Legal
Privacy Policy
Last updated: July 19, 2026
This Privacy Policy explains what information Timeless Messages ("we", "us") collects, how we use it, and the choices you have. If anything below is unclear, email hello@timelessmessages.org.
Information we collect
- Account information — your email address, name, and password hash when you sign up. If you sign in with Google, we receive your email and basic profile from Google.
- Memorial content — the videos, photos, names, dates, and biographical text you upload for a memorial.
- Payment information — when you purchase a package, Stripe processes your card. We store the order (package, amount, status) but never see your full card number.
- Analytics — when someone views a public memorial page, we record an anonymous view event (timestamp, coarse location, referrer) so the memorial's owner can see engagement.
- Technical logs — standard server logs (IP address, user agent, request path) kept for security and debugging.
How we use it
- To operate the Service: host your memorial, display it at the public URL you choose, generate QR codes.
- To communicate with you about your account, orders, and important service changes.
- To provide the paid production packages you purchase.
- To improve reliability, prevent abuse, and comply with legal obligations.
We do not sell your personal information. We do not use your memorial videos to train AI models.
Who we share it with
We share limited information with the service providers we rely on to run Timeless Messages ("subprocessors"):
- Lovable Cloud / Supabase — database, authentication, and file storage.
- Stripe — payment processing for package purchases.
- Lovable Email — sending transactional email (confirmations, order updates).
- Cloudflare — hosting and content delivery.
Each subprocessor has access only to the data it needs to perform its function and is bound by confidentiality obligations. We may also disclose information if required by law.
Public memorial pages
A memorial page is public only if you publish it. Anyone with the link (or who scans the QR code) can view a published memorial's video, photos, and biographical text. If you keep a memorial unpublished, only you can view it. You can unpublish a memorial at any time from your dashboard.
Cookies
We use a small number of cookies to keep you signed in and to remember your preferences. We do not use third-party advertising cookies.
Retention
We keep account information and memorial content as long as your account is active. If you delete a memorial, we remove it from public view immediately and purge it from our storage within 30 days (backups may retain copies for up to 90 days). If you close your account, we delete your data within 30 days, except records we are legally required to keep (for example, payment records for tax purposes).
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, and to object to certain uses of it. Email hello@timelessmessages.org to make a request; we'll respond within 30 days.
Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13.
International transfers
Our subprocessors may store or process data in the United States and other countries. Where required, we rely on standard contractual clauses to protect transfers of personal information out of your region.
Security
We use industry-standard measures to protect your information — encrypted connections, access controls, and least-privilege database policies. No system is perfectly secure, but if we ever discover a breach affecting your data, we will notify you promptly.
Changes
We may update this Policy from time to time. If we make a material change, we'll notify you by email or in-app before it takes effect.
Contact
Privacy questions? Email hello@timelessmessages.org.
This page describes our general practices and is not legal advice. Have a lawyer review a privacy policy before relying on it for regulatory compliance (GDPR, CCPA, etc.).