Privacy Policy
Last updated 2026-08-30 · Opentech OÜ
fewbase is built for one person at a time, and its data handling is meant to be small enough to describe in full. This page does that: every category of data we hold, why we hold it, and every third party that sees any of it.
Who is responsible
The data controller is Opentech OÜ, a company registered in Estonia, European Union.
- CompanyOpentech OÜ
- Registry code14633128
- AddressRavi tn 13-41, Järve linnaosa, Kohtla-Järve, Ida-Viru maakond, 30326, Estonia
- VAT numberEE102129232
- Emailinfo@opentech.ee
We have not appointed a Data Protection Officer: the scale of processing does not require one under Article 37 GDPR. Privacy questions go to the address above and are answered by a person, not a queue.
What we collect, and why
Account
Your email address, the interface language and time zone you choose, and — only if you connect it yourself — your Telegram chat identifier and username. The email address is both your identity and the only way to sign in; there is no password to store, and we do not ask for your name.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
What you put into the tools
Whatever you record while using them: project names, domains and monitored URLs and their running costs in Infra Tracker; service names, amounts, billing dates, categories and notes in Subscriptions Tracker; tasks, projects, tags, time entries and their notes in Time Recorder. We treat this as yours. We do not read it, mine it, profile you with it or train anything on it.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Payments and invoices
Card details never reach our servers: the payment itself runs entirely inside Stripe. On our side we store the Stripe customer identifier, which product you bought, its status and period — enough to give you access.
Invoices are issued by us, not by Stripe: once a month we issue a single invoice covering that month's payments, rather than one document per charge. To produce it we use the billing details collected at checkout — your name or company name, address, and VAT number if you gave one — and keep the issued invoices as accounting records. Those details are used for invoicing and bookkeeping, and for nothing else.
Legal basis: performance of a contract (Art. 6(1)(b)) for access; legal obligation (Art. 6(1)(c)) for invoices and accounting records.
Technical records
Our hosting provider, Cloudflare, processes the usual request metadata — IP address, user agent, timestamps — to deliver and protect the site. We do not build our own analytics on top of it, and there is no advertising, tracking or profiling anywhere in fewbase.
Legal basis: legitimate interest in a working, non-abused service (Art. 6(1)(f) GDPR).
Cookies
One cookie, fb_session, set after you sign in and holding nothing but a random session token. It is strictly necessary to keep you signed in, so it needs no consent banner — and there is nothing else to consent to: no analytics cookies, no third-party pixels, no fingerprinting. Signing out deletes it.
Who else sees your data
These are our processors. Each one gets the minimum it needs to do its job, under a data processing agreement.
- Cloudflare — hosting, database and network protection. All fewbase data is stored here.
- Stripe — payments and card data, and the billing details collected at checkout. Acts as an independent controller for the payment itself. Invoices are ours, not Stripe's.
- Resend — delivery of sign-in links, alerts and digests. Sees your email address and the message content.
- Telegram — only if you connect it: bot messages and alerts pass through Telegram's infrastructure.
- Anthropic — only when you upload a receipt for recognition in Subscriptions Tracker: that file is sent to Anthropic's API to be read, and its contents are not used to train models. Do not upload a receipt whose contents you would not want processed this way; you can always type the subscription in by hand instead.
Infra Tracker also queries public registries (RDAP/WHOIS and an SSL checking service) about the domains you monitor. Those requests carry the domain, never you.
We do not sell data, and we do not share it with anyone else — unless the law obliges us to.
Transfers outside the EU
Cloudflare, Stripe, Resend and Anthropic are US-based or operate globally. Transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
How long we keep things
- Sign-in links: 15 minutes, and they stop working once used.
- Sessions: 30 days, or until you sign out.
- Account and the data in your tools: until you ask us to delete them — deletion removes them from the live databases immediately and from backups as those rotate.
- Invoices we issue and the accounting records behind them: 7 years, as Estonian accounting law requires. This is the one thing we cannot delete on request.
Your rights
Under the GDPR you may request access to your data, correction, deletion, a portable copy, restriction of processing, or object to processing based on legitimate interest. Write to info@opentech.ee and we will answer within one month. There is no fee and no form to fill in.
If you think we handled your data badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee, or to the supervisory authority where you live.
Changes
If this policy changes materially, we will email account holders before the change takes effect. The date at the top always reflects the current version.