LEGAL

GDPR Policy

Last modified: September 13, 2026

What is GDPR?

GDPR stands for General Data Protection Regulation — a law enforced by the EU to protect the personal data of end users. It covers several aspects of data security. Here we want to give you a guideline on how we protect your data, what our responsibility is, and what your responsibility is as a user of Wably.

We strongly suggest you read our full documentation, or any other article about GDPR, before deciding whether to use our application. We are not responsible for any negligence or fault in data protection on your side or on the side of any third party. Take your time to read the documentation and act wisely — stay safe.

Definition of Personal Data

Any data owned by an individual is that individual's personal data — it could be a name, image, email address, physical address, social media post, location, computer IP address, and so on. Ownership of a user's personal data is absolute: wherever and however the data is saved, it belongs solely to the user. The data collector or data user (Facebook, YouTube, or any similar platform) cannot show, save, share, or perform any other activity with a user's personal data without that user's explicit or implicit permission. If a user gives permission for a specific type of action (storing data, viewing data, etc.), then it can be used by the admin of the application.

To visualise this, consider a hypothetical situation: you post a status on social media. Here, you have given implicit permission for that post to be shown to your public or private contacts. The application admin is not responsible for an abusive comment made on your post by one of your contacts — because you made your data public, that is your responsibility. But the application admin does hold responsibility for any sharing of your data with a third party; if data is shared, this must be stated explicitly in advance. So data uploading and showing depends on both the app admin and the user. You will find further detail in our full documentation.

Responsibility of the Developer

Safeguarding user personal data on the application back end is the responsibility of the developer. The developer is responsible for how user data (name, phone number, email, etc.) and other information (such as logs of user interaction with the application) is stored on the database and server. We describe in detail, in our full documentation, how data you submit directly (name, email, etc.) and indirectly (browser name, computer IP, etc.) is saved on the database and server. Once data is uploaded to the server, its security depends on the security of the server and, at times, the admin of the application.

You will be notified about all temporary (cookie and session) and permanent (database) data saving, and you will get the option to have all your personal data erased permanently upon account deletion or service cancellation. We assure you that we do not keep logs of user activity, and there is no backdoor to extract user data. From time to time, cPanel access or another credential of the app admin may be needed by the developer to support and maintain the application for a short period before it goes fully live — we strongly recommend that the app admin change these credentials once the job is done. The developer cannot be held responsible for any credential leak on this ground, nor for any unintentional security glitch in the application. Data shared online always carries some risk of being leaked, so we strongly suggest not sharing any data that could compromise you or any other individual.

Responsibility of the Application Admin

The application admin has unrestricted access to user personal data — access to the database, server logs, and any other information within the admin's reach. The app admin can view and copy data saved on the database and server, and can share a user's personal data with third parties, but how a user's data is used must be announced explicitly before registration. The admin should not allow anyone to extract data openly, or under the disguise of a survey, a form, or any other means. Because the app admin enjoys the highest level of privilege on the application, the admin carries the highest responsibility for safekeeping user personal data.

User's Responsibility

Ultimately, it depends on the user. If a user does not submit data, there is no risk of a data breach — but that is rarely a practical option. A user's top priority should be to read all documentation, from both the app developer and the app admin, before submitting any data. Safekeeping your own credentials is solely your responsibility: a password may be encrypted in the database, but a dictionary word or an easily guessed password can still give a hacker access to your account. Change your credentials immediately if you notice any suspicious activity, or if you have shared your credentials with someone else for an unavoidable reason. Always think before you submit.

Our Action on GDPR

To meet our obligations under GDPR, we:

Collect as little data as possible, and tell users why any specific data is necessary.

Enforce HTTPS across the application.

Destroy all sessions and cookies after logout.

Do not track user activity for commercial purposes.

Tell users about any logs that save computer IP address or location.

Maintain clear terms and conditions.

Inform users of any data sharing with third parties.

Maintain clear policies on data breaches.

Delete data on cancellation of a subscription or account.

Patch web vulnerabilities promptly.

Supported GDPR Features

Adios, application

Once you cancel your subscription or delete your account, you have the option to delete all data existing or related to your account. This action is irreversible — the moment you confirm deletion, your data is erased from the database and server forever. We recommend backing up your data before deleting it, in case you re-subscribe or re-register later.

Secrecy is your right

We encrypt most of your personal data in the database. If a data breach were to occur, a hacker would get an encrypted hash, not your personal data in plain text — so your secrecy stays intact even in the event of a breach. Some data cannot be encrypted because we need to show it to you on login (like your username); we hide all other personal data as much as possible.

No cookie and session saving

You can choose whether or not to save cookies and sessions. Even if you choose to save them, they are destroyed after logout. We strongly suggest you do not save your credentials in your browser — please memorise your credentials, or use a password manager to manage them.

Destroy footprints

We do not save or track your activity for any commercial purpose. We may store your login time or IP address for security purposes only. When you delete your account, every piece of your data is deleted from our servers.

Social engineering is bad

We do not record your personal activity on the application in order to analyse it and try to sell you a product, or to influence your thinking. We consider that practice a malpractice, and we do not engage in it.

Notify me

Get notified by email about activity relating to your account, such as account creation or a password change. We suggest changing your credentials if anything unusual occurs.

Policy update notification

You will be notified of any updates to our privacy policy or disclaimers. Please read the email regarding any such update and decide on your action — feel free to contact us if you have questions.

Connect without worry

We enforce HTTPS everywhere, so data sniffing is not possible. Even if it were attempted, the sniffer would only get an encrypted hash — so feel safe using our application.

No data collecting

We do not collect data beyond what is necessary to run the application — no backdoors, no hidden options to collect data. Once the application is uploaded to a server, even we cannot access it without the app admin's password, so there is no hidden data leak to worry about.

Data breach policy

We implement strong security to store your data carefully in the database, including data encryption, secure database access, SQL-injection prevention, and input validation. However, we do not take responsibility for data breaches originating from the server, since securing the server is the responsibility of the app admin and the server admin. A weak or predictable password chosen by the app admin or server admin, an inherent fault in database configuration, or a security flaw in the server can all lead to a data leak — please contact your app admin regarding any such concern.