WeFocusBuddy

Privacy Policy

Last updated: 25 September 2026 · version 16

1. Data controller. The data controller is Daniele Cattaneo, reachable at [email protected]. No Data Protection Officer has been appointed, as one is not required under art. 37 GDPR.

2. What data we process.

(a) Account data: the email address you sign in with, with a code we send you by email or with a Google or Microsoft account (personal, work or university). If you sign in with Google or with Microsoft we receive your email and basic profile identifiers from them; we use only the email.

(b) App data: the content you voluntarily enter (study or work sessions, focus ratings, exams, grades, goals, settings) and, optionally, the name you choose to display and, if you upload one, your profile photo. With the Agenda on, this also includes the topic you worked on in a session, the note you write and the score from 0 to 10 you give it. We save the app settings (for example sounds, theme, alerts and the Agenda) on your account, so you find them on every device.

(c) Coworking data: if you use coworking we process the time slot you book, the session status (queued, matched, completed, cancelled), the name or nickname you choose to show other participants, required in order to use coworking, the «Favourite companions» you add in a call, with «Favourite companion» or, when matching with priorities is on, with «Meet … again» (only you see them, no other user does; whoever runs the service counts only the total; they stay until you remove them, until you block that person or until one of the two accounts is deleted; we also keep the name the person showed in the session where you added them, so you can recognise them in the list; if someone else adds you, you do not see it and you are not told; when matching with priorities is on, two people where one has added the other to «Favourite companions» are matched with each other first, if they book the same time), changes of companion for one of your bookings (if your companion changes up to 10 minutes before the start, we keep the name of the new companion, or the fact that there isn't one yet, and whether you have seen the notice), the people you block, with the name they showed in the session (we no longer pair you with each other, in either direction; if someone else blocks you, you do not see it and you are not told), and any reports sent or received, the early exits, that is, when you leave with confirmation a session in progress with another real person (the time slot, the minutes completed and the identifier of the other person), the precautionary holds following a no-show and the identifier of the person who triggered them. See also sections 3 and 5.

(d) Messages with ideas, problems and other matters: if you write to us through the form on the website or the “You” tab of the app, we process the text of the message, the type you choose (idea, technical problem, other), the interface language and, only if you leave it, your email. If you do not leave it, the submission is anonymous: we do not store your account or your email. From the app, some technical data arrives together with the message: app version, open screen, language, screen size and the first 120 characters of the string your browser identifies itself with. We do not use them to recognise you.

(e) Technical data: information strictly necessary to run the service, such as authentication tokens, timestamps and the hosting providers' security logs.

(f) Aggregated traffic statistics: for each page opened we record the page path, the domain it was served from, the referring page, the browser language, the device type (phone or computer), whether you've installed the app on your device, the time of the visit and — only if you arrived through one of our labelled links, for example wefocusbuddy.com/c1 — that link's label. The label belongs to the link, not to you: it is identical for everyone who clicks it, it is never saved on your device, and it disappears from the address bar right away. We use no cookies, store no identifier on your device (to count visits, the browser generates on each page opening a random number that is valid only for that opening and does not let us recognize you in later visits) and never link separate visits together: it is not possible to reconstruct one person's path or to identify you. We also record the country you come from, as a two-letter code (IT, DE...): it is Cloudflare that derives it from the IP address, at the edge of its network, before the request reaches us. We receive only those two letters: the IP address never reaches us, we do not store it and we do not pass it to anyone, and no third-party geolocation service is involved. A country code on its own identifies nobody. If Cloudflare does not provide it, we derive it from the time zone set on your device. See section 10.

(g) Anti-abuse code for submissions: to prevent repeated mass submissions from the form, our server computes from your IP address an encrypted code (a hash), using a secret key kept on our server and a value that changes every day, and uses it to count submissions over the last hour. The code is deleted within 2 days and is not linked to your message. We do not store your IP address; it passes through the technical logs of the hosting provider and of the server functions (point 2(e)). Because the code derives from an IP address, for us it is personal data, not anonymous data.

(h) Reminders on your device: if you turn on notifications and give the browser permission to show them, we save the delivery address the browser creates for your device (the address of the notification service of your browser's maker and two keys used to encrypt the message), together with the app language. We use it only to send you reminders of the coworking sessions you have booked, 15 minutes and 2 minutes before they start. We also save the device time zone, which is used to write the right time in the reminder.

(i) Invite-a-friend data: if you create an invite we process the times and length of the sessions you propose, the link code, which session was taken and by whom, and when it was accepted. Anyone who opens the link, even without an account, sees the name you chose to show, the times you propose with their length, the time zone you proposed them in, the language you created the invite in, and whether each session is still open or already taken: they are the only information the link makes visible to someone who is not yet signed up. If you share the link in a messaging app, that app usually generates a preview with the same name, times and time zone, under its own rules; that preview may remain visible in the conversation even after the inviter's account has been deleted. To limit abuse, openings of the link are counted minute by minute per network address (for an IPv6 address, per the network it belongs to), using a code of the address computed with a secret key, which changes every day and is deleted within 2 days, as in point (g); if you open the link while signed in, we count your account identifier instead of the address, which is also deleted within 2 days.

(j) Studying at university: if the question is on for your account and you answer «I study at university» in «You», or you create your account from the page for university students, we process your answer (yes or no). It is used only to order the matching, when matching with priorities is on; we do not show it to the other person or to any other user; you can change it at any time; it is included in the data export. It is your own statement: we do not verify it.

(k) Withdrawal: if you withdraw from the contract with the «Withdraw from contract here» button in «You», we process the name and email you enter in the withdrawal statement only to send you the acknowledgement of receipt required by law, with the content of the statement and the date and time of submission (Art. 6(1)(c) GDPR; Article 11a of Directive 2011/83/EU). We do not save them in our database: the acknowledgement is sent through the provider we use for emails (section 6) and right afterwards the account is deleted as described in section 8.

2-bis. If you don't provide the data. Your email is needed to create an account and sign in: without it the service cannot be provided to you. The display name is needed only for coworking: without it the timer and the rest of the app stay available. All other data is entered by you whenever you want, and not entering it has no consequences.

3. Purposes and legal bases. We process your data to: provide the service, authenticate you and sync your data across devices (art. 6(1)(b) GDPR, performance of a contract); enable the matching and running of the coworking sessions you request (art. 6(1)(b)); answer support requests (art. 6(1)(b)); keep the service secure, prevent abuse and handle reports between users (art. 6(1)(f), our legitimate interest and that of other users in a safe environment); measure in aggregate form which pages are used (art. 6(1)(f), legitimate interest in understanding whether the service works, with the lowest possible impact on your privacy); automatically collect the app's technical error messages, that is, what broke, on which screen and with which browser, never what you wrote, in order to fix faults (art. 6(1)(f), legitimate interest in keeping the service working); receive and read messages with ideas and problems (art. 6(1)(f), legitimate interest in improving the service and in replying to the people who write to us); limit repeated mass submissions from the form by means of the anti-abuse code (art. 6(1)(f), legitimate interest in protecting the service from spam); send you reminders on your device, if you turn them on (art. 6(1)(a), consent, which you give through the browser's permission and can withdraw at any time by turning notifications off); comply with legal obligations (art. 6(1)(c)). We do not sell your data, we do not use it for advertising, and we carry out no profiling for advertising or marketing purposes and no automated decision-making producing legal effects on you. Whoever reviews a report also sees how many earlier reports concern the same person and with what outcome: it is context information, and the decision is always taken by a person. We use only one automatic measure, which is temporary: the precautionary hold on your future bookings when the person you were paired with reports that you did not show up for the session. A notice in the app tells you, and you can lift it yourself at any time, choosing whether to keep or cancel the bookings; in any case it lasts no longer than 30 days. This measure is not a decision that produces legal effects or similarly significantly affects you within the meaning of art. 22 GDPR: it does not touch your account or your data, does not lock you out of the app, does not prevent you from working alone or with the virtual companion, lasts until you lift it, and no longer than 30 days, and has no consequence outside the Service. Regardless of that classification, we still recognise your right to obtain human intervention, to express your point of view and to contest the measure: just write to [email protected]. Closing an account, or any lasting limitation of the account or of access to coworking, is instead decided by a person (see section 5). Internally we look, as per-account statistics, at how often you book, show up, report or are reported, leave early, and how long you stay in sessions, in order to detect abuse and improve matching (art. 6(1)(f)). They are calculated at the time of viewing from the coworking data in section 2(c), with no separate archive, and are seen only by the people who run the service. Balancing: the impact on you is low because the statistics stay internal, appear in no public profile, are not shown to other users, are not used for advertising or commercial profiling, are not a score and on their own trigger no measure; you can in any case object (section 9-bis). We also look at usage trends in aggregate form (art. 6.1.f, legitimate interest in understanding whether the service works and improving it): how many people sign up and use the service each week, how many do a first session within 7 days of signing up, how many come back after 1, 2 or 4 weeks, how many have been inactive for more than 14 days and how often sessions repeat. These are overall counts calculated on the data in section 2(c), on the account sign-up date and on the statistics in section 2(f): the view shows no lists, names or identifiers, we install no tracking on your device, we use no cookies or additional identifiers and we do not share this data with third parties. Balancing: the impact on you is low because these are overall numbers that do not concern any particular person. You can object at any time (section 9-bis). Invites to a friend fall under the performance of the contract (art. 6(1)(b) GDPR). Matching with priorities (your «Favourite companions» and, if the question is on, people who gave the same answer as you to «I study at university») and the notices when your companion changes also fall under the performance of the contract (art. 6(1)(b) GDPR).

4. Coworking video calls. Matched sessions take place over video through Jitsi Meet, free software running on a server of ours in Frankfurt (Germany, European Union). The machine is provided by Oracle (see point 6); the video call software is free software and we run it ourselves. There is no third-party video conferencing provider: the call passes through no commercial platform.

4-bis. The direct connection and your IP address. When there are two of you in a room, your devices try to connect directly to each other instead of sending audio and video through our server. It serves one purpose only, and it is the reason we do it: removing the delay, because a conversation with a few seconds of delay is not a conversation. The consequence must be stated plainly: on a direct connection the two devices see each other's IP address, as in any direct call between two computers. An IP address is personal data, the legal basis is the performance of the service you asked us for (art. 6(1)(b) GDPR), and we neither store nor display it: it remains a technical detail of the connection between your two devices. To discover the public address we use our own server in Frankfurt (STUN), not a third-party service. If the direct connection fails, which happens on some corporate or mobile networks, audio and video go back through our server, and in that case the addresses are not exchanged. If you prefer never to connect directly, the only option today is not to use coworking: we tell you here rather than let you find out.

How the video travels, precisely. When there are two of you, your devices first try to connect directly: it is the shortest path, and without it the delay grows enough for you to talk over each other. On a direct connection the two devices see each other's IP address, as in any direct link between two computers: it is personal data, we neither store nor display it, and it is the price of a conversation without delay (see point 4-bis). If the direct connection fails — which often happens on mobile networks — audio and video go through our Frankfurt server, which only forwards them: it does not record them, does not store them, does not open them, and in that case the two addresses never meet. In neither case does the call pass through a commercial platform.

One true thing we tell you anyway: our server is in the European Union, but the video call reaches the person you are talking to, wherever they are — including outside the EU, if that is where they live. That is what a video call is, and writing that no data leaves Europe would not be honest. What we can tell you is that what leaves is only what you chose to show them: your image and your voice, for the duration of the call.

We do not record audio or video: on our server recording is not a disabled feature, it is a feature that does not exist. The session's text chat is ephemeral too and is not saved anywhere. The other person can see your image and hear your voice while the call is running, plus the name or nickname you chose to display: we never show them your email or your account name. We recommend not sharing personal information on the call that you don't want known. Recording the call is prohibited by the Terms of Service.

5. Reports and moderation. When you choose to report the person you were matched with, we process the category selected, any description you write, the session identifier, time and length, the display names of the two people, the accounts involved and the number of earlier reports concerning the same person, with their outcome. The session time and length, the display names and the number of earlier reports are added by our server, not by you. You can send at most 5 reports a day and only one per person and per session. Reports are read by a person, and none of them, on its own, suspends an account. The exception is the temporary automatic measure described in section 3, which the app applies on its own: the precautionary hold on future bookings after a session in which the other person did not connect, which you can lift yourself. Following review we may limit, suspend or close access to coworking or to the account.

If you are the person reported: we process this data about you although we did not receive it from you; we give you here the information required by art. 14 GDPR, together with that in sections 3, 8 and 9. If you make an access request, we tell you whether there are reports concerning you, of what type and with what outcome. We do not disclose the identity of the person who reported, other people's data or the time of the session, to the extent that the law allows or requires us to protect them (art. 15(4) GDPR; art. 2-undecies of Italian Legislative Decree no. 196/2003); in that case we explain the reason.

If you are the one reporting: we do not show the reported person your email or your account name. If a measure is taken against you, you have the right to challenge it by writing to [email protected], and you will receive a reasoned reply.

5-bis. Special categories of data. Messages with ideas, problems and other matters, the optional description of a report on a session, the name or nickname you choose to show other participants, the topic and note of a session in the Agenda, and in the site's calculators the entries you type yourself, for example the description of a work item or the subject of an appointment, are free-text fields. They are not meant to collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, or data concerning health or sex life or sexual orientation (art. 9 GDPR), and we ask you not to enter it there. If you do so anyway, that data is processed only for the same security and support purposes described in section 3, with the same safeguards as any other data you give us, and you can ask us to delete it at any time by writing to [email protected]. In reports we ask you to describe the facts and not to attribute criminal offences.

6. Recipients of the data. Your data is never sold and is not disclosed to third parties for marketing purposes. We draw a distinction here, because the safeguards are not the same. Processing data on our behalf, as processors under art. 28 GDPR: Supabase (database, authentication, server functions), Cloudflare (site hosting and email routing), Resend (delivery of your sign-in emails, of withdrawal acknowledgements and of the internal alerts through which we receive sign-ups, reports and messages) and Oracle (the Frankfurt machine our video call server runs on: it provides the infrastructure, not the video call service). Processing data independently, as their own controllers and not on our behalf: Google and Microsoft, only if you choose to sign in with their account and limited to authentication. If you turn on reminders on your device, the message passes through the notification service of your browser's maker, which receives the delivery address and the encrypted message but cannot read it. There are no other recipients: the app loads no scripts, fonts, maps or images from third-party servers, uses no external content delivery networks and employs no third-party analytics. We may also disclose data to judicial or competent authorities where legally required. Messages and reports can be read only by the WeFocusBuddy team, that is, by people authorised by us and bound by confidentiality.

7. Where the data lives and transfers. The database and authentication are hosted by Supabase in the Frankfurt, Germany (European Union) region. The video call server is also in Frankfurt. Access to app data is protected by row-level security: each account can only read and write its own data. For Supabase, Cloudflare, Oracle and Resend, where some technical traffic or support activity may involve infrastructure outside the European Union (for Resend, in the United States), the transfer relies, depending on the provider, on the European Commission's adequacy decision of 10 July 2023 for certified companies or on the standard contractual clauses adopted by the Commission, set out in the respective data processing agreements; you can request a copy at [email protected]. Google, Microsoft and the browser's notification service, as their own controllers, may process data outside the European Union under their own safeguards. There is no exception, and there used to be one: until 7 September 2026 the video call ran on a third-party provider's United States infrastructure, which we stated plainly and for which we asked your specific consent under art. 49.1.a GDPR. Since the video call runs on a server of ours in the European Union that transfer no longer happens, and that consent has been removed because it no longer has anything to authorise.

8. Retention. Account and app data are kept for as long as your account is active. If you request deletion of your account they are erased without undue delay; residual copies in technical backups are removed within the providers' normal backup cycles, as a rule within 30 days. Coworking session data is kept for as long as needed to show you your history and handle any reports. Reports and the outcome of their review are kept for up to 24 months from submission, so that repeated behaviour can be assessed and claims defended; if the account of the reported person or of the person who reported is deleted, the report is deleted together with the account. Messages with ideas and problems are kept for up to 12 months from submission. Anonymous messages are not linked to you: we cannot find or delete yours on request, but they expire on their own. The anti-abuse code is kept for 2 days at most. Precautionary holds following a no-show and the identifier of the person who triggered them are kept for no longer than 30 days from their creation. The people you block stay until you unblock them or until one of the two accounts is deleted. The delivery address for reminders on your device stays while notifications are on: it is deleted when you turn them off in the app, when you sign out, when the notification service tells us it no longer exists, after 5 failed deliveries, or when the account is deleted. Early exits are kept for 90 days. Aggregated traffic statistics are kept for a maximum of 12 months. The aggregated usage trend is calculated when it is viewed and is not stored separately. The data of an invite link are deleted automatically 30 days after the link's last session. Notices of a companion change are deleted within one day of the end of the session, or earlier if you cancel the booking. Your answer to «I study at university» stays until you change it or delete your account. «Favourite companions» stay until you remove them, until you block that person or until one of the two accounts is deleted.

9. Your rights. Under arts. 15–22 GDPR you have the right of access, rectification, erasure, restriction, objection and data portability. You can export by yourself the data you entered that is saved on your account from You → Danger zone. The export does not include calendar bookings or reports; for the latter see section 5 and write to [email protected]. You can delete your account and data from You → Danger zone. To exercise the other rights write to [email protected]: we reply within one month. You can also ask at any time for a person to intervene, express your point of view and contest the automatic measures described in section 3, by writing to [email protected]. You also have the right to lodge a complaint with the supervisory authority of your country; in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).

9-bis. Right to object. You have the right to object at any time, on grounds relating to your particular situation, to the processing we carry out on the basis of legitimate interest (section 3): security and handling of reports, handling of messages with ideas and problems, the anti-abuse code for submissions, aggregated traffic statistics, internal per-account statistics on coworking use, usage trends in aggregate form, automatic collection of technical errors. To exercise it, just write to [email protected]. We say it here separately because art. 21 GDPR requires this right to be brought to your attention explicitly and separately from any other information.

10. Cookies and local storage. The app uses no cookies, neither strictly necessary cookies nor profiling cookies. It only uses the browser's local storage (localStorage) and the installed app's cache, needed to run: the local copy of your data, the session token, your preferences, such as language and theme, the last virtual companion shown, the companion-change notices already shown and, if you arrive from the page for university students, a marker that lasts at most two hours and is deleted after you sign in. For every page opened, we also log aggregated visit statistics (which page, the referring page, the browser language, the device type, the time) but with no cookies, no identifier saved on your device, and without linking two visits from the same person together. There are no advertising cookies, no third-party analytics tools and no tracking pixels. That is why no consent banner appears: cookie law requires consent to store or read information on your device, except where this is strictly necessary to provide the service you asked for; the local storage described here falls under that exception, the statistics store nothing on your device, and the browser creates the delivery address for reminders only if you give it permission.

11. Security. We apply technical and organisational measures appropriate to the risk: encrypted transmission (HTTPS), per-account data access through row-level security, and authentication with no passwords stored by us. No system is absolutely secure: in the event of a personal data breach involving a high risk to your rights, we will inform you under art. 34 GDPR.

12. Minors. The service is reserved for people aged 18 or over. We do not knowingly collect data from minors. If you believe a minor has created an account, write to [email protected] and we will delete it. If a report indicates that a person may be under 18, we may suspend that account's access to coworking until the situation is clarified.

13. Changes. We may update this policy. Material changes will be announced in the app with reasonable notice and the date at the top will be updated. If you do not agree with them you can close your account at any time from You → Danger zone, at no cost. Changes never apply retroactively to processing that has already taken place.

Terms of Service  ·  Open the app