privacy
Privacy policy
Last updated: 26 September 2026
The Bench stores only what it needs to run your account and your projects. No ads, no tracking, nothing sold. Here is exactly what, why, for how long, and who can see it.
The details marked “to be completed” will be filled in before launch.
Who is responsible
The Bench is published by a sole trader based in France, who is the controller of your data. They also host the service themselves: no third-party host is involved.
- Status
- Sole trader (French micro-entreprise), in France
- Trading name
to be completed - SIREN
to be completed - Address
to be completed
What we store
Everything lives in one database on our server. Tokens (sessions, links sent by email) are never kept as they are, only as a hash.
- Your account
- Your email address, a hash of your password (the password itself is never kept), your language, when the address was verified, and when the account was created and last seen. If an account is suspended: when, and why.
- Google or Facebook, if you use them
- The id the provider gives your account and the email address it tells us, with when they were linked and last used. No name, no photo, no friends list.
- Your sessions
- For each signed-in device: its kind (browser or app), the identification its browser sends (the “user agent”), and when it was created, last used, and expires.
- Single-use links and codes
- Address verification, password reset, the app's sign-in code, the sign-in round trip with Google or Facebook: which account each belongs to, when it expires, and whether it was used.
- Your subscriptions
- The app, the plan, the status, the end of the current period, and where the subscription came from (granted by hand, or by Stripe once payment opens, with Stripe's reference). No payment is taken yet.
- Your projects
- The name and content of each plan saved to the account, its revision number and its dates. A project you delete is hidden, then erased for good along with the account.
- The “opening soon” list
- If you ask to be told when a plan opens: the email address, the app and plan you are interested in, the language and the date. No account needed.
Your IP address is used only to slow down abuse (too many sign-in attempts, for example): it is counted in memory, then forgotten, and never written to the database. When an email cannot be sent, the server log records the kind of message and the recipient's address.
The trial without an account keeps your plan in your browser: it is not sent to us.
Why
To provide the service (performance of a contract, GDPR Article 6(1)(b)): the account, sessions, projects, subscriptions, signing in with Google or Facebook, and the emails that go with them: address verification, password reset, password changed, account deleted.
Because you asked (consent, Article 6(1)(a)): the “opening soon” list, used only to tell you when subscriptions open. You can withdraw your request at any time by writing to us.
To keep the service secure (legitimate interest, Article 6(1)(f)): slowing down abuse, and recognising the devices signed in to your account.
Nothing is used for advertising or profiling, and nothing is sold or passed on.
For how long
| What | How long |
|---|---|
| Account, Google and Facebook links, subscriptions, projects | Until you delete the account |
| Sessions | 180 days after last use, or until you sign out |
| Address verification link | 48 hours |
| Password reset link | 1 hour |
| Sign-in round trip with Google or Facebook | 10 minutes |
| The app's sign-in code | 60 seconds |
| “Opening soon” list | Until subscriptions open, then deleted |
| Database backups | 30 days, then replaced |
Expired sessions and links are erased within the hour. Anything deleted from the database is gone from the backups once they are replaced.
Who can see it
- Hosting
- The server is a virtual machine that belongs to the publisher and runs at their home, in France. So the publisher is also the host: no hosting provider has access to the data.
- Sending email
- The email provider (Resend) receives the recipient's address and the content of each message, in order to deliver it. Provider to be confirmed. If the one chosen processes data outside the European Union, this page will say what safeguards cover that transfer.
- Google or Facebook
- Only if you choose to sign in with them. They then know you use The Bench, under their own privacy rules.
- Nobody else
- No ad network, no analytics tool. The site's fonts and scripts are served by the site itself, not by a third party.
Cookies and browser storage
No tracking or analytics cookies. The site sets one cookie, which signing in needs, so there is no consent banner.
bench_sessioncookie- Your session, once you are signed in. The page's scripts cannot read it; it lasts 180 days, extended when you come back, and is removed when you sign out.
Your browser also keeps a few settings in its local storage, which are never sent to us:
themelocal storage- The theme you chose, light or dark.
terrasse-generator.panelslocal storage- Which of the editor's columns you opened or closed.
terrasse-generator/plan/v1local storage- The plan open in the editor, saved automatically.
You can erase them at any time by clearing the site's data in your browser.
Your rights
The GDPR gives you the right:
- to access your data and get a copy of it;
- to have it corrected;
- to have it erased;
- to receive it in a machine-readable format (portability);
- to object to processing, or ask for it to be restricted;
- to withdraw your consent, for the “opening soon” list.
Your Account page lets you change your password, unlink Google or Facebook, and delete the account.
If you believe your rights are not being respected, you can complain to the CNIL, the French data protection authority: www.cnil.fr (opens in a new tab)
Deleting your data
You can delete everything yourself, or ask us to. How to do it: Delete your data
If this page changes
The date at the top changes with it. A change to what we store or to who can see it will be announced by email to account holders.