Last updated
What NovaWeaver does with personal data, why, and what you can do about it — as the product is built today, not as planned.
NovaWeaver is run by Federico Paolo Oberdan Storti, an individual (not a company) established in Italy, who is the data controller. Contact: f.storti@outlook.com — for anything here, including the rights below.
There is no Data Protection Officer, because no Art. 37 trigger applies: we are not a public authority and do no large-scale monitoring or special-category processing. There is no Art. 27 representative, because that duty falls only on controllers established outside the Union.
| What | Why | Legal basis |
|---|---|---|
| Email address, password, optional name, session, and a TOTP factor if you enrol one | Create your account, sign you in, keep you signed in, reset your password | Art. 6(1)(b) — our contract with you |
| Your designs, tables, columns, option sets, publishers and generated documents — the content you author | Deliver the product | Art. 6(1)(b) — contract |
| Schema metadata extracted from a connected Dataverse environment | Show it in your workspace and put it in your documents | Art. 6(1)(b) for our side of it. Whether we are controller, joint controller or processor over this half is a question we are working through with counsel, and we will not pre-empt it here |
| Organisation URL, Microsoft tenant ID and an encrypted refresh token per connected Dataverse environment | Keep the connection authenticated so we can read schema metadata when you ask | Art. 6(1)(b) — contract |
| Email address and IP address, as short-lived rate-limit counters | Stop brute-force and password-spray attacks, and automated abuse of our endpoints | Art. 6(1)(f) — our interest in keeping accounts and the service from being taken over or overwhelmed |
| Security records of events such as failed sign-ins and sign-ups, password mismatches on destructive actions, Dataverse tenant-binding mismatches and skipped breach checks, with IP address and user-agent | Detect and investigate attacks on accounts | Art. 6(1)(f) — our interest in the security of the service and of your account |
| Error reports and server logs: user and request IDs, environment and design IDs, error text | Keep the service working and fix faults | Art. 6(1)(f) — our interest in a service that runs and can be debugged |
| The first five characters of a hash of a new password, checked against Have I Been Pwned | Refuse passwords already known to be breached; the password itself never leaves our server | Art. 6(1)(f) — account security |
| Handling an export or deletion request | Meet our Art. 15, 17 and 20 obligations | Art. 6(1)(c) — legal obligation |
About those logs, precisely. They strip a fixed list of sensitive field names and any email-shaped string — not the same as “no personal data”. The stripping works on field names, so anything under a name we do not treat as sensitive passes through: error text from Dataverse or our database, which can echo names from your client’s tenant, and your own name or any free text you typed. The address of a connected environment is no longer written to a log in readable form — we record a one-way digest of it instead — but nothing in the scrubber would have caught it, so treat that as a decision we made at each site rather than a guarantee of the machinery. We would rather say so than claim a scrubbing we do not perform.
There is no profiling and no automated decision-making, and no analytics, advertising or session-replay tooling installed anywhere.
eu-west-1); provider US-headquartered.eu-west-1). Your email or IP address is replaced with a keyed hash before being used as a key here: pseudonymisation, not anonymisation. Rate-limit keys expire within 60 seconds; the export-cooldown key after 24 hours; a cached Dataverse access token shortly before that token itself expires. That cache key contains your account and environment identifiers.Several are US-headquartered, so their staff may access data from outside the EEA for support and administration. We have not yet completed the data-processing agreements and transfer documentation for these providers. We would rather state that than imply paperwork we do not hold. The remaining “still confirming” points are open items, not reassurances. No analytics platform or ad network is installed anywhere, and nothing in the product takes a payment.
You can access your data, have it corrected or erased, restrict or object to the processing we base on legitimate interests, and take it elsewhere (portability). Two are self-serve:
Three honest limits: the export has size caps and says inside the archive if it truncated; it omits what our authentication provider holds — sign-in history, or the label you gave an MFA device; and if you change your name in Settings, the original name you signed up with stays with that provider, which we cannot correct in-app either. Email f.storti@outlook.com and we will complete it by hand. There is also no in-app way to change your account email today; write to us.
If you think we have got this wrong, complain to a supervisory authority — in Italy the Garante per la protezione dei dati personali, or the one where you live or work.
Nothing here is required by law. An email address and password are a contractual requirement: without them we cannot create or secure an account, so you cannot use NovaWeaver. Your name is optional, and so is connecting a Dataverse environment — you can build and document a model without one.
| Item | For | How long |
|---|---|---|
sb-…-auth-token | Your signed-in session. HttpOnly, Secure in production, SameSite=Lax | Up to 400 days |
sb-…-auth-token-flow-…-code-verifier, sb-…-auth-token-flows-code-verifier and sb-…-auth-token-code-verifier | Three one-time values securing the sign-in exchange: the verifier for this attempt, the list of attempts still open, and a compatibility copy | Removed when sign-in completes; an abandoned attempt leaves them until the same default expiry |
sidebar_state | Whether you collapsed the sidebar | 7 days |
theme | Light / dark / system | Until you clear it |
Those are the things our own code stores. Because the domain is proxied through Cloudflare, it also sets security cookies of its own — __cf_bm for bot management, and cf_clearance if you are ever shown a challenge. We do not control their contents or lifetimes; Cloudflare documents them as strictly necessary, which is why they too sit outside the consent question. Every one of ours either delivers the service you asked for or remembers a preference you set yourself; none is used for analytics, profiling or advertising. That is why we ask for no consent and show no cookie banner: it would offer a choice that does not exist.
You connect with Microsoft’s device code flow: you sign in on Microsoft’s own page, so that exchange never passes through our servers and we never see your Microsoft password. We receive a refresh token, store it encrypted (AES-256-GCM) and use it only server-side. Access tokens never reach your browser; every Dataverse call is made from our backend.
We read schema metadata only — table, column, relationship and option-set definitions. Nothing in the product queries your business records.
That metadata still contains free text written by your client’s Dataverse administrators, and we do not inspect or filter it. It is your client’s content, mirrored into your workspace because you asked for it, and you choose what to extract. How controller and processor roles fall on that content is a point we are working through with legal counsel; we will update this notice when it is settled.
Disconnecting an environment, or deleting your account, removes our copy of the token and the environment record. Disconnecting does not delete what you already extracted: the design, its metadata and the name you gave the environment stay in your workspace until you delete the design or your account. It also does not revoke the grant at Microsoft — to do that, remove NovaWeaver’s access from your Microsoft account.
If we add a provider, a new kind of data, or anything else stored on your device, this notice changes before that ships. See also our terms of service.