This page explains what data Sobmit processes, why, and what rights you have. Short version: we store what is needed to run your account and your flows, we count visits without cookies, and we do not sell or share data for advertising.
Tayfun Gülcan, Franz-Liszt-Straße 38, 38106 Braunschweig, Germany. Email: hello@sobm.it. Full details are in the imprint.
Signing in works with a one-time link sent by email — there is no password. We store your email address, a display name and session data (a session cookie plus technical metadata such as IP address and user agent, used to secure the session). Sign-in emails are delivered through Resend (Resend, Inc.). Legal basis: performance of a contract, Art. 6 (1)(b) GDPR.
Flows you save, their version history, run results and usage records are stored to provide the service. Values you store as secrets (for example API keys used by HTTP nodes) are encrypted at rest and are never embedded in flow data; credential headers are stripped when a flow is shared or published to the gallery. Flows you publish to the public gallery are visible to everyone.
When a flow runs, the inputs of agent, image, video, audio and transcription nodes are sent to the model you selected and processed by the respective model provider to generate the response. Web-search nodes send the search query to the configured search provider. Only put data into a flow that you are allowed to process this way.
Credit top-ups are processed by Stripe (Stripe Payments Europe Ltd.). We do not receive or store your card details — Stripe shares with us only what is needed to credit your account. Legal basis: performance of a contract, Art. 6 (1)(b) GDPR.
The application and its database are hosted by service providers in the EU (Frankfurt region). Where processors outside the EU are involved, transfers are covered by EU standard contractual clauses.
We use a privacy-friendly analytics service to count page visits and anonymous product events — for example which node types are added to flows. It sets no cookies, stores nothing on your device, does not track you across sites and builds no profile; we never see who you are. You can still opt out at any time via the notice banner — the choice is saved on your device and analytics stays off. Legal basis: legitimate interest in understanding aggregate usage, Art. 6 (1)(f) GDPR.
Sobmit uses one strictly necessary session cookie for sign-in. Your preferences (theme, editor settings), unsaved scratch flows, local run history and your analytics choice are kept in your browser's localStorage and are never sent to us. There are no advertising or third-party tracking cookies.
Your data is kept as long as your account exists. You can export all your data and delete your account yourself in the app; deletion removes your flows, runs, secrets and usage records. Billing records are retained as long as commercial law requires.
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a supervisory authority. Contact: hello@sobm.it.