1. Who is responsible
OnlyText is operated by Alessio Vertemati, Bernareggio (Monza Brianza), Italy ("we", "us", "OnlyText"). We are the controller for the personal data described in section 3 of this policy.
-
VAT identification number: IT08579170963
-
Privacy contact: privacy@onlytext.tech
2. Two different roles
OnlyText handles two kinds of personal data, and our responsibility differs between them. Keeping them apart is the most important thing to understand about this policy.
As controller we decide how the data of the people who use the service is processed: account details, organisation membership, authentication, security logging and billing. Section 3 describes that data.
As processor we handle the documents a customer uploads or connects, everything derived from them, and the records of who reached them. Any personal data inside those documents belongs to the customer, who decides what to publish and to whom. We process it only on their instructions, under Art. 28 GDPR. Section 10 describes that role.
3. Data we process as controller
Account. Name, email address, a hashed password, and the time the email address was verified. Used to create and operate the account. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
Authentication. If you enable them, the public key and identifier of each passkey you register and the time it was last used, and the secret and recovery codes behind two-factor authentication. Recovery codes and two-factor secrets are stored encrypted. Sessions record your IP address, browser user agent and last activity so you can see and revoke them. Legal basis: Art. 6(1)(b) and our legitimate interest in account security, Art. 6(1)(f).
Security audit log. Successful logins, logouts, failed login attempts (including the email address entered), password resets, and actions taken on organisations, sites and files, each recorded with a timestamp, IP address and user agent. This is what lets an organisation owner see who did what, and lets us investigate a compromised account. Legal basis: legitimate interest in the security of the service, Art. 6(1)(f).
Organisation and membership. The organisation name, its members and their roles, and invitations, which store the invited email address and who sent the invitation. If you are invited to an organisation, the person who invited you and the organisation owners can see your name and email address. Legal basis: Art. 6(1)(b), and for invitations sent to people who do not yet have an account, our customer's and our legitimate interest in enabling team collaboration, Art. 6(1)(f).
Billing. Billing contact and address, tax identifiers, the customer identifier assigned by our payment processor, the brand and last four digits of the payment method, and the history of subscriptions, invoices and payments. Full card numbers never reach our servers: they are entered directly into Stripe. Legal basis: Art. 6(1)(b), and Art. 6(1)(c) for the retention periods that German commercial and tax law impose on invoices.
Correspondence. Messages you send us by email or through support, and our replies. Legal basis: Art. 6(1)(b) where it concerns your contract, otherwise our legitimate interest in answering enquiries, Art. 6(1)(f).
Server logs. Requests to the application are logged with IP address, timestamp, requested address, response status and user agent, to keep the service running and to detect abuse. Legal basis: Art. 6(1)(f).
4. What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not run advertising or third-party tracking on the application or on the sites we publish for customers.
- We do not use customer documents, or anything extracted from them, to train machine learning models — neither our own nor anyone else's.
- We do not profile you, and no decision with legal or similarly significant effect is made about you by automated means (Art. 22 GDPR).
5. Cookies
OnlyText sets only the cookies it needs to log you in and to protect forms against cross-site request forgery. There are no analytics or advertising cookies, which is why you are not asked for cookie consent. The cookie notice lists each one.
6. Who else processes the data
We use a small number of service providers to run OnlyText — hosting, transactional email, payments and uptime monitoring. Each acts as a processor on our instructions under a data processing agreement. They are listed, with their purpose and location, on the sub-processors page.
Application data and customer documents are stored in the European Union. Payment processing with Stripe may involve a transfer to the United States; that transfer is covered by the European Commission's standard contractual clauses and Stripe's certification under the EU–US Data Privacy Framework. Beyond our processors, we disclose personal data only where we are legally obliged to, or to enforce our terms.
7. How long we keep it
- Account data — for as long as the account exists. After deletion it is removed within 30 days, except where a longer period is legally required.
- Security audit entries — 365 days.
- Session records — until the session expires or you revoke it.
- Delivery and access records — 365 days, unless the customer instructs a shorter period.
- Invoices and accounting records — up to ten years, as required by law.
- Customer documents — until the customer deletes them or their organisation, then removed within 30 days including from backups on their next rotation.
8. Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you and receive a copy (Art. 15);
- have inaccurate data corrected (Art. 16);
- have data erased (Art. 17);
- have processing restricted (Art. 18);
- receive the data you gave us in a portable, machine-readable form (Art. 20);
- object to processing we base on legitimate interest, on grounds relating to your particular situation (Art. 21);
- withdraw consent at any time, where processing rests on consent, without affecting what was done before.
Write to privacy@onlytext.tech to exercise any of them. We answer within one month. If the data sits inside a customer's documents rather than in your account with us, we will point you to the customer responsible for it, since they decide what happens to it.
You may also lodge a complaint with a supervisory authority.
9. How we protect the data
- Traffic to and from OnlyText is encrypted with TLS.
- Passwords are stored only as hashes; two-factor secrets and recovery codes are encrypted at rest.
- Passkeys and two-factor authentication are available on every account, and password confirmation is required before sensitive changes.
- Access to a document follows its visibility setting for humans and for agents alike; private content is reachable only by members of the organisation that owns it.
- Administrative access to production systems is limited to the people who need it, and privileged actions are logged.
10. Documents customers deliver through OnlyText
When a customer uploads documents, or connects a website, Nextcloud, S3 bucket or similar source, we process those documents to make them deliverable. That means storing them, extracting their text, structure and metadata, detecting their language, producing the delivery formats (Markdown, HTML, preview cards, unfurl metadata), and serving them to people and to AI agents according to the visibility the customer set. We also record which document, and which part of a document, was requested, and whether the request came from a person or an agent — that is the analytics the customer sees.
If those documents contain personal data, the customer is the controller for it and we are their processor. We do not read the content for our own purposes, and we do not use it to train models. Detection of personal data before publication runs on our own infrastructure using a local model, so a document does not leave our systems to be checked.
One consequence is worth stating plainly: when a customer connects their own AI agent to OnlyText, the content that agent requests is delivered to that agent, and from there it is governed by the customer's relationship with whoever provides it. We deliver what the customer's access rules allow; we do not control what the receiving agent does with it.
A data processing agreement covering this processing, including the security measures under Art. 32 GDPR and the list of sub-processors, is available on request from privacy@onlytext.tech.
11. Children
OnlyText is offered to organisations, not to consumers, and is not directed at children. We do not knowingly create accounts for anyone under 16.
12. Changes to this policy
We update this policy when the service changes. The date at the top says when it was last revised. If a change materially affects how we handle your personal data, we will tell account holders by email before it takes effect.