Privacy Policy
This English translation is provided for convenience only. The legally binding version is the German one — see Datenschutzerklärung (Deutsch).
1. Overview
Web Highlights ("we", "us") respects your privacy. This Privacy Policy explains what personal data we collect when you use our website (web-highlights.com), our web app (app.web-highlights.com), and the Web Highlights browser extension (collectively, the "Service"); how we use it; with whom we share it; and the rights you have under the EU General Data Protection Regulation (GDPR), the German Bundesdatenschutzgesetz (BDSG), and other applicable laws. We do not sell your personal data.
2. Data Controller
The data controller within the meaning of Art. 4(7) GDPR is:
Web Highlights GmbH
Glockenstraße 35
40476 Düsseldorf, Germany
Represented by the managing director Marius Bongarts
E-Mail: marius@web-highlights.com
Web: web-highlights.com
3. Minors
Web Highlights can be used by readers and learners of any age, including students. Under Art. 8 GDPR, the processing of personal data of children under 16 requires the consent of a parent or legal guardian. If you are under 16, please ask a parent or guardian to register on your behalf or to confirm your registration. We do not knowingly process personal data of children under 13 in any case. If you believe a minor has registered without the required parental consent, contact us at marius@web-highlights.com and we will delete the account.
4. Categories of Personal Data and Purposes
- Account data: email address, display name, and an authentication identifier (Firebase UID). Passwords themselves are managed and hashed by Firebase Authentication; we do not store passwords on our own servers. We also keep a small amount of account metadata to operate and localise the service: your browser and app type, device platform, timezone, and the language we should write to you in (derived from your browser’s language settings).
- Content data: highlights, notes, tags, bookmarks, AI chat history that you create.
- Subscription / billing data: name, billing address, VAT-ID where applicable, payment method (processed by Paddle as Merchant of Record).
- Usage data: aggregated, anonymised page views via Plausible Analytics; in-app feature usage events (no third-party recipients beyond those listed below).
- Server log data: IP address, user-agent, request URL, timestamp — kept for security and abuse prevention.
- Feature-board votes: when you vote on our public feature-request board, we store a salted hash of your IP address so each vote is only counted once — the raw IP address itself is never stored.
- Recommendation metrics: if you are on a plan that sees recommendations, we count how often a recommendation was viewed and clicked. We store daily totals only, grouped by country, language, browser and whether the device is mobile. The country is derived from your IP address at the moment of the request and the address is then discarded — no IP address, no browser fingerprint and no device identifier is stored, and these counts can never be traced back to you.
- Affiliate data (free plan, Chrome/Edge extension only): the domains of shops you open that match GiveFreely’s merchant list, and coupon/checkout interaction events — see section 11.
- Communication data: emails you send to us and our replies.
5. Legal Bases
We process personal data on the following legal bases under Art. 6(1) GDPR: (a) your consent — for optional features such as advertising on tutorial pages and the Notion export; (b) performance of a contract — to provide the Service you signed up for, including authentication, storage, payment, and email delivery; (f) legitimate interests — for security, fraud prevention, server logs, retention analytics, the recommendation feed for free-tier users together with the aggregate view and click counts we keep for it, the affiliate partnership with GiveFreely that helps fund the free plan (section 11), and the operation and improvement of the Service. Where we rely on legitimate interest, you have the right to object under Art. 21 GDPR.
6. Recipients / Subprocessors
We use the following processors and recipients to operate the Service. Where these are based outside the EU/EEA, transfers are protected by Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework (DPF) — with the single exception marked in the table and explained in section 7:
| Provider | Purpose | Data | Location | Legal basis |
|---|---|---|---|---|
| Hetzner Online GmbH | Server hosting | All server data, IP, server logs | Germany (EU) | Art. 6(1)(b), (f) GDPR |
| MongoDB Atlas (MongoDB, Inc.) | Primary database (accounts, highlights, content) | Account and content data | USA (Standard Contractual Clauses + EU-US Data Privacy Framework) | Art. 6(1)(b) GDPR |
| Google Firebase Authentication (Google Ireland Ltd.) | Authentication, JWT issuing | Email, UID, login metadata | USA (EU-US Data Privacy Framework) | Art. 6(1)(b) GDPR + Art. 49 / DPF |
| Paddle.com Market Ltd. (Merchant of Record) | Payment processing, billing, tax | Name, billing address, payment data, VAT | UK / EU | Art. 6(1)(b) GDPR |
| Profitwell, Inc. (a Paddle company) | Subscription retention analytics | Email address, subscription status | USA (Data Privacy Framework) | Art. 6(1)(f) GDPR (legitimate interest) |
| Give Freely, LLC | Coupon and affiliate offers on partner shops (free plan; Chrome and Edge extension only) | Domains of shops you open that are on GiveFreely’s merchant list, coupon and checkout interaction events, IP address (technically required for the request) | USA (no adequacy decision, no DPF listing — see section 7) | Art. 6(1)(f) GDPR (legitimate interest) |
| Amazon Web Services (AWS SES, EMEA SARL) | Transactional email delivery | Email address, message content | eu-central-1 (Frankfurt, Germany) | Art. 6(1)(b), (f) GDPR |
| Cloudflare R2 (Cloudflare, Inc.) | Object storage for user content (highlights, attachments, AI chats) and uploaded PDFs, including transient PDFs uploaded by visitors without an account via the free PDF Highlighter tool, which are automatically deleted after 1 hour unless the visitor creates an account | User content; transient visitor uploads | EU jurisdiction (preferred) | Art. 6(1)(b), (f) GDPR |
| Redis Cloud (Redis Ltd.) | Caching, session state | Cache keys, tokens | USA (us-east-1, AWS) — Standard Contractual Clauses | Art. 6(1)(b), (f) GDPR |
| Plausible Analytics (Plausible Insights OÜ) | Cookieless, privacy-friendly website analytics | Aggregated, anonymised page views (no cookies, no personal identifiers) | EU (Estonia / self-hosted) | Art. 6(1)(f) GDPR (no consent required) |
| Google AdSense (Google Ireland Ltd.) — only on /tutorials/* | Advertising on tutorial pages | IP address, cookies, device identifiers, ad interactions | USA (Data Privacy Framework) | Art. 6(1)(a) GDPR (consent via Google CMP) |
| Sanity.io (Sanity AS) | Image CDN for product screenshots and Open Graph images on the marketing website (cdn.sanity.io) | IP address and user-agent of visitors loading these images | USA / EU | Art. 6(1)(f) GDPR |
| Notion Labs, Inc. | Optional export of user content to Notion | User content exported on demand | USA (Data Privacy Framework) | Art. 6(1)(a) GDPR (opt-in via OAuth) |
| YouTube (Google Ireland Ltd.) | Video transcript feature | Video URLs / IDs | USA (Data Privacy Framework) | Art. 6(1)(b) GDPR |
| Chrome Web Store / Mozilla Add-ons / Microsoft Edge Add-ons | Extension distribution | Distribution metadata only (no app-level data) | USA / EU | Art. 6(1)(b) GDPR |
7. International Transfers
Web Highlights is used internationally, with the majority of our users based in the United States. For reasons of latency, availability, and service quality for this user base, parts of our infrastructure (in particular MongoDB and Redis Cloud) are hosted in US regions. Some of our subprocessors therefore process personal data in countries outside the EU/EEA, in particular the United States. For these transfers we rely on the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the recipient is certified, the EU-US Data Privacy Framework (Art. 45 GDPR). You have the right to receive a copy of the safeguards on request. One recipient is covered by neither safeguard: Give Freely, LLC (USA) is not certified under the DPF and has not concluded SCCs with us. Data reaches it only if you use the Chrome or Edge extension on the free plan and open a shop on its merchant list (see section 11) — never on a Premium account, in the Firefox or Reader extensions, or in the web app. We are working to put contractual safeguards in place for this transfer.
8. Retention Periods
We retain personal data only as long as necessary for the purposes described above. Account and content data are kept while your account exists and are deleted promptly after you close your account; copies in routine backups are overwritten in the normal backup rotation. Billing data are retained for the period required by German tax and commercial law (currently up to 10 years under § 147 AO). Server logs are kept only for as long as needed for security and abuse prevention. Analytics data are aggregated and do not allow identification of individuals.
9. Your Rights
Under the GDPR, you have the right to (a) access your data (Art. 15), (b) rectification (Art. 16), (c) erasure / "right to be forgotten" (Art. 17), (d) restriction of processing (Art. 18), (e) data portability (Art. 20), (f) object to processing based on legitimate interest (Art. 21), and (g) withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3)). To exercise any of these rights, email us at marius@web-highlights.com. You also have the right to lodge a complaint with a supervisory authority — for users in Germany this is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf, https://www.ldi.nrw.de.
10. Cookies and Local Storage
We use cookies and browser storage only to the extent technically necessary or with your consent. Specifically: (i) `jwt_webmarker` (localStorage, app.web-highlights.com) — your authentication token, strictly necessary; (ii) Plausible Analytics — cookieless, no consent required; (iii) Google AdSense — only on /tutorials/* pages, behind Google's own consent management platform (CMP); (iv) Profitwell — strictly subscription-related signals on the web app, processed under our legitimate interest in retention analytics; (v) the recommendation feed is served by Web Highlights itself: your browser only talks to our own backend, no third party is involved, and no cookies are set for it. You can withdraw AdSense consent at any time via Google's "Privacy & Terms" controls.
11. Browser Extension
The Web Highlights browser extension requests `<all_urls>` host permissions so it can render and create highlights and notes on any page you choose. The extension's content script runs locally in your browser to detect existing highlights on the pages you visit, but it only transmits data to our servers when you actively highlight, note, bookmark, or sync a page. It does not collect your browsing history and contains no third-party tracking pixels; the one third-party component it does include is the GiveFreely SDK described in the next paragraph. Distribution happens via the Chrome Web Store, Microsoft Edge Add-ons, and Mozilla Add-ons; those stores process metadata according to their own policies.
On the free plan, the Chrome and Edge extensions include the GiveFreely SDK (Give Freely, LLC). When you open a shop that is on GiveFreely’s merchant list, it can show available coupons and turn your purchase into a donation to a charity; the shop pays an affiliate commission, part of which funds the free plan. To do this, the SDK compares the domain you are on with a merchant list it fetches from GiveFreely and reports coupon and checkout events to Give Freely, LLC. The SDK is not loaded on Premium accounts and is not part of the Firefox extension, the Reader extension, or the web app. GiveFreely’s own privacy policy applies to the data it receives: https://givefreely.com/privacy-policy.
12. AI Features (On-Device)
The optional AI features in Web Highlights — such as summarisation and AI chat with your highlights — run on-device in your browser via Chrome's built-in Summarizer and Prompt APIs. Your prompts and the highlight excerpts you send to those features are processed locally by Chrome and are not transmitted to any third-party AI provider. The chat history itself (your messages and the model's replies) is stored on our servers (MongoDB and Cloudflare R2) so you can revisit and sync conversations across devices, on the same legal basis as your other content (Art. 6(1)(b) GDPR). The AI features are opt-in and only activate when you explicitly use them.
13. Security
We use commercially reasonable safeguards to protect personal data, including TLS encryption in transit, encryption at rest where supported by the storage provider, password hashing via Firebase Authentication, restricted access by role, and regular updates of dependencies. No system is perfectly secure; please use a unique password and report any suspected unauthorised access immediately.
14. Changes to this Policy
We may update this Privacy Policy from time to time, for example to reflect new subprocessors, regulatory changes, or new product features. The current version is always available at https://web-highlights.com/legal/privacy-policy. Please review it periodically; the date at the top indicates when it was last revised.
15. Contact
For any questions about this Privacy Policy or your data:
Web Highlights GmbH
Glockenstraße 35
40476 Düsseldorf, Germany
Represented by the managing director Marius Bongarts
E-Mail: marius@web-highlights.com
Web: web-highlights.com