MessageWeave — back to the home page

Privacy policy

Last updated: 1 October 2026

In short

1. Who we are

The data controller is Code Level 39 di Anderlini Michele (“CodeLevel39”), a sole proprietorship, VAT no. IT03778360549, registered at Via Piave 20, 06028 Sigillo (PG), Italy. MessageWeave (the website messageweave.com, the app at app.messageweave.com and the API at api.messageweave.com) is a service of CodeLevel39: there is no separate company called MessageWeave.

For questions about this policy or to exercise your rights, write to info@codelevel39.it. We have not appointed a data protection officer (DPO): we answer directly at that address.

This policy is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the Italian Privacy Code (Legislative Decree 196/2003). The Italian version is the reference text.

2. CodeLevel39's two roles

There are two kinds of data in the service, and we have a different role for each:

3. The data we process as controller

When you visit messageweave.com

The website uses no cookies, stores nothing in your browser and contains no analytics tools, social buttons or third-party resources (even the typeface is hosted by us). Like any web server, it technically records the requests it receives (IP address, page requested, date and time, browser type) to work and to defend itself against abuse.

When you create and use an account

Today the service only has a free plan: we collect no payment data.

4. Why we process it and on what legal basis

PurposeLegal basis
Creating and running your account and workspace, providing the service, sending you service emails (address verification, password recovery, invitations, security alerts, a daily activity digest you can turn off)Performance of the contract (Art. 6(1)(b) GDPR)
Protecting the service, users and recipients: operation logs, sign-in attempts, account and IP blocks, spam and abuse preventionLegitimate interest in security (Art. 6(1)(f) GDPR)
Knowing which invitation or referral a new customer comes fromLegitimate interest (Art. 6(1)(f) GDPR)
Answering your support requestsPerformance of the contract or pre-contractual steps (Art. 6(1)(b) GDPR)
Complying with legal obligations and defending our rightsLegal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f) GDPR)

We don't use your data for advertising, we don't sell it, and we make no decisions based solely on automated processing that have legal effects on you (Art. 22 GDPR). If we ever want to send you promotional messages, we will ask you first.

The data requested at sign-up is required: without it we cannot create the account.

5. How long we keep it

DataRetention
Account and profileAs long as the account is active. When it is closed we delete them, except what we must keep by law or to defend our rights.
Sign-ups never confirmed (email not verified and workspace never used)Deleted after 30 days
Operation log (with IP address)90 days
Failed sign-in attempts30 days
Session tokensExpire after 30 days; revoked ones are deleted within 30 days
IP address blocksA block lasts 24 hours (7 days for repeat offenders); a record of the block is kept as security history
Support requestsAs long as needed to handle them and document the answer

6. Your recipients' data

When you use MessageWeave you upload or collect data about the people you write to: address book details and contact points, consent status and its history, message contents and attachments, templates, delivery results and events received from channel providers (delivered, opened, clicked, bounced), and replies recipients send on chat channels.

For this data you (the customer) are the controller and CodeLevel39 is a processor (Art. 28 GDPR): we process it only to provide the service and according to your instructions, which are those in the Terms of service (section "Data processed on the customer's behalf") and the settings you choose in the app. We don't use it for our own purposes.

Your responsibilities

The tools we give you

Open and click tracking

For email senders, open and click counting is on by default and can be turned off for each sender. It uses an invisible image and links that go through api.messageweave.com; for each message we only store the number of opens and clicks and the date, not the recipient's IP address. If you use it, it is up to you to inform recipients and, where required, collect their consent.

Default retention

DataRetention
Messages sent (recipient and content)180 days from creation, once the sending is concluded
Attachments30 days, then the files are deleted
Delivery attempts90 days
Events received from channel providers90 days
Replies received from recipients180 days
Status notifications sent to your systems (callbacks and webhooks)30 days after completion
Address bookUntil you delete the contact. 30 days after deletion the personal data is anonymised; only contact points that had objected are kept (as a suppression list), together with the consent history (channel, contact point, date and method), as proof of the objection.

When your account is closed, your recipients' data is deleted, with the exceptions just described. Before that you can export your address book.

Are you a recipient? If you received a message sent with MessageWeave, the controller of your data is the organisation that sent it: contact them to exercise your rights. You can always unsubscribe from the link in the message. If you write to us, we will forward your request to the customer concerned.

7. Where the data is and who helps us

To provide the service we rely on these providers, which process data on our behalf under contracts binding them to confidentiality and security:

Channel providers chosen by you. Messages to your recipients are sent through the providers you configure with your own accounts and credentials: for example Twilio and SendGrid, Meta (WhatsApp Cloud API), Telegram, Aruba, Google Firebase Cloud Messaging, Slack, Microsoft Teams, Discord, or your mailbox's mail server. You choose them, under your own contract: MessageWeave passes messages to them on your instruction and receives results and replies from them. Their terms and privacy notices apply, and some may process data outside the European Union.

We disclose data to authorities only when the law requires it. We don't sell or hand over data to third parties for their own purposes.

Transfers outside the EU. If one of our providers processes data outside the European Economic Area, it does so under the safeguards of Articles 44–49 GDPR, such as an adequacy decision of the European Commission (for the United States, the Data Privacy Framework) or standard contractual clauses. You can ask us for more information at info@codelevel39.it.

8. Security

We protect data with technical and organisational measures appropriate to the risk: connections always encrypted (HTTPS), passwords stored in a non-reversible form, short-lived sessions, role-based access and strict separation between workspaces, account locking after repeated wrong sign-in attempts, limits against abusive use, signatures on communications exchanged with external systems, and automatic deletion of data when the periods above expire.

Found a security issue? Report it to the address in our security.txt (help@codelevel39.it). If a personal data breach occurs, we will notify the Italian Data Protection Authority and, where required, the people affected; for recipients' data we will notify the customer (the controller) without undue delay.

9. Cookies and browser storage

Website messageweave.com

No cookies and no data stored in the browser.

App (app.messageweave.com)

The app only uses strictly necessary tools that it needs to work:

We use no profiling, advertising or statistics cookies, neither ours nor third parties'. Strictly necessary tools do not require consent (Art. 122 of the Italian Privacy Code and the Italian Data Protection Authority's cookie guidelines of 10 June 2021): that is why we show no banner. You can clear cookies and local storage in your browser settings; without the session cookie you will have to sign in again.

10. Your rights

For the data we control, you can ask us at any time:

Write to info@codelevel39.it. It is free and we reply within one month (for complex requests this can be extended by two more months, and we will tell you). We may ask you to confirm your identity, for example by writing from your account's email address.

If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of the EU country where you live or work.

11. Changes to this policy

We may update this policy, for example when the service or our providers change. The current version is always on this page, with the date of the last update; if the changes are significant we will also tell you by email.