Privacy Policy

Last Updated: March 19, 2026

Your Privacy is Our Priority

LastingNote is designed with privacy at its core. We use end-to-end encryption to ensure your messages remain private and secure. This privacy policy explains how we handle your information.

Information We Collect

Account Information

  • Email address (used for account identification and check-in reminders)
  • Your name (optional, for personalization)
  • Password (cryptographically hashed and never stored in plain text)
  • Recovery phrase (generated locally, never transmitted to our servers)

Message Data

  • Encrypted message content (we cannot read your messages)
  • Recipient email addresses (encrypted)
  • Delivery settings and preferences
  • Check-in history and timestamps
  • File attachments (encrypted)

Technical Information

  • IP address (for security and fraud prevention)
  • Device type and browser information
  • Log data (access times, error logs for debugging)

How We Use Your Information

We use the information we collect to:

  • Provide and maintain the LastingNote service
  • Send check-in reminders via email or SMS
  • Deliver your messages when your check-in window passes
  • Authenticate your identity and secure your account
  • Comply with legal obligations
  • Prevent fraud and abuse

Encryption & Security

Guardian Mode

In Guardian Mode, your messages are protected with keys that only you control. Not even we can access your messages. Your Trusted Guardian is the only person who can authorize message delivery.

Automatic Mode

In Automatic Mode, messages are protected with server-managed keys to ensure reliable automatic delivery. Your messages are delivered automatically to your recipients when your check-in window passes. This is the same level of protection used by leading messaging apps (WhatsApp, Telegram, etc.).

Security Measures

  • Industry-standard encryption (ChaCha20-Poly1305)
  • Secure password hashing (Argon2id)
  • Regular security audits and updates
  • Encrypted data transmission (HTTPS/TLS)
  • No employee access to user data

Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may share data only in these limited circumstances:

  • Service Providers: Email delivery (MailPace), SMS delivery (Twilio), cloud hosting (Supabase)
  • Legal Requirements: When required by law, court order, or government request
  • Safety & Security: To protect against fraud, abuse, or security threats
  • Business Transfers: In case of merger, acquisition, or sale of assets (you will be notified)

In Guardian Mode, your message content cannot be shared because we do not have the ability to access it.

Data Retention

  • Active account data is retained while your account is active
  • Messages are deleted after successful delivery to recipients
  • Check-in history is retained for up to 12 months
  • Deleted accounts are permanently removed within 30 days
  • Backups may retain data for up to 90 days for disaster recovery

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and data
  • Export your data (where technically feasible)
  • Opt-out of marketing communications
  • Withdraw consent for data processing

To exercise these rights, contact us at info@lastingnote.me

Cookies & Tracking

We use minimal cookies and tracking technologies:

  • Essential Cookies: Required for authentication and session management
  • Analytics: We do not use third-party analytics or tracking
  • Local Storage: Used for app functionality and encrypted session data

International Users

LastingNote is operated from the United States. If you are accessing our service from outside the U.S., your information may be transferred to, stored, and processed in the U.S. By using LastingNote, you consent to this transfer.

For users in the European Union, we comply with GDPR requirements and provide appropriate safeguards for international data transfers.

Children's Privacy

LastingNote is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the service. Your continued use of LastingNote after changes become effective constitutes acceptance of the revised policy.

Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

  • Email: info@lastingnote.me
  • Support: support@lastingnote.me