Life365Hub

Life365Hub — Privacy Policy

Last updated: September 7th, 2026

Our Privacy Commitment — Life365Hub was built on a foundation of zero-knowledge privacy. All vault contents are encrypted entirely in your browser before reaching our servers. We cannot read or see your documents, journal entries, photos, videos, notes or files. Nobody can — not even us.

1. Information We Collect

1.1 Information You Provide Directly

When you create an account and use the Service, we collect:

Your Legacy Plan and Trusted Contacts

If you choose to set up escrow and designate trusted contacts, a portion of your Account Key is held, encrypted, by us as one piece of a multi-party split — we cannot use it alone to access your content, and we do not attempt to. Trusted contacts’ email addresses are stored so we can facilitate the invitation and consent process; a contact must explicitly accept before any relationship is established.

1.2 Information Collected Automatically

1.3 What We Do NOT Collect

We are committed to data minimization. The following data is never collected:

2. How We Use Your Information

If you share data to The Living Gallery of the Life365Hub website at your own discretion and choosing, we only provide placeholders and card (name, photo, dates, quote). This is plaintext, public and outside the zero-knowledge architecture.

We do not sell, rent or trade your personal information to third parties for marketing purposes — ever.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, our legal bases for processing your personal data are:

4. Who We Share Information With & Third-Party Services

Life365Hub uses the following third-party services to operate:

Stripe, Neon, Cloudflare, Vercel, Resend Data Processing Agreement (DPA) — links to the Data Processing Agreement documents from these sub-processing service providers are listed below:

Your encrypted vault data is stored on Neon and Cloudflare data centers. Data may be replicated to other regions for redundancy as per their infrastructure policies.

None of these providers can read your encrypted content — the encryption happens on your device before it ever reaches any of them.

5. Data Retention

We retain your account and encrypted content for as long as your account remains active. If you downgrade to a plan with less storage than you’re currently using, we do not delete your existing content — it remains fully accessible; you simply cannot add new content until you’re back under your plan’s limit.

6. Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at contact@life365hub.com. We will respond within 30 days. Note that because your vault contents are encrypted and we cannot access them, we cannot provide copies of vault contents — only you can access them with your passphrase.

7. Tokens & Tracking

Authentication uses a short-lived bearer access token held in memory on the client for per-request authorization, combined with an httpOnly, strictly-scoped refresh cookie used only to silently restore a session. Neither is delegated to a third-party identity provider — the entire mechanism is implemented directly. Authentication tokens are essential for maintaining your login session. We do not use advertising tokens, cookies, or third-party tracking for marketing purposes.

8. Children’s Privacy

Life365Hub is not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will take immediate steps to delete that information. If you believe a child under 18 has registered for the Service, please contact us immediately.

9. Authentication and Account Access

Life365Hub offers MFA for accessing your account. The authentication method you choose does not affect the zero-knowledge encryption of your vault contents.

9.1 Email and Password Authentication

When you create an account with email and password authentication, we store:

10. Security Measures

Despite these measures, no security system is impenetrable. In the event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours of discovery as required by GDPR Article 33.

In the event of a breach of Life365Hub infrastructure, the practical impact is expected to be limited. Because all vault contents are stored as encrypted ciphertext and Life365Hub holds no decryption keys, any data breach would expose only encrypted data that is computationally infeasible to decrypt without the user’s passphrase.

Important Limitation: Because Life365Hub operates on a zero-knowledge basis and cannot decrypt vault contents, we cannot provide plaintext copies of Personal Data within vaults to any party — including law enforcement or regulatory bodies. Only the vault owner, using their passphrase, can access vault contents. This further reduces Life365Hub’s liability under GDPR’s “Risk to Rights and Freedoms” framework.

Reduced Transfer Risk: Because vault contents are encrypted client-side and Life365Hub holds no decryption keys, the practical risk to data subjects from international transfers of vault ciphertext is materially lower than for transfers of plaintext Personal Data.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your personal information, and the right to opt-out of the sale of personal information. We do not sell personal information. Because Life365Hub does not track users, sell personal data, or use third-party advertising cookies, our application inherently honors opt-out preference signals such as Global Privacy Control (GPC) by default.

To exercise your CCPA rights, contact us at contact@life365hub.com.

12. International Data Transfers

Your data may be transferred to and stored in countries outside your own, including the United States where Cloudflare (R2), Neon, Vercel, and Stripe primary servers are located. These countries may have different data protection laws than your country. By using the Service, you consent to this transfer. We take steps to ensure adequate protections are in place through our third parties’ standard contractual clauses and other appropriate safeguards.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email at least 14 days before the changes take effect. The updated Policy will be posted on our website with a new effective date. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

14. Contact Us — Privacy Officer

For privacy-related enquiries, requests to exercise your rights, or to report a privacy concern, please contact our Privacy Officer:

Life365Hub — Privacy Officer
Email: contact@life365hub.com
Website: https://life365hub.com

Response time: Within 30 days of receipt.

If you are located in the EU and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.

For details on how we process data on behalf of businesses and organizations, see our full Data Processing Addendum.