← Back to home

Privacy Policy

Last updated: 22 August 2026 · GDPR (EU 2016/679) compliant

1. Data controller

The controller of your personal data is Pau Serrano García (sole trader / autónomo), NIF 48059727P, registered at Carrer Orient, 4, 25318 Les Puelles (Lleida), Spain, contact email hello@hmilibrary.com.

2. What data we collect

CategoryDataWhen
AccountEmail, password (hashed), optional companyOn sign-up
Public profile PublicUsername, name (your display name), avatar, bio, website (all optional except the username)When you create or edit your profile
Community content PublicSymbols you publish (title, description, category, tags, files, preview, automatic ISA-101 check result), likes you give, comments you post, remix links to the original symbolWhen you publish, like, comment or remix
Private symbolsSymbols you save in the Symbol Builder without publishingWhen you save to your account (visible only to you)
ReportsContent you report, the reason you give, your user IDWhen you report a symbol or comment (not public)
BillingVAT/Tax ID, billing address, card data (processed by Stripe — we never see it)On subscribing
UsageSymbols downloaded (official and community), format, date/timeWhile using the app — used to count your monthly download quota
Technical logsIP address, browser type, requested page and time, kept briefly in the standard server and security logs of our hosting and database providers (Section 6)On every request — security, abuse prevention and debugging only; not linked to your download quota
Functional storageSession token, preferred languageDuring the session

3. What is public

HMI Library includes a community where users publish symbols. The following is visible to anyone on the internet, without an account, and may be indexed by search engines:

Your email address, company, billing data, download history, private symbols and reports are never public. The name you enter at sign-up is your display name and is public: it is shown on your profile and is available, together with your username, to anyone viewing your symbols and comments; you can change or clear it in Settings.

You control this data: you can edit or clear your profile fields, unpublish (make private) or delete your own symbols directly from the Dashboard, and remove likes at any time; to remove a comment, email hello@hmilibrary.com. Note that copies of a symbol downloaded while it was published remain licensed under CC BY 4.0 and may be kept by the people who downloaded them. Please do not include personal data about yourself or others in symbol titles, descriptions or comments.

4. Why we use your data

Page counting (first-party, no identifier)

To know which pages lead people to the Symbol Builder and where they leave, we run our own page counter. It is worth being precise about what it does and does not do, because it is unusual:

This is first-party and self-hosted: no data reaches any analytics company. It remains true that we use no third-party analytics, no advertising and no profiling, and that no consent banner is required, because we store nothing on your device.

5. Legal basis

6. Who we share your data with

Your data is stored and processed by the following sub-processors:

ProviderPurposeLocation
Supabase Inc.Database, authentication & file storage (symbol files and previews)EU (eu-central-1, Frankfurt)
Stripe Payments EuropePayment processingEU (Ireland) / US (DPF + SCCs)
Cloudflare Inc.Hosting & CDNGlobal (with SCCs)
Google LLCOAuth (sign-in with Google), optionalUS (with SCCs)

Public content (Section 3) is, by its nature, shared with anyone who visits the site. We do not sell or rent your data to third parties for commercial purposes.

7. Retention

8. Your rights

As a data subject, you have the right to:

To exercise any of these rights, email hello@hmilibrary.com with "GDPR" in the subject. We respond within 30 days at most.

If you believe processing does not comply with the law, you may lodge a complaint with your local data protection authority — in Spain, the Spanish Data Protection Agency (AEPD).

9. Security

We apply appropriate technical and organisational measures: encryption in transit (TLS 1.3), encryption at rest, role-based access control, audit logs, encrypted backups. Passwords are stored as bcrypt hashes — never in plain text. Clean symbol files are served through authenticated, time-limited links; only watermarked previews are publicly cached.

10. Minors

HMI Library is aimed at professionals and does not knowingly collect data from minors under 16. If you believe a minor has provided us data, contact us and we will delete it.

11. Changes to this policy

If we update this policy we will notify you by email to the address associated with your account at least 15 days in advance when the changes affect material rights.