What WebBites collects, why, who else ever sees it, and how to make us delete it.
Last updated 16 September 2026
WebBites is operated by Elias Ruiz Monserrat ([NIF — to be filled in]), [street, postcode, city] — Spain. We are the data controller for the processing described here. You can reach us at contact@webbites.io — a person reads it, and it is also the address for any request about your data.
We are a small operation based in Spain, so the GDPR (Regulation (EU) 2016/679) and the Spanish LOPDGDD apply to everything below. We are not required to appoint a Data Protection Officer and have not appointed one; write to the address above instead.
This policy covers the website and web app at https://www.webbites.io, the WebBites apps for iPhone, iPad, Mac, Apple Vision Pro, Apple TV and Apple Watch, the share and Safari extensions, the browser extension, and the public API.
The native apps work signed out. In that mode there is a local library on your device: bites, collections, tags and your view preferences are kept in the app's own storage, and none of it reaches our servers. There is no account, so there is nothing for us to hold.
Two things are worth being precise about, because "offline" is a word people stretch:
The exception, stated plainly: the apps send crash and performance reports (a stack trace, the OS version, the device model — no bookmark contents) to our own error-tracking server, which we run ourselves on our own infrastructure. It is not a third-party analytics product and there is no advertising identifier involved. We do not run any usage analytics inside the native apps.
The web app is the other case: it is an account product and needs our servers to do anything at all.
Your email address, your username or display name, a password hash (never the password itself), your language and app preferences, and the dates your account was created and last used. If you sign in with Apple and choose to hide your email, we get Apple's private relay address and that is all we ever have.
Everything you save and everything the service derives from it so it can be found again: URLs, titles, descriptions, notes, annotations, tags, boards and collections, highlights, drawings, uploaded files and PDFs, screenshots and images, extracted article text, RSS feeds you follow, and AI-generated summaries, tags and search embeddings.
IP address, browser or device type and OS version, and server logs of the requests your client makes (endpoint, timestamp, response status). We use these to keep the service up, debug it and stop abuse — not to build a profile of you.
If you subscribe, we store your plan, its status and renewal date, and the customer or transaction identifier from the payment provider. We never see or store your card number. Card details go straight to Stripe (on the web and Mac) or to Apple (for in-app purchases), who are the ones processing the payment.
Support emails, feedback and feature requests posted in the app, and anything you choose to include in them.
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Running the service: your account, storing and syncing what you save, search, sharing, enrichment | Performance of a contract — art. 6(1)(b) |
| Taking payment, managing subscriptions, preventing payment fraud | Contract — art. 6(1)(b); legal obligation for invoices and VAT — art. 6(1)(c) |
| Security, rate limiting, abuse prevention, backups, crash and error reports | Legitimate interests — art. 6(1)(f): keeping the service working and safe |
| Aggregate, cookieless website statistics on our own analytics server | Legitimate interests — art. 6(1)(f): knowing whether the site works, without tracking anyone |
| Session recording and heatmaps on the marketing site (Microsoft Clarity) | Consent — art. 6(1)(a). Nothing is recorded unless you accept the banner, and you can change your mind |
| Product emails you asked for, and answering your support messages | Contract — art. 6(1)(b); consent for anything promotional — art. 6(1)(a) |
| Complying with tax, accounting and law-enforcement obligations | Legal obligation — art. 6(1)(c) |
We do not deliberately collect special-category data (health, beliefs, biometrics and the rest). You can of course save a page about anything you like; we treat the contents of your library as private either way and do not analyse it beyond what is needed to show, enrich and search it for you.
With an account, WebBites can summarise a page, suggest tags, answer questions about your library and build the embeddings that make semantic search work. To do that, the relevant text — the page content, your query, and the metadata around it — is sent to our AI providers, OpenAI and Anthropic, over their business APIs.
There is no automated decision-making that produces legal effects for you, and no profiling in the art. 22 sense.
To change your answer, visit the site with ?resetConset appended to the URL and the banner comes back.
We do not sell your data and we do not share it for advertising. We use these processors and providers to run the service:
| Who | What for | Where |
|---|---|---|
| Our own servers | Accounts and authentication, your library's database, realtime sync, the application backend, the search index, image and file storage, website statistics and error tracking — all of it on hardware we rent and administer ourselves | EU |
| Upstash | Job queue and cache for the save pipeline | EU / USA |
| Algolia | Legacy search index, still written to while it is retired | EU / USA |
| Stripe | Payments and subscriptions on the web and Mac | USA / EU |
| Apple | Sign in with Apple, App Store in-app purchases, push notifications, iCloud sync of app settings | EU / USA |
| OpenAI | Summaries, tagging, embeddings, semantic search | USA |
| Anthropic | Summaries, tagging, answering questions about your library | USA |
| Mailgun | Transactional email: sign-up, password reset, receipts | EU / USA |
| Microsoft (Clarity) | Website session analytics — only with your consent | USA |
When you save a link, our servers fetch that page to build the preview, and may ask the relevant public service (for example a film, music or game database) for metadata about it. Those requests contain the URL you saved, never your identity.
We will also disclose data where the law requires it — a valid order from a competent authority — and, if WebBites were ever sold or merged, to the acquirer, who would be bound by this policy until it told you otherwise.
Your library itself stays in the EU: the database, your files and images, and the search index all live on servers we rent and administer ourselves in Europe. The transfers below are limited to the specific features named above.
Some of the providers above are in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on the provider's certification under the EU–US Data Privacy Framework where it has one, together with the supplementary measures (encryption in transit, access controls, data minimisation) that we apply on our side. You can ask us for the details of the mechanism used for any given provider.
Everything travels over TLS. Passwords are hashed, never stored in a readable form. Access to production systems is limited to the people who operate the service and protected by strong authentication. Backups are encrypted. Your session token lives in your device's Keychain on Apple platforms.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal data and poses a risk to you, we will notify the Spanish supervisory authority within 72 hours and tell you directly where the law requires it.
You can, at any time:
Write to contact@webbites.io and we will answer within one month. We may ask you to confirm the email address on the account before acting, to be sure we are not handing your library to someone else.
If you think we have got this wrong, you can complain to the Spanish Data Protection Agency — Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es — or to the supervisory authority where you live. We would rather you told us first, but it is your right either way.
WebBites is not directed at children. You need to be at least 14 to use it with an account, which is the age of digital consent in Spain (art. 7 LOPDGDD); where you live sets a higher age, that age applies. If we learn we are holding an account belonging to a child below that age, we delete it.
When we change something material we will update the date at the top and, if it affects how your data is handled, tell you in the app or by email before it takes effect. The current version is always at https://www.webbites.io/privacy.
Questions about this page? Write to contact@webbites.io.