Privacy Policy
Last updated: 11 June 2026
This Privacy Policy explains how personal data is collected and processed when you use belenos.app (the "Service"). We process the minimum data necessary and are committed to protecting your privacy.
1. Data Controller
- Controller: José Luis Pellicer
- Contact: [email protected]
- Country: Spain
- Address: Calle Nueve de Mayo 2, C.P. 33002, Oviedo, Asturias, España
To exercise your rights or ask a privacy question, contact us at the email above.
2. What we collect, why, and our legal basis
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Waiting-list email address | To notify you about the launch and availability of the Service | Consent — Art. 6(1)(a) |
| The public page URLs you submit, the text extracted from them, and the resulting scan files | To perform the scan and deliver and preserve your results | Performance of a contract — Art. 6(1)(b) |
| Payment status and transaction reference (e.g. paid, pending, failed) | To process and record your payment | Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| IP address and request metadata (scan tokens, rate-limiting, abuse prevention, security) | To secure the Service and prevent abuse | Legitimate interests — Art. 6(1)(f) |
| Cookieless analytics data (pages viewed, referrer, browser, OS, device, screen size, language, approximate location) | To understand and improve use of the Service | Legitimate interests — Art. 6(1)(f) |
We do not require accounts or logins, do not store credit-card details (handled entirely by our payment provider, Polar), do not send newsletters, do not use cookies, and do not sell your data or use it for advertising.
3. The scanning service
You submit the URL of a public web page, and the Service scans that page for text only. We do not crawl the website, follow links, or access pages you did not submit. We store the URL you provided, the extracted text, and the resulting scan file in order to deliver your results and keep them available to you (see Retention, §9). You are responsible for ensuring you are entitled to submit a given page for scanning.
4. Payments
Payments are handled by Polar (Polar Software Inc.), which acts as our Merchant of Record: your purchase is sold and invoiced by Polar, and Polar collects and remits any applicable sales tax or VAT. Your card details are collected and processed directly by Polar and its PCI-DSS-compliant payment processor under their own terms — we never receive or store your card number or payment credentials. We retain only the status and reference of each transaction to manage your purchase and meet accounting obligations. See Polar's Privacy Policy.
5. Analytics
We use Umami, a privacy-focused, self-hosted analytics tool running on our own infrastructure. It does not use cookies and does not collect personal information. For each visit we record non-identifying technical data: pages viewed, referring site, browser, operating system, device type, screen size, language, and approximate location (country/region/city). Your IP address is used only momentarily to derive that approximate location and a daily, anonymised visitor hash — it is never stored, and the hash resets every day, so visitors cannot be tracked over time or across other sites. This data is never shared or sold.
6. Cookies
belenos.app does not use cookies of any kind — neither for analytics nor for session management. We therefore do not display a cookie-consent banner because there is nothing to consent to in that respect.
7. Service providers (sub-processors)
We share data only with the following providers, strictly to operate the Service:
| Provider | Role | Location | Safeguards |
|---|---|---|---|
| Hetzner | Hosting / infrastructure | Germany (EU/EEA) | Within the EEA; Data Processing Agreement |
| Cloudflare | CDN, proxy, security/DDoS protection (processes IP addresses) | Global / USA | Data Processing Addendum; EU Standard Contractual Clauses |
| MailerSend | Sending waiting-list / transactional emails | USA / EU | Data Processing Agreement; Standard Contractual Clauses |
| Polar (Polar Software Inc.) | Merchant of Record — payment processing, invoicing & sales-tax/VAT handling | USA | PCI-DSS-compliant card processing; Data Processing Addendum; SCCs |
We do not transfer your data to any other third parties except where required by law.
8. International data transfers
Some providers above may process data outside the European Economic Area (e.g. in the USA). Where this happens, the transfer is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses and the providers' data-processing agreements.
9. Data retention
We keep personal data only as long as necessary for the purposes described above:
- Waiting-list email: until the launch notification has been sent and for a reasonable period thereafter, or until you ask to be removed.
- Paid scans (purchase-related data — the pages you submitted, the resulting scan files, and the payment record): retained indefinitely, so your purchased results remain available to you and as part of our business and accounting records. You may still request deletion (see §10), subject to any minimum retention required by Spanish commercial and tax law.
- Unpaid scans (data not linked to a completed payment): anonymised after 90 days and permanently deleted after 365 days. Once anonymised, the data can no longer be linked to you and is no longer personal data.
- Security and rate-limiting data (IP-based): retained only as long as needed for security, up to 90 days.
- Analytics: retained for 24 months in aggregated form.
10. Your rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase your data; restrict or object to processing; data portability; and to withdraw consent at any time (without affecting processing already carried out). To exercise any of these, email [email protected].
You may also lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD) — www.aepd.es.
11. Data security
We apply appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS), access controls, and infrastructure hardening. No method of transmission or storage is completely secure, but we use industry-standard practices to protect your data.
12. Children
The Service is not directed to, and we do not knowingly collect data from, children under the age of 14 (the age of digital consent in Spain).
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date reflects the latest version, and material changes will be communicated through the Service.
14. Contact
For any question about this Privacy Policy or your personal data: [email protected].
← Back to belenos.app