Privacy Policy

1. Who is responsible

The data controller for both services is Davide Ghiotto, an individual based in Italy, acting as the operator of the sharp project. Contact for any privacy matter — including the rights listed in section 10:[email protected].

No Data Protection Officer is appointed: the processing here is small-scale and none of the criteria in Article 37 GDPR apply. Requests go to the address above and are handled by the operator personally.

2. The website

sharp.davideghiotto.it is a static site. It sets no cookies, runs no analytics, embeds no third-party scripts, fonts, pixels or iframes, and loads nothing from a CDN — the typeface ships with the page. We build no profile of you and we cannot: there is nothing collecting.

What does exist is ordinary web-server logging by our hosting provider, needed to serve the page and to keep the machine reachable: your IP address, the requested URL, the referrer, the user agent, and a timestamp. Those logs are retained for a short period (currently up to 30 days) and are used only for delivery, error diagnosis, and abuse or attack mitigation. They are not combined with anything else and never used for advertising.

3. The hosted instance

app.sharp.davideghiotto.it is a sharp workspace we run. It is provided free of charge, best-effort, and without any service guarantee (see theTerms of Service). If you hold an account there, the following data exists on our server.

What we do not do, on either service: no advertising, no ad or social tracking, no selling or renting of personal data, no sharing for anyone else's marketing, no automated decision-making or profiling with legal effect, and no product telemetry — the sharp application ships with none, which isdocumented and auditable in the source.

4. Why we are allowed to process it

5. Third parties that may see data

We use as few as possible, and most of them are optional features that stay completely inert until enabled. Nobody in this list receives data for their own purposes.

Each of these acts as a processor on our instructions, under a data processing agreement where the GDPR requires one. We may also disclose data if compelled by a valid legal order, or to protect the rights and safety of users — and we will tell you unless we are legally barred from doing so.

6. Transfers outside the EEA

Some processors above operate from outside the European Economic Area, principally the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one covers the recipient, or on your explicit consent for the optional features involved. You can ask us which mechanism applies to a given recipient at [email protected].

7. How long we keep it

8. Security

Traffic is TLS-encrypted end to end at the transport layer. Passwords are hashed with Argon2 and are not recoverable — nobody, including us, can read them or reset them to a value we know. Sessions are signed tokens with a fixed expiry. Access to workspace content is authorised per channel and per document on every request, including for the AI assistant. Optional end-to-end encrypted DMs use per-device X25519 and Ed25519 keys, so the server holds only ciphertext.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the Italian supervisory authority within 72 hours where the GDPR requires it, and notify you directly where the risk to you is high. To report a vulnerability, email [email protected] rather than opening a public issue.

9. Cookies and local storage

The website sets nothing at all. The app is not cookie-based either: your session token and your interface preferences live in your browser's local storage undersharp.* keys, and clearing site data signs you out and resets them. The only cookie the app uses is a short-lived, HttpOnly one set during a social sign-in to protect that flow against cross-site request forgery. Both are strictly necessary, so neither needs a consent banner — which is why you are not seeing one.

10. Your rights

Under the GDPR you may, at any time:

Write to [email protected]. We reply within 30 days, free of charge, and we may ask you to confirm control of the account's email address before acting — not as an obstacle, but so we do not hand your data to someone else.

If you are unhappy with how we handled it you can complain to your local data protection authority. In Italy that is the Garante per la protezione dei dati personali(garanteprivacy.it).

11. Children

The services are not intended for anyone under 16, and we do not knowingly create accounts for children. If you believe a child has registered on our instance, write to[email protected] and we will delete the account and its data.

12. Self-hosted deployments

This is the part most people are actually here for. When you run sharp yourself:

The claim above is verifiable rather than promised — the network-destination inventory ships with the app and iskept in the repository. Downloading a release from GitHub is a request to GitHub, governed by their privacy policy, not ours.

13. Changes to this policy

If the data flows change, this page changes with them, and the effective date at the top moves. Material changes affecting the hosted instance are announced in the workspace before they take effect. Because this site is open source, you can also read the exact diff of any revision. Continuing to use the services after a change means you accept the updated policy.

Questions: [email protected] · Terms:Terms of Service · The instance:app.sharp.davideghiotto.it