Legal
Privacy Policy
Effective date: June 18, 2026
1. Introduction
"SaveMyVibe" is the operator of this service. Contact: hello@savemyvibe.com
2. What We Collect
| Data | Purpose |
|---|---|
| Email address | Account creation, OTP authentication, service alerts, billing receipts |
| Session cookies | Keeping you logged in |
| Backup metadata | Original filename, file size, upload timestamp, S3 storage key |
| Archive settings | Retention policy, expected upload interval, alert preferences |
| Token metadata | Token names, scopes, expiry dates, last used timestamps |
| Billing data | Polar customer ID, checkout status, plan assignment |
| IP address | Recorded with each upload for security and rate limiting |
| Server logs | Standard HTTP request logs for debugging and security |
3. What We Do NOT Do
- No analytics or tracking. We do not use Google Analytics, Plausible, or any tracking pixels.
- No password storage. Authentication is passwordless OTP.
- No file content inspection. We store your backup files on infrastructure we control. We do not read, inspect, or analyze the content of your files except as necessary to provide the service (e.g., streaming during upload, generating download URLs, or as required by law).
- No third-party ad networks.
4. How We Use Data
- Provide the backup hosting service
- Authenticate you via OTP and maintain your session
- Send missed-backup alerts
- Process subscriptions via Polar.sh
- Detect and prevent abuse
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Backup files | Per-archive policy: 30 days (Free) / 1 year (Pro), plus minimum surviving copies |
| Account & metadata | Until account deletion |
| Deleted backups | Permanently removed from S3 upon retention deletion or archive deletion |
| Deleted account | All personal data and backups removed within 30 days |
| Server logs | 90 days |
| OTP records | Deleted after verification or expiry |
| Billing records | 7 years (tax/legal obligation) |
6. Third-Party Processors
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Polar.sh | Subscription billing | Email, plan selection, checkout status | EU/US |
| Hetzner Object Storage | File storage | Backup files (encrypted in transit and at rest) | EU (Germany) |
7. Cookies
We use essential cookies only for session authentication:
access_token— 24 hoursrefresh_token— 7 days
Both are Secure, HttpOnly, and SameSite=Lax in production. No tracking cookies. We use essential cookies for authentication. No consent required.
8. Your Rights
- Access — request a copy of data we hold about you
- Rectification — update your email or archive settings
- Erasure — delete your account; all data permanently removed
- Export — download all your data (coming soon via app settings)
9. Security
- HTTPS/TLS for all communications
- Archive tokens are bcrypt-hashed; plaintext never stored
- S3 storage uses provider-standard encryption at rest
- No malware scanning in MVP (users must ensure uploaded content is lawful)
10. International Transfers
Primary storage is in the EU (Hetzner, Germany). Billing processor Polar.sh may process data in the EU and US under Standard Contractual Clauses.
11. Changes to This Policy
We may update this policy. Material changes will be notified via email. Continued use constitutes acceptance.