Yumeboard · last updated 21 September 2026
Yumeboard is a board of widgets you arrange yourself. You can use all of it without an account. This page describes what happens if you choose to sign in, and what the app keeps on your own device either way.
Yumeboard is run by an individual based in Italy, who is the data controller for everything described here. For any question, correction or deletion request, write to yumeboard@proton.me.
Your board, your theme, your accent colour and your other preferences are stored in your own
browser using localStorage, and stay there. They are not sent anywhere. The keys are
board.widgets, board.visits, board.shape,
board.analytics, board.layoutmode, theme,
accent, amoled, alertSound and introSeen.
Clearing your browser data removes all of them, and the board with them.
Signing in is optional and adds one thing: the ability to save a board to a server and get it back on another device. What is stored, and for how long:
| What | Why | Kept for |
|---|---|---|
| Your email address | It is the account — it is how a sign-in code reaches you | Until you ask for deletion |
| The date you created the account, and the date you were last seen | Basic account housekeeping | Until you ask for deletion |
| Any board you choose to save, and the name you give it | It is the thing being saved | Until you delete it, or ask for account deletion |
| A sign-in session | So you are not asked to sign in on every visit | 180 days, or until you sign out |
| A pending sign-in request, holding your address and one-way hashes of the code and link | To check the code you type | 15 minutes |
| A salted, one-way hash of your address in a rate-limit counter | To stop someone requesting endless sign-in emails for an address | Rolling 1-hour window |
The legal basis is performance of a contract (Art. 6(1)(b) GDPR): you asked to sign in, and this is what delivering that requires.
The only cookie Yumeboard sets is the sign-in session cookie, and it exists solely to keep you signed in. Signing out removes it.
Those are the only two. Yumeboard is not advertising-funded, and your address is never sold or passed to anyone for marketing.
Some widgets request data directly from the service they show, from your browser, the same way any other website would: Weather from Open-Meteo, approximate location from BigDataCloud, Daily Art from Picsum. Those services see the request and your IP address, as they would for any site. Yumeboard sends them nothing about you, and carries no credential identifying this app, so to them the request looks like any other browser's.
Yumeboard uses Cloudflare Web Analytics, which is cookieless and keeps no cross-visit identity. It reports page counts, referrers and rough geography, and cannot follow an individual.
Whether you have returned is worked out on your own device and stays there. All that is reported is which of a few anonymous buckets a visit falls into — first visit, a return, a return after a week — plus how many widgets are on the board and whether it includes a timer. There is nothing in any of that which can be traced back to a person.
Under GDPR you can ask for a copy of your data, have it corrected, have it deleted, or object to how it is used. Write to yumeboard@proton.me and it will be actioned. Deletion removes your account, every board saved under it, and every session — the whole record, not a flag on it.
If you believe your data has been handled improperly, you can complain to a supervisory authority — the one where you live, the one where you work, or the one where you think the problem happened. The authority for Yumeboard itself is the Italian Garante per la protezione dei dati personali.
If what this page describes changes, the page changes with it and the date at the top moves.