Legal

Privacy Policy

Effective date: June 18, 2026

1. Introduction

"SaveMyVibe" is the operator of this service. Contact: hello@savemyvibe.com

2. What We Collect

DataPurpose
Email addressAccount creation, OTP authentication, service alerts, billing receipts
Session cookiesKeeping you logged in
Backup metadataOriginal filename, file size, upload timestamp, S3 storage key
Archive settingsRetention policy, expected upload interval, alert preferences
Token metadataToken names, scopes, expiry dates, last used timestamps
Billing dataPolar customer ID, checkout status, plan assignment
IP addressRecorded with each upload for security and rate limiting
Server logsStandard HTTP request logs for debugging and security

3. What We Do NOT Do

  • No analytics or tracking. We do not use Google Analytics, Plausible, or any tracking pixels.
  • No password storage. Authentication is passwordless OTP.
  • No file content inspection. We store your backup files on infrastructure we control. We do not read, inspect, or analyze the content of your files except as necessary to provide the service (e.g., streaming during upload, generating download URLs, or as required by law).
  • No third-party ad networks.

4. How We Use Data

  • Provide the backup hosting service
  • Authenticate you via OTP and maintain your session
  • Send missed-backup alerts
  • Process subscriptions via Polar.sh
  • Detect and prevent abuse

5. Data Retention

Data TypeRetention Period
Backup filesPer-archive policy: 30 days (Free) / 1 year (Pro), plus minimum surviving copies
Account & metadataUntil account deletion
Deleted backupsPermanently removed from S3 upon retention deletion or archive deletion
Deleted accountAll personal data and backups removed within 30 days
Server logs90 days
OTP recordsDeleted after verification or expiry
Billing records7 years (tax/legal obligation)

6. Third-Party Processors

ServicePurposeData SharedLocation
Polar.shSubscription billingEmail, plan selection, checkout statusEU/US
Hetzner Object StorageFile storageBackup files (encrypted in transit and at rest)EU (Germany)

7. Cookies

We use essential cookies only for session authentication:

  • access_token — 24 hours
  • refresh_token — 7 days

Both are Secure, HttpOnly, and SameSite=Lax in production. No tracking cookies. We use essential cookies for authentication. No consent required.

8. Your Rights

  • Access — request a copy of data we hold about you
  • Rectification — update your email or archive settings
  • Erasure — delete your account; all data permanently removed
  • Export — download all your data (coming soon via app settings)

9. Security

  • HTTPS/TLS for all communications
  • Archive tokens are bcrypt-hashed; plaintext never stored
  • S3 storage uses provider-standard encryption at rest
  • No malware scanning in MVP (users must ensure uploaded content is lawful)

10. International Transfers

Primary storage is in the EU (Hetzner, Germany). Billing processor Polar.sh may process data in the EU and US under Standard Contractual Clauses.

11. Changes to This Policy

We may update this policy. Material changes will be notified via email. Continued use constitutes acceptance.