Freshcard Home

Privacy

Last updated 3 October 2026

The short version

  • Freshcard has no analytics, no advertising and no tracking tools.
  • The demo works in your browser. What you add there is not sent to a server, and I never see it.
  • If you make an account, Freshcard stores your email address and what you save in your workspace, and other members of a workspace can see your email address.
  • A card you share by link can be read by anyone who has the link.
  • The only cookies are two that the services delivering the site set so that it works and stays secure.
  • No data is sold, and there are no marketing emails. The only emails are sign-in links.
  • You can ask for your account and workspace data to be deleted by emailing tagline.privacy+freshcard at gmail dot com. I'll do it within a month.

Who runs Freshcard

Freshcard is a free portfolio project run by Jonathan Burns, an individual rather than a company. I am the person responsible for your information under UK data protection law. You can contact me at tagline.privacy+freshcard at gmail dot com.

I use one inbox for privacy questions across my projects.

What is stored, and where

The demo: stored in your browser only

The demo workspace runs in your browser. The cards, claims and proof you add or change there are not sent to a server, and I never see them. They are kept in your browser tab's session storage, so they survive a reload and disappear when you close the tab.

Loading the pages themselves is different, as it is on any website: your browser asks the site's hosting provider for them, and the provider sees your IP address and browser details in the ordinary way (see “Who handles your data”).

Accounts and workspaces

If you sign in, Freshcard stores:

  • your email address;
  • a display name, which starts as the part of your email address before the @ and which you can change in Settings;
  • the workspace name and its settings, such as how long each type of claim stays fresh;
  • the competitors, cards, claims and proof you save, including proof's source links and customer names, and who owns each claim;
  • when each claim and piece of proof was last checked and who checked it, and a history of changes to each card's claims, with who made them;
  • who belongs to each workspace and their role, and the email addresses invited to it;
  • a copy of each card shared by link (see “Shared links”).

Your email address is saved as soon as you submit it on the sign-in page, before you click the link in the email. If you are invited to a workspace, an account is created for your address straight away. Freshcard does not ask for or store a password: you sign in with a link emailed to you.

Other members of a workspace can see the email address and display name of every member, and everything saved there, with the names of the people who own, checked or changed it. Members with the viewer role don't see proof marked internal-only. Workspace admins can also see invitations: the email addresses invited and their roles.

I can see everything in the database, and the providers' staff could in principle. If you leave a workspace, or are removed from it, what you made there stays, with your name on it, until it is deleted.

Shared links

When someone shares a card, Freshcard saves a copy of its rep view, and anyone with the link can read that copy without signing in. The link is long and random, and it asks search engines not to list it, but it is public to anyone who has the URL. The copy never includes people's names or proof marked internal-only. It changes only when someone updates it, and it is deleted, and the link stops working, as soon as someone stops sharing the card.

Who handles your data

  • Lovable hosts the site and runs its back end (Lovable Cloud).
  • Supabase provides the database and the sign-in service behind Lovable Cloud. The account and workspace data above is stored there. When you sign in, use a workspace or open a shared link, your browser contacts Supabase directly, which sees your IP address and browser details and may keep its own technical records of sign-ins and requests.
  • Cloudflare sits in front of the site as a network and security layer, so it sees requests to the site, including IP addresses.
  • Lovable Cloud's built-in authentication service sends the sign-in emails, through Lovable's managed email delivery, from a default Lovable-owned sender.

Your account data is stored in the EU (Ireland), AWS eu-west-1. Some providers may also process data outside the UK, including in the US. They rely on their own legal safeguards for international transfers, set out in their data-processing terms.

The site's fonts are served from the site itself, not from Google. Links to other sites, including source links on proof, only connect to those sites if you click them, and Freshcard loads nothing from them. Apart from the providers above, I do not share your information with anyone, unless the law requires it.

Why it is used

Only to run the service: to sign you in, show you your workspace, let the people you invite use it and show the cards you choose to share. That is necessary to run the service for you, or for the workspace you were invited to. Freshcard does not sell data, show ads or send marketing emails. The only emails it sends are sign-in links, including the ones sent when someone is invited to a workspace.

Cookies and browser storage

Freshcard sets no cookies of its own and adds no analytics, advertising or tracking tools to its pages. The services that deliver the site keep ordinary request logs (see “Who handles your data”), and they set two cookies that the site needs to work and stay secure:

  • __cf_bm: set by Cloudflare as bot protection, and lasts about 30 minutes.
  • __dpl: set by the hosting platform to identify the version of the site you are using, and lasts 24 hours.

Both are set automatically to keep the site secure and serving the right version, so there is no cookie banner. Freshcard does not use either of them for analytics or advertising. If you click a sign-in link, Cloudflare may also set its __cf_bm cookie on the sign-in service's own address (supabase.co).

In your browser's session storage, which is cleared when you close the tab, the demo keeps its data and the site remembers how far down each page you had scrolled, so that going back returns you to the same place. If you sign in, your sign-in session, which includes your email address, is kept in local storage so you stay signed in, along with the id of the workspace you last opened. Signing out removes both.

How long it is kept, and deleting it

Your information is kept until you ask for it to be deleted. A workspace admin can remove you from a workspace or delete what is in it, but that does not delete your account or email address.

To have your account and workspace data deleted, email tagline.privacy+freshcard at gmail dot com. I'll do it within a month. In a workspace shared with other people, I'll remove your account and email address from it; the cards stay for the other members, and your name comes off them. If you are the only admin of a shared workspace, I'll first ask another member to take over, or tell the members before the workspace is deleted. The providers' own technical logs and backups are outside my control and clear on their own schedule.

Your rights

Under UK GDPR you can ask to see the information Freshcard holds about you, have it corrected or deleted, ask for its use to be restricted, object to it being used, and ask for a copy you can reuse. Email tagline.privacy+freshcard at gmail dot com and I'll deal with it within a month.

If you are unhappy with how your information has been handled, please tell me first. You can also complain to the Information Commissioner's Office at ico.org.uk.

Changes

I update the date at the top whenever this page changes.