This Privacy Policy explains how ALLLAST collects, uses, stores, shares, protects, and deletes personal data when you use the ALLLAST website, iOS application, accounts, message vault, recipient and trusted-contact workflows, verification features, support services, and related communications.
Operator / Data Controller: Mighty Adventist Company LimitedEffective date: 15 August 2026Last updated: 15 August 2026Version: 2.0
Important
ALLLAST is designed to handle highly personal material. This policy does not claim that every item is legally privileged, absolutely confidential, immune from lawful process, or technically inaccessible to ALLLAST. No online service can guarantee absolute security.
1. Scope and Data Controller
ALLLAST is operated by Mighty Adventist Company Limited (“ALLLAST,” “we,” “us,” or “our”). For personal data processed for ALLLAST’s own purposes, Mighty Adventist Company Limited acts as the data controller unless applicable law provides otherwise.
This policy applies to ALLLAST websites, mobile applications, account services, message and file storage, recipient and trusted-contact workflows, verification processes, customer support, purchase records, and operational communications.
Separate privacy terms may apply where a third party independently controls data, including Apple, payment processors, telecommunications providers, identity providers, or a government authority.
2. Personal Data We May Collect
Depending on the features you use, we may process:
Account and identity data: name, email address, user ID, authentication records, profile information, account status and settings.
Recipient and trusted-contact data: names, email addresses, phone numbers, relationship information, role, consent/acceptance status, verification status and communication records.
User content: text messages, letters, notes, images, photos, videos, audio, documents, file metadata, titles, instructions, delivery preferences and other content you choose to store.
Verification and trigger data: scheduled dates, inactivity/check-in status, confirmations, one-time links or codes, audit events, evidence submitted for verification, and records of decisions or escalations.
Purchase and entitlement data: product or plan, subscription/lifetime entitlement status, purchase identifiers, transaction references, renewal/cancellation status and purchase history necessary to provide paid features. We do not need your full payment-card number when payment is handled by Apple or another payment processor.
Technical and security data: IP address where available, device/browser information, app version, timestamps, session and authentication events, error logs, abuse/fraud indicators and security audit records.
Support and legal data: support messages, complaint details, account references, attachments you submit to support, and records needed to resolve disputes or comply with law.
Analytics data: limited usage or event data used to understand service reliability and product performance, where enabled and permitted by law.
3. How We Obtain Data
We obtain personal data directly from you, from people who nominate you as a Recipient or Trusted Contact, from your interaction with the Service, from payment and platform providers, and—where a verification feature expressly uses them—from lawful public records, authorised verification sources, or documents supplied by an authorised person.
We do not treat a public record or a third-party report as automatically conclusive. Verification may be delayed, rejected, escalated, or require additional evidence.
4. Why We Process Personal Data
We may process personal data for the following purposes and legal bases, depending on applicable law:
Purpose
Typical legal basis
Create and operate accounts; store and deliver configured content; provide paid features.
Performance of a contract or steps requested before entering a contract.
Contact Recipients and Trusted Contacts about invitations, verification, available content, delivery, refusal, preservation or recovery.
Contractual necessity, legitimate interests, consent where required, and/or another lawful basis available under local law.
Process optional marketing or non-essential communications.
Consent or another lawful basis permitted by local law.
Comply with tax, accounting, consumer, data-protection, court, law-enforcement and other legal requirements.
Legal obligation and/or legitimate interests in establishing, exercising or defending legal claims.
Improve performance, diagnose failures and understand aggregate use.
Legitimate interests and/or consent where required.
Where we rely on consent, you may withdraw it for future processing, subject to legal and operational consequences. Withdrawal does not make prior lawful processing unlawful.
5. Recipient, Trusted-Contact and Other Third-Party Data
Users may provide personal data about other people. The User is responsible for having a lawful basis to submit that data and for giving any notice or obtaining any consent required by law.
When a person accepts a Trusted Contact, co-validator, executor-related, Recipient, or similar role, ALLLAST may record that acceptance and use the person’s contact and verification data for that role. Acceptance of a role does not waive all privacy rights and does not authorise disclosure beyond the scope reasonably necessary for the accepted role, the User’s lawful instructions, and applicable law.
A Recipient or Trusted Contact may decline a role, refuse access, unsubscribe from non-essential communications, or ask us to stop future contact, subject to security, legal-hold, fraud-prevention, or other mandatory requirements.
6. Messages, Files, Sensitive Content and Verification Data
ALLLAST does not use private message content for unrelated advertising. Access to private Content is restricted and may occur only where technically possible and reasonably necessary for service operation, delivery, security, support requested by an authorised person, abuse investigation, backup/recovery, legal compliance, or another purpose disclosed to you.
Unless a feature is expressly documented as end-to-end encrypted or zero-access in binding product documentation, you must not assume that ALLLAST is technically incapable of accessing Content. Marketing wording does not override this policy.
You should not use ALLLAST as the only repository for irreplaceable legal originals, emergency instructions, passwords, private keys, or information that must be immediately available to prevent harm.
7. Optional Public Summary or Memorial Features
If ALLLAST offers a public-summary, memorial, announcement, or similar feature, it will be optional unless otherwise clearly disclosed. Where enabled by the Account Holder, ALLLAST may publish only the categories of information configured for that feature and only after the applicable release or verification process.
A User instruction to publish information does not override mandatory privacy, confidentiality, court, safety, or data-protection requirements. We may delay, restrict, redact, or refuse publication where disclosure is unlawful, disputed, unsafe, technically unsupported, or inconsistent with the User’s latest valid settings.
8. Free Content and Recipient Follow-Up
Free storage is not guaranteed permanent storage.
Where Content is stored without an active paid entitlement, ALLLAST may contact a designated Recipient after an applicable release condition to ask whether the Recipient wishes to receive/access the Content, decline it, request deletion where legally available, or purchase an optional preservation, verification, recovery or delivery service.
Such contact may explain that ALLLAST has incurred ongoing storage and operational costs. No Recipient is automatically charged. Any paid option, price, scope, identity checks and response deadline must be disclosed before purchase.
If the Recipient declines, asks not to be contacted, cannot be reached, or does not respond, ALLLAST may archive or delete Free Content under the retention rules below. We may retain minimal evidence of contact, refusal, consent, delivery or deletion where reasonably necessary for security, legal claims, compliance or audit purposes.
9. Payments, Subscriptions and In-App Purchases
Purchases made in the iOS app may be processed by Apple. Apple may provide ALLLAST with transaction and entitlement information necessary to unlock or maintain the purchased service. Apple independently processes payment information under Apple’s own terms and privacy practices.
Web purchases may be processed by a third-party payment provider. ALLLAST generally receives transaction status and related billing metadata rather than complete card credentials.
We retain purchase and entitlement records as needed to provide service, restore purchases, prevent fraud, handle disputes, comply with accounting/tax obligations and establish legal claims.
10. Analytics, Cookies and Similar Technologies
The website may use essential browser storage for authentication/session functions, preferences and security. The web service may also use analytics tools to understand aggregate usage and service performance.
The iOS app is not intended to use collected data to track a person across apps or websites owned by other companies for third-party advertising. ALLLAST does not use private message content for targeted advertising.
Where local law requires consent for non-essential analytics, cookies or similar technologies, we will request it or disable the relevant technology until consent is obtained.
11. Service Providers and Other Disclosures
We may disclose or make data available to service providers that perform functions for ALLLAST, such as authentication, database/storage, hosting, content delivery, email communications, payment processing, analytics, fraud prevention, customer support and infrastructure operations.
Current or intended providers may include Supabase for authentication/database/storage, Resend for transactional email, Apple for iOS distribution and in-app purchases, Stripe or another payment provider for web billing, and hosting/analytics infrastructure. Providers process data under their own terms and, where applicable, contractual obligations to ALLLAST.
We may also disclose information where reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate abuse or fraud, enforce agreements, or support a merger, financing, reorganisation, sale of assets or transfer of the Service, subject to applicable law.
12. International Data Transfers
ALLLAST and its service providers may process data in countries other than the country where you live. Data-protection laws may differ between countries. Where required, we use appropriate legal mechanisms and safeguards for international transfers.
13. Retention, Account Deletion and Content Deletion
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including providing configured delivery/preservation services, maintaining security, completing support requests, enforcing agreements, resolving disputes, and meeting legal, accounting and tax obligations.
Paid Content: may be retained while the applicable entitlement is active and for a reasonable period needed for delivery, recovery, account closure, legal hold or technical deletion cycles.
Free Content: may be subject to shorter, capacity-dependent retention. After a reasonable documented contact attempt, refusal or non-response, Free Content may be placed into a recovery window of up to 12 months where technically and operationally available. ALLLAST is not required to retain Free Content for the entire period and may delete it sooner for legal, security, technical, capacity or business reasons after reasonable notice where practicable.
Backups: deletion from active systems may take time to propagate to encrypted or rotated backups. Limited residual copies may remain until normal backup cycles complete or where preservation is required for security, legal hold, accounting or compliance.
Account deletion: authenticated users may use an available in-app account-deletion feature. If account access is unavailable, a request may be submitted through the official support channel. We may verify identity before processing a deletion request.
14. Your Privacy Rights
Subject to applicable law and exceptions, you may have rights to:
request access to personal data and information about its processing;
request correction of inaccurate or incomplete data;
request deletion or anonymisation where legal grounds apply;
request restriction of processing;
object to certain processing, including processing based on legitimate interests where applicable;
receive or transfer certain data in a portable format where applicable;
withdraw consent for future processing where processing depends on consent; and
submit a complaint to a competent data-protection authority.
We may request reasonable verification before fulfilling a rights request. Some requests may be limited where data must be retained for legal claims, fraud prevention, security, accounting, the rights of another person, or another lawful exception.
In Thailand, complaints regarding personal-data protection may be made to the Office of the Personal Data Protection Committee where applicable.
15. Security
We use administrative, technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Measures may include authenticated access, access controls, private storage configurations, encryption in transit and at rest where supported by the relevant infrastructure, logging, monitoring, backup controls and least-privilege practices.
No method of storage or transmission is completely secure. Users must protect their credentials, keep contact details current and notify ALLLAST promptly if they suspect unauthorised access.
16. Children
ALLLAST accounts and paid plans are intended for persons who are at least 18 years old and legally capable of entering a contract. A minor may be named as a Recipient only where permitted by law and where an authorised adult provides and manages the relevant information.
17. Advertising, Sale and Use of Private Content
ALLLAST does not sell private message content. ALLLAST does not use private message, video, document or audio content for third-party targeted advertising.
If ALLLAST later introduces a materially different advertising or data-use model, this policy and any required consent mechanisms must be updated before that processing begins.
18. Legal Requests, Complaints and Preservation
We may preserve, restrict, disclose or delete information in response to valid legal process or where reasonably necessary to protect rights, safety, Service integrity or legal claims. We may notify affected persons unless prohibited by law or where notification would create risk.
ALLLAST does not adjudicate complex inheritance, family, ownership, capacity or authority disputes. We may suspend release and require the parties to resolve a dispute through the appropriate authority or court.
19. Changes to This Policy
We may update this policy to reflect changes to features, providers, business practices or legal requirements. The current version will state its effective date. For material changes, we will provide reasonable notice where required or practicable, and seek fresh consent where applicable law requires it.
When submitting a privacy request, include your account email, country, the nature of your request and enough information to verify your identity. Do not send passwords, full payment-card details, private keys or unnecessary sensitive content.
This policy is designed to describe ALLLAST’s intended production practices and to preserve mandatory consumer and data-protection rights. It is not legal advice to users and does not create guarantees beyond applicable law or an express written service commitment.