data Controller

The data controller is Alessio Gedda, a natural person established in Italy.

For any matter relating to your personal data or to exercise your rights, you can contact the controller at: alessiogedda@yahoo.com.

2. What personal data we collect

We only collect the data needed to provide the Service:

  • Account data: your name, email address and an encrypted password.
  • Technical and security data: IP address, browser/device user-agent, session and activity timestamps, used for authentication, security and abuse prevention.
  • Content you create: notes, tasks and calendar events, planning and reviews, contacts and people, trips and places, recipes, bookmarks, wishlists, inventory (bags, hardware, software), and your subscriptions to YouTube/Twitch channels and RSS feeds.
  • Financial data you enter yourself: budgets, payments, cashflow and subscription records.
  • Health data you enter yourself: medication (pills) and water-intake tracking. This is a special category of data (see section 4).
  • Preferences: language, theme, timezone, calendar and notification settings, and push-notification subscriptions if you enable them.

3. Purposes and legal bases

We process your data for the following purposes and on the following legal bases under Art. 6 GDPR:

  • To create your account and provide the Service — performance of the contract with you (Art. 6(1)(b)).
  • To send transactional emails (email verification, password reset) — performance of the contract (Art. 6(1)(b)).
  • To keep the Service secure (rate-limiting, inactivity lock, abuse prevention) — our legitimate interest in protecting the Service and its users (Art. 6(1)(f)).
  • To send push notifications you opt into — your consent (Art. 6(1)(a)), which you can withdraw at any time in your settings.

4. Health and other special-category data

The Service lets you record health-related information (such as medication and water intake). Under Art. 9 GDPR this is a special category of data.

We process it solely to provide you the tracking features you choose to use, on the basis of your explicit consent (Art. 9(2)(a)), which you give by entering this data. You are never required to enter health data, and you can delete it at any time. Withdrawing consent means deleting the related entries or your account.

5. Cookies and local storage

We use only technical cookies and browser storage that are strictly necessary to keep you signed in and to remember your language. We do not use profiling, advertising or analytics cookies, and we do not embed third-party trackers.

For details see our Cookie Policy.

6. Recipients and processors

We do not sell your data. We share it only with service providers that process data on our behalf (data processors), namely:

  • Hetzner Online GmbH, located in Germany (European Union), which hosts the database and application.
  • Brevo (Sendinblue), located in France (European Union), to deliver transactional emails.
  • The public YouTube and Twitch APIs, queried only to fetch public channel/video information for the channels you follow; no account data of yours is shared with them.

7. Where your data is stored and transfers

Your data is hosted within the European Union (Germany), and all the processors we use are located within the European Union, so no transfer of your data outside the EU takes place.

8. Data retention

We keep your personal data for as long as your account is active. When you delete your account, your personal data and all related content are permanently erased from the database. Backups, if any, are overwritten on their normal rotation cycle. Some technical logs may be retained for a limited period for security purposes.

9. Your rights

Under the GDPR you have the right to access your data, to rectify it, to erase it, to restrict or object to its processing, to data portability, and to withdraw any consent at any time. You can:

  • Access and correct most data directly in the app.
  • Export all your data as a file from your Profile page ("Download my data").
  • Delete your account and all associated data from your Profile page.
  • Contact us at alessiogedda@yahoo.com for any other request.

10. Complaints

If you believe your data is processed unlawfully, you have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of your country of residence.

11. Security

Passwords are stored hashed, sensitive secrets are encrypted, and access requires authentication over an encrypted connection. No system is completely secure, but we take reasonable technical measures to protect your data.

12. Minimum age

The Service is not intended for children under 14, the minimum age set in Italy for consent to information society services (Art. 8 GDPR and Art. 2-quinquies of the Privacy Code). If you are under 14, please do not use the Service.

13. Changes to this policy

We may update this Privacy Policy. The date at the top reflects the latest version, and significant changes will be communicated within the Service.

Questions about this document? Contact us at alessiogedda@yahoo.com.

Back to home