Operational draft

ALLLAST Privacy Notice

Legal completion required before paid public launch. The data controller’s legal name, registered address, privacy contact, final retention schedule, lawful bases, international-transfer details and jurisdiction-specific rights process must be completed and approved by qualified counsel.

1. Information handled

2. Service providers

The release uses Supabase for authentication, database, Storage and Edge Functions; Stripe for checkout and payment events; Resend for transactional email; and Google Analytics 4 for website and commerce-event measurement. Message content, names and email addresses must not be intentionally sent to Analytics.

3. Private file handling

Files are stored in private Supabase Storage buckets using a user-ID path prefix and random identifier. The database stores a storage locator rather than a permanent public URL. Short-lived signed URLs are created when authorized access is required. Attached files remain in a pending state until a trusted scanner marks them clean.

4. Access controls

The supplied migrations enable Row Level Security for exposed account tables and use ownership policies based on the authenticated user ID. Live cross-account isolation must still be tested with separate accounts before public launch.

5. Browser storage

Colour theme is stored in local storage. When a user explicitly saves wizard progress for the current tab, temporary text fields are stored in session storage and removed after a successful save. Selected file bytes are not stored in browser storage.

6. Sharing and delivery

Recipient information is used to prepare and deliver messages according to the owner’s selected rule. Access is intended to be issued through time-limited or server-controlled recipient access mechanisms after required release checks complete.

7. Retention, deletion and rights

Users can remove message and recipient records through the current interface. Final account deletion, export, backup retention, legal hold and verified rights-request procedures must be documented before paid public launch.

8. Claims excluded

ALLLAST does not claim zero-knowledge architecture, end-to-end encryption, regulatory certification or automatic government-record integration.

Draft updated: July 20, 2026