Life365Hub — Privacy Policy
Last updated: September 7th, 2026
Our Privacy Commitment — Life365Hub was built on a foundation of zero-knowledge privacy. All vault contents are encrypted entirely in your browser before reaching our servers. We cannot read or see your documents, journal entries, photos, videos, notes or files. Nobody can — not even us.
1. Information We Collect
1.1 Information You Provide Directly
When you create an account and use the Service, we collect:
- Email address — used for authentication, notifications and communications.
- A password verifier — not your actual password. Your password is processed entirely on your own device; we only ever receive a cryptographic value derived from it, which we cannot reverse to learn your password.
- Encrypted vault data — the ciphertext of your vault contents (we cannot decrypt this).
- Vault and item metadata — creation and modification timestamps, which encrypted vault an item belongs to, and similar structural information needed to organize and serve your content back to you. This metadata does not reveal the actual content.
Your Legacy Plan and Trusted Contacts
If you choose to set up escrow and designate trusted contacts, a portion of your Account Key is held, encrypted, by us as one piece of a multi-party split — we cannot use it alone to access your content, and we do not attempt to. Trusted contacts’ email addresses are stored so we can facilitate the invitation and consent process; a contact must explicitly accept before any relationship is established.
1.2 Information Collected Automatically
- Log data — IP address, browser type, and access timestamps.
- Device information — operating system and browser version.
- Usage data — features used, vault creation and access events.
- Billing status — which plan you’re on, subscription status, and renewal date, synced from Stripe. We do not store your card number or full payment details; those are held by Stripe directly.
- Basic technical data — IP address, used only transiently for rate-limiting (preventing abuse like repeated failed login attempts) and never stored as a persistent log tied to your activity.
- Share link access logs — if you create a share link, we record only the timestamp of each time it’s opened, so you can see whether and when it was viewed. We do not log the IP address or device of whoever opened it.
1.3 What We Do NOT Collect
We are committed to data minimization. The following data is never collected:
- We do not track you across other websites.
- We do not use analytics or advertising trackers.
- We do not use your content — encrypted or otherwise — to train any AI model.
- We cannot see your search queries; search happens entirely on your own device.
- Your passphrase — it never leaves your device.
- The plaintext contents of your vaults — we store only encrypted ciphertext.
- Payment card details — handled directly by Stripe.
2. How We Use Your Information
- Providing and operating the Service — authentication, vault storage, access control, and billing.
- Sending your account verification email — an automated message sent once, at signup, to confirm you own the email address you registered with.
- Sending administrative account notices — informational messages about your account (such as storage status) that our team sends manually when relevant; these are not automated.
- Service improvement — understanding usage patterns to improve features and reliability.
- Legal compliance — meeting our obligations under applicable laws and regulations.
- Customer support — responding to enquiries and resolving issues.
If you share data to The Living Gallery of the Life365Hub website at your own discretion and choosing, we only provide placeholders and card (name, photo, dates, quote). This is plaintext, public and outside the zero-knowledge architecture.
We do not sell, rent or trade your personal information to third parties for marketing purposes — ever.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area, our legal bases for processing your personal data are:
- Contract performance — processing necessary to provide the Service you have requested.
- Legitimate interests — security monitoring, fraud prevention and service improvement.
- Legal obligation — compliance with applicable laws and regulations.
- Consent — where you have given explicit consent, such as for marketing communications.
4. Who We Share Information With & Third-Party Services
Life365Hub uses the following third-party services to operate:
- Vercel Servers: Application hosting; standard hosting-level data necessary to serve the application. Vercel’s Privacy Policy and Terms of Service do apply.
- Cloudflare (R2): Encrypted file storage — encrypted media files only, never in a readable form.
- Neon: Provides database hosting to store encrypted content and account metadata.
- Stripe: Payment processing for paid subscriptions. Stripe receives your email address and payment details (which we never see or store on our servers) to process subscription payments on our behalf. Stripe may offer Stripe Link, a feature that lets customers save payment details for faster checkout across merchants that use Stripe. If you opt in to Link, your saved payment information is managed by Stripe under Stripe’s own Link Terms and Privacy Policy — receipts and payment confirmations may reference “Link” as the payment method even when a credit or debit card was used. Stripe is subject to Stripe’s Privacy Policy at stripe.com/privacy.
- Resend: Transactional email delivery. Used to send your account verification email. Resend receives your email address and the content of that specific email (a one-time, short-lived verification link). Resend’s Privacy Policy applies.
Stripe, Neon, Cloudflare, Vercel, Resend Data Processing Agreement (DPA) — links to the Data Processing Agreement documents from these sub-processing service providers are listed below:
- https://stripe.com/privacy
- https://neon.com/blog/gdpr-compliance-and-neon
- https://www.cloudflare.com/privacypolicy/
- https://vercel.com/legal/privacy-notice
- https://resend.com/legal/privacy-policy
Your encrypted vault data is stored on Neon and Cloudflare data centers. Data may be replicated to other regions for redundancy as per their infrastructure policies.
None of these providers can read your encrypted content — the encryption happens on your device before it ever reaches any of them.
5. Data Retention
We retain your account and encrypted content for as long as your account remains active. If you downgrade to a plan with less storage than you’re currently using, we do not delete your existing content — it remains fully accessible; you simply cannot add new content until you’re back under your plan’s limit.
- Account data — retained for the lifetime of your account.
- Vault data — retained until you delete the vault data or close your account.
- Access logs — retained for 12 months for security purposes.
- Deleted vault data — deleted items move to the Trash bin, where they remain recoverable for 30 days before being permanently removed. You may restore an item from the Trash bin at any time during that 30-day window.
- Account closure — you may request account closure and permanent data deletion at any time from your Account Security page. Once requested, all personal data is deleted within 30 days. You may cancel this request at any time before deletion completes.
6. Your Rights & Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate personal data.
- Deletion — request deletion of your personal data and account.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — request restriction of processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdrawal of consent — withdraw consent at any time where processing is consent-based.
To exercise any of these rights, contact us at contact@life365hub.com. We will respond within 30 days. Note that because your vault contents are encrypted and we cannot access them, we cannot provide copies of vault contents — only you can access them with your passphrase.
7. Tokens & Tracking
Authentication uses a short-lived bearer access token held in memory on the client for per-request authorization, combined with an httpOnly, strictly-scoped refresh cookie used only to silently restore a session. Neither is delegated to a third-party identity provider — the entire mechanism is implemented directly. Authentication tokens are essential for maintaining your login session. We do not use advertising tokens, cookies, or third-party tracking for marketing purposes.
8. Children’s Privacy
Life365Hub is not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will take immediate steps to delete that information. If you believe a child under 18 has registered for the Service, please contact us immediately.
9. Authentication and Account Access
Life365Hub offers MFA for accessing your account. The authentication method you choose does not affect the zero-knowledge encryption of your vault contents.
9.1 Email and Password Authentication
When you create an account with email and password authentication, we store:
- Email address — used for account identification and communications.
- Securely hashed password; we never see or store your password in plain text.
- Account metadata — creation date, last sign-in timestamp.
10. Security Measures
- Argon2id encryption for all vault contents — client-side before upload.
- HTTPS/TLS encryption for all data in transit.
- Admin dashboard — monitors users’ storage quota and tiers of the Service.
- Zero-knowledge architecture — plaintext data never reaches our servers.
Despite these measures, no security system is impenetrable. In the event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours of discovery as required by GDPR Article 33.
In the event of a breach of Life365Hub infrastructure, the practical impact is expected to be limited. Because all vault contents are stored as encrypted ciphertext and Life365Hub holds no decryption keys, any data breach would expose only encrypted data that is computationally infeasible to decrypt without the user’s passphrase.
Important Limitation: Because Life365Hub operates on a zero-knowledge basis and cannot decrypt vault contents, we cannot provide plaintext copies of Personal Data within vaults to any party — including law enforcement or regulatory bodies. Only the vault owner, using their passphrase, can access vault contents. This further reduces Life365Hub’s liability under GDPR’s “Risk to Rights and Freedoms” framework.
Reduced Transfer Risk: Because vault contents are encrypted client-side and Life365Hub holds no decryption keys, the practical risk to data subjects from international transfers of vault ciphertext is materially lower than for transfers of plaintext Personal Data.
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your personal information, and the right to opt-out of the sale of personal information. We do not sell personal information. Because Life365Hub does not track users, sell personal data, or use third-party advertising cookies, our application inherently honors opt-out preference signals such as Global Privacy Control (GPC) by default.
To exercise your CCPA rights, contact us at contact@life365hub.com.
12. International Data Transfers
Your data may be transferred to and stored in countries outside your own, including the United States where Cloudflare (R2), Neon, Vercel, and Stripe primary servers are located. These countries may have different data protection laws than your country. By using the Service, you consent to this transfer. We take steps to ensure adequate protections are in place through our third parties’ standard contractual clauses and other appropriate safeguards.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email at least 14 days before the changes take effect. The updated Policy will be posted on our website with a new effective date. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
14. Contact Us — Privacy Officer
For privacy-related enquiries, requests to exercise your rights, or to report a privacy concern, please contact our Privacy Officer:
Life365Hub — Privacy Officer
Email: contact@life365hub.com
Website: https://life365hub.com
Response time: Within 30 days of receipt.
If you are located in the EU and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.
For details on how we process data on behalf of businesses and organizations, see our full Data Processing Addendum.