Legal
Privacy Policy
Last updated 3 September 2026
This is a product whose entire proposition is that your things stay yours, so this page is specific: what we hold, where it physically sits, the three companies that ever touch a byte of it, and how to get it all back or have it destroyed.
1What we collect
Account data. Your email address, handle, display name, and a password stored as an argon2id hash — a one-way transformation we cannot reverse. Optionally a profile, an avatar, a birth date and a timezone, if you fill them in.
What you upload. Files, photos, stories, clips, writing, notes, music, expenses, countdowns and calendar entries, plus what a file says about itself: its size, type, checksum, and any EXIF the camera wrote — including, on photos, the coordinates the camera recorded.
Location, only if you use it. The Location section exists to keep your own track. If you connect a device to it, we store the points that device sends. Nothing is collected from your browser or phone unless you set that up deliberately.
Technical data. For each session: a device name you can see and revoke, an IP address, and a user agent. For security: rate-limit counters, and an audit record of administrative actions. Server logs hold request lines for a short period.
Payments. Whether you have a subscription, which plan, and Stripe's identifiers for it. Card numbers go from your browser to Stripe and never reach us.
Cookies. Three, all first-party, none for advertising: the session cookie that keeps you signed in, and two preferences — theme and language — that only decide how the page is drawn.
2Why we hold it
To run the account you asked for; to bill for it; to keep it secure — rate limits, audit trails and abuse handling are what stop someone else reaching your data; and to meet obligations the law places on us. We do not profile you, we do not advertise, and we do not sell or rent anything about you to anyone. There is no analytics or tracking script on this site.
3Where it is
The database runs on our own server in Germany. Files live in Hetzner Object Storage in Falkenstein, Germany, in a bucket whose objects are private: opening a storage URL directly returns a refusal. Every file a browser sees is streamed through our own proxy, which checks who is asking first, so the storage address is never handed to a visitor.
If you are in Thailand or elsewhere outside the EU, that means your data is transferred to and stored in Germany, under the same protections described here.
4Who else sees any of it
Three companies, each for one job. Hetzner stores the files. Stripe takes the payments and holds the card details we deliberately never receive. Mapbox serves map tiles — when you open a map, your browser asks Mapbox for the tiles around the area being shown; your track itself is never sent there.
Nobody else. No advertising networks, no data brokers, no analytics vendors. We disclose data to authorities only when a valid legal order compels it, and we will tell you unless we are forbidden to.
Our own staff do not read your content. Support access to an account requires a stated reason, expires in 30 minutes, shows a banner on screen the whole time, and is written to an audit log you can ask to see.
5How long we keep it
Your content stays until you delete it. Deleted files sit in trash for 30 days and are then destroyed, including the earlier versions storage keeps as protection against our own mistakes. Delete your account and the same 30-day clock starts on everything in it; your public page disappears at once.
Payment records are kept as long as tax law requires. Audit and security logs are kept for a limited period and then discarded.
6Your rights
Whatever law applies to you — Thailand's PDPA, the GDPR in Europe, or another — you can see what we hold, correct it, export it, have it deleted, object to a particular use, or withdraw a consent you gave. Most of it you can do yourself in settings without asking us. For the rest, write and we will answer within 30 days.
You also have the right to complain to your data protection authority. We would prefer you told us first.
7Security
Passwords are hashed with argon2id. Two-factor authentication is available and mandatory for administrators. Accounts are isolated from each other in the database itself, so a mistake in application code is not enough to expose one account's rows to another. Objects are private at the storage layer; delivery is authorised per request and the link expires in minutes. Sessions are listed in your settings and can be revoked one by one.
If a breach ever affects your data, we will tell you and the relevant authority promptly, with what we know and what we are doing about it.
8Children
Accounts are not for children under 13, and under Thai law a minor needs a guardian's consent. If we learn we hold a child's data without that, we delete it.
9Changes, and how to reach us
Changes appear here with a new date, and material ones are emailed before they take effect. For anything about your data — a copy, a correction, a deletion, or a question about a sentence on this page — write to privacy@1ife.app. The Terms of Service cover the rest of the agreement.