Privacy Policy
Last updated: June 2, 2026
1. Who we are
PostItUp is a collaborative sticky note board application. We are not a large corporation — this is a personal project. Contact: varshithvh@gmail.com
2. What data we collect
When you create an account we collect: • Email address (required for authentication) • Display name (derived from your email, editable) • Boards you create: title, description, prompt, settings • Notes you post: content, color, position, author name • Vote fingerprint: a random string stored in localStorage to prevent duplicate votes — it is NOT linked to your identity When you use the app without an account (anonymous): • Author name you type (stored in your browser's localStorage only) • Vote fingerprint (localStorage only — never sent to our server linked to you personally)
3. How we use your data
• To provide the PostItUp service • To display your boards and notes • To attribute notes to your account when you are signed in • We do NOT sell your data • We do NOT use your data for advertising • We do NOT share your data with third parties except Supabase (our database infrastructure provider)
4. Data storage
Your data is stored in Supabase, hosted on AWS infrastructure in the ap-south-1 (Mumbai, India) region. Data is encrypted at rest and in transit.
5. Your rights (GDPR / DPDP)
You have the right to: • Access your data — download a full JSON export from your Account page • Correct your data — edit your display name from your Account page • Delete your data — delete your account and all associated data from your Account page. Notes you posted on other boards will be anonymised. • Withdraw consent — you can delete your account at any time • Lodge a complaint with your supervisory authority To exercise any of these rights, visit your Account page or email us at varshithvh@gmail.com.
6. Cookies & local storage
We use: • Supabase session cookies (essential) — required for authentication, expire when you sign out • localStorage: "piu_name" — your preferred author name (cleared when you delete your account) • localStorage: "piu_fp" — a random vote fingerprint (cleared when you delete your account) We do not use tracking cookies, analytics cookies, or advertising cookies.
7. Data retention
We keep your data as long as your account exists. When you delete your account, all your data is permanently deleted immediately. Anonymised contributions (notes on other boards) retain only the text content with no link to your identity.
8. Children's privacy
PostItUp is not directed at children under 13. We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy. We will update the 'Last updated' date at the top. Continued use after changes constitutes acceptance.
10. Contact
Questions about this policy? Email varshithvh@gmail.com