Skip to content

Privacy Policy

Effective Date: August 14, 2026

1. Introduction

LastFlare is a private-content and check-in application operated by Nimbus Foundry, LLC ("we," "us," or "our"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our service.

If you have questions about this policy, contact us at [email protected].

2. Information We Collect

Account and Profile

Subscription and Purchase Records

Check-in Schedule and Activity

Messages and Media

Recipients (Third-Party Contacts)

Guardians (Third-Party Contacts)

Device Information

Website Analytics (Public Pages Only)

Life Story / Memorial Profile

Tribute Wall Submissions (Third Party)

Switches

Notifications

Delivery Link Logging

Security and Audit

3. How We Use Your Information

4. How We Store and Protect Your Data

5. Sub-Processors and International Data Transfers

We share data with the following sub-processors only as necessary to operate the service:

ProviderPurposeData SharedCountryDPA & Transfer Mechanism
SupabaseAuthentication, databaseEmail, hashed password, user dataUSADPA at supabase.com/privacy; EU SCCs, UK IDTA/Addendum
DigitalOceanMedia storage, hostingEncrypted media files, application dataUSADPA at digitalocean.com/legal/data-processing-agreement; EU SCCs, UK IDTA/Addendum
TwilioSMS deliveryPhone numbers, message contentUSADPA at twilio.com/en-us/legal/data-protection-addendum; EU SCCs, UK IDTA/Addendum
PlivoSMS delivery (failback)Phone numbers, message contentUSADPA via Plivo DPA; EU SCCs, UK IDTA/Addendum
Postmark (ActiveCampaign, LLC)Transactional emailEmail addresses, email contentUSADPA at postmarkapp.com/gdpr; EU SCCs, UK IDTA/Addendum
Firebase (Google)Android push notificationsDevice tokens, notification payloadUSAGoogle Cloud DPA; EU SCCs, UK IDTA/Addendum
Apple (APNs)iOS push notificationsDevice tokens, notification payloadUSAApple DPA; EU SCCs, UK IDTA/Addendum
RevenueCatSubscription managementUser ID, purchase dataUSARevenueCat DPA; EU SCCs, UK IDTA/Addendum
SentryError monitoring & crash reportingDevice info, stack traces, user ID where presentUSADPA at sentry.io/legal/dpa; EU SCCs, UK IDTA/Addendum
Better Stack (Logtail)Log management & observabilityApplication logs (may include identifiers in request paths)Germany (EU)Better Stack DPA; processed within the EU
TallyFeedback / survey formsFeedback you submitBelgium (EU)Tally DPA; processed within the EU
Plausible AnalyticsCookieless website analyticsSanitized page path and referrer, browser/device data; coarse location derived from IPEstonia / Germany (EU)DPA at plausible.io/dpa; visitor data processed within the EU

Data processing agreements and appropriate transfer mechanisms are executed with each sub-processor listed above.

Where data is transferred out of your region, we rely on appropriate safeguards: EU/EEA transfers under the EU Standard Contractual Clauses; UK transfers under the UK International Data Transfer Agreement / Addendum; Australian transfers under APP 8 cross-border accountability. We do not rely on your consent as a transfer mechanism.

Your personal information may be stored or processed in the United States and the European Union (Germany and Belgium).

For users in Singapore, we take reasonable steps to ensure overseas recipients of your personal data provide a standard of protection comparable to the Singapore PDPA.

Each provider processes data under their own privacy policy.

6. SMS/Text Messaging

What we send: Where SMS functionality is enabled, LastFlare may process a mobile phone number and send SMS/text messages for check-in reminders, account verification, and service notifications related to your messaging and check-in schedule. SMS is only used where the applicable consent and messaging requirements have been satisfied.

Opt-in: Where SMS is enabled, you opt in to receive SMS messages when you provide your phone number in the app and enable SMS-based check-in reminders. Consent is not a condition of purchase. You may use the app with push notifications only.

Guardian SMS consent: Where guardian SMS is enabled, guardians you invite receive an email invitation and must affirmatively opt in before we send them any SMS. Verification text messages are only sent to guardians who have confirmed their SMS opt-in.

Message frequency: Message frequency varies based on your check-in schedule and account activity. You control the frequency by setting your own check-in intervals.

Message and data rates: Message and data rates may apply. Check with your mobile carrier for details.

Opt-out: You can opt out of SMS messages at any time by replying STOP to any message from LastFlare, or by disabling SMS notifications in your account settings. After opting out, you will receive a one-time confirmation message and no further SMS messages.

Help: Reply HELP to any message from LastFlare for assistance, or contact [email protected].

Carriers: Supported carriers include but are not limited to AT&T, Verizon, T-Mobile, and other major US carriers. Guardians and recipients may be located outside the United States; carrier support varies by country. Carrier participation may change without notice.

No SMS data sharing: We do not sell, rent, or share your phone number or SMS opt-in data with third parties for their marketing purposes. SMS consent and phone numbers are used solely for delivering the LastFlare service.

A2P opt-in retention: We retain a record of SMS opt-in consent for as long as required to evidence compliance with applicable messaging regulations (A2P 10DLC / TCPA).

7. Private Content Delivery

8. Posthumous and Incapacity Delivery

LastFlare is designed to store messages and Life Story chapters for potential delivery after the account holder has passed, is incapacitated, or is otherwise unreachable. This is a non-standard data processing scenario. This private content may remain stored for months or years before delivery is triggered.

Users acknowledge this use case when they set up their check-in schedule and message recipients. Encryption and access controls remain active during the entire storage period.

9. Sensitive Information

Because LastFlare supports end-of-life and incapacity planning, some information you provide — including message content and a guardian's response about an account holder's wellbeing — can be personal or sensitive, and in some U.S. states it may fall within "consumer health data" as defined by laws such as Washington's My Health My Data Act. We process this information only as necessary to provide the service you have requested — to store your messages and to make the check-in and delivery decisions you set up — and for no secondary purpose. We do not use it for advertising or profiling, we do not sell it, and we do not share it with third parties for their own purposes; where we deliver it, it goes only to the recipients you designate. Where this information is consumer health data, we handle it as described in our Consumer Health Data Privacy Policy, which explains the categories we process, why, who receives it, and how to exercise your rights. California residents have the right to limit the use of sensitive personal information; because we already restrict our use to providing the service, no additional limitation request is necessary, but you may contact us at [email protected].

10. Automated Decision-Making and the Verification Cascade

LastFlare uses an automated verification cascade to decide when to deliver your active messages and Life Story chapters selected for recipients. If you miss a check-in, the system automatically progresses through escalating reminders and guardian verification. An affirmative guardian threshold can move eligible content into a final warning period. If the threshold is not met, valid automatic- delivery consent can do the same; otherwise the case is routed to operator review. An operator may dismiss the case or authorize it to enter that same final warning period used by other cascade paths — you receive a final cancel notice and a grace window before any content is delivered — unless a current owner stop request blocks manual delivery.

You set thresholds such as how many guardians must confirm. Before sharing begins, available check-in and cancellation controls may halt the cascade. Once sharing begins, available cancellation controls may stop content not yet sent or record a stop request for review, but cannot recall content already delivered. Pausing is not available during every cascade state. If you have questions about this process or wish to intervene, contact us at [email protected].

11. Notice to Guardians, Recipients, and Tribute Authors

If someone has named you as a recipient or guardian, LastFlare processes your personal information (such as your name, contact details, and relationship) because a LastFlare user provided it to enable our check-in and private-content delivery service. We obtained your information from that user. We use it only to operate the service (for example, to deliver a message or a Life Story chapter selected for that recipient, or to ask a guardian to confirm a check-in) and we rely on our legitimate interest in operating a reliable check-in service, balanced against your rights, as our legal basis for processing guardian and recipient contact data. You have the same rights described in Section 13 (including access, correction, and erasure) and may exercise them by contacting [email protected]. Invitations we send on a user's behalf include a link to this Privacy Policy.

If you left a tribute on a public memorial, we collected your information directly from you when you submitted it — the name and email address you provided, the tribute content you wrote, and the IP address you submitted it from (recorded to help prevent abuse). Each tribute is reviewed by the memorial's owner before it appears, and a tribute the owner approves — including the submitted name and content — is shown publicly on the memorial page. We rely on our legitimate interest in operating a memorial tribute wall and preventing abuse. You have the rights described in Section 13 and may exercise them by contacting [email protected].

If you accepted an invitation as a guardian, or accepted the Recipient Terms as a recipient, we keep an append-only record of that acceptance as described in Section 12. A guardian acceptance record holds internal identifiers, hashes, versions, timestamps, and, for guardians who accepted on or after August 29, 2026, the guardian's affirmative 18-or-older (adult) attestation and the time it was recorded; guardian records created before that date do not carry that attestation, and we do not add it retroactively. It contains no name, email address, phone number, IP address, or browser User-Agent. A recipient acceptance record holds the same internal identifiers, hashes, versions, and timestamps, additionally records the recipient's affirmative 18-or-older (adult) attestation and its timestamp, and additionally records the request IP address described in Section 2. Both are kept separately from your contact details, so they remain after the contact details are erased — and, for the guardian acceptance record, that deletion also automatically severs its attribution (its identifiers are set to null), as described in Section 12. You may ask us for a copy of either acceptance record. You may also ask us to erase a guardian acceptance record: we will do so by severing its attribution (as described above and in Section 12) unless we still need it to establish, exercise, or defend a legal claim, and we record an audit entry when we do. A recipient acceptance record is an append-only record of an adult-only access decision that we retain on the legitimate-interest and legal-claim basis described in Sections 12 and 13; it cannot be edited or deleted through this process, so we do not erase it on request. Contact [email protected] to make either request.

A recipient accesses the private-content viewer as an accountless visitor; receiving or opening a link does not create a LastFlare account. Before content is revealed, the viewer is limited to adults and requires the visitor to affirm that they are at least 18 and accept the current Recipient Terms. Because the link is a bearer credential, LastFlare does not independently verify that the person using it is the named recipient. Keep recipient links private and contact us if a link has reached the wrong person.

12. Data Retention

Delivered message content (text, audio, video, photos) is retained for up to 12 months from the delivery date to ensure recipients have adequate time to access and save their messages. After this period, all message content is permanently and irreversibly deleted from our servers. For delivered Life Story chapters, the recipient's access link expires after 12 months; a minimal delivery record that the chapter was delivered to that recipient is kept after that, and is removed when the chapter, the recipient, or the account is deleted. The owner's chapter remains subject to the account retention policy.

13. Your Rights

EU/EEA Residents (GDPR)

You have rights under Articles 15–22 of the GDPR, including the right to access, rectification, erasure, restriction of processing, data portability, and objection. Contact us to exercise these rights. We aim to respond to verified requests within 30 days, and in any case within the time required by applicable law.

You have the right to withdraw your consent at any time (Art. 13(2)(c)). You also have the right to lodge a complaint with your supervisory authority (Art. 13(2)(d)).

Where we rely on legitimate interest (Art. 6(1)(f)) — for example, when processing guardian and recipient contact data to operate the verification cascade, and when keeping guardian acceptance and recipient acceptance records as evidence of an affirmative acceptance and for the establishment, exercise, or defense of legal claims — we have balanced that interest against your rights and freedoms (Art. 13(1)(d)).

Whether provision of data is statutory or contractual: providing account and recipient data is necessary to use the service; not providing it means we cannot deliver active messages or Life Story chapters selected for recipients (Art. 13(2)(e)).

Legal basis per processing activity:

Processing ActivityLegal Basis
Account managementArt. 6(1)(b) — Performance of contract
Message storage and deliveryArt. 6(1)(b) — Performance of contract
Guardian contact processing (third-party data)Art. 6(1)(f) — Legitimate interest (enabling the verification cascade to prevent false-positive message delivery)
Guardian acceptance evidence (append-only acceptance record)Art. 6(1)(f) — Legitimate interest (evidencing the guardian's affirmative acceptance and establishing, exercising, or defending legal claims)
Push notification deliveryArt. 6(1)(b) — Performance of contract
Service improvement and bug fixingArt. 6(1)(f) — Legitimate interest
Legal compliance (audit logs, tombstones)Art. 6(1)(c) — Legal obligation
Tribute IP address collectionArt. 6(1)(f) — Legitimate interest (abuse prevention)

United Kingdom Residents (UK GDPR)

You have the same core rights as EU/EEA residents under the UK GDPR, including access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

California Residents (CCPA/CPRA)

You have the right to know, delete, correct, and opt-out of the sale or sharing of personal information. We do not sell or share personal information. LastFlare does not use personal information for cross-context behavioral advertising.

Notice at collection is provided in Section 2. Categories of sources: you (directly), and people who invite you as a guardian or recipient. Third parties who process data on our behalf are listed in Section 5. The right to limit sensitive personal information is addressed in Section 9.

We offer no financial incentives or price differences in exchange for the retention or sale of personal information.

To submit a rights request, email [email protected] or use our data deletion page. Authorized agents may submit requests on your behalf with proof of authorization.

Australia Residents (Privacy Act / APPs)

You have the right to access and correct your personal information under the Australian Privacy Principles. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). Cross-border disclosure is handled under APP 8 (see Section 5).

Singapore Residents (PDPA)

You have the right to access, correct, and withdraw consent to the processing of your personal data under the Personal Data Protection Act (PDPA). Our Data Protection Officer can be reached at [email protected]. Transfer-limitation obligations are addressed in Section 5.

General contact for rights requests: [email protected]

14. Operator Access and Audit Logging

Nimbus Foundry may access user data during manual review stages of the verification cascade (e.g., when automated verification is inconclusive). These access events are logged in an immutable audit log (operator_access_log).

After account deletion, the structured user identifier in the operator access log is set to NULL and the audit trail is preserved. The access record itself persists, and limited free-text operational context an operator recorded may remain with it.

15. Children's Privacy

LastFlare is intended only for adults. Account holders and recipients who access private content must be at least 18 years old. The recipient viewer presents a separate, unchecked 18-or-older attestation and an "I am under 18" route. Selecting the under-18 route blocks content from being revealed and does not record acceptance of the Recipient Terms or an adult attestation. A guardian invited to help confirm someone's wellbeing must likewise affirm that they are at least 18 years old before they can accept the guardian role, and that affirmation is stored as part of the guardian acceptance record described above.

An account holder may nevertheless have provided us with contact information about an under-18 recipient, and a request made with a valid recipient link may update the link's request count and last-access timestamp before the visitor reaches the age decision. We do not intentionally offer private-content access to people under 18. If you believe we hold information about someone under 18, contact [email protected] so we can investigate and take action required by applicable law.

16. Cookies and Local Storage

17. Changes to This Policy

We will notify you of material changes by posting the revised Policy on our website and in the app with a revised Effective Date, and by email where an email channel is available, before they take effect, giving you the opportunity to review them and, if you disagree, to close your account before the changes apply.

Last updated: August 14, 2026

18. App Store and Play Store Privacy Labels

LastFlare's data practices are declared in the Apple App Store privacy nutrition labels and Google Play Data Safety section. The categories declared include: contact information, user identifiers, user content (messages, Life Story chapters, photos, videos, and audio you create), financial information (subscription/purchase data via the app stores), usage data, diagnostics and crash data, and optional coarse location (chapter location tags). Our in-store declarations are kept consistent with this policy; the authoritative, current declarations are in the respective store listings.

19. Contact Us

General inquiries: [email protected]

Data protection / privacy contact (including our Singapore PDPA Data Protection Officer): [email protected]

You can also delete your account directly in the app under Settings → Delete Account, or via our data deletion page.

Nimbus Foundry, LLC

7345 W Sand Lake Rd, Ste 210, Office 3903, Orlando, FL 32819, United States