Privacy Policy
Effective Date: August 14, 2026
1. Introduction
LastFlare is a private-content and check-in application operated by Nimbus Foundry, LLC ("we," "us," or "our"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our service.
If you have questions about this policy, contact us at [email protected].
2. Information We Collect
Account and Profile
- Email address and phone number (via Supabase Auth), display name, subscription tier, app mode (Adventure or Legacy), storage used, and SMS consent timestamp
Subscription and Purchase Records
- When you buy a subscription through the Apple App Store or Google Play, we keep a record of the purchase and its lifecycle: store and product identifiers, transaction and original-transaction identifiers, the app-user identifier and any linked aliases or account transfers, environment (production or sandbox), price and currency, subscription period and renewal events, cancellation or expiration reasons, timestamps, and the automatic-renewal disclosure version shown to you at purchase. We do not receive your full payment card number or bank details — those stay with the app store.
Check-in Schedule and Activity
- Device timezone (IANA format, collected from your device to compute check-in day boundaries and schedule reminders at the correct local time), check-in intervals and active mode, next check-in deadline and last check-in, guardian confirmation threshold, cascade state, auto-deliver preference and consent record, pause state and history, nudge settings, check-in streak count and streak-freeze status, check-in timestamps and method
Messages and Media
- Message title and body (encrypted at rest with AES-256-GCM), media files you upload (photos, videos, audio) with file type, size, and name, and per-recipient delivery status
Recipients (Third-Party Contacts)
- Name, email, phone, relationship, SMS opt-in and invitation timestamps. (Third party — see Section 11.)
- Recipients use an accountless web viewer and do not need to create a LastFlare account, install the app, or sign in. When someone requests a valid recipient link, we update that link's request count and last-access timestamp, including before the recipient completes the adult-access and Recipient Terms gate. These values count requests to the link; they do not identify a unique person or confirm that anyone read the private content.
- When an adult recipient accepts the Recipient Terms, we record the account holder's and recipient's internal identifiers, a one-way hash of the access token, the Recipient Terms version, the affirmative 18-or-older attestation and its timestamp, acceptance and server-record timestamps, and the request IP address. We do not store the raw access token in this acceptance record.
Guardians (Third-Party Contacts)
- Name, email, phone, relationship, status history (pending, invited, accepted, declined), guardian verification responses ("safe," "cannot reach," "passed"), SMS opt-in confirmation and invitation timestamps. (Third party — see Section 11.)
- When a guardian accepts their invitation, we record the guardian's and the inviting account holder's internal identifiers, a one-way hash of the guardian onboarding token, the acceptance timestamp, the version of the guardian acceptance wording shown to them, a one-way hash of that wording, the Privacy Policy version then in effect, and the guardian's affirmative 18-or-older (adult) attestation together with the time it was recorded. We do not store the guardian's name, email address, phone number, IP address, or browser User-Agent in this acceptance record, and we do not store the raw onboarding token.
- Guardian verification responses are retained as part of the verification cascade audit record until the associated account is deleted. The guardian acceptance record described above is kept separately on a different schedule and currently survives that deletion in pseudonymized form — see "Guardian acceptance records" in Section 12.
Device Information
- Push notification token (Firebase Cloud Messaging for Android, Apple Push Notification Service for iOS), platform (iOS/Android), device name, a device identifier (hardware/IDFV id), and app version
Website Analytics (Public Pages Only)
- On a reviewed allowlist of public marketing and legal pages, we use cookieless Plausible Analytics to measure aggregate page views and outbound-link clicks. We send a sanitized page path and referrer plus browser and device information. Plausible derives coarse location from the request IP address and uses the IP address and User-Agent transiently to create a rotating daily identifier; it does not store the raw IP address or User-Agent. Query strings and URL fragments are removed before an analytics event is sent. Analytics is disabled on authentication, password reset, private-message, data-deletion, memorial, and other unreviewed routes.
Life Story / Memorial Profile
- Display name, biography, birth year, profile username, public memorial subdomain (the public URL identifier), chapter content with dates and location tags, custom prompt responses, memorial access settings (public, private, or selected recipients), and recipient assignments for chapters selected for delivery
Tribute Wall Submissions (Third Party)
- Tribute author name, email, message content, and IP address (for abuse prevention). IP addresses in tribute submissions are retained for 90 days. Tribute submissions are kept while the memorial profile is active and are deleted when the profile owner deletes their account.
Switches
- The name you give each check-in switch (free text), its mode, and paused state
Notifications
- In-app notification title, body, type, related metadata (including device name for sign-in alerts), read status, and your per-switch notification preferences
Delivery Link Logging
- Each successful request using a valid delivery link ordinarily increments a request counter and updates the last-access time for that delivery token. A normal visit may make multiple requests, including an initial count-only request before acceptance, the acceptance request, and a request that reveals content. We do not treat these request counts as proof that the intended recipient opened or read the content.
Security and Audit
- SMS opt-out records (see Section 12), operator access logs (see Section 14), verification cascade events, and anonymized deletion records
3. How We Use Your Information
- Provide and operate the service (store messages and Life Story chapters, manage check-ins, and deliver active messages and Life Story chapters selected for recipients according to your settings)
- Send notifications via multiple channels (push notifications, email, and, where SMS is enabled, SMS)
- Authenticate your identity and secure your account
- Process subscription payments (via Apple App Store / Google Play in-app purchases)
- Improve the service and fix bugs
- Respond to support requests
- Enforce the adult-only recipient gate, secure delivery links, and maintain evidence of an adult recipient's acceptance of the applicable Recipient Terms
- Maintain evidence that a guardian affirmatively accepted the guardian role and the acceptance wording shown to them
- Comply with legal obligations
4. How We Store and Protect Your Data
- Message text is encrypted at rest with AES-256-GCM using keys we manage on our servers (this is not end-to-end encryption)
- Media files are encrypted at rest by our storage provider (DigitalOcean Spaces) using AES-256, with TLS in transit
- Tenant data is isolated at the application layer — every database query is scoped to the authenticated user and enforced by server-side authorization checks
- All data transmitted over TLS 1.2+
- Access controls and audit logging for internal operations
- If a data breach affecting your personal information occurs, we will notify affected individuals and the relevant supervisory authority without undue delay and within the timeframe required by applicable law
5. Sub-Processors and International Data Transfers
We share data with the following sub-processors only as necessary to operate the service:
| Provider | Purpose | Data Shared | Country | DPA & Transfer Mechanism |
|---|---|---|---|---|
| Supabase | Authentication, database | Email, hashed password, user data | USA | DPA at supabase.com/privacy; EU SCCs, UK IDTA/Addendum |
| DigitalOcean | Media storage, hosting | Encrypted media files, application data | USA | DPA at digitalocean.com/legal/data-processing-agreement; EU SCCs, UK IDTA/Addendum |
| Twilio | SMS delivery | Phone numbers, message content | USA | DPA at twilio.com/en-us/legal/data-protection-addendum; EU SCCs, UK IDTA/Addendum |
| Plivo | SMS delivery (failback) | Phone numbers, message content | USA | DPA via Plivo DPA; EU SCCs, UK IDTA/Addendum |
| Postmark (ActiveCampaign, LLC) | Transactional email | Email addresses, email content | USA | DPA at postmarkapp.com/gdpr; EU SCCs, UK IDTA/Addendum |
| Firebase (Google) | Android push notifications | Device tokens, notification payload | USA | Google Cloud DPA; EU SCCs, UK IDTA/Addendum |
| Apple (APNs) | iOS push notifications | Device tokens, notification payload | USA | Apple DPA; EU SCCs, UK IDTA/Addendum |
| RevenueCat | Subscription management | User ID, purchase data | USA | RevenueCat DPA; EU SCCs, UK IDTA/Addendum |
| Sentry | Error monitoring & crash reporting | Device info, stack traces, user ID where present | USA | DPA at sentry.io/legal/dpa; EU SCCs, UK IDTA/Addendum |
| Better Stack (Logtail) | Log management & observability | Application logs (may include identifiers in request paths) | Germany (EU) | Better Stack DPA; processed within the EU |
| Tally | Feedback / survey forms | Feedback you submit | Belgium (EU) | Tally DPA; processed within the EU |
| Plausible Analytics | Cookieless website analytics | Sanitized page path and referrer, browser/device data; coarse location derived from IP | Estonia / Germany (EU) | DPA at plausible.io/dpa; visitor data processed within the EU |
Data processing agreements and appropriate transfer mechanisms are executed with each sub-processor listed above.
Where data is transferred out of your region, we rely on appropriate safeguards: EU/EEA transfers under the EU Standard Contractual Clauses; UK transfers under the UK International Data Transfer Agreement / Addendum; Australian transfers under APP 8 cross-border accountability. We do not rely on your consent as a transfer mechanism.
Your personal information may be stored or processed in the United States and the European Union (Germany and Belgium).
For users in Singapore, we take reasonable steps to ensure overseas recipients of your personal data provide a standard of protection comparable to the Singapore PDPA.
Each provider processes data under their own privacy policy.
6. SMS/Text Messaging
What we send: Where SMS functionality is enabled, LastFlare may process a mobile phone number and send SMS/text messages for check-in reminders, account verification, and service notifications related to your messaging and check-in schedule. SMS is only used where the applicable consent and messaging requirements have been satisfied.
Opt-in: Where SMS is enabled, you opt in to receive SMS messages when you provide your phone number in the app and enable SMS-based check-in reminders. Consent is not a condition of purchase. You may use the app with push notifications only.
Guardian SMS consent: Where guardian SMS is enabled, guardians you invite receive an email invitation and must affirmatively opt in before we send them any SMS. Verification text messages are only sent to guardians who have confirmed their SMS opt-in.
Message frequency: Message frequency varies based on your check-in schedule and account activity. You control the frequency by setting your own check-in intervals.
Message and data rates: Message and data rates may apply. Check with your mobile carrier for details.
Opt-out: You can opt out of SMS messages at any time by replying STOP to any message from LastFlare, or by disabling SMS notifications in your account settings. After opting out, you will receive a one-time confirmation message and no further SMS messages.
Help: Reply HELP to any message from LastFlare for assistance, or contact [email protected].
Carriers: Supported carriers include but are not limited to AT&T, Verizon, T-Mobile, and other major US carriers. Guardians and recipients may be located outside the United States; carrier support varies by country. Carrier participation may change without notice.
No SMS data sharing: We do not sell, rent, or share your phone number or SMS opt-in data with third parties for their marketing purposes. SMS consent and phone numbers are used solely for delivering the LastFlare service.
A2P opt-in retention: We retain a record of SMS opt-in consent for as long as required to evidence compliance with applicable messaging regulations (A2P 10DLC / TCPA).
7. Private Content Delivery
- Active messages and Life Story chapters selected for recipients are delivered to those designated recipients based on your check-in schedule and settings
- Delivered messages and recipient-selected Life Story chapters may be accessed by intended adult recipients via secure web links. The recipient viewer requires two separate, unchecked confirmations before revealing content: that the visitor is at least 18 years old and that the visitor agrees to the current Recipient Terms
- A visitor who selects "I am under 18" is routed to an adults-only block screen and cannot reveal the private content. That selection does not create a Recipient Terms acceptance or an adult-attestation record. A valid-link request made before the selection may already have updated the delivery token's request count and last-access timestamp as described in Section 2
- Recipient access links remain valid for 12 months after delivery and may be used multiple times within that period. After 12 months, delivered messages are permanently deleted, recipient access to delivered Life Story chapters ends, and the link stops working. The owner's Life Story chapters remain in their account under the account retention policy. You can revoke a recipient's access at any time before then by contacting us at [email protected]
- Once delivered, private content generally cannot be recalled. If a recipient wishes to exercise data-deletion rights over content they have received, they may contact us at [email protected]
- We do not read or review private content except as required by law
- Requests made with a valid delivery link update the link's request count and last-access timestamp. Multiple requests can occur during one visit, so these values are operational and security telemetry, not a read receipt or confirmation that the intended recipient viewed the content
8. Posthumous and Incapacity Delivery
LastFlare is designed to store messages and Life Story chapters for potential delivery after the account holder has passed, is incapacitated, or is otherwise unreachable. This is a non-standard data processing scenario. This private content may remain stored for months or years before delivery is triggered.
Users acknowledge this use case when they set up their check-in schedule and message recipients. Encryption and access controls remain active during the entire storage period.
9. Sensitive Information
Because LastFlare supports end-of-life and incapacity planning, some information you provide — including message content and a guardian's response about an account holder's wellbeing — can be personal or sensitive, and in some U.S. states it may fall within "consumer health data" as defined by laws such as Washington's My Health My Data Act. We process this information only as necessary to provide the service you have requested — to store your messages and to make the check-in and delivery decisions you set up — and for no secondary purpose. We do not use it for advertising or profiling, we do not sell it, and we do not share it with third parties for their own purposes; where we deliver it, it goes only to the recipients you designate. Where this information is consumer health data, we handle it as described in our Consumer Health Data Privacy Policy, which explains the categories we process, why, who receives it, and how to exercise your rights. California residents have the right to limit the use of sensitive personal information; because we already restrict our use to providing the service, no additional limitation request is necessary, but you may contact us at [email protected].
10. Automated Decision-Making and the Verification Cascade
LastFlare uses an automated verification cascade to decide when to deliver your active messages and Life Story chapters selected for recipients. If you miss a check-in, the system automatically progresses through escalating reminders and guardian verification. An affirmative guardian threshold can move eligible content into a final warning period. If the threshold is not met, valid automatic- delivery consent can do the same; otherwise the case is routed to operator review. An operator may dismiss the case or authorize it to enter that same final warning period used by other cascade paths — you receive a final cancel notice and a grace window before any content is delivered — unless a current owner stop request blocks manual delivery.
You set thresholds such as how many guardians must confirm. Before sharing begins, available check-in and cancellation controls may halt the cascade. Once sharing begins, available cancellation controls may stop content not yet sent or record a stop request for review, but cannot recall content already delivered. Pausing is not available during every cascade state. If you have questions about this process or wish to intervene, contact us at [email protected].
11. Notice to Guardians, Recipients, and Tribute Authors
If someone has named you as a recipient or guardian, LastFlare processes your personal information (such as your name, contact details, and relationship) because a LastFlare user provided it to enable our check-in and private-content delivery service. We obtained your information from that user. We use it only to operate the service (for example, to deliver a message or a Life Story chapter selected for that recipient, or to ask a guardian to confirm a check-in) and we rely on our legitimate interest in operating a reliable check-in service, balanced against your rights, as our legal basis for processing guardian and recipient contact data. You have the same rights described in Section 13 (including access, correction, and erasure) and may exercise them by contacting [email protected]. Invitations we send on a user's behalf include a link to this Privacy Policy.
If you left a tribute on a public memorial, we collected your information directly from you when you submitted it — the name and email address you provided, the tribute content you wrote, and the IP address you submitted it from (recorded to help prevent abuse). Each tribute is reviewed by the memorial's owner before it appears, and a tribute the owner approves — including the submitted name and content — is shown publicly on the memorial page. We rely on our legitimate interest in operating a memorial tribute wall and preventing abuse. You have the rights described in Section 13 and may exercise them by contacting [email protected].
If you accepted an invitation as a guardian, or accepted the Recipient Terms as a recipient, we keep an append-only record of that acceptance as described in Section 12. A guardian acceptance record holds internal identifiers, hashes, versions, timestamps, and, for guardians who accepted on or after August 29, 2026, the guardian's affirmative 18-or-older (adult) attestation and the time it was recorded; guardian records created before that date do not carry that attestation, and we do not add it retroactively. It contains no name, email address, phone number, IP address, or browser User-Agent. A recipient acceptance record holds the same internal identifiers, hashes, versions, and timestamps, additionally records the recipient's affirmative 18-or-older (adult) attestation and its timestamp, and additionally records the request IP address described in Section 2. Both are kept separately from your contact details, so they remain after the contact details are erased — and, for the guardian acceptance record, that deletion also automatically severs its attribution (its identifiers are set to null), as described in Section 12. You may ask us for a copy of either acceptance record. You may also ask us to erase a guardian acceptance record: we will do so by severing its attribution (as described above and in Section 12) unless we still need it to establish, exercise, or defend a legal claim, and we record an audit entry when we do. A recipient acceptance record is an append-only record of an adult-only access decision that we retain on the legitimate-interest and legal-claim basis described in Sections 12 and 13; it cannot be edited or deleted through this process, so we do not erase it on request. Contact [email protected] to make either request.
A recipient accesses the private-content viewer as an accountless visitor; receiving or opening a link does not create a LastFlare account. Before content is revealed, the viewer is limited to adults and requires the visitor to affirm that they are at least 18 and accept the current Recipient Terms. Because the link is a bearer credential, LastFlare does not independently verify that the person using it is the named recipient. Keep recipient links private and contact us if a link has reached the wrong person.
12. Data Retention
- Account data: Retained for the duration of your active account, plus 30 days following deletion
- Messages (undelivered): Retained for the duration of your active account; deleted within 30 days of account deletion
- Messages (delivered): Retained for 12 months after delivery to allow recipients to access them, then permanently deleted
- Life Story chapters selected for recipients: Recipient access ends 12 months after delivery. A minimal delivery record — that this chapter was delivered to that recipient — is kept after access ends, and is removed when the chapter, the recipient, or the account is deleted. The owner's chapter remains in their Life Story while the account is active and follows the account deletion policy
- Device push tokens: Tokens inactive for 90 days are automatically deactivated and purged (per GDPR Art. 5(1)(e) storage limitation). All tokens are deleted when the associated account is deleted.
- Cascade event logs: Verification cascade event records (verification_cascade_events) are deleted when the associated account is deleted
- Operator access logs: Retained indefinitely. After account deletion, the structured user identifier is set to NULL, but limited free-text operational context recorded by an operator may remain with the access record
- Deletion tombstone records: Retained indefinitely. Contains only an HMAC hash of the subject identifier — no personally identifiable information
- SMS opt-out / compliance suppression log: The minimum information needed to honor an opt-out, including the phone number, may be retained after account deletion for as long as reasonably necessary to prevent future messages, document compliance, resolve disputes, and meet applicable legal obligations
- Tribute submission IP addresses: Retained for 90 days for abuse prevention, after which the IP address is removed
- Tribute submissions (author name, email, and message): Kept while the memorial profile is active; deleted when the profile owner deletes their account
- Data export files: Export ZIP files are temporarily stored on DigitalOcean Spaces for 7 days from the time of export. The download link in the export email is valid for about an hour; you can generate a fresh link anytime within that 7-day window from the app. The export job record is purged after 30 days.
- Memorial subdomain content: If a memorial subdomain is not renewed, the memorial becomes inaccessible upon expiry and its content is permanently deleted 12 months after expiry. Your account itself is not deleted by this process
- Account-holder consent records: When an account holder accepts our Terms of Service or Privacy Policy, we retain a record of that acceptance even after account deletion. The account-holder consent event contains internal consent evidence, including the document versions and acceptance timestamps, and is kept to evidence the account holder's agreement.
- Recipient Terms and adult-attestation records: Each successful recipient acceptance is an append-only record containing the account-holder and recipient identifiers, hashed delivery token, Recipient Terms version, affirmative adult attestation and timestamp, acceptance and server-record timestamps, and IP address. These records cannot be edited or deleted through the normal account or recipient deletion process, currently survive those deletions, and currently have no scheduled expiration. We retain them as evidence of the adult-only access decision and agreement, and to protect the service and resolve disputes.
- Guardian acceptance records: Each guardian acceptance of a guardian invitation is an append-only record containing the guardian and inviting account-holder identifiers, a one-way hash of the guardian onboarding token, the acceptance timestamp, the guardian acceptance wording version, a one-way hash of the acceptance wording shown, the Privacy Policy version in effect at that time, and — for guardians who accepted on or after August 29, 2026 — the guardian's affirmative 18-or-older (adult) attestation together with the time it was recorded. Guardian records created before that date do not carry that attestation and we do not add it retroactively. No name, email address, phone number, IP address, or browser User-Agent is stored in this record, and the raw onboarding token is not stored. These records are append-only and are never hard-deleted, but they are not left untouched by deletion: when the associated account or guardian is deleted, the normal deletion process automatically severs the record's attribution in the same operation — the guardian and account identifiers and the one-way onboarding-token hash are set to null and an erasure marker is recorded — while the acceptance evidence (the acceptance and Privacy Policy versions, the one-way hash of the acceptance wording, the acceptance timestamp, and — for records created on or after August 29, 2026 — the adult-attestation flag and its timestamp) is preserved and remains immutable. These records currently have no scheduled expiration; what is retained after deletion is pseudonymized evidence rather than contact information. We retain them as evidence that the guardian affirmatively accepted the guardian role and the wording shown to them, and to protect the service and resolve disputes. Our legal basis is our legitimate interest in evidencing that acceptance and in establishing, exercising, or defending legal claims (Art. 6(1)(f)), balanced against the guardian's rights. A guardian may request a copy of their acceptance record, or ask us to erase it, as described in Section 11 and Section 13.
- Subscription and automatic-renewal records: We keep an append-only ledger of subscription lifecycle events — purchase, renewal, cancellation, expiration, transfer, and billing issue — received from our payment processor (RevenueCat) and the app stores, together with the version and a one-way content hash of the automatic-renewal disclosure shown to you at purchase, and, where we send you automatic-renewal notices, delivery evidence for those notices. We retain these records to comply with automatic renewal laws (including California's Automatic Renewal Law, Bus. & Prof. Code §17600 et seq.), which require us to keep subscription and consent verification for at least the greater of three years, or one year after the subscription terminates; our retention floor is a minimum of four years after the last lifecycle or termination event. These records are append-only and are never hard-deleted, but they are not left untouched by deletion: when the associated account is deleted, the normal deletion process automatically severs the record's attribution in the same operation — the direct identifiers are unlinked (set to null) and an erasure marker is recorded — while the timestamps, the disclosure versions, and the one-way content hashes are preserved and remain immutable. We do not retain plaintext contact details (email address or phone number) in this post-erasure legal-hold record; what is retained after deletion is pseudonymized evidence rather than contact information, exactly as guardian acceptance evidence is. Our legal basis is compliance with a legal obligation (Art. 6(1)(c)) and our legitimate interest in establishing, exercising, or defending legal claims (Art. 6(1)(f)), balanced against your rights. You may request a copy of your subscription and automatic-renewal record, as described in Section 11 and Section 13.
Delivered message content (text, audio, video, photos) is retained for up to 12 months from the delivery date to ensure recipients have adequate time to access and save their messages. After this period, all message content is permanently and irreversibly deleted from our servers. For delivered Life Story chapters, the recipient's access link expires after 12 months; a minimal delivery record that the chapter was delivered to that recipient is kept after that, and is removed when the chapter, the recipient, or the account is deleted. The owner's chapter remains subject to the account retention policy.
13. Your Rights
- Access: Request a copy of your data
- Deletion: Delete your account and data via our data deletion page. A small number of records identified in Section 12 — including account-holder consent records, Recipient Terms and adult-attestation records, guardian acceptance records, subscription and automatic-renewal records, SMS suppression entries, operator access logs, and deletion tombstones — are retained after deletion on the terms described there
- Correction: Update inaccurate personal information
- Portability: Export your data in a standard format. On request, a data-subject access export includes your subscription and automatic-renewal records — the retained lifecycle timestamps, disclosure versions, and one-way content hashes described in Section 12
EU/EEA Residents (GDPR)
You have rights under Articles 15–22 of the GDPR, including the right to access, rectification, erasure, restriction of processing, data portability, and objection. Contact us to exercise these rights. We aim to respond to verified requests within 30 days, and in any case within the time required by applicable law.
You have the right to withdraw your consent at any time (Art. 13(2)(c)). You also have the right to lodge a complaint with your supervisory authority (Art. 13(2)(d)).
Where we rely on legitimate interest (Art. 6(1)(f)) — for example, when processing guardian and recipient contact data to operate the verification cascade, and when keeping guardian acceptance and recipient acceptance records as evidence of an affirmative acceptance and for the establishment, exercise, or defense of legal claims — we have balanced that interest against your rights and freedoms (Art. 13(1)(d)).
Whether provision of data is statutory or contractual: providing account and recipient data is necessary to use the service; not providing it means we cannot deliver active messages or Life Story chapters selected for recipients (Art. 13(2)(e)).
Legal basis per processing activity:
| Processing Activity | Legal Basis |
|---|---|
| Account management | Art. 6(1)(b) — Performance of contract |
| Message storage and delivery | Art. 6(1)(b) — Performance of contract |
| Guardian contact processing (third-party data) | Art. 6(1)(f) — Legitimate interest (enabling the verification cascade to prevent false-positive message delivery) |
| Guardian acceptance evidence (append-only acceptance record) | Art. 6(1)(f) — Legitimate interest (evidencing the guardian's affirmative acceptance and establishing, exercising, or defending legal claims) |
| Push notification delivery | Art. 6(1)(b) — Performance of contract |
| Service improvement and bug fixing | Art. 6(1)(f) — Legitimate interest |
| Legal compliance (audit logs, tombstones) | Art. 6(1)(c) — Legal obligation |
| Tribute IP address collection | Art. 6(1)(f) — Legitimate interest (abuse prevention) |
United Kingdom Residents (UK GDPR)
You have the same core rights as EU/EEA residents under the UK GDPR, including access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
California Residents (CCPA/CPRA)
You have the right to know, delete, correct, and opt-out of the sale or sharing of personal information. We do not sell or share personal information. LastFlare does not use personal information for cross-context behavioral advertising.
Notice at collection is provided in Section 2. Categories of sources: you (directly), and people who invite you as a guardian or recipient. Third parties who process data on our behalf are listed in Section 5. The right to limit sensitive personal information is addressed in Section 9.
We offer no financial incentives or price differences in exchange for the retention or sale of personal information.
To submit a rights request, email [email protected] or use our data deletion page. Authorized agents may submit requests on your behalf with proof of authorization.
Australia Residents (Privacy Act / APPs)
You have the right to access and correct your personal information under the Australian Privacy Principles. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). Cross-border disclosure is handled under APP 8 (see Section 5).
Singapore Residents (PDPA)
You have the right to access, correct, and withdraw consent to the processing of your personal data under the Personal Data Protection Act (PDPA). Our Data Protection Officer can be reached at [email protected]. Transfer-limitation obligations are addressed in Section 5.
General contact for rights requests: [email protected]
14. Operator Access and Audit Logging
Nimbus Foundry may access user data during manual review stages of the verification cascade (e.g., when automated verification is inconclusive). These access events are logged in an immutable audit log (operator_access_log).
After account deletion, the structured user identifier in the operator access log is set to NULL and the audit trail is preserved. The access record itself persists, and limited free-text operational context an operator recorded may remain with it.
15. Children's Privacy
LastFlare is intended only for adults. Account holders and recipients who access private content must be at least 18 years old. The recipient viewer presents a separate, unchecked 18-or-older attestation and an "I am under 18" route. Selecting the under-18 route blocks content from being revealed and does not record acceptance of the Recipient Terms or an adult attestation. A guardian invited to help confirm someone's wellbeing must likewise affirm that they are at least 18 years old before they can accept the guardian role, and that affirmation is stored as part of the guardian acceptance record described above.
An account holder may nevertheless have provided us with contact information about an under-18 recipient, and a request made with a valid recipient link may update the link's request count and last-access timestamp before the visitor reaches the age decision. We do not intentionally offer private-content access to people under 18. If you believe we hold information about someone under 18, contact [email protected] so we can investigate and take action required by applicable law.
16. Cookies and Local Storage
- Authentication session cookies (httpOnly, secure)
- Preview access cookie (lastflare_preview_auth — httpOnly, secure, 7-day expiration)
- We do not use third-party tracking cookies or advertising pixels
- Plausible Analytics is cookieless, uses no browser storage, and is limited to the reviewed public pages described in Section 2
17. Changes to This Policy
We will notify you of material changes by posting the revised Policy on our website and in the app with a revised Effective Date, and by email where an email channel is available, before they take effect, giving you the opportunity to review them and, if you disagree, to close your account before the changes apply.
Last updated: August 14, 2026
18. App Store and Play Store Privacy Labels
LastFlare's data practices are declared in the Apple App Store privacy nutrition labels and Google Play Data Safety section. The categories declared include: contact information, user identifiers, user content (messages, Life Story chapters, photos, videos, and audio you create), financial information (subscription/purchase data via the app stores), usage data, diagnostics and crash data, and optional coarse location (chapter location tags). Our in-store declarations are kept consistent with this policy; the authoritative, current declarations are in the respective store listings.
19. Contact Us
General inquiries: [email protected]
Data protection / privacy contact (including our Singapore PDPA Data Protection Officer): [email protected]
You can also delete your account directly in the app under Settings → Delete Account, or via our data deletion page.
Nimbus Foundry, LLC
7345 W Sand Lake Rd, Ste 210, Office 3903, Orlando, FL 32819, United States