Privacy policy

Last updated: 19 July 2026

This privacy policy explains how Noel Huibers, operating NotebookFlow, processes personal data in the hosted NotebookFlow web application and its associated execution service. A separately hosted deployment is controlled by its respective operator.

Controller

The controller is Noel Huibers, 81737 München, Germany. Privacy requests can be sent to notebookflow@huibers.io or through the contact form in the legal notice.

Data processed and purposes

  • Account and sign-in data: provider account identifier, name, email address, profile image, verification status, OAuth tokens and scopes, session token, IP address, and user agent. These data create and secure your account and authenticated sessions.
  • Workspace data: notebook names and serialized notebook/workspace content that you explicitly save to the hosted service. These data provide cloud persistence and synchronization.
  • Provider-key data: provider and model settings and, only when you opt in, an API key encrypted at rest with AES-256-GCM. The active key is decrypted in memory when needed for your request.
  • Execution and upload data: notebook cells, prompts, selected files, outputs, errors, and the active provider key can be sent to the configured execution engine and the AI provider you select when you request execution or AI assistance.
  • Technical data: request metadata, IP addresses, user agents, timestamps, rate-limit counters, and operational or security logs needed to deliver, protect, and troubleshoot the service.

Sign-in with GitHub or Google

When you choose GitHub or Google sign-in, you are redirected to that provider. NotebookFlow receives the account details and credentials needed for sign-in. GitHub or Google also processes the sign-in under its own privacy terms. NotebookFlow does not receive your provider password.

Hosting and service providers

The hosted web application runs on Vercel, account and saved-workspace data use Turso/libSQL, and the hosted execution engine runs on Fly.io. GitHub and Google provide optional OAuth sign-in. The AI provider selected by you receives request content only when you use the corresponding AI feature. These providers process data only to the extent required for their respective service and configuration.

Contact messages

The contact form does not post its fields to NotebookFlow. It creates a pre-filled email locally and opens your email application. If you send that email, the sender's and recipient's email providers process the address, message, attachments, and delivery metadata. Messages are retained only as long as needed to answer the request and meet applicable record-keeping duties.

Legal bases

  • Article 6(1)(b) GDPR for account creation, saved workspaces, requested execution, and other steps needed to provide the service you request.
  • Article 6(1)(f) GDPR for service security, abuse prevention, debugging, and reliable operation. The legitimate interest is operating and protecting NotebookFlow and its users.
  • Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation, and Article 6(1)(a) GDPR where consent is expressly requested for an optional future feature.

Recipients and international transfers

Data may be disclosed to Vercel, Turso, Fly.io, GitHub, Google, and the AI provider you select, depending on the feature used. Some providers or subprocessors may process data outside the European Economic Area. Where GDPR Chapter V applies, a valid transfer mechanism such as an adequacy decision or appropriate safeguards is required.

Retention

Sessions expire after at most seven days. Account, OAuth, saved-workspace, and opt-in provider-key data are retained until you remove them, close the account, or request deletion, subject to required legal retention. Uploaded files remain in the configured engine storage until removed or the associated service data is deleted. Security and infrastructure logs follow the shortest operational period supported by the relevant provider, unless they are needed to investigate abuse or establish legal claims.

Is providing data required?

You can view public pages without an account. Account data is required for signed-in cloud features. Notebook content, uploads, and provider keys are provided voluntarily, but the requested feature cannot operate without the data it needs. You may keep a provider key only in your browser instead of saving it to your account.

Your rights

Subject to the statutory conditions, you may request access, correction, deletion, restriction, data portability, or object to processing based on legitimate interests. You may withdraw consent at any time for the future. Send requests to notebookflow@huibers.io. Identity verification may be required before account data is disclosed or changed.

Right to complain

You may complain to a data-protection supervisory authority. The authority responsible for private-sector controllers in Bavaria is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), www.lda.bayern.de.

www.lda.bayern.de

Automated decisions

NotebookFlow does not make decisions producing legal or similarly significant effects through solely automated processing. AI-generated suggestions and outputs may be inaccurate and remain subject to your review.

Security

NotebookFlow uses transport encryption in production, restricted session cookies, owner-scoped records, rate limiting, and authenticated encryption for opt-in cloud-stored provider keys. No online service can guarantee absolute security.

Cookies and local browser storage

NotebookFlow currently uses the following first-party storage for sign-in and user-selected functionality.

  • Signed-in session cookie

    Name
    __Secure-better-auth.session_tokenbetter-auth.session_token
    Classification
    Essential
    Purpose
    Keeps you signed in and authenticates account requests. The cookie is HttpOnly, SameSite=Lax, and Secure in production.
    Retention
    Up to seven days; deleted when you sign out.
  • Temporary OAuth state cookie

    Name
    __Secure-better-auth.oauth_statebetter-auth.oauth_state
    Classification
    Essential
    Purpose
    Protects GitHub and Google sign-in by correlating the sign-in request with its callback. The cookie is HttpOnly, SameSite=Lax, and Secure in production.
    Retention
    Up to ten minutes.
  • Language preference cookie

    Name
    nf_locale
    Classification
    Functional (selected by you)
    Purpose
    Remembers the language you explicitly select so server-rendered and browser-rendered pages use the same language.
    Retention
    One year, or until you delete it in your browser.
  • Application settings

    Name
    notebookflow.settings.v1
    Classification
    Functional (selected by you)
    Purpose
    Stores your engine URL, theme, model/provider, and optional BYOK API key in this browser. A key is stored in your account only if you explicitly choose that option; the active key is sent when you make an AI request.
    Retention
    Until you change the settings or clear this site's browser storage.
  • Panel layout

    Name
    notebookflow.panels.v2notebookflow.panels.v1
    Classification
    Functional (selected by you)
    Purpose
    Remembers which workspace panels you collapsed. The v1 name is read only to preserve layouts saved by older versions.
    Retention
    Until you change the layout or clear this site's browser storage.

Analytics and tracking

NotebookFlow currently uses no analytics, advertising, cross-site tracking, or tracking cookies.

No consent banner is currently shown because storage is limited to essential sign-in technology and functionality you request, and no analytics or tracking is enabled. If non-essential storage or tracking is introduced, it will remain disabled until you opt in and this disclosure is updated.

Storage on your device is assessed under Section 25(2)(2) TDDDG.

Changes to this policy

This policy will be updated when the service, providers, or legal requirements materially change. The date at the top identifies the current version.

These texts describe the current NotebookFlow implementation. They should receive individual legal review before a public launch.