Privacy
This notice covers the website hey-albert.app and the list. The application at app.hey-albert.app and the Hey Albert app will get their own notice when they launch. Last updated: 19 September 2026. The controller is based in Sofia; the GDPR and the Bulgarian Personal Data Protection Act apply. The Bulgarian version is legally binding.
Who is responsible
Emma Rocket Ltd OOD, 41 Kutlovitsa str., Slatina Distr., Entr. V, Apt. 52a, 1505 Sofia, Bulgaria, UIC 208636237, represented by the managing director Bogomil Kachamachkov. E-mail: contact@hey-albert.app. No data protection officer needs to be appointed under Art. 37 GDPR. The company is based in the EU, so no representative under Art. 27 GDPR is required.
What this site does not do
It sets no cookies. It measures nothing, tracks nobody, embeds no advertising or analytics services and loads no fonts or scripts from third-party servers. There is no automated decision-making and no profiling. When you choose a language, your browser remembers the choice in its own storage (localStorage). That is not a cookie, it never leaves your device, and you delete it together with your browser's site data.
Visiting the site
When you visit, our hosting provider processes the technically necessary data: IP address, time, requested address, browser identifier. The purpose is delivering the site and keeping it secure, legal basis Art. 6 (1) (f) GDPR. This data is kept briefly in logs and is not linked to other data.
Hosting: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Data processing agreement under Art. 28 GDPR; Vercel is certified under the EU-US Data Privacy Framework, and the EU Commission's standard contractual clauses apply in addition. The site is delivered through a global network, in Europe from European data centres; the function behind the list runs in Frankfurt am Main.
Name resolution: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, operates the domain's name servers. Only the name hey-albert.app is resolved into an address; the page request itself does not pass through Cloudflare. Cloudflare is certified under the EU-US Data Privacy Framework.
The list
When you join the list, we store your email address, the language you chose and the time. Purpose: to write to you once, when Albert is ready. Before that we send an email to confirm your address (double opt-in), and after confirmation a welcome email. Nothing else. The legal basis is your consent, Art. 6(1)(a) GDPR. So that we can prove the consent (Art. 7(1) GDPR), we record at sign-up, confirmation and unsubscribe the time, IP address, browser identifier, originating page and the wording of the consent, plus the identifier of every email sent; the legal basis for this is our legitimate interest in being able to prove it, Art. 6(1)(f). You can withdraw your consent at any time, with the link in every email or by writing to contact@hey-albert.app. Then we stop writing; we keep the record of consent and withdrawal for three years and then delete everything.
Database: Supabase, Inc., 970 Toa Payoh North #07-04, Singapore, servers in Frankfurt am Main (processing agreement under Art. 28 GDPR, standard contractual clauses). Sending: Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA; processing in the EU region (Ireland), processing agreement under Art. 28 GDPR, EU-US Data Privacy Framework and standard contractual clauses. We pass the address on to nobody else.
We keep the entry until you withdraw, at most six months after the app launches. An address that is not confirmed is deleted after 30 days.
When you write to us
A mail to contact@hey-albert.app reaches our mailbox through the e-mail forwarding of Cloudflare, Inc. (processing agreement, EU-US Data Privacy Framework). We process it to answer you, Art. 6 (1) (b) and (f) GDPR, and delete it once the matter is settled and no retention duty applies.
Security
The site is delivered encrypted only (TLS, HSTS). A content security policy blocks foreign scripts. Access to the list is limited to two narrow functions; the table itself cannot be reached from outside. This corresponds to Art. 32 GDPR.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw consent at any time; processing up to that point remains lawful. Write to contact@hey-albert.app.
You can complain to a data protection authority. The authority responsible for us is the Commission for Personal Data Protection of the Republic of Bulgaria (CPDP), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia. You may also contact the authority where you live.
Children
This website is aimed at adults. You can join the list if you are at least 16 years old.
The app, in one paragraph
For Hey Albert, what the start page says applies: your data stays in Frankfurt. Albert reads only what you give him. Every answer is a draft. Everyone sees what is theirs. Your device encrypts the vault. There is no advertising and no sale of data. We will publish the full notice for the app here when it launches.
Changes
If services or purposes change, we change this notice and update the date above. Older versions are available on request.
Short links, mails and visits
Links in our mails go through hey-albert.app and carry an identifier of your entry so we can see which mails are opened and clicked (opens via a tiny image that mail apps often preload). Short links (hey-albert.app/l/…) count clicks with country, city and browser, without IP address and without a cookie. Whether we may attribute your website visits to your entry, we ask you after the first click from a mail; only your “yes” sets a cookie (al_spur, 180 days). You can withdraw at any time by deleting the cookie or writing to us. Legal basis: Art. 6(1)(f) (mails, short links) and (a) GDPR (visits).
Website and app statistics (PostHog)
For visitor numbers, origin and paths through the website we use PostHog (PostHog Inc., data centre in Frankfurt, EU cloud). Without your consent PostHog counts anonymously: no cookies, nothing stored on your device, an identifier that changes daily. If you accept statistics in the banner, PostHog sets a cookie with a random identifier (12 months) so we can see whether you return, which paths you take and where you came from; if you sign up afterwards we link that identifier to your entry to understand the path to sign-up. Never collected: inputs, session recordings, form contents. We store your banner choice in your browser (al_consent) and as a record without a person (time, version, choice). You can change it any time via “Cookie settings” at the bottom of every page. Data processing agreement under Art. 28 GDPR; legal basis Art. 6 (1) (a) (with consent) or (f) (anonymous counting), § 25 TDDDG.