Privacy Policy
Effective July 17, 2026
Adap is in private preview. This policy explains what is collected on adap.app and in the early Adap service, how it is used, and the choices you have.
Who controls your data
Adap is operated by blackplate, a sole proprietorship (eenmanszaak), registered in the Netherlands. Full operator details are on the legal notice page. For privacy requests, contact hey@adap.app orlegal@adap.app.
What we collect
- Email address, if you join the early group, request updates, or become a founding member.
- Basic subscription records, such as signup time (kept as proof of consent), list membership, and unsubscribe status.
- First-party, cookieless analytics events, if enabled, to understand whether the site is being read and whether signups work.
- Technical logs needed to operate and secure the site and subscription system.
- When the product is available, account, conversation, check-in, and tool-use data that you choose to put into Adap.
What we do not do
- We do not sell personal data.
- We do not use advertising trackers, cross-site tracking, ad SDKs, or data brokers.
- We do not use your conversations to train models.
- We do not set non-essential cookies on the landing page.
How we use data
We use data to provide the service, send requested updates, manage early access or founding-member interest, keep the system secure, debug problems, and meet legal obligations.
Where this runs
This site and the services behind it run on our own servers in the European Union, under EU jurisdiction. Analytics and email are self-hosted on that same infrastructure rather than handed to an outside platform, which is why there are no third-party requests on these pages and nothing to hand to an advertising network or data broker.
The whole server is defined as code in a single reproducible configuration, and we intend to publish that configuration on Codeberg so the claims on this page can be checked rather than taken on trust. Publication is pending a security review: a server configuration names every service, port, and trust boundary in the system, so it gets checked before it is public rather than after.
Data is encrypted in transit, and production data is intended to be encrypted at rest.
Service providers
We use infrastructure and operational providers to host the site, run email subscriptions, analytics, and related systems. They process data only as needed to provide those services.
Your rights
If GDPR applies to you, you can ask to access, correct, delete, export, or restrict processing of your personal data. You can also object to certain processing and lodge a complaint with your local data protection authority.
Retention and deletion
We keep email subscription data while your subscription is active. Addresses that unsubscribe are deleted automatically within 30 days, and you can ask us to delete your data at any time. Technical logs are kept only as long as needed for operations and security. Product data retention will be documented before public launch. When Adap accounts exist, you will be able to delete your account and its data at any time. See account deletion.
Changes
We may update this policy as Adap moves from private preview to public availability. Material changes will be reflected on this page by updating the effective date.