Pattio · legal
Privacy policy
Last updated: 11 August 2026
In three sentences
Pattio works entirely on your device and without an account: if you never create one, there is nothing of yours anywhere on our side. If you do create one, what you sync travels encrypted with a key that only your devices hold and that we neither have nor can recover. The one exception, and we say it plainly because it matters, is what you deliberately share: that has to be readable by the server so the people you invite can open it, and therefore we could read it too. And it is exactly that and nothing more: if you share a single item, the server can only read that item and the name of the board it comes from; the rest of the board — the other notes, the zones, the scribbles — stays encrypted. If you share the whole board, then it really is everything.
In the app there is no analytics, no advertising, no trackers, and no selling of data to anyone. It is not a slogan: there simply is no SDK in the app’s code that does any of that. The only measurement anywhere in the project is page-view analytics on the web pages — this site and the one that shared links open — only if the visitor says yes, and nobody’s content ever travels with it (§3.6 and §3.8).
1. Who the data controller is
There is no data protection officer: this activity is not among those for which article 37 GDPR requires one.
- Controller: Joan Cama Ribot
- Trading name: Somia Digital
- Tax ID (NIF): 41531670H
- Address: Carrer de Sant Joan, 17200 Palafrugell (Girona), Spain
- Contact email: hola@somia.digital
2. The principle: local first
Pattio is a local-first app. The boards, the notes, the photos, the drawings and everything else you put in are stored in your device’s database. Without an account, not a single byte leaves the phone to reach any server of ours: there is no copy in the cloud, no identifier of ours and no file of ours.
Creating an account is optional and serves one purpose only: syncing between your devices and, if you want, sharing boards.
3.1. The account
If you sign in with Apple, you can hide your email: Apple gives us a relay address and we never see the real one. If you sign in with Google, Google handles the verification. The app asks Apple for your full name but does not store it anywhere: it only uses the identity token.
The key fingerprint is a shortened cryptographic digest (truncated SHA-512). It does not allow the key to be reconstructed or anything to be decrypted: it is only good for comparing.
The acceptance of the Terms is stored on your device when you finish (or skip) the welcome tour, and it contains only two things: the version of the document and the moment. No identifier, no language, no personal data. If you have an account it travels inside the encrypted vault like everything else — so we cannot read it — and if you do not, it never leaves the device. Anyone who already had Pattio installed before this existed has none, and we do not invent one for them: an acceptance nobody ever saw is not proof.
- Email address — identify you and let you in (code by email, Apple or Google) — legal basis: performance of the contract, art. 6.1.b GDPR — as long as the account exists.
- User identifier (UUID) — tie your content to your account — art. 6.1.b — as long as the account exists.
- Key fingerprint (key_check) — warn you if a device is carrying a key that is not yours — art. 6.1.b — as long as the account exists.
- Which version of the Terms you accepted, and when — being able to say which version of the contract you accepted and on what day — art. 6.1.b (proof that the contract exists) — as long as the account exists.
3.2. The content of PRIVATE boards
This content travels and is stored end-to-end encrypted with XSalsa20-Poly1305 (NaCl secretbox). The key is generated on your device, lives in the iOS Keychain and never reaches us. What we see is an unreadable block of bytes.
How the key gets to your second device, and what that costs. So that signing in to the same account on your iPad or Mac does not force you to transcribe anything, the key is also stored as a synchronisable Keychain item (the iCloud Keychain): that way it travels on its own between the devices of your own Apple Account, end-to-end encrypted by Apple, and it never passes through our server. We still do not see it.
What that costs, and we say it here rather than in a footnote: it ties the security of your content to that of your Apple Account — whoever gets into a person’s iCloud Keychain has the key that decrypts their boards. It is exactly the same deal the Keychain already makes with all of that person’s passwords, their bank one included. The recovery code still exists and is still the fallback: for anyone with iCloud Keychain switched off, for a change of Apple Account, and for anyone who wants a key that does not depend on Apple.
If you lose the key and the recovery code, nobody can recover what was there — not us either. That is the price of real encryption, and it is worth knowing beforehand, not afterwards.
Data processed: encrypted content of boards, zones, items and strokes, and encrypted files (photos, videos, scans, drawings, documents) — purpose: sync you between devices — legal basis: art. 6.1.b GDPR — retention: until you delete it or delete the account.
What we do see, even though the content is encrypted (and there is no way to hide it if we want syncing to work):
- which table each row belongs to (an item, a board, a zone…);
- the row’s identifier (a UUID generated on your device, meaningless in itself);
- the timestamps of creation, modification and deletion;
- the path and the size in bytes of each file, because that is how we count the space you take up and it is what we bill you for.
- In other words: we can know that you have 412 items and that you touched one on a Tuesday at eleven, but not what it says.
3.3. The content of what you SHARE
End-to-end encryption is not here, and that has to be said without dressing it up. What opens in the browser of someone who does not have your key has to arrive there readable, and therefore it is stored readable on the server. While it is shared, its content and its photos could be read by whoever administers our infrastructure. When you stop sharing it, it goes back to travelling encrypted.
And «it» is exactly what you shared and nothing more. There are two sizes, and both are spelled out in words before they happen: if you share a single item, what leaves in the clear is that item, its photos, and the name (with the emoji and the colour) of the board it comes from — the page the recipient sees has to be able to say where it is from — and the rest of the board stays encrypted; if you share the whole board, then everything does leave in the clear: every note, the zones, the scribbles, the notebooks and the photos.
The practical rule: if you would not upload something to a server, do not share it by link.
The people you invite get an anonymous session: we ask them for no email, no account and no data beyond the name they type themselves.
Exactly who sees a guest’s name. The name exists so that, in a poll, people know who voted for what — which means the other people who can read that same thing see it, and nobody else. And one clarification that runs the other way and is also true: votes by the owner and by members with an account come out with no name, because they are not on the guest list. The page gives the name when it knows it and the count always, and it never invents a «Someone».
- Content IN THE CLEAR of what you share and its files — so the people you invite can open it from the browser — art. 6.1.b — until you stop sharing it or delete it.
- Email of the people invited — give them access when they sign in with that email — art. 6.1.b — until you withdraw the invitation.
- Name typed by whoever opens a guest link — so everyone else knows who wrote what and who voted — art. 6.1.b — until sharing stops.
- Poll votes on a shared board — count the votes — art. 6.1.b — the same.
- Link tokens — open the board without an account — art. 6.1.b — until you revoke it.
- If what is shared is the whole board, the guest’s name is seen by those who have the board (owner, members and the other guests of that link).
- If what is shared is a single item, they only see it through that item, and only for the guests who voted on it: opening the link to one poll does not hand over the board’s guest list.
- A guest’s link token is never visible to any other guest. The server serves only their name and the vote identifier, never anything else from their row.
3.4. Purchases
Subscriptions are charged by Apple through your App Store account: we never see your card, your billing name or your address. The one who tells us «this person has Plus» is RevenueCat, a subscriptions intermediary to whom we pass your user identifier (and nothing else: not the email, not the name). Its SDK, on its own account, collects technical device data for its function (for example Apple’s vendor identifier, the model and the country); that is done by them and is described in their own policy.
- User identifier and history of purchases and renewals — know which plan you have and how much space you get — art. 6.1.b — as long as the account exists.
3.5. Device permissions
Pattio does not ask for microphone, contacts, health, Bluetooth or local network, and never uses location in the background.
- Camera — when you take a photo to put on the board — the photo goes on the board, like any other.
- Photo library — when you pick a photo or a video — the same.
- Location (while in use only) — only when you tap «Current location» — the coordinates are turned into an address by Apple. If you save the card to a synced board, they go there encrypted (or in the clear if the board is shared).
- Calendar and Reminders — when you put an agenda card on a board — they are read on the device and do not leave it. We upload nothing anywhere.
3.6. The guest web portal and its analytics
This section is about the web page ONLY — the one that opens when someone sends you a Pattio link (pattio-convidats.netlify.app). The app has nothing to do with it: the iOS binary contains no analytics SDK and never will.
What the portal always stores, and why we do not ask for permission. When you open a link, the browser stores an anonymous session, and that session is what lets you into the board. Without it there is no page. This is strictly necessary storage for delivering the service you asked for, and Article 5.3 of the ePrivacy Directive therefore exempts it from consent. We do not ask permission for the one thing without which the link would not open.
What the portal does NOT do without your permission. If the portal has analytics configured, before measuring anything it asks you with a notice offering two equally easy options: accept and reject. Until you answer — and also if you say no — not a single byte is downloaded from Google and no measurement cookie is stored. The page looks and works exactly the same whether you say yes or no: there is no wall.
Data processed: page view (which of the three page kinds, approximate country inferred from the IP, browser and device type) — purpose: knowing how many people open shared links — legal basis: art. 6.1.a, your consent, and nothing else — retention: whatever the Google Analytics property is configured to keep.
What is NEVER sent, and this is the part that matters: the link token — which is the key to the board — no board or item identifier, no guest name and no content. The path that is sent is not the one in the address bar but one of three fixed strings (/convidat, /e or /), written into the code for that single purpose. There are no custom events either: one page view and nothing more.
Who processes it. Google Ireland Limited / Google LLC as processor, with the IP anonymised (Google Analytics 4 does this by default), with Google signals and ad personalisation switched off, and with Consent Mode v2 configured with every permission denied by default. Transfers to the United States rely on the standard contractual clauses and on the EU–US Data Privacy Framework (§4).
You can change your mind at any time. At the foot of every page of the portal there is «Cookies», which reopens the question. Your choice is remembered for twelve months in your own browser and carries the version of the purposes it covers: if those ever changed, you would be asked again rather than have an older «yes» reused.
And right now this is switched off. As long as no analytics property is configured for the portal, there is neither a notice nor any measurement: the page only stores the anonymous session described in the first paragraph.
3.7. What we do NOT process
So that it is on the record and can be checked by opening the code:
- No analytics in the app. There is no Firebase, no Amplitude, no PostHog, no Mixpanel, no Segment, nor anything like them. The only measurement anywhere in the project is the web pages’, it runs with your permission, and it is described in §3.6 and §3.8.
- No automatic crash reporting. There is no Sentry and no Crashlytics.
- No advertising and no ad network.
- No tracking. The app does not ask for tracking permission (ATT) because it does not need it: it does not use the IDFA or any advertising identifier, and it does not share any data of yours with third parties for advertising purposes or with any data broker.
- No profiling and no automated decision-making with legal effects (art. 22 GDPR).
- No sale and no transfer of data to anyone.
3.8. This website: the waiting list and the analytics
This section is about pattio.app ONLY, the page that presents Pattio. There are no user accounts here and the content of your boards never passes through it.
If you join the waiting list, you leave us your email address and the language you are browsing in, and nothing else. We use them to let you know when Pattio reaches the App Store, and for nothing else. The legal basis is your consent (art. 6.1.a GDPR), which you can withdraw at any time by writing to hola@somia.digital. We keep the address until we send you the launch notice and, at most, twelve months after that. It is stored with Supabase, the processor listed in §4.
This site also uses Google Analytics 4, and only if you accept it in the cookie notice. If you do not answer, or if you decline, not a single byte is downloaded from Google. The detail of what is stored in your browser and how to change your choice is in the Cookie policy (/cookies).
4. Who else touches it (processors)
We have no servers of our own: we rent other people’s. All of them have a data processing agreement in place (art. 28 GDPR).
International transfers. RevenueCat, Apple and Google are in the United States. These transfers are made under the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards at hola@somia.digital.
- Supabase Inc. — database, authentication and (depending on the configuration) file storage, and this site’s waiting-list table — West EU (European Union).
- Cloudflare, Inc. (R2) — file storage, when enabled: today it is NOT — Cloudflare’s global network.
- RevenueCat, Inc. — subscription status — USA.
- Apple Inc. — payment, Sign in with Apple, maps and song search — USA / global.
- Google LLC — Sign in with Google, only if you choose that door; and the web pages’ page-view analytics, only if you consent (§3.6 and §3.8) — USA / global.
- Netlify — hosting for this website and for the guest portal.
Third parties that see your IP (and why)
There are three moments when your device talks directly to someone who is not us. We send them nothing of yours; you go there yourself.
- Link previews. When you paste an address — or when you share a page in from another app — Pattio goes and fetches its title and image directly from your device. That website sees your IP, just as if you had visited it with your browser. (We do it this way on purpose: routing it through a server of ours would mean we saw every link you save.) For a handful of well-known platforms — YouTube, Reddit, Spotify, Instagram, Facebook, TikTok, Pinterest — the card is requested from their own embed service instead of reading the page, and the cover image is stored on your device, because their addresses expire within a few days.
- Song search. What you type goes to Apple’s iTunes search.
- Maps and addresses. Maps and the translation of coordinates into an address are done by Apple.
5. How long we keep it
- As long as the account exists, whatever you have synced to it.
- If the subscription expires or you cancel it, nothing is deleted that same day: you go back to the free plan, everything can still be read and downloaded, and the only thing that is blocked is uploading more while you are over quota. There are 30 days of grace with warnings and the date written out; after that, only the excess is withdrawn (from the oldest to the newest) and what is withdrawn lives another 30 days in the bin, where it can still be recovered by renewing. On day 60 there is no going back. The full timetable, with the numbers, is in §9 of the Terms and conditions (/termes).
- Deletion tombstones. When you delete an item, we keep its row with a «deleted» marker and with no content, so that your other devices know it has to disappear there too. That is sync machinery, not your content, and it goes away with the account.
- Deleting the account really does delete everything: the rows, the files, the key fingerprint and your user. You can do it yourself from the app, and what you have on the device stays on the device.
- Backups. The database provider makes routine backups; a deleted piece of data may survive in them until the backup expires (30 days at most). Once expired, it is nowhere any more.
- This site’s waiting-list email address, until we send you the launch notice and, at most, twelve months after that (§3.8).
6. Portability: the button that is always there
In Settings ▸ Your data ▸ Download all your data there is a button that gives you a ZIP with everything: all the boards in JSON and all the original files byte for byte.
This covers your right to portability (art. 20 GDPR) and the obligation under article 119 ter of the TRLGDCU (Spain’s consumer code), and your device does it all on its own: the ZIP passes through no server of ours.
- It is free, on the free plan too and also if the subscription has expired.
- It is self-service: no need to write to us, no waiting, no asking permission.
- It is machine-readable: JSON and original files, with no need for Pattio.
7. Your rights
You have the right to access your data, to rectify it, to erase it, to restrict its processing, to object to it and to portability. If something is based on your consent, you can withdraw it whenever you like (withdrawing it does not make unlawful what had already been done).
To exercise them, write to hola@somia.digital. We answer within one month at most. We may ask you to confirm who you are, and that is all.
A good part of these rights you can exercise yourself and instantly, without writing to anyone: the export ZIP (access and portability), deleting items (erasure), stopping sharing a board (objection), deleting the account (total erasure) and the cookie settings button (withdrawing or re-granting consent for the analytics, §3.6 and §3.8).
An honest limitation: because private content is encrypted and we do not have the key, we cannot give you a readable copy of what is on the server, nor rectify anything on it from the outside. The one that can do that is your device, which is the one that holds the key — and that is why the export is done by it.
If you think we are not doing it right, you can complain to the Agencia Española de Protección de Datos (the Spanish data protection authority: www.aepd.es, C/ Jorge Juan 6, 28001 Madrid). If you are in another country, you can also complain to your own supervisory authority. We would be grateful if you told us first, but you do not have to.
8. Security
No system is infallible. If there is ever a security breach that puts you at risk, we will tell you and the AEPD within the deadlines of article 33 GDPR.
- End-to-end encryption of private content (NaCl secretbox, XSalsa20-Poly1305), with the key in the device’s Keychain and never on the server. If iCloud Keychain is on, the key travels between your devices over Apple’s transport, end-to-end encrypted by Apple (§3.2).
- TLS on all traffic.
- Row Level Security in the database: each row checks, in the database itself, who is allowed to read it, rather than relying only on the client behaving well. Queries that have to cross the boundary of a guest link go through server functions that return only the necessary columns — the name of whoever voted, for instance, never their link token.
- The file credentials are not inside the app: what signs the access permissions is a server function that first checks whether you have a right to that board, and the addresses it hands out expire after a few minutes.
- Guest links can be revoked whenever you like.
- No analytics, advertising or crash-reporting SDK inside the app: what is not there cannot leak.
9. Minors
Pattio is not aimed at children under 14 and we do not deliberately ask them for data. That is the age from which Spanish law lets you consent to the processing of your own data (art. 7 LOPDGDD), and it is the same age the Terms and conditions require (§3): both documents state the same number on purpose.
If we realise we have processed the data of a child under 14 without the consent of whoever holds parental responsibility, we will delete it. If you are a mother, father or guardian and you think this has happened, write to us at hola@somia.digital.
10. Changes to this policy
If we change something that matters, we will change the date at the top and, if the change is substantial, we will tell you inside the app before it takes effect. Older versions can be requested by email.
This policy is provided for information, not accepted: the GDPR does not allow you to «accept privacy» as a block, and the specific consents — today only the web pages’ analytics (§3.6 and §3.8) — are each asked for in their own place and can be withdrawn whenever you want. What you do accept are the Terms and conditions (/termes), and the app stores their version and date (§3.1).