Skip to content
writings.io

Privacy notice

Who is responsible

The controller for the processing of data on writings.io is Naim Wöllmer, U1 8, 68181 Mannheim, Germany. For any privacy question, or to exercise the rights described below, the contact is naim@woellmer.io.

What this is

writings.io is a portal for studying the Bahá'í writings in depth. It is in a closed test phase: access exists only by personal invitation. As little data as possible is processed — no name, no address, no payment data, no advertising services, and no sharing for marketing purposes. A cookieless service measures reach and loading performance; it cannot recognise anyone across page views (see below).

What is processed

For the account and sign-in. The user's email address and the times and technical details of their sign-ins. Signing in is passwordless: a code or link is sent by email. Without this data there is no access. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

For settings. The chosen language, the accent color, and when the introduction was completed. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

For the reading place and collections. Which works the user opened, where they last read (down to the paragraph), which passages they saved or highlighted, their compilations and notes, and — when a compilation is shared — the email address of the person it is shared with.

This reveals the user's religious practice and is therefore specially protected (Art. 9 GDPR). It is processed solely on the basis of their explicit consent (Art. 9(2)(a) together with Art. 6(1)(a) GDPR), given when the account is set up and withdrawable at any time with effect for the future — for instance by deleting the account.

For the waitlist. On signing up from the public landing page: the email address and the browser's language setting, used only to say when access opens. Legal basis: consent (Art. 6(1)(a) GDPR).

For operating the service. The providers used log technical access data (such as IP address, time, and requested address) to keep the service running and fix faults. Errors occurring in the portal are recorded without any user identifier, without IP address and without search terms, and are deleted after 90 days. Legal basis: legitimate interest in secure operation (Art. 6(1)(f) GDPR).

For reach and loading times. Pages requested, referring page, country, device and browser class, and loading-performance measurements. The service sets no cookies and does not recognise a user beyond a single request. The requested address is shortened before it is transmitted: the portal replaces work and passage identifiers with placeholders and removes every search query, so that precisely *what* someone reads is not sent. Legal basis: legitimate interest in a service that works and can be understood (Art. 6(1)(f) GDPR); an objection can be raised at any time at the address below.

Who processes data on our behalf

  • Supabase (database and sign-in). Data is held in a data center in Frankfurt am Main. The company is based in the US; the transfer is covered by a data processing agreement with standard contractual clauses.
  • Vercel (running the website, and measuring reach and performance through Vercel Analytics and Speed Insights). Processing is set to the Frankfurt region; a data processing agreement with standard contractual clauses covers the transfer to the US.

Beyond this, data is passed to no one. Content a user chooses to share with another person is visible to that person — that decision is theirs alone.

How long data is kept

Account data and content stay until the user deletes their account. Deletion removes everything belonging to it: reading history, compilations, highlights, and shares. A waitlist entry is deleted once access has been granted or the person asks for its removal. The providers' technical logs are deleted according to their own retention periods.

Rights of users

Every user has the right of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time. They can export their data and delete their account themselves at any time, both under Settings. For everything else, a message to naim@woellmer.io is enough; an answer follows within one month.

There is also the right to lodge a complaint with a data protection supervisory authority — the one where the user lives or where the controller is established.

Cookies

Only the technically necessary cookies that keep a user signed in are set. There are no advertising or statistics cookies, and therefore no cookie banner.

Changes

If the processing changes, this notice is updated. For material changes users are told by email before they take effect, and are asked for their consent again.

Version of August 28, 2026 · Auf Deutsch lesen · Legal notice · Back to sign-in