Privacy policy
Last updated on 10 October 2026.
Michi Binder is a tool for composing binder pages: you arrange cards, add your own artwork and print the pieces. This page states which personal data the service collects, why, who receives it and how you keep control of it.
1.Who is responsible
Nader Chebbo, sole trader (micro-entreprise) registered in France, publisher of michibinder.com, decides why and how this data is processed.
Any question about your data, including a request to exercise your rights, goes to contact@michibinder.com. The site is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, États-Unis.
2.What is collected
Your account: email address, password (never stored in clear text, only as a hash), display name, username, one-line bio, avatar, language, theme, editing preferences, plan, creation date, last visit and account status. Signing in with Google or Discord provides the email address, the name and the picture of that account, and nothing else.
What you compose: binders, pages, referenced cards, uploaded artwork, owned cards, want lists, likes, the people you follow and what you pin to your profile. In a shared binder, each change is kept with its author, which is what makes it possible to undo it.
Messages: what you write from the contact page (address, name, subject, text, language) and the replies sent back to you.
Emails: for every message the service sends you, the recipient, the subject, the delivery status and, when it can be told, whether it was opened or clicked. That is how a password reset can be shown to have arrived.
Subscription, once paid plans open: the customer identifier held by the payment provider, the subscription status and the paid-until date. No card number ever passes through Michi Binder or is stored by it; payment happens entirely on Stripe's pages.
Technical data: server logs kept by the host (IP address, requested page, response code, timestamp), a short-lived counter per IP address that limits abuse, and audience measurement run by the site itself, with no cookie of its own and no third-party tracker: page views, some clicks and the time spent on a page, with the country, region and approximate city (worked out from the IP address by the host), device type, system, browser, window width, language and the page you came from. For a visitor who is not signed in, a visit is tied only to a fingerprint that changes every day, computed from the IP address, which is never stored: it cannot recognise you from one day to the next. When you are signed in, your visits are tied to your account, and where your first visit came from is kept with it.
3.Why, and on what legal basis
| Providing the service and keeping your account | performance of the contract |
|---|---|
| Service emails: address verification, password reset, invitation, reply to a message | performance of the contract |
| News about the site | your consent, withdrawn with one link in every message |
| Security, abuse prevention, rate limiting | legitimate interest |
| Audience measurement, and knowing how accounts use the service in order to improve it | legitimate interest |
| Subscription, invoices and bookkeeping | performance of the contract and legal obligation |
4.Who receives it
The service relies on the following processors, each receiving only what it needs to do its job:
- Vercel: hosting and audience measurement. Pages are served from the London region.
- Neon: the database.
- Cloudflare: object storage for the images you upload.
- Upstash: the counter that limits abuse.
- Resend: sending emails.
- Ably: the real-time channel of shared binders.
- Google: sign-in, if you choose to sign in with a Google account.
- Discord: sign-in, if you choose to sign in with a Discord account.
- Stripe: subscription payment, if you subscribe.
Nothing is sold, rented or passed on for advertising. Some of these providers are established in the United States or process data there; those transfers rely on the guarantees provided for by the GDPR, namely the European Commission's standard contractual clauses or the EU-US Data Privacy Framework for certified companies.
5.What is public, and what is not
A binder is private until you decide otherwise. You can publish it, or make it reachable by a secret link that no list ever gives away.
An open profile shows your username, display name, bio, avatar and what you have published. Your email address is never shown to anyone.
Closing your profile removes it from searches and listings. A binder you published stays reachable at its own address until you set it back to private.
6.How long it is kept
- Account and content: for as long as the account exists.
- Pending invitations and their refusals: 30 days. Invitation links: 7 days.
- Files no longer used by any binder: removed by the nightly clean-up, after a 30-day grace period during which an offline tab could still refer to them.
- Contact messages and their replies: for as long as the exchange is being followed up.
- Email log: kept as proof that a message was sent.
- Invoices: 10 years, as required of any trader by French commercial law.
- Server logs: a few days at most, by the host.
- Audience measurement: 13 months. The key that computes the daily fingerprint is deleted the next day. Where an account came from is kept as long as the account exists; deleting the account removes any link between it and its visits.
To have your account deleted, write to contact@michibinder.com. Deletion removes the account, its binders and its pages; the files you uploaded are then removed from storage by the next clean-up. What you contributed to someone else's shared binder stays in that binder, which belongs to its owner.
7.Your rights
You may ask for access to your data, for its correction or erasure, for processing to be restricted, for a portable copy, and you may object to processing based on legitimate interest. Consent to receive news can be withdrawn at any time, with the link at the bottom of every message.
Write to contact@michibinder.com. You will get an answer within one month. If you believe your rights are not respected, you may lodge a complaint with the CNIL, the French data protection authority, at cnil.fr.
8.How it is protected
Traffic is served over HTTPS only. Passwords are stored as hashes, never in clear text, and are never displayed or emailed back. Sessions rely on signed cookies. Access to the database and to storage is restricted to the service itself and to its administration, which keeps an audit trail of its actions. A content security policy restricts what a page may load, and rate limiting protects sign-in and the costly routes.
No system is beyond reach. If a breach were to affect your data and present a risk to you, you would be informed, and the CNIL notified within the legal deadline.
10.Age
The service is not intended for children under 15 without the agreement of a parent or guardian, who may write to us to have an account removed.
11.Changes to this policy
This policy changes when the service does. The date at the top says when it last did. A change that materially affects your data will be announced to account holders by email before it takes effect.