Privacy Policy
Last updated: September 4, 2026
Abunch ("we", "us", or "our") operates abunch.io. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data.
1. Information We Collect
1.1 Information You Provide
| Data | When Collected | Purpose |
|---|---|---|
| Email address | Account registration | Account identification, email notifications |
| Full name (optional) | Registration / profile | Display name |
| Password (hashed) | Email/password registration | Authentication |
| Interests/topics (optional) | Onboarding | Personalized collection recommendations |
| Links and categories you save | Normal service use | Core service functionality |
1.2 Information Collected Automatically
- IP address — Rate limiting, security, abuse prevention
- User agent — Debugging, compatibility
- Request logs (method, path, status, duration, referrer) — Service monitoring
Product usage events — Understanding whether the service actually works for you
When you use Abunch, we record events about how you use Abunch itself — for example, that you open your board on a given day, whether you come back, which parts of Abunch you use, whether you look at pricing, whether an import worked or ran into a limit, and how you arrived at Abunch.
We do not follow you across other websites. We do not sell these events or use them for advertising, and we share them only with the third-party service providers that host and operate Abunch for us, as described in Section 4. We use these events to understand whether Abunch is working for the people using it, and to improve it.
Usage events have been recorded since July 19, 2026. Newer event types are recorded from the date each is introduced.
1.3 Information from Third Parties
When you sign in with Google OAuth, we receive from Google: your Google account email address, display name, and profile photo URL (if available). We do not receive your Google password.
1.4 Payment Information
We do not collect or store your payment card information. All payment processing is handled by Paddle, our payment processor. For more information on how Paddle handles your data, see Paddle's Privacy Policy.
2. How We Use Your Information
- Providing the Abunch service (account management, saving links and categories)
- Authentication (verifying your identity on each request)
- Transactional email notifications (email verification, password reset, team invitations)
- Account security (detecting suspicious login activity via IP address)
- Service monitoring and debugging (aggregated request logs)
- Understanding how people use Abunch — including how they arrive, whether they come back, and which parts they use — so we can tell whether the service works and improve it (see Section 1.2)
- Processing payments (email passed to Paddle, subscription status management)
We do not use your data for advertising, sell your data to third parties, or share it with third parties except as described in Section 4.
3. Email Communications
We send you email only for service and account reasons — things like:
- Verifying your email address
- Resetting your password
- A one-time welcome email when you create your account
- Invitations and membership changes for a team or shared workspace
- Notices about your account, such as a plan change, a scheduled deletion, or a security hold
These are examples, not the complete set of messages we may need to send for these reasons. New message types appear as features are introduced.
Payment receipts and subscription confirmations are sent by our payment provider, Paddle, rather than by us.
We do not send marketing or promotional emails.
4. Third-Party Services
We share your data with the following third parties only as necessary to provide the service:
| Service | Purpose | Data Shared |
|---|---|---|
| Paddle | Payment processing (Reseller of Record) | Email address, subscription details |
| Resend | Transactional email delivery | Email address, email content |
| Google Cloud Platform | Application hosting, database, logging | All service data (hosted on GCP infrastructure) |
| Cloudflare | CDN, DDoS protection, DNS | IP address, request metadata |
| Google OAuth | Social login (if used) | Google account email, name, photo URL |
We do not sell your personal data to any third party.
Site icons
Any page that shows links — your board, public collections, and pages that can be viewed without an account — displays a small icon for each site. To load those icons your browser sends a request to the linked website itself, or, for the collections we publish, to Google's public favicon service. Those requests come from your browser, so whoever receives one can see things like your IP address and browser version in their own logs. We do not send your account details with them.
5. Data Storage and Security
Your data is stored on Google Cloud Platform servers in us-central1 (Iowa, USA). Security measures include:
- Passwords hashed with bcrypt (cost factor 12)
- All data in transit encrypted via HTTPS/TLS (enforced by Cloudflare)
- Database accessible only via Google Cloud SQL private IP
- API authentication uses short-lived JWT tokens (15-minute expiry) with rotation
- All secrets stored in Google Cloud Secret Manager
6. Data Retention
| Data | Retention Period |
|---|---|
| Active account data | Until account deletion |
| Soft-deleted accounts | 30 days after deletion request, then permanently deleted |
| Archived team workspaces | 30 days after Business cancellation, then permanently deleted |
| Request logs | 30 days (Google Cloud Logging default) |
| Payment records | As required by Paddle and applicable tax law |
| Product usage events | Deleted with your account (soft-deleted accounts: 30 days, then permanently deleted). We may keep aggregated counts that do not identify you. |
7. Your Rights
You may have the following rights regarding your personal data:
- Access & Export — Download your data via Settings → Data → Export (JSON format)
- Correction — Update your profile via Settings → Preferences
- Deletion — Delete your account via Settings → Account. Data is permanently deleted within 30 days.
- Other requests — Contact service@abunch.io
Product usage events are not included in the Settings export. To request a copy, email service@abunch.io.
8. Children's Privacy
Abunch is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, please contact service@abunch.io and we will delete the account.
9. Cookies and Local Storage
See our Cookie Policy for details. In summary: we use browser localStorage (not cookies) to store authentication tokens. We do not use advertising cookies or tracking pixels. We also record product usage events on our own servers (not cookies) — see Section 1.2. Third-party services (Paddle, Google OAuth) may set their own cookies during checkout/login.
10. International Data Transfers
Your data is stored and processed in the United States (Google Cloud Platform, us-central1). If you are accessing Abunch from outside the United States, your data is transferred to the US for processing. We rely on standard contractual clauses and the data processing agreements of our sub-processors to ensure adequate protection.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. The "Last Updated" date at the top reflects the most recent revision.
12. Contact
For privacy-related questions, requests, or to exercise your rights — we aim to respond within 30 days:
- Email: service@abunch.io
- Website: abunch.io/about