raoul.studio Back
Legal

Privacy.

Last updated — August 2026

This policy explains what personal data raoul.studio collects, why we collect it, and what rights you have over it. It covers this website and the apps the studio runs, including the Poofy todo app for iPhone and Mac. We keep data collection to the minimum needed to run the studio, reply to the people who get in touch, and keep your tasks in sync.

Who we are

raoul.studio is a product and engineering studio run by Raoul Guillermo, based in the EU. For anything in this policy — or to exercise your rights — reach us at [email protected].

For the purposes of the GDPR, raoul.studio is the data controller for the personal data described here.

What we collect

We only collect personal data you give us or that your browser sends when you use the site:

  • Contact form: your name, email address, optional company name and the message you write.
  • Technical data: when you submit the form we store the IP address and browser user-agent of the request, to protect against spam and abuse.
  • Language preference: a small "lang" cookie remembers which language you chose to read the site in.
  • Newsletter: if you subscribe, your email address and the language you chose, so we can send you the weekly newsletter. Every newsletter has a one-click unsubscribe link, and you can opt out at any time.

Poofy — the iPhone and Mac app

Poofy is the studio’s own todo app for iPhone and Mac. It needs an account so your lists can follow you from one device to the other, and that account is the only reason it holds anything about you.

  • Account: your email address, and — if you register with a password — a hashed version of that password. The password itself is never stored and cannot be read back.
  • Continue with Google: if you sign in with Google, we receive your email address, your basic profile information and your Google account ID. We use them for one thing — to create your account and recognise you next time.
  • Continue with Apple: if you sign in with Apple, we receive a stable identifier for your Apple account and your email address — a private relay address if you chose “Hide My Email”. Apple only sends the email the first time you authorise the app; after that the identifier is what recognises you.
  • Your content: the lists and tasks you write, whether each task is done, and the order you put them in.

How Poofy uses Google data

Signing in with Google is offered purely as a way to identify your account. Poofy asks Google only for your email address and basic profile. It requests no access to Gmail, Drive, Calendar, Contacts, Photos or any other Google service, and it cannot read, write or delete anything in your Google account.

Poofy’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google is used only to provide the sign-in feature. It is never sold, never used for advertising or profiling, never transferred to third parties except as needed to run the service or where the law requires it, and never used to train AI models.

Your tasks are yours. We do not read them for any purpose beyond storing them and serving them back to you, we do not share them, and we do not use them for advertising or to train models.

Deleting your Poofy account

You can delete your account and everything in it from inside the app: open the ⋯ menu, choose “Delete account” and confirm. The account, its lists and its tasks are removed straight away, and it cannot be undone.

You can have your account and everything in it removed at any time by emailing [email protected] from the address the account uses. We delete the account, its lists and its tasks. Signing in with Google can also be disconnected at any time from your Google account’s security settings, and Sign in with Apple under “Sign in with Apple” in your Apple ID settings; that stops any further sign-in, so email us as well if you want the data itself deleted.

We keep account data for as long as the account exists, and no longer.

Why we use it, and our legal basis

We use your contact details and message for one thing: to read and reply to your enquiry. The legal basis is our legitimate interest in responding to people who contact us, and taking steps at your request before any possible agreement.

We use the technical data (IP, user-agent) on the basis of our legitimate interest in keeping the form secure and free of spam. The language cookie is a functional cookie set on the basis of your choice.

Cookies

The site uses a single functional cookie ("lang") to remember your language. We do not use advertising cookies, and we do not run third-party tracking or profiling on you.

Who processes your data

We keep the number of third parties small. The ones that may handle your data are:

  • SendGrid (Twilio Inc.) — delivers the contact-form email to us. Your name, email and message pass through it.
  • Google (Google Ireland Limited) — only if you choose “Continue with Google” in Poofy. Google runs the sign-in and tells us your email address and basic profile. What happens on Google’s side is governed by Google’s own privacy policy.
  • Apple (Apple Distribution International Ltd.) — only if you choose “Sign in with Apple” in Poofy. Apple runs the sign-in and tells us an identifier for your Apple account and an email address, which may be one of Apple’s private relay addresses. What happens on Apple’s side is governed by Apple’s own privacy policy.
  • DigitalOcean — provides the servers and the managed database, in Amsterdam, where the website and all Poofy accounts, lists and tasks are stored.
  • Our own servers — the website and the Poofy API run on infrastructure we manage, and contact submissions are stored in our database there.

Where your data lives

Website data and Poofy accounts, lists and tasks are stored in the EU, on servers and a managed database in Amsterdam. Connections to the site and to the Poofy API are encrypted in transit, and access to the database is restricted.

International transfers

SendGrid (Twilio) is a US company, so sending a contact email may involve transferring your data outside the EU. DigitalOcean is likewise US-headquartered, although the servers holding your data are in Amsterdam. Where a transfer outside the EU happens, it is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Google and Apple provide the Poofy sign-in through their Irish entities; any transfer that happens on their side is governed by their own policies and safeguards.

How long we keep it

We keep contact submissions for as long as we need them to handle your enquiry and for our own records, and no longer than necessary. You can ask us to delete your data at any time.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have it corrected or deleted;
  • restrict or object to how we use it;
  • receive it in a portable format.

Complaints

To exercise any of these rights, email [email protected]. If you believe we’ve mishandled your data, you also have the right to complain to your local data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens.

Security

We take reasonable technical and organisational measures to protect your data, including transport encryption and restricted access. No system is perfectly secure, but we keep the attack surface small by collecting little in the first place.

Software, security and liability

The website and any tools or software we make available are provided on an "as is" and "as available" basis. We take reasonable care to keep them secure and running, but no software or online service can be guaranteed to be completely safe, uninterrupted or error-free.

To the fullest extent permitted by law, raoul.studio is not liable for any loss of data, downtime, security breach, unauthorised access, or any direct or indirect damage arising from your use of — or inability to use — the website or our software, including incidents outside our reasonable control such as third-party hacks, attacks or service outages.

Nothing here limits any rights you have under the GDPR, or any liability that cannot legally be excluded — including liability for intent or gross negligence.

Changes to this policy

We may update this policy as the studio changes. When we do, we’ll update the date at the top of this page.

Privacy questions[email protected]
Digital product studioPrivacy · Legalraoul.studio