Legal & privacy

Updated August 2026
Local firstMost processing stays in your browser.
Optional analyticsGoogle Analytics requires your consent.
Your choiceChange consent at any time.
On this page 18 sections
Policy details tools.mattiacapomagi.it

Scope and overview

This notice applies to tools.mattiacapomagi.it, the MWorkspace account area, the project library and the browser-based creative editor.

It explains what information is processed, why it is needed, where projects may be stored, which providers support the service and which choices are available to you.

The editor is local-first, but signed-in features are not exclusively local: account information, project metadata, private notes, thumbnails and saved project documents may be stored in the cloud as described below.

Data Controller

Mattia Capomagi is the data controller for this website.

For privacy requests, write to mattia.capomagi@gmail.com.

A dedicated data protection officer has not been appointed because the current scale and nature of the processing do not require one. Privacy requests are handled directly by the controller.

Data we process

Account data may include your email address, display name, username, authentication identifiers, linked login provider and session information.

Project data may include project names, folders, private notes, dimensions, DPI, previews, timestamps, storage size and the project document itself, including media embedded in a saved document.

Technical data may include browser and device information, IP address, requested pages, timestamps, security events and diagnostic information generated by hosting, authentication and analytics providers.

Preference data may include language, theme, workspace defaults, recent searches, open editor tabs and cookie consent choices stored in your browser.

Accounts and authentication

An account is required to save and retrieve cloud projects. Authentication is provided through Firebase Authentication using email and password or, when selected, Google sign-in. Supabase keeps the internal user identifier used by project and account data and is connected to Firebase through an authentication bridge.

MWorkspace does not intentionally store plaintext passwords. Password credentials and authentication tokens are handled by the authentication provider and protected browser storage.

If Remember me is disabled, the session is kept in session storage and normally ends when the browser session closes. If enabled, the session can persist in local storage until sign-out, expiration or browser data removal.

Projects and cloud storage

Project metadata is stored in Supabase Postgres and protected by account-level access controls. Larger project documents are compressed and stored in Cloudflare R2 through authenticated server routes; smaller documents may fall back to the database when object storage is unavailable.

Storage object paths are generated server-side from the verified account and project identifiers. Cloud storage credentials are not exposed to the browser.

The current personal cloud storage allowance is 50 MB per account. Saving is stopped when the quota cannot be verified or would be exceeded, to reduce accidental overuse.

Deleted documents and folders are moved to the account Trash and continue to occupy storage until they are restored, permanently deleted or their selected retention period expires. Permanent removal deletes the database record and associated object-storage file.

Local Processing

Most tool operations, including visual previews, canvas rendering and exports, happen locally inside your browser.

Generated exports are downloaded by your browser and are not intentionally added to your cloud project unless you explicitly save project content that contains them.

Some imported images may be sent to an authenticated conversion endpoint for temporary format conversion. The endpoint applies size limits, returns a private no-store response and does not intentionally persist the uploaded source or converted result.

Local processing reduces unnecessary transfers, but browser extensions, operating-system services and files you later share or upload elsewhere remain outside the control of MWorkspace.

Purposes and legal bases

Account, authentication and project data are processed to provide the service you request, including sign-in, autosave, cloud storage, project recovery and account preferences.

Technical and security data may be processed for the legitimate interests of protecting accounts, preventing abuse, troubleshooting failures, enforcing storage limits and maintaining service reliability.

Google Analytics is processed only after consent. Consent can be withdrawn at any time without affecting processing that took place before withdrawal.

Information may also be retained or disclosed where necessary to comply with applicable law, respond to valid legal requests or establish, exercise or defend legal claims.

Cookies and browser storage

Essential browser storage remembers language, theme, cookie preferences, authentication persistence and selected workspace settings. These functions are required to provide the choices you make and are not used for advertising.

The language preference may also be written as a first-party cookie so the selected language can remain consistent across the Mattia Capomagi domain.

Google Analytics is optional and loads only after consent. Google Analytics may set identifiers such as _ga in accordance with Google's own documentation.

Vercel Web Analytics records anonymous, aggregated page views without using cookies or creating advertising profiles.

You can change analytics consent from this page or clear site data from your browser. Clearing browser storage may also sign you out and reset interface preferences.

Analytics

If accepted, Google Analytics helps understand which tools and pages are used. MWorkspace does not use these reports to make automated decisions about users or build advertising profiles.

When Google Analytics is active, the browser may send page URL, IP address and browser or device information to Google. Google's processing is governed by its own privacy documentation.

Vercel Web Analytics provides aggregated page-view information without third-party cookies and is designed by Vercel not to identify or reconstruct individual visitors across sites.

Analytics reports are used to improve usability, performance and product priorities, not to sell personal data.

Service providers

Firebase Authentication, a Google service, provides email/password and Google account authentication. IONOS delivers transactional account messages, including email-verification links, and may process the recipient address and technical delivery metadata for that purpose. Supabase supports the internal user directory and database storage. Cloudflare R2 supports project object storage. Vercel hosts the application and provides privacy-focused web analytics. Google also provides optional Analytics.

These providers process data only for their respective technical functions and under their own contractual terms and privacy documentation.

Depending on provider infrastructure and account configuration, data may be processed outside your country. Where required, international transfers are handled through mechanisms made available by the providers and applicable data-protection law.

Supabase privacy Firebase privacy and security IONOS privacy Cloudflare privacy Vercel analytics privacy Google privacy

Retention and deletion

Account and document information is generally retained while your account remains active. Items moved to Trash remain recoverable for the account-level period selected in Preferences: 30, 60 or 90 days. Changing that preference also changes the remaining period for items already in Trash.

After that period, or when you choose permanent deletion, the active database record and associated Cloudflare R2 object are scheduled for removal. The automated cleanup runs daily, so physical deletion may occur after the displayed expiry time rather than at the exact minute.

Browser preferences remain on your device until they expire, are overwritten or are cleared by you. Session data follows the persistence option selected at sign-in.

Operational logs, backups and analytics data may be retained for limited periods determined by service configuration, security needs and provider policies. Removal from active systems may therefore not be immediately reflected in every backup copy.

To request full account deletion, contact the controller from the email address associated with the account so ownership can be verified.

Security

MWorkspace uses authenticated requests, per-user database access rules, server-generated storage paths, upload limits and server-only object-storage credentials to reduce unauthorized access and cross-account exposure.

Connections to deployed services use the transport protections provided by the hosting and infrastructure providers. You are responsible for keeping your password and device secure and for signing out on shared devices.

No online service can guarantee absolute security. If you believe an account or project has been exposed, contact the controller promptly and change your credentials.

Your Rights

Where the GDPR or similar law applies, you may request access, correction, deletion, restriction, portability or objection in relation to your personal data.

You may withdraw analytics consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

Requests can be sent to mattia.capomagi@gmail.com. Additional information may be requested when reasonably necessary to verify identity and protect the account from unauthorized requests.

You may also lodge a complaint with the Garante per la protezione dei dati personali or another competent supervisory authority.

GDPR text Italian Data Protection Authority

Children

MWorkspace is a professional creative workspace and is not specifically directed to children.

If you believe that a child has provided personal data without the authorization required by applicable law, contact the controller so the situation can be reviewed and appropriate action taken.

Terms of use

You may use MWorkspace for lawful creative work. You must not attempt to bypass authentication or storage limits, access another person's projects, disrupt the service, introduce malicious content or use the service in violation of applicable law or third-party rights.

You are responsible for reviewing generated exports, maintaining independent copies of important work and ensuring that imported material and final output can be used lawfully.

The tools are provided as a creative service and do not constitute legal, financial, medical or other professional advice.

Content and intellectual property

You retain rights in the original content you import and in your project files, subject to any rights held by third parties in fonts, images, software, datasets or other source material.

You permit MWorkspace and its infrastructure providers to process and store project content only to the extent necessary to provide, secure and maintain the service.

The MWorkspace interface, branding and original software remain protected by applicable intellectual-property law. No ownership of the service itself is transferred to users.

Availability and liability

The service may change, be interrupted or become temporarily unavailable because of maintenance, provider outages, security work or product development.

Reasonable care is taken to protect saved projects, but cloud save is not a substitute for independent backups. Keep exported or otherwise important work in a location you control.

To the extent permitted by applicable law, the service is provided without a guarantee that every tool, export format or third-party integration will always be error-free or continuously available.

Changes and contact

This page may be updated when the product, providers or legal requirements change. Material changes will be reflected by updating the date shown at the top of the page and, where appropriate, by an additional notice.

For privacy, account deletion, legal or security questions, contact mattia.capomagi@gmail.com.

Questions about this policy? mattia.capomagi@gmail.com
MWorkspace
Legal & Privacy