Facondia Lab by nicastro.in
Home Apps Books Resources Authors Initiative Settemotivi ODV Legal
EN ▾
  • Italiano
  • English
  • Español
  • Français
  • Deutsch
  • 한국어
  • 日本語
  • 简体中文
  • Română
  • Polski
  • Português (Brasil)
  • Türkçe
  • Bahasa Indonesia
Home Apps Books Resources Authors Initiative Settemotivi ODV Legal
All Site-wide Chroma Closet Elephant Steampunk Morse Code Park Pin Data deletion
Legal documents › Elephant › Privacy policy
Index
  1. 1. Data Controller
  2. 2. Who this Policy applies to
  3. 3. Minimum age
  4. 4. Personal data we collect
    1. 4.1 Data you process locally in the App (not transmitted to the Controller or to third parties)
    2. 4.2 Data transmitted to third parties while using the App
    3. 4.3 Data we do NOT collect
    4. 4.4 Device permissions requested by the App
    5. 4.5 Android system auto-backup (Android Auto Backup)
  5. 5. Purposes and legal bases of processing
  6. 6. Third-party services
  7. 7. International data transfers
  8. 8. Data retention
  9. 9. Your rights
    1. 9.0 How to delete your data
    2. 9.1 GDPR rights (EU/EEA and UK)
    3. 9.2 CCPA/CPRA rights (California, USA)
    4. 9.3 LGPD rights (Brazil)
    5. 9.4 APP rights (Australia)
    6. 9.5 PIPEDA/CPPA rights (Canada)
    7. 9.6 PDPA rights (Thailand and Singapore)
    8. 9.7 POPIA rights (South Africa)
    9. 9.8 PIPL rights (People’s Republic of China)
    10. 9.9 APPI rights (Japan)
    11. 9.10 PIPA rights (South Korea)
    12. 9.11 DPDP rights (India)
    13. 9.12 FADP rights (Switzerland)
    14. 9.13 152-FZ rights (Russian Federation)
    15. 9.14 Other jurisdictions
  10. 10. Children — COPPA (USA)
  11. 11. Data security
  12. 12. Advertising and consent (AdMob / Google UMP)
  13. 13. Cookies and tracking technologies
  14. 14. Automated decision-making
  15. 15. Changes to this Policy
  16. 16. Governing law and jurisdiction
  17. 17. Contact

Privacy policy

Last updated 08/09/2026

Version: 1.0 Effective date: 08/09/2026 Last updated: 08/09/2026

1. Data Controller

Sara Nicastro Trieste, Italy Email: saranicastro.sn@gmail.com

(“Controller”, “we”, “us”)

For any question about this Policy or the processing of your personal data, contact us at the email address above.

Data Protection Officer (DPO): No Data Protection Officer has been appointed under Art. 37 GDPR, as the Controller is a single independent developer who does not carry out large-scale processing or systematic processing of special categories of data.

2. Who this Policy applies to

This Privacy Policy (“Policy”) applies to the mobile application Elephant (“App”), available on the Google Play Store for Android devices, developed and operated by the Controller identified above.

Elephant is a local-first bookmark manager: it captures a link via the Android share sheet (or the in-app ”+” button), detects the source platform, pre-fills the title and preview image by reading the page’s public metadata (https links only), and stores the link in a local library on your device, organisable with folders, tags and filters.

Privacy-relevant characteristics:

  • No account. There is no registration, sign-in or user profile. We use no authentication system.
  • No Controller server. We operate no backend, remote database or cloud infrastructure. The Controller has, at no time, access to your bookmarks or to any other content you enter in the App.
  • Data on the device. All your bookmarks, folders, tags and preferences are stored in the App’s private storage on your device. The only exception is Android’s system auto-backup, which may copy them to the Google Drive space of your Google account (see section 4.5): it is run by Google, not by the Controller, and you can turn it off.

By using the App, you accept the practices described in this Policy. If you do not agree, please do not use the App.

3. Minimum age

The App is intended for users at least 13 years old, or the higher threshold that may apply in your country of residence for independent digital consent (between 13 and 16 in European Union countries; in Italy, 14 under Legislative Decree 101/2018; in South Korea, 14 under PIPA; in China, 14 under PIPL). We do not knowingly collect personal data from children below that age. If you believe a minor has used the App without the consent of a parent or guardian, contact us: we will tell you how to remove the local data from the device (see section 9.0).

4. Personal data we collect

4.1 Data you process locally in the App (not transmitted to the Controller or to third parties)

This data stays on your device, in the App’s private storage. It is not sent to the Controller and is not transmitted to the third-party providers listed in section 6. The App offers no cloud backup of its own; the only exception to this data staying on the device is Android’s system auto-backup described in section 4.5, which copies part of it to the Google Drive space of your Google account (never to the Controller).

CategoryDescriptionWhere it is processed
BookmarksSaved URL, title, description, saved and modified dates, detected source platform, assigned folder, “favourite” flagLocal database on the device (Room)
Preview images (thumbnails)Preview image URL taken from the page metadata, or, only when the page provides no preview image, an image you pick from your gallery as a custom preview (copied into the App’s private storage)Local database + App private storage on the device
Folders and tagsNames of the folders and labels you create to organise your bookmarksLocal database on the device
App preferencesTheme (light/dark/system), interface language, sort order, a local flag recording the “remove ads” purchase, the last legal-documents version seen, the timestamp of the last interstitial ad shownLocal preferences storage (DataStore) on the device
Import/export filesWhen you export your library to CSV or HTML, or import a file, the file is generated or read locally. Import happens by picking a file already on the device through the Android system file picker. Export happens through the Android share sheet: you choose the app or destination, and from that point the file is outside the App’s controlLocal device; import and export initiated by the user

4.2 Data transmitted to third parties while using the App

The App connects to the internet (INTERNET permission) solely for the purposes described below. In these operations some technical data — in particular your IP address, unavoidably visible to any server you contact, and request information such as the user agent — is processed by third parties.

OperationData processed by third partiesWhoPurpose
Reading page metadataWhen you save a link with the https scheme (for http links the App makes no request and pre-fills nothing), the App makes an HTTPS request directly to the link’s website to read its public metadata (<title>, og:title, og:image and similar tags) and pre-fill the title and preview. The operator of that site receives the request, including your IP addressThe operator of the website you are saving (an independent third party, not our vendor)Pre-filling the bookmark’s title and preview
Loading the preview imageIf the bookmark has a remote preview, the App downloads that image from the server hosting it; that server receives the request, including your IP addressThe operator of the server hosting the image (an independent third party)Displaying the preview in the bookmark list
Advertising (free plan only)Android Advertising ID (AAID), IP address, device and App information, ad interaction data. Where the law requires it (e.g. EEA, UK), collection for personalised advertising happens only after explicit consent via the form described in section 12; elsewhere, according to the device’s ad settingsGoogle (Google Ireland Limited / Google LLC) via the Google Mobile Ads SDK (AdMob)Serving banner and interstitial ads to free-plan users
Ad consent formA record of your consent choice and minimal technical data needed to show you the correct form for your regionGoogle, via Google User Messaging Platform (UMP)Collecting and storing advertising consent under the GDPR
“Remove ads” purchaseAn anonymous user identifier generated by the SDK (not linked to any account, no registration data), purchase status, transaction identifier, device identifiers, operating system version, IP addressRevenueCat, Inc. (purchase-management SDK)Verifying and restoring the one-time “remove ads” purchase across reinstalls and devices linked to the same Google Play account
Payment processingIn-app purchase data handled directly by GoogleGoogle (Google Play Billing)Processing payment for the one-time purchase

The App does not send to AdMob, RevenueCat or any other party your bookmarks, titles, saved URLs, folder or tag names, or any other content of your library.

4.3 Data we do NOT collect

  • No account, no identity. The App has no login, does not ask for name, email, phone number or other identifying data, and creates no user profile.
  • No usage data or analytics. The App does not integrate Firebase Analytics, Google Analytics or any other measurement, statistics or telemetry tool. We do not record which screens you visit, which features you use or how long you spend in the App.
  • No crash reporting. The App does not integrate Firebase Crashlytics or any other automatic error-reporting system. If a crash occurs, no report is sent to us.
  • No push notifications. The App does not integrate Firebase Cloud Messaging or any other push service. We register no notification token.
  • No location data. The App does not request the location permission and collects no GPS coordinates. Images you pick as a custom preview are copied into the App’s private storage and are never uploaded to any server: any EXIF metadata in them therefore stays on your device.
  • No biometric data.
  • No library content to third parties. See section 4.2, last paragraph.
  • We do not sell personal data to third parties.

4.4 Device permissions requested by the App

PermissionReasonMandatory
Internet (INTERNET)Reading metadata of saved pages, loading previews, advertising (free plan), managing the “remove ads” purchaseYes, for features that require the network. The local library remains readable without a connection; on the free plan, however, after 30 consecutive seconds without a connection the App shows a full-screen notice that suspends use until the network is back (see Terms and Conditions, section 2.1)
Advertising ID (com.google.android.gms.permission.AD_ID)Automatically added to the App’s manifest by the Google Mobile Ads SDK. Lets the SDK read the Android Advertising ID (AAID) to serve and measure free-plan ads. You can reset or delete the AAID in Android settings (Settings > Google > Ads) or remove advertising entirely with the “remove ads” purchaseNo: relevant only for the free plan with advertising
Network state (ACCESS_NETWORK_STATE)Added to the App’s manifest by Google Play services. Used by the App to detect whether the device is connected (the free plan’s no-connection notice, see the Internet row) and by the advertising and purchase SDKs to know when to attempt network requests. It does not identify the network you are connected to or your locationYes (install-time)
In-app purchases (com.android.vending.BILLING)Added to the App’s manifest by the RevenueCat SDK. Enables the “remove ads” purchase and restore flow through Google Play BillingOnly for the “remove ads” purchase
Android Privacy Sandbox (ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, ACCESS_ADSERVICES_TOPICS)Automatically added to the App’s manifest by the Google Mobile Ads SDK. On Android 13 and later they let the SDK use the Android Privacy Sandbox APIs: reading the Advertising ID through the new system API, measuring ad conversions (Attribution Reporting) and on-device interest categories (Topics) to serve relevant ads without cross-app identifiers. Manageable from Android’s Settings > Privacy > Ads (or Privacy Sandbox); subject to the consent choices described in section 12No: relevant only for the free plan with advertising
Wake lock (WAKE_LOCK)Automatically added to the App’s manifest by the Google Mobile Ads SDK, which uses it to complete short background operations (e.g. loading an ad). The App does not use it directlyNo: relevant only for the free plan with advertising

All permissions above are normal (install-time) permissions: they are granted automatically at install and, on many Android devices, do not appear in the App’s permissions screen, which lists only runtime permissions (e.g. camera, location, contacts) — which the App does not request. You can limit or block the App’s network access through the per-app data-usage / data-saver controls offered by Android or your device manufacturer, where available, or by uninstalling the App; this will disable features that require the network.

Gallery: picking an image as a custom preview happens through the Android system photo picker (Photo Picker), which requires no storage permission: the App receives only the image you choose, never access to your whole gallery.

Share sheet and file picker: capturing a link from another app and exporting files happen through Android’s system share sheet; importing a file happens through the Android system file picker. None of these require any additional permission.

4.5 Android system auto-backup (Android Auto Backup)

The App offers no cloud backup of its own and the Controller runs no server. However, as an operating-system default, Android Auto Backup may copy the App’s data (bookmark database, folders, tags, custom previews, preferences) to the Google Drive space of your Google account, so it can be restored automatically when you reinstall the App or set up a new device.

Characteristics of this backup:

  • it is run entirely by Google and the Android operating system, not by the Controller, who has no access to it at any time;
  • the data is kept in your Google account’s Drive space, under your control, and is encrypted with a key tied to the device credentials;
  • it falls under Google’s terms of service and privacy policy for your Google account / Google Drive;
  • you can turn it off at any time in Android settings (Settings > Google > Backup, or Settings > System > Backup) and delete backups already made from the same screen or from Google Drive (Backup section).

This is the only case in which your library data can leave the device, and even then only to your own Google account’s space, never to the Controller or to the third-party providers listed in section 6.

5. Purposes and legal bases of processing

PurposeLegal basis (GDPR Art. 6)Detail
Operating the service (saving and organising bookmarks locally)Performance of the contract (Art. 6.1.b)Core of the App; no data is sent to the Controller (Android system backup aside — see section 4.5)
Reading page metadata and loading previewsPerformance of the contract (Art. 6.1.b)Needed to pre-fill and display the bookmark’s title and preview; involves an HTTPS request to the source site (https links only) and the image host
Personalised advertising (AdMob)Consent (Art. 6.1.a)Requested via Google UMP before any tracking, where local law requires it; revocable at any time
Non-personalised advertisingLegitimate interest (Art. 6.1.f)Contextual ads with no individual profiling; support the App’s free offering
Collecting and storing advertising consentConsent (Art. 6.1.a); retaining the record of consent meets the duty to be able to demonstrate it under Arts. 5.2 and 7.1 GDPR (accountability)Google UMP records your choice so its validity can be demonstrated
Managing the “remove ads” purchase (RevenueCat, Google Play Billing)Performance of the contract (Art. 6.1.b)Verifying, activating and restoring the one-time purchase
Compliance with legal obligationsLegal obligation (Art. 6.1.c)E.g. responding to lawful requests from authorities, tax/accounting obligations relating to the purchase

6. Third-party services

We use the following third-party services, each subject to its own privacy policy:

ServiceProviderPurposePrivacy policy
Google Mobile Ads SDK (AdMob)Google Ireland Limited / Google LLCIn-app advertising (free plan)https://policies.google.com/privacy
Google User Messaging Platform (UMP)Google Ireland Limited / Google LLCCollecting advertising consent (GDPR)https://policies.google.com/privacy
RevenueCatRevenueCat, Inc.Managing the one-time in-app purchasehttps://www.revenuecat.com/privacy
Google Play BillingGoogle LLCProcessing the in-app paymenthttps://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice

Websites of the links you save: when you save or open a bookmark, or when the App loads its preview, the server of the source site (and the image host) receives an HTTP request from your device, with your IP address and the request’s technical information. These parties are not our vendors: they are independent third parties, each with its own privacy practices, over which we have no control. It is the same kind of connection that would occur if you opened that link in a browser.

All listed providers process data in compliance with the GDPR (including via Standard Contractual Clauses where applicable) and with the laws of the United States and other countries in which they operate. This Policy does not cover the privacy practices of third-party sites and services reachable via links in the App. Links to provider policies are subject to update by the respective third parties; if a link does not work, search for the current privacy policy directly on the provider’s site.

7. International data transfers

The listed third-party providers (Google LLC, RevenueCat, Inc.) are based in the United States and may transfer and process personal data in the USA and in other countries outside the European Union.

Such transfers take place in compliance with applicable rules, including:

  • Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914/EU);
  • Google’s participation in the EU-US Data Privacy Framework (in force since July 2023).

The Controller does not transfer your bookmark library data to any country: it does not leave your device, except for the optional Android auto-backup to the Google Drive space of your Google account (see section 4.5), which is run by Google and subject to Google’s data-location policies for your account.

Note for residents of Japan: under Art. 28 of the APPI, transferring personal data to a third party located in a foreign country is subject to specific requirements when that country is not recognised by the Personal Information Protection Commission as having a data protection system equivalent to Japan’s (unlike the European Economic Area and the United Kingdom, the United States is not so recognised). By using the App with advertising active (free plan) or by making the “remove ads” purchase, you consent to the transfer of the related technical data to Google LLC and RevenueCat, Inc. (both based in the United States — see section 6). You can withdraw consent by switching to the paid plan (which removes advertising) or by ceasing to use the App.

Note for residents of China: under Art. 39 of the Personal Information Protection Law (PIPL), transferring personal data outside the People’s Republic of China requires the data subject’s separate, specific consent. By using the App with advertising active or by making the “remove ads” purchase, you give that separate consent for the transfer of the related technical data to Google LLC and RevenueCat, Inc., revocable at any time by switching to the paid plan or by ceasing to use the App.

8. Data retention

CategoryRetention period
Bookmarks, folders, tags, custom previews, App preferencesOn the device, until you delete them manually (individual items included) or you uninstall the App / clear the App’s data. The Controller cannot delete this data remotely because it has no access to it
Advertising consent (Google UMP)For the period indicated by Google; you can revoke or change it at any time (see section 12)
Technical advertising data (AdMob)According to Google’s retention policies
Technical purchase data processed by RevenueCat and Google Play BillingFor as long as needed to verify and restore the purchase, under RevenueCat’s and Google’s retention policies
Accounting and tax records relating to the purchase (held by the Controller)10 years, as required by art. 2220 of the Italian Civil Code and applicable tax law. The Controller receives the transaction’s financial data from Google Play’s payment reports, not from RevenueCat
Copies made by Android Auto Backup (section 4.5)Kept by Google in your account’s space; typically removed after a period of device inactivity or when backup is turned off. You can delete them at any time from Android settings or Google Drive
Server logs of the sites you visit (metadata / previews)Outside our control: determined by the operators of those sites

9. Your rights

9.0 How to delete your data

Because there is no account and the Controller runs no server, you have direct and complete control over all your library data:

  • Delete individual items: you can delete individual bookmarks, folders or tags directly in the App at any time.
  • Clear everything: from Android settings, Settings > Apps > Elephant > Storage > Clear data immediately and irreversibly removes the entire local database and all preferences.
  • Uninstall the App: uninstalling removes all of the App’s local data from the device.
  • Delete the system backup: if Android’s auto-backup is on (section 4.5), the copy on your Google Drive must be deleted separately, from Android settings (Settings > Google > Backup) or from Google Drive.
  • Before deleting: if you want to keep your library, use the App’s export function (CSV or HTML) to save a file first.

If you have already uninstalled the App: the local data has already been removed from the device by Android at uninstall time. For data processed by third-party providers in connection with advertising or the purchase (see section 6), you may contact those providers directly or write to the Controller at the email address at the top of this document. General instructions are also available at https://nicastro.in/legale/data-deletion-cancellazione-dati/.

Because the library data resides solely on your device and the Controller has no access to it, the Controller cannot provide you with a copy of that data or delete it on your behalf: you exercise the rights of access, rectification, erasure and portability over that data directly through the App (viewing, editing, deleting, exporting to CSV/HTML). All rights remain fully exercisable against the third-party providers listed in section 6 for the data they process.

9.1 GDPR rights (EU/EEA and UK)

As a data subject under the GDPR (Regulation (EU) 2016/679) and the UK GDPR, you have the right to:

  • Access (Art. 15): obtain confirmation of processing and a copy of your personal data.
  • Rectification (Art. 16): correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”, Art. 17): request deletion of the data, subject to legal obligations requiring its retention.
  • Restriction of processing (Art. 18).
  • Portability (Art. 20): receive your data in a structured, machine-readable format. For library data, you exercise this right directly via the App’s CSV/HTML export function; the Controller has no access to it.
  • Objection (Art. 21): object to processing based on legitimate interest.
  • Withdrawal of consent: withdraw consent at any time (e.g. advertising preferences) without affecting the lawfulness of prior processing.
  • Complaint to the competent supervisory authority:
    • Italy and EU: Garante per la protezione dei dati personali (www.garanteprivacy.it, +39 06 696771)
    • United Kingdom: Information Commissioner’s Office (ICO, ico.org.uk, 0303 123 1113)

To exercise your rights, write to saranicastro.sn@gmail.com with the subject “GDPR rights request”. We will respond within 30 days (extendable to 90 days in particularly complex cases, with notice within the first month).

9.2 CCPA/CPRA rights (California, USA)

If you are a California resident, under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), you have the right to:

  • Know which categories of personal data we collect and with whom we share them (see sections 4 and 6).
  • Deletion of your personal data, with the exceptions provided by law.
  • Correction of inaccurate personal data.
  • Opt out of the sale or sharing of personal data. We do not sell personal data. Serving personalised ads via Google AdMob may constitute “sharing” under the CPRA: you can opt out at any time by not giving consent in the Google UMP form (where applicable), by disabling ad personalisation in Android settings (Settings > Google > Ads) or resetting the Android Advertising ID, or by purchasing “remove ads”. After opting out you will receive only non-personalised ads, for as long as you remain on the free plan.
  • Non-discrimination for exercising your rights.

Do Not Track (DNT): Elephant is a native mobile application and does not operate through a browser. DNT signals sent by browsers do not apply to the App and are not recognised. To manage advertising tracking preferences, use the controls described in section 12.

To exercise CCPA/CPRA rights, contact us at saranicastro.sn@gmail.com with the subject “California Privacy Request”. We will respond within 45 days, extendable by a further 45 days with notice.

Other US states: if you reside in another US state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Texas, Oregon, Montana), we grant you rights equivalent to those described in this section, in addition to the minimum standard described in section 9.14.

9.3 LGPD rights (Brazil)

If you are a Brazilian resident, under the Lei Geral de Proteção de Dados Pessoais (LGPD, Law No. 13.709/2018), you have the right to: confirmation of processing, access, correction, anonymisation/blocking/deletion of unnecessary data, portability, information about the third parties with whom data is shared, withdrawal of consent and objection to processing. We will respond within 15 days of the request. You may lodge a complaint with the ANPD (Autoridade Nacional de Proteção de Dados, www.gov.br/anpd).

9.4 APP rights (Australia)

If you are an Australian resident, data processing complies with the Australian Privacy Principles (APP, Privacy Act 1988 Cth). You have the right to access your personal data and request its correction; we will respond within 30 days. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC, www.oaic.gov.au).

9.5 PIPEDA/CPPA rights (Canada)

If you are a Canadian resident, we process your data in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the Consumer Privacy Protection Act (CPPA) and equivalent provincial laws (PIPA Alberta/BC, Law 25 Quebec). You have the right of access and rectification; we will respond within 30 days. You may lodge a complaint with the Office of the Privacy Commissioner of Canada (www.priv.gc.ca).

9.6 PDPA rights (Thailand and Singapore)

If you are a resident of Thailand, we respect the Personal Data Protection Act B.E. 2562 (PDPA 2019). If you are a resident of Singapore, we respect the Personal Data Protection Act 2012 (PDPA). In both cases you have the right of access, correction, deletion and portability of data. To exercise them, contact us at the email address indicated.

9.7 POPIA rights (South Africa)

If you are a South African resident, we process your data in compliance with the Protection of Personal Information Act (POPIA, Act 4 of 2013). The Information Regulator is the competent supervisory authority (www.inforegulator.org.za, inforeg@justice.gov.za).

9.8 PIPL rights (People’s Republic of China)

If you are a resident of the People’s Republic of China, we process your data in compliance with the Personal Information Protection Law (PIPL, in force since 1 November 2021). You have the right to request access to and a copy of your personal data, correction of inaccurate data, deletion, withdrawal of consent to processing, and an explanation of the rules by which we process your personal data. You may lodge a complaint with the Cyberspace Administration of China (CAC, www.cac.gov.cn). The PIPL also requires your separate consent to transfer your personal data outside China (Art. 39): see the dedicated note in section 7.

9.9 APPI rights (Japan)

If you are a Japanese resident, we process your data in compliance with the Act on the Protection of Personal Information (APPI, Act No. 57/2003, as amended). You have the right to request disclosure of the purposes of use and of the retained personal data, correction, addition or deletion of inaccurate data, and suspension of use or deletion where processing does not comply with the APPI or is no longer necessary. To exercise these rights, contact us at the email address indicated. The competent supervisory authority is the Personal Information Protection Commission (PPC — www.ppc.go.jp).

9.10 PIPA rights (South Korea)

If you are a resident of the Republic of Korea, we process your data in compliance with the Personal Information Protection Act (PIPA, Act No. 10465/2011, as amended). You have the right to request access, rectification, deletion and suspension of the processing of your personal data. You may lodge a complaint with the Personal Information Protection Commission (PIPC, www.pipc.go.kr). The PIPA also requires your consent to transfer your personal data outside South Korea: by using the App with advertising active or by making the “remove ads” purchase, you give that consent, revocable by switching to the paid plan or by ceasing to use the App.

9.11 DPDP rights (India)

If you are an Indian resident, we process your data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act). You have the right to access your personal data, request its correction and deletion, and nominate a person to exercise your rights in the event of incapacity or death. You may lodge a complaint with the Data Protection Board of India.

9.12 FADP rights (Switzerland)

If you are a Swiss resident, we process your data in compliance with the Federal Act on Data Protection (nFADP, in force since 1 September 2023). You have rights of access, rectification and deletion analogous to those under the GDPR (see section 9.1). The competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch).

9.13 152-FZ rights (Russian Federation)

If you are a resident of the Russian Federation, we process your data in compliance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (as amended). You have the right to request access, rectification, blocking and deletion of your personal data, and to withdraw consent to processing at any time. You may lodge a complaint with Roskomnadzor (rkn.gov.ru).

Data localisation (Art. 18(5)): the Controller operates no servers of its own: the library data resides on your device, under your control — not on infrastructure managed by the Controller inside or outside Russia. The optional Android auto-backup (section 4.5) is run by Google to your Google account’s space, not by the Controller. The third-party providers listed in section 6 act as independent processors and may process technical data outside the Russian Federation as part of their respective services.

9.14 Other jurisdictions

If you reside in a country not expressly listed in this section, we apply, as a minimum standard, the protections provided by the GDPR (access, rectification, erasure, objection — see section 9.1). You may exercise the rights granted by the law of your country of residence by writing to saranicastro.sn@gmail.com: we will respond within 30 days.

10. Children — COPPA (USA)

In compliance with the Children’s Online Privacy Protection Act (COPPA, 15 U.S.C. 6501 et seq.), the App is not directed to children under 13 and we do not knowingly collect personal data from such children without verifiable parental consent. If you are a parent or guardian and believe your child has used the App and provided personal data to a third-party provider, contact us at saranicastro.sn@gmail.com.

11. Data security

We adopt technical and organisational measures appropriate to the risk, including:

  • Local data protected by the Android operating-system sandbox: the database, the custom previews and the preferences reside in the App’s private storage, not accessible to other applications.
  • Network communications over encrypted connections (HTTPS/TLS) to third-party providers and to the websites of saved links: metadata is read exclusively over https links (no request is made for http links); preview images are downloaded from the address given in the page metadata.
  • No Controller server and no account: the Controller holds no central store of user data that could be breached.
  • App updates via Google Play.

No system of transmission or storage can guarantee absolute security. Because we process no personal data on our own systems, a data breach under Arts. 33-34 GDPR attributable to the Controller cannot arise; any incidents affecting the third-party providers listed in section 6 are handled by those providers under their own procedures.

12. Advertising and consent (AdMob / Google UMP)

The App shows advertising only to free-plan users: a banner at the bottom of some screens and occasional full-screen interstitial ads, shown with a limited frequency. Users who have made the “remove ads” purchase see no ads at all: for them the advertising SDK is not even initialised, no consent form is shown and no data is sent to Google for advertising purposes.

Where local law requires it (e.g. European Union, United Kingdom, Switzerland), before any collection of data for advertising purposes you are shown a GDPR-compliant consent form (via Google User Messaging Platform — UMP) in which you can:

  • Accept personalised ads (based on your interests and behaviour).
  • Decline personalisation (you may still see non-personalised contextual ads).

Where the consent form is not required by local law, ads may be personalised based on your device’s and Google account’s ad settings. You can disable personalisation at any time using the controls described below.

How to change your preferences:

  • Review or change advertising consent via the Advertising privacy options entry in the App’s Settings, which reopens the Google UMP consent form (the entry appears only in regions where the law requires consent, e.g. EEA/UK/Switzerland, and only for free-plan users).
  • On Android 13 and later, manage the Android Privacy Sandbox APIs (Topics, Attribution Reporting) from the device’s Settings > Privacy > Ads.
  • Disable ad personalisation in Android settings: Settings > Google > Ads > Opt out of Ads Personalisation, or reset your Android Advertising ID.
  • Manage Google ad settings: https://adssettings.google.com
  • Remove advertising entirely by making the one-time “remove ads” purchase in the App.

13. Cookies and tracking technologies

Elephant is a native Android mobile application and does not use cookies. The integrated third-party services (AdMob) may use cookie-like identifiers (e.g. Android Advertising ID — AAID) and, on Android 13 and later, the Android Privacy Sandbox APIs (Topics, Attribution Reporting) described in section 4.4, subject to the consent preferences described in section 12. You can reset or disable the AAID in Android settings: Settings > Google > Ads.

14. Automated decision-making

The App uses two automated processes, both run entirely on the device and purely auxiliary:

  • Source-platform detection: the App compares the domain of the saved URL against a list of known platforms (e.g. YouTube, Instagram, TikTok) to assign a label to the bookmark. If the domain is not recognised, it is classified as “Other”. You can correct the outcome manually.
  • Metadata pre-fill: the title and preview are proposed from the saved page’s public metadata (Open Graph / HTML). You can edit or replace both.

Neither process produces legal effects or decisions that significantly affect the individual within the meaning of Art. 22 GDPR. No behavioural profiling for commercial purposes is carried out beyond the personalised advertising described in section 12, subject to consent where required and always able to be disabled.

15. Changes to this Policy

We reserve the right to update this Policy to reflect legislative, technical or operational changes. The current version is always available at https://nicastro.in/legale/elephant-privacy-policy/ and reachable from within the App: please check it periodically. The date of the last change is always shown at the top of the document. Continued use of the App after any change constitutes acceptance of the updated version.

16. Governing law and jurisdiction

This Policy and any dispute concerning the processing of personal data carried out by the Controller are governed by Italian law, in compliance with applicable European rules (in particular the GDPR).

For any dispute concerning the interpretation, validity or performance of this Policy, the Court of Trieste (Italy) has exclusive jurisdiction, subject to any mandatory provision of law applicable in the user’s country of residence.

Users resident in the European Union retain in any case the right to lodge a complaint with the supervisory authority of their country of residence under Art. 77 GDPR, regardless of the contractual jurisdiction indicated.

17. Contact

For any question, request to exercise rights or complaint:

Data Controller Sara Nicastro Trieste, Italy Email: saranicastro.sn@gmail.com

We will respond to all requests within 30 days of receipt.


Policy drafted in compliance with: Regulation (EU) 2016/679 (GDPR) · UK GDPR · California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA) · Children’s Online Privacy Protection Act (COPPA) · Lei Geral de Proteção de Dados (LGPD, Brazil) · Personal Information Protection Law (PIPL, China) · Personal Data Protection Act (PDPA, Thailand 2019 and Singapore 2012) · Australian Privacy Principles — Privacy Act 1988 (Australia) · PIPEDA/Consumer Privacy Protection Act (Canada) · Protection of Personal Information Act (POPIA, South Africa) · Act on the Protection of Personal Information (APPI, Japan) · Personal Information Protection Act (PIPA, South Korea) · Federal Law No. 152-FZ on Personal Data (Russian Federation) · Digital Personal Data Protection Act (DPDP, India 2023) · Federal Act on Data Protection (nFADP, Switzerland)

This Policy was drafted by the Controller for informational purposes. For complex legal questions or to verify compliance in specific jurisdictions, consulting a lawyer specialised in privacy law is recommended.

Facondia Lab by nicastro.in

Android apps that make everyday things lighter.

Subscribe to the newsletter · RSS feeds
Apps Chroma ClosetElephantSteampunk Morse CodePark Pin All applications
Books Too Many Clothes, Nothing to WearMeal Prep for GF+DF Athletes All books
Resources Resources
Authors Alice FabrisAnna Ferro Authors
Legal documents Site privacy policy Cookie policy All documents Cookie preferences
© 2026 Facondia Lab · All rights reserved.