Privacy Policy — Modeloop
Last updated: 2026-08-11 · Version: 1.9
1. Status and contact
Modeloop is a pre-incorporation project. No incorporated Modeloop legal entity currently exists. This policy intentionally does not publish a personal name, home address or telephone number and is not a complete Article 13 notice.
- Privacy and data-rights requests:
privacy@modeloop.app - General support:
info@modeloop.app
No Data Protection Officer has been appointed for the project. The privacy contact above remains available for questions about previously submitted data.
2. Scope and data we process
This policy covers the public website, waitlist and referral workflow, Modeloop accounts, licences, hosted projects, optional version-control connections, and the public Modeloop plugin for ChatGPT and Codex.
| Data | Purpose | Legal basis proposed for counsel review | Retention |
|---|---|---|---|
| Waitlist name, email, selected plan, form source, referral attribution, referral count, and timestamps | Register the person on the requested waitlist and operate the requested referral workflow | Steps taken at the person’s request before a possible contract — Art. 6(1)(b) GDPR | No longer than 24 months from collection, unless deletion is requested earlier; a daily database job enforces this maximum |
Referral code in browser localStorage | Recognise a returning waitlist member and show on-site referral progress | Provide the function requested by the visitor — Art. 6(1)(b) | Maximum 720 days from browser storage; the versioned record is removed when read at or after expiry, and legacy values without an expiry are discarded |
| Optional website measurement: page origin and path, referrer, timestamp, approximate location, operating system/browser/device class, daily visitor hash, and Web Vitals | Produce aggregate traffic and performance statistics after the visitor opts in | Consent — Art. 6(1)(a) GDPR and the applicable terminal-equipment rule; proposed for counsel review | Current Vercel Pro reporting windows: 12 months for Web Analytics and 30 days for Speed Insights. Vercel states that analytics data may be stored longer than the guaranteed reporting window; the exact deletion tail remains a release gate. The visitor hash resets after 24 hours. |
| Supabase sign-in data: Supabase user identifier, email and, for the selected Google or GitHub sign-in, authorised name and avatar | Authenticate the user and provide the Modeloop application | Performance of a contract — Art. 6(1)(b) | Until the sign-in is deleted. No maximum provider-backup expiry has been verified, so new sign-in collection remains suspended until that period is obtained and published. |
| Hosted-app account data: internal user identifier, email, Supabase user identifier, account status and timestamps | Authorise hosted Modeloop API access and associate hosted projects with their owner | Performance of a contract — Art. 6(1)(b) | Until the hosted data are deleted or verified erasure is completed. No maximum database/backup expiry has been verified, so new hosted-account collection remains suspended. |
| Licence tier and acceptance evidence: user ID, terms/EULA version, acceptance time, specific approvals, platform, application target, document-content hash, server-captured IP address and user agent | Issue a licence and prove which terms were accepted | Performance of a contract and legitimate interest in maintaining an accurate audit trail — Art. 6(1)(b) and (f) | No applicable limitation period has been approved. New server-side acceptance collection remains suspended until the exact period or usable legal criterion is approved and published. |
| Successful promo-code redemption evidence: user ID, redeemed code and time, previous and resulting licence tiers, and previous/resulting expiry times | Apply the requested promotional licence tier, preserve its expiry and prevent duplicate redemption | Performance of a contract — Art. 6(1)(b) | No maximum backup expiry or applicable limitation period has been verified. New redemption processing remains suspended until both are approved and published. |
| Diagrams, projects, model data and file references saved through the hosted Modeloop application | Provide modelling, simulation, storage and code-generation functions | Performance of a contract — Art. 6(1)(b) | Until the user deletes the content or verified hosted-data erasure is completed. No maximum volume/database backup expiry has been verified, so new hosted storage remains suspended. |
| Optional version-control connection data: provider and instance URL, provider username and email, link time, selected repository URL, encrypted access/refresh credentials and encrypted short-lived OAuth-flow state | Connect a user-selected GitHub account and repository, list authorised repositories and perform requested version-control operations | Performance of a contract — Art. 6(1)(b) | Until unlinking, credential expiry or verified erasure. The maximum orphaned-record, OAuth-state and backup tails are unverified, so new hosted VCS linking remains suspended. |
| Plugin arguments: Modeloop MDL text, optional diagram identifier, simulation timing and input profiles | Validate or convert the requested model and, when requested, run a bounded model-in-the-loop simulation | Provide the tool operation expressly requested by the user — Art. 6(1)(b) | Request-local temporary files are deleted at the end of the call |
| Plugin result: canonical SSP, diagnostics and numeric signal traces | Return the requested result to the user’s ChatGPT or Codex conversation | Same as above | Returned immediately to the selected OpenAI service; Modeloop does not create a persistent project from the plugin call |
| Network and security metadata, such as IP address, request time, route, method, status and diagnostic metadata | Deliver the service, protect it from abuse and investigate failures | Legitimate interests in availability and security — Art. 6(1)(f) | Railway application and HTTP logs: 7 days on the current Hobby plan |
The plugin does not need names, contact details, credentials, health data, payment data, government identifiers, or other sensitive information. Do not place personal data, secrets, regulated data, or confidential third-party material in model names or MDL text. We do not intentionally use plugin data for advertising or profiling. Across the processing described in this policy, Modeloop does not use solely automated decision-making that produces legal or similarly significant effects for a person.
3. Where the data comes from
Modeloop receives waitlist, project and profile data directly from the user; sign-in profile data from Google, GitHub or Supabase when the user selects that method; version-control account and repository data from GitHub when the user expressly connects it; plugin arguments from the user’s selected OpenAI service; and network/security metadata from the user’s device and the infrastructure that delivers the request. Modeloop does not buy personal-data lists or obtain these data from data brokers.
4. Required and optional data
Name and email are required to join the waitlist; without them we cannot record the registration. Referral attribution and plan selection are optional. The plugin requires complete MDL text for both tools; the diagram identifier and input profiles are optional. The simulation tool also uses the timing values selected for the requested run. The plugin does not require a Modeloop account. Hosted projects require a Modeloop sign-in. Connecting GitHub for version control is optional. Entering a promo code is optional and requires an active sign-in; only a successful account-scoped redemption creates a redemption record.
5. Waitlist communications
Automatic waitlist welcome and referral-milestone emails are currently paused.
Modeloop will not send unrelated promotional or marketing email unless a
separate, specific opt-in and a working unsubscribe mechanism have first been
implemented. A person may leave the waitlist or request deletion at any time by
emailing privacy@modeloop.app.
6. Browser storage and analytics
The public site does not set advertising cookies. The browser storage currently used by the website and web application is:
| Item or category | Purpose and operational classification | Duration and clearing method |
|---|---|---|
Versioned waitlist referral record (modeloop_ref_code) | Functional storage requested when a visitor joins the referral workflow; not used for advertising | Maximum 720 days after creation; removed automatically when read at or after expiry. Legacy or malformed values without a provable expiry are removed. The visitor can also clear site data in the browser. |
Versioned analytics choice (modeloop_analytics_consent) | Necessary preference record that proves whether optional Vercel measurement may load; it stores only the choice, schema and notice versions, decision time and expiry | Six calendar months. It is replaced when the visitor changes the choice, removed if malformed or expired, and can also be removed by clearing site data. |
Supabase session keys and Modeloop bearer token (sb-*, token) | Necessary only for the sign-in method selected by the user and authenticated API access | Until provider session expiry, sign-out, sign-in deletion, or browser site-data clearing. Modeloop removes its local copies on sign-out and sign-in deletion. |
Pending magic-link email in persistent localStorage (modeloop-auth-pending-email) | Necessary to recover the requested passwordless sign-in flow. The email is stored as plaintext inside a versioned record and can be read by scripts running on the same website origin. | Maximum 24 hours; also removed when the flow completes, on sign-out/sign-in deletion, or when browser site data is cleared. Legacy values without an expiry are removed. |
Licence token and account-scoped EULA acceptance state (license_token, modeloop-eula-account:*) | Necessary to apply the selected licence and remember the accepted EULA version; not used for marketing | Licence token until its expiry, sign-out or sign-in deletion. Local account-scoped acceptance state until sign-in deletion or browser site-data clearing; any separate server acceptance evidence follows the unresolved server retention described above. |
Random device-scoped EULA identity (modeloop-eula-device-id) | Distinguishes the local guest/device acceptance record; not used for advertising | Until browser site data are cleared. Account deletion does not remove this device-only guest identity. |
Account scope, browser-local projects, diagrams, signal-exposure/testing files and autosave records (modeloop-local-storage-account-id, legacy account/project keys and account-scoped dynamic keys) | Necessary only when the user chooses guest/offline browser persistence or saves local work | Until the user deletes the project/SWC, deletes the sign-in for that account, or clears browser site data. Sign-in deletion removes the active account namespace and legacy unscoped project/autosave data. |
Account-scoped onboarding state, guest-mode flag and interface preferences (modeloop-onboarding-*, modeloop-auth-guest-mode, modeloop.build.spineCollapsed) | Functional state used to resume onboarding, guest mode and selected interface layout | Until the user resets/changes the preference, deletes the sign-in where account-scoped, or clears browser site data. |
Pending VCS OAuth state in sessionStorage (modeloop.vcs.oauth.pending) | Necessary to return to the user-requested repository-linking flow | For the current browser-tab session; removed on flow completion/cancellation or when the tab/session is closed. |
Analytics and performance
Vercel Web Analytics and Speed Insights are optional and remain off by default. With no choice, a rejection, closure of the choice surface, unavailable browser storage, or an invalid or expired choice, the site does not import their SDKs or inject their telemetry scripts. If the visitor selects Allow analytics, the site loads both SDKs and Vercel may receive the optional measurement data listed above. Modeloop removes query strings and fragments from the measured page URL before either SDK sends an event and does not send custom analytics events.
The choice can be changed through Privacy choices in the global footer. Choosing Decline replaces the local choice, stops collection and reloads the page so already-loaded telemetry listeners are discarded. Withdrawing consent does not affect processing that occurred before withdrawal. Vercel still receives the network and hosting metadata necessary to deliver the website, independently of this optional choice.
7. Recipients
Data is disclosed only where needed for the purposes above:
| Recipient | Role and data |
|---|---|
| Supabase | Database, authentication and edge-function infrastructure in the current eu-north-1 (Stockholm) project for waitlist, account, licence and legal-acceptance data |
| Vercel | Website hosting and the network/hosting metadata needed to deliver requests; after opt-in only, aggregate Web Analytics page-view data and Speed Insights Web Vitals described above |
| Railway | Hosts the public MCP and hosted-app compute plus project files and encrypted version-control credential/flow stores in Amsterdam; the current hosted-app PostgreSQL service holding account/project metadata and file references is in San Francisco, United States; Railway also processes operational logs |
| OpenAI | The ChatGPT or Codex service selected by the user sends explicit plugin arguments to Modeloop and receives tool results; OpenAI’s handling is also governed by the terms and privacy choices for the user’s selected OpenAI service |
| Google or GitHub | Authentication provider selected by the user; supplies the account profile fields authorised in the sign-in flow |
| GitHub | Optional version-control provider selected separately by the user; receives the authorised repository operations and supplies account/repository metadata and credentials or tokens needed for that connection |
| jsDelivr | Delivers browser runtime assets and necessarily receives network request metadata when that delivery path is used |
Modeloop does not sell personal data. A current processor and international transfer register is maintained internally and must be checked before a new recipient is enabled. No email-delivery provider receives waitlist data while automatic lifecycle emails are paused; enabling one requires a policy and unsubscribe-flow update before processing starts.
8. International transfers
The current Supabase project is in Stockholm. Railway’s MCP compute and project-file volume are in Amsterdam, while the current Railway PostgreSQL service for hosted-app account/project metadata is in San Francisco. Vercel and OpenAI may also process through global or United States infrastructure.
For Vercel processing, the current Pro Data Processing Addendum applies through
the customer agreement, incorporates the 2021 EU Standard Contractual Clauses,
and Vercel states that it participates in the EU-US Data Privacy Framework. The
current documents are available at https://vercel.com/legal/dpa and
https://vercel.com/legal/privacy-notice. For other affected non-EEA flows, the
evidence register still does not establish every applicable adequacy decision,
SCC module, transfer-impact assessment or supplementary measure. Modeloop does
not claim a hypothetical safeguard for those unresolved flows; information or a
copy of an applicable mechanism can be requested through
privacy@modeloop.app.
9. Rights, account closure and complaints
Subject to the GDPR conditions, a person may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Consent for optional website measurement can be withdrawn at any time through Privacy choices in the footer without affecting earlier lawful processing.
Requests can be sent to privacy@modeloop.app. Modeloop may request information
needed to verify the requester and will respond within the period required by
law, normally one month. There is also a right to complain to the competent
supervisory authority; in Italy this is the Garante per la protezione dei dati
personali at https://www.garanteprivacy.it/.
The in-app Delete Sign-In Account action currently deletes the authenticated
Supabase identity and its Supabase-cascaded records, then clears the active
browser’s account-scoped authentication, licence, EULA, project and onboarding state.
It does not delete hosted Railway account/project records, project files or
connected version-control data. A user who wants those hosted records erased
should email privacy@modeloop.app before deleting the sign-in so Modeloop can
use the existing account channel for verification. A person who has already
deleted the sign-in may still request full erasure through that address;
Modeloop will use proportionate alternative evidence tied to the former account
or hosted projects and will not require account reactivation merely to exercise
a data right.
Deleting the Supabase identity and clearing the active browser do not by themselves prove immediate invalidation of every previously issued access token. An issued token may remain cryptographically valid until its configured expiry unless separately revoked; the final release procedure therefore requires verified hosted-session revocation and a protected-route denial test.
10. Security and incidents
Modeloop applies proportionate technical and organisational measures, including
encrypted transport, restricted provider access, removal of direct public
waitlist-table privileges, fixed-search-path and bounded waitlist RPCs, bounded
plugin inputs, request-scoped temporary simulation directories and removal of
temporary filesystem paths from returned simulation errors. No internet service
is risk-free. Security reports can be submitted through the route listed at
https://www.modeloop.app/support.
11. Children
The services described in this policy are designed for a general technical audience and are not directed to children. A person who cannot validly accept the applicable terms independently may use them only with the authorisation required by local law. Modeloop does not knowingly request children’s personal data.
12. Changes
The current version and update date appear at the top of this policy. Material changes will be communicated by an appropriate method before they take effect where the law requires notice.
Informativa sulla privacy — Modeloop
Ultimo aggiornamento: 2026-08-11 · Versione: 1.9
1. Stato e contatti
Modeloop è un progetto in fase pre-societaria. Al momento non esiste una persona giuridica Modeloop costituita. Questa informativa non pubblica nome personale, indirizzo di residenza o numero di telefono e non costituisce un’informativa completa ai sensi dell’articolo 13 GDPR.
- Privacy e diritti:
privacy@modeloop.app - Assistenza generale:
info@modeloop.app
Non è stato nominato un DPO per il progetto. Il contatto privacy resta disponibile per domande su dati eventualmente inviati in precedenza.
2. Ambito, dati, finalità e conservazione
L’informativa riguarda sito pubblico, waitlist e referral, account, licenze, progetti hosted, collegamenti opzionali al version control e plugin pubblico Modeloop per ChatGPT e Codex.
- Waitlist: nome, email, piano, provenienza del form, attribuzione referral, conteggio e date; per registrare la richiesta e gestire il referral; base proposta art. 6(1)(b); massimo 24 mesi dalla raccolta, salvo cancellazione anticipata; un job giornaliero applica il limite. Anche il record referral nel browser scade dopo massimo 720 giorni; record legacy privi di scadenza vengono eliminati.
- Misurazione opzionale del sito: origine e percorso della pagina, referrer, timestamp, posizione approssimativa, sistema operativo/browser/classe del dispositivo, hash visitatore giornaliero e Web Vitals; per statistiche aggregate di traffico e prestazioni dopo opt-in; consenso ex art. 6(1)(a) GDPR e regola applicabile al terminale, da validare con il legale. Le finestre di reporting del piano Vercel Pro corrente sono 12 mesi per Web Analytics e 30 giorni per Speed Insights. Vercel dichiara che i dati analytics possono essere conservati oltre la finestra garantita; la coda di cancellazione esatta resta un gate di rilascio. L’hash visitatore si azzera dopo 24 ore.
- Accesso Supabase: identificativo Supabase, email e, se autorizzati tramite Google o GitHub, nome e avatar; per autenticazione e servizio; art. 6(1)(b); fino alla cancellazione dell’accesso. Non è stata verificata una scadenza massima dei backup provider: la raccolta di nuovi accessi resta sospesa finché tale periodo non sarà ottenuto e pubblicato.
- Account applicativo hosted: identificativo interno, email, identificativo Supabase, stato account e date; per autorizzare le API e associare i progetti al titolare; art. 6(1)(b); fino alla cancellazione dei dati hosted o all’evasione verificata. Non è stata verificata una scadenza massima di database/backup: la raccolta di nuovi account hosted resta sospesa.
- Licenza e prova di accettazione: user ID, versione termini/EULA, data, approvazioni specifiche, piattaforma, target applicativo, hash del documento, IP e user agent acquisiti server-side; per servizio e audit; art. 6(1)(b) e 6(1)(f). Non è stato approvato il periodo prescrizionale applicabile: la nuova raccolta server-side resta sospesa finché non saranno approvati e pubblicati il periodo esatto o un criterio giuridico utilizzabile.
- Riscatto promo riuscito: user ID, codice e momento del riscatto, livello licenza precedente e risultante, scadenze precedente e risultante; per applicare il livello promozionale richiesto, conservarne la scadenza ed evitare riscatti duplicati; art. 6(1)(b); fino alla cancellazione dell’account o al completamento verificato della cancellazione. Non sono stati verificati né il periodo prescrizionale né la scadenza massima dei backup: i nuovi riscatti restano sospesi finché entrambi non saranno approvati e pubblicati.
- Progetti e modelli salvati: diagrammi, file e riferimenti; per modellazione, simulazione, storage e codegen; art. 6(1)(b); fino alla cancellazione del contenuto o all’evasione verificata. Non è stata verificata la scadenza massima dei backup di volume/database: il nuovo storage hosted resta sospeso.
- Version control opzionale: provider e URL istanza, username/email provider, data collegamento, repository selezionato, credenziali access/refresh cifrate e stato OAuth temporaneo cifrato; per collegare GitHub e svolgere le operazioni richieste; art. 6(1)(b); fino a scollegamento, scadenza credenziale o evasione verificata. Le code massime di record orfani, stato OAuth e backup non sono verificate: i nuovi collegamenti VCS hosted restano sospesi.
- Plugin: testo MDL, identificatore diagramma opzionale, tempi e profili; per validare/convertire il modello o svolgere la simulazione MIL richiesta; art. 6(1)(b). I file temporanei della singola richiesta vengono eliminati al termine e il plugin non crea un progetto Modeloop persistente.
- Metadati tecnici e di sicurezza: IP, orario, route, metodo, stato e diagnostica; per erogazione, sicurezza e indagine errori; art. 6(1)(f). I log Railway sono conservati 7 giorni sul piano Hobby corrente.
Il plugin non necessita di dati personali, credenziali, dati sanitari, di pagamento, identificativi rilasciati da autorità pubbliche o altri dati sensibili. Non inserirli nei nomi dei modelli o nel testo MDL. Non usiamo intenzionalmente i dati del plugin per pubblicità o profilazione. Per i trattamenti descritti in questa informativa, Modeloop non adotta decisioni basate unicamente su trattamenti automatizzati che producano effetti giuridici o analogamente significativi per una persona.
3. Provenienza dei dati
I dati di waitlist, progetto e profilo arrivano direttamente dall’utente; i dati profilo di accesso da Google, GitHub o Supabase quando l’utente sceglie quel metodo; i dati account/repository da GitHub quando viene collegato espressamente; gli argomenti plugin dal servizio OpenAI scelto; i metadati tecnici dal dispositivo e dall’infrastruttura che consegna la richiesta. Modeloop non compra liste né usa data broker.
4. Dati necessari e facoltativi
Nome ed email sono necessari per la waitlist; senza di essi non possiamo registrare la richiesta. Referral e piano sono facoltativi. Il plugin richiede il testo MDL completo; identificatore e profili sono facoltativi. La simulazione usa inoltre i tempi scelti per l’esecuzione. Non serve un account Modeloop per il plugin; i progetti hosted richiedono l’accesso e GitHub VCS è facoltativo. L’inserimento di un codice promo è facoltativo e richiede un accesso attivo; solo un riscatto riuscito e associato all’account crea il relativo record.
5. Comunicazioni waitlist
Le email automatiche di benvenuto e milestone referral sono sospese. Email
promozionali o di marketing non correlate non saranno inviate senza un consenso
separato e specifico e senza un meccanismo di disiscrizione funzionante. È
possibile uscire dalla waitlist o chiederne la cancellazione scrivendo a
privacy@modeloop.app.
6. Browser e analytics
Il sito non imposta cookie pubblicitari. Lo storage browser attualmente usato è:
| Voce o categoria | Finalità e classificazione operativa | Durata e cancellazione |
|---|---|---|
Record referral waitlist versionato (modeloop_ref_code) | Storage funzionale richiesto quando il visitatore aderisce al referral; non è usato per pubblicità | Massimo 720 giorni dalla creazione; viene eliminato automaticamente alla prima lettura dalla scadenza. Record legacy o malformati senza scadenza verificabile vengono eliminati. È cancellabile anche dai dati sito del browser. |
Scelta analytics versionata (modeloop_analytics_consent) | Record di preferenza necessario per dimostrare se la misurazione Vercel opzionale può essere caricata; salva solo scelta, versioni dello schema e dell’informativa, data decisione e scadenza | Sei mesi di calendario. Viene sostituito quando cambia la scelta, eliminato se malformato o scaduto ed è cancellabile anche pulendo i dati sito. |
Chiavi sessione Supabase e bearer token Modeloop (sb-*, token) | Necessari solo per il metodo di accesso scelto e per le API autenticate | Fino a scadenza della sessione provider, logout, cancellazione dell’accesso o pulizia dei dati sito. Le copie locali Modeloop vengono rimosse al logout e alla cancellazione dell’accesso. |
Email magic-link pendente in localStorage persistente (modeloop-auth-pending-email) | Necessaria per recuperare il flusso passwordless richiesto. L’email è salvata in chiaro in un record versionato ed è leggibile dagli script eseguiti sulla stessa origine del sito. | Massimo 24 ore; rimossa anche al completamento, logout/cancellazione dell’accesso o pulizia dei dati sito. I valori legacy senza scadenza vengono eliminati. |
Token licenza e accettazione EULA locale per account (license_token, modeloop-eula-account:*) | Necessari per applicare la licenza e ricordare la versione EULA accettata; non usati per marketing | Token fino a scadenza, logout o cancellazione dell’accesso. Stato EULA locale fino a cancellazione dell’accesso o dei dati sito; l’eventuale prova server segue la retention server ancora non definita sopra. |
Identità EULA casuale per dispositivo (modeloop-eula-device-id) | Distingue il record locale di accettazione guest/dispositivo; non è usata per pubblicità | Fino alla pulizia dei dati sito. La cancellazione dell’account non elimina questa identità locale guest del dispositivo. |
Ambito account, progetti/diagrammi locali, file testing/signal exposure e autosave (modeloop-local-storage-account-id, chiavi legacy account/progetto e chiavi dinamiche scoped) | Necessari solo se l’utente sceglie persistenza guest/offline o salva lavoro locale | Fino a cancellazione di progetto/SWC, cancellazione dell’accesso per quell’account o pulizia dei dati sito. La cancellazione dell’accesso rimuove il namespace attivo e i dati progetto/autosave legacy non scoped. |
Onboarding per account, flag guest e preferenze UI (modeloop-onboarding-*, modeloop-auth-guest-mode, modeloop.build.spineCollapsed) | Stato funzionale per riprendere onboarding, modalità guest e layout scelto | Fino a reset/modifica, cancellazione dell’accesso se scoped per account o pulizia dei dati sito. |
Stato OAuth VCS pendente in sessionStorage (modeloop.vcs.oauth.pending) | Necessario per tornare al flusso di collegamento repository richiesto | Per la sessione della scheda corrente; rimosso a completamento/annullamento o alla chiusura della scheda/sessione. |
Analytics e prestazioni
Vercel Web Analytics e Speed Insights sono facoltativi e restano disattivati per impostazione predefinita. In assenza di scelta, dopo un rifiuto o la chiusura del pannello, se lo storage browser non è disponibile o se la scelta è malformata o scaduta, il sito non importa gli SDK e non inserisce gli script di telemetria. Se il visitatore seleziona Allow analytics, il sito carica entrambi gli SDK e Vercel può ricevere i dati di misurazione opzionali elencati sopra. Modeloop rimuove query string e frammenti dall’URL della pagina misurata prima dell’invio e non invia eventi analytics personalizzati.
La scelta può essere modificata con Privacy choices nel footer globale. Scegliendo Decline, il record locale viene sostituito, la raccolta viene interrotta e la pagina viene ricaricata per eliminare i listener di telemetria già caricati. La revoca non pregiudica i trattamenti precedenti. Vercel riceve comunque i metadati di rete e hosting necessari a servire il sito, indipendentemente da questa scelta opzionale.
7. Destinatari e trasferimenti
I destinatari necessari sono: Supabase (database/autenticazione nel progetto Stockholm), Vercel (hosting e, solo dopo opt-in, Web Analytics e Speed Insights opzionali), Railway (MCP, compute, volume file progetti e archivi VCS cifrati ad Amsterdam; PostgreSQL metadata account/progetti oggi a San Francisco), OpenAI (piattaforma scelta dall’utente che invia gli argomenti espliciti e riceve i risultati), Google/GitHub se scelti per l’accesso, GitHub separatamente se collegato per il version control e jsDelivr per asset runtime. Nessun provider email riceve dati waitlist mentre le email automatiche sono sospese; la riattivazione richiede prima aggiornamento dell’informativa e del flusso di disiscrizione. Modeloop non vende dati personali.
Per i trattamenti Vercel, il Data Processing Addendum corrente del piano Pro si
applica tramite l’accordo cliente, incorpora le Clausole Contrattuali Standard UE
del 2021 e Vercel dichiara di aderire all’EU-US Data Privacy Framework. I
documenti correnti sono disponibili su https://vercel.com/legal/dpa e
https://vercel.com/legal/privacy-notice. Per gli altri flussi extra-SEE
interessati, il registro non dimostra ancora ogni decisione di adeguatezza,
modulo SCC, valutazione d’impatto o misura supplementare applicabile. Modeloop
non dichiara garanzie ipotetiche per tali flussi irrisolti; informazioni o copia
del meccanismo applicabile possono essere richieste tramite
privacy@modeloop.app.
8. Diritti, cancellazione, reclami e sicurezza
Nei limiti e alle condizioni del GDPR sono esercitabili accesso, rettifica,
cancellazione, limitazione, portabilità e opposizione. Le richieste vanno inviate
a privacy@modeloop.app; potremo verificare l’identità e risponderemo entro il
termine di legge, normalmente un mese. È possibile reclamare al Garante per la
protezione dei dati personali (https://www.garanteprivacy.it/).
L’azione in-app Delete Sign-In Account cancella oggi l’identità Supabase e i
record Supabase eliminati in cascata, quindi pulisce dal browser attivo dati di
autenticazione, licenza, EULA, progetti locali e onboarding. Non cancella account e
progetti Railway, file hosted o dati del version control collegato. Per cancellare
anche questi dati è preferibile scrivere a privacy@modeloop.app prima di
eliminare l’accesso, così da usare il canale account esistente per la verifica.
Chi abbia già eliminato l’accesso può comunque chiedere la cancellazione completa
allo stesso indirizzo; Modeloop userà evidenze alternative proporzionate legate
al precedente account o ai progetti hosted e non richiederà la riattivazione
dell’account al solo fine di esercitare un diritto.
La cancellazione dell’identità Supabase e la pulizia del browser non dimostrano, da sole, l’invalidazione immediata di ogni token già emesso. Un token può restare crittograficamente valido fino alla scadenza configurata se non viene revocato separatamente; la procedura di rilascio finale richiede quindi la revoca verificata delle sessioni hosted e una prova negativa su una route protetta.
Adottiamo misure proporzionate, tra cui trasporto cifrato, accessi provider
ristretti, assenza di grant diretti dei client sulla tabella waitlist, RPC con
search_path fisso e input limitati, limiti del plugin, directory temporanee per
richiesta e rimozione dei path temporanei dagli errori di simulazione. Le
segnalazioni di sicurezza seguono https://www.modeloop.app/support.
9. Minori e modifiche
I servizi descritti in questa informativa sono destinati a un pubblico tecnico generale e non sono rivolti ai minori. Chi non può accettare autonomamente i termini secondo la propria legge deve avere l’autorizzazione necessaria. Versione e data sono indicate sopra; le modifiche sostanziali saranno comunicate quando richiesto dalla legge.