Legal

Privacy Policy

Last updated : March 1, 2026

Who we are

mysaas.blog is operated by Amorem SAS, a simplified joint-stock company incorporated in France, with its registered office at 50 Rue Saint André des Arts, 75006 Paris.

Amorem SAS acts as the data controller under Regulation (EU) 2016/679 (GDPR) for all personal data collected through the mysaas.blog platform.

Data we collect

We collect the following data depending on how you use the platform.

Account and authentication

Email address (required), display name (optional), avatar (optional), magic link login token (temporary, expires after 15 minutes), and session data (IP address, browser user-agent).

Public profile

Username, biography, personal website URL, links to your Twitter/X, GitHub, and LinkedIn profiles, and booking link (Calendly/Cal.com).

Published content

Posts (build logs): title, content, excerpt, tags, publication date. Comments published on posts. First-party analytics events on founder/post pages and outbound links (views, clicks, acquisition source, technical visit data).

Third-party authentication data

If you choose to sign in with Google or GitHub, we receive your identifier, email address, and name from those services. No other access to your accounts is requested.

Legal basis and purposes

Performance of a contract (Art. 6(1)(b) GDPR)

Managing your account, magic link authentication, publishing your posts and comments, and displaying your public profile.

Legitimate interest (Art. 6(1)(f) GDPR)

First-party audience measurement (views/clicks, source attribution, technical dimensions), security and fraud prevention, and platform improvement.

Sharing with third parties

We do not sell or rent your data. We rely on technical processors to operate the platform.

UseSend

Transactional email provider

Email address — only for sending your login magic link.

Cloudflare R2

File storage

Uploaded files (avatars, images used in posts).

Google (OAuth)

Optional authentication

Google email address and user identifier if you choose this sign-in method.

GitHub (OAuth)

Optional authentication

GitHub email address and user identifier if you choose this sign-in method.

Your data may also be disclosed where required by law or to protect our legal rights.

Retention period

Your data is kept for as long as your account remains active. When you delete your account, all of your data (profile, posts, comments, sessions) is deleted immediately and permanently.

Magic link tokens automatically expire after 15 minutes and are invalidated after use.

Your GDPR rights

Under the GDPR, you have the following rights regarding your personal data.

Right of access Obtain a copy of the data we hold about you.
Right to rectification Correct inaccurate or incomplete data.
Right to erasure Request deletion of your data. You can also do this directly from your account.
Right to portability Receive your data in a structured, machine-readable format.
Right to object Object to processing based on our legitimate interest.
Right to restriction Request a temporary restriction on the processing of your data.

To exercise these rights, contact us at legal@mysaas.blog. You also have the right to lodge a complaint with the French data protection authority, the CNIL (cnil.fr).

Cookies and analytics

mysaas.blog uses first-party analytics to measure audience and conversions (SaaS and posts), with the following characteristics:

First-party event tracking (SaaS and post views/clicks)

Source attribution (UTM > referrer > direct)

Technical enrichment (IP, user-agent, device, geo)

Human/bot traffic filtering at the analytics layer

Session cookies are used only to keep you signed in to your account. These cookies are strictly necessary for the service to operate. First-party analytics primarily relies on HTTP requests (headers and URL parameters) and is processed on the basis of legitimate interest.

Security

We implement appropriate technical measures to protect your data: encrypted communications (HTTPS), single-use authentication tokens with limited lifetime, and restricted database access. No password is ever stored — authentication is handled exclusively through magic links or OAuth.

Changes

We may update this policy at any time. The date of the latest update appears at the top of this page. If we make a material change, we will notify you by email. Continued use of the platform after notice constitutes acceptance of the updated policy.

Contact

For any question about this policy or to exercise your rights:

Amorem SAS

50 Rue Saint André des Arts, 75006 Paris

legal@mysaas.blog