Still Time
Still Time

Privacy Policy

The short version: nothing you write on this site has ever left your device.

Last updated: 2026-09-21

1. At a glance

2. Who is the controller

For the processing described here, the controller within the meaning of Art. 4(7) GDPR is:

Jun Li
Utrecht, Netherlands
This is a personal, non-commercial project. Written correspondence is handled by email; a full postal address is provided on request and will be published here if the site ever carries advertising or takes payment.
Email: privacy@stilltimeto.com

EU representative (Art. 27 GDPR, where applicable): Not applicable — the operator is established in the European Union (Netherlands).

We have not appointed a Data Protection Officer: the processing carried out by this site does not meet the thresholds of Art. 37 GDPR. Please send all privacy matters to the address above.

3. What stays on your device, where we cannot see it

The core of the site runs entirely in your browser. The following is kept in local storage (localStorage and IndexedDB) and is sent neither to us nor to any third party:

Because this content never reaches us, it is not personal data that we process. By the same token we cannot retrieve, export or delete it for you — the way to delete it is to clear this site's data in your browser, or use the clear button on the page.

Photos: when you choose an image, the browser resizes it and re-encodes it as JPEG locally. That process discards the EXIF metadata of the original file, including location and device information. The result is stored in IndexedDB on your machine. Photos are never uploaded.

A note on shared devices: because the content sits in the browser, anyone who can use that device and browser profile may be able to see it. On a public computer, use a private window or clear the data before you leave.

4. Data we do process

4.1 Server access logs

Like any website, the pages are delivered by a hosting provider (Cloudflare, Inc. (Cloudflare Pages), 101 Townsend St, San Francisco, CA 94107, USA). Its servers automatically record, for each request: IP address, time of access, the page requested, HTTP status code, bytes transferred, referrer and browser user-agent string.

4.2 Emails you send us

If you write to us we process your email address, your name if you give one, and the content of your message.

4.3 Cookies and similar technologies

Beyond what is strictly necessary, cookies and similar technologies (advertising, analytics) are set only after you consent through the banner at the bottom of the page. The legal basis is Art. 6(1)(a) GDPR together with Art. 5(3) of the ePrivacy Directive; consent is obtained before any non-essential storage is written or read. You can withdraw consent at any time through Cookie settings in the footer, as easily as it was given, without affecting the lawfulness of processing carried out beforehand. The full list is in the Cookie Policy.

4.4 Share links and share cards

Share cards are images drawn in your browser and saved to your device; who you send them to is entirely your decision. Share links may carry the nickname and numbers you entered as URL parameters. Once you send such a link, that content appears on the recipient's device and may be recorded in their browser history and in the server logs of sites they visit. Please do not type anything into those fields that you would not want another person to see.

5. What we do not do

6. Third parties

6.1 Google Fonts

Typefaces are loaded from Google's servers (fonts.googleapis.com, fonts.gstatic.com). Your browser makes a request to Google for them, and Google therefore receives your IP address and user-agent. Legal basis: Art. 6(1)(f) — our legitimate interest in a consistent presentation. If you prefer to avoid this, a browser extension that blocks third-party requests will do so; the pages remain usable without the fonts.

6.2 Google AdSense (if enabled)

The site may display advertising served by Google Ireland Limited / Google LLC. Only if you have consented to the "Advertising" category will Google and its partners set or read cookies and advertising identifiers on your device for ad delivery, frequency capping, invalid-traffic detection and measurement. In that processing Google acts as an independent controller for its own purposes.

We have implemented Google Consent Mode v2: before you make a choice, advertising and analytics storage default to denied.

Further information: How Google uses cookies in advertising, Google Privacy Policy, Google Ads Settings.

6.3 Analytics (if enabled)

We may use a privacy-focused analytics tool or Google Analytics to understand how many people visit which pages. Those cookies are likewise set only after you consent to the "Analytics" category.

6.4 Hosting provider

Cloudflare, Inc. (Cloudflare Pages), 101 Townsend St, San Francisco, CA 94107, USA provides hosting and content delivery as our processor under Art. 28 GDPR and processes the log data described in section 4.1 on our behalf, under a data processing agreement.

7. International transfers

Some of the providers above are located outside the European Economic Area, principally in the United States. Such transfers take place on the basis of the European Commission's Standard Contractual Clauses and, where the provider participates, the adequacy decision for the EU–U.S. Data Privacy Framework. Google LLC is certified under that framework. You may request a copy of the relevant safeguards at the address above.

8. Retention at a glance

DataRetention
Local browser content (lists, letters, photos)Under your control, until you clear your browser data
Server access logsTypically ≤ 30 days
Email correspondence≤ 24 months
Consent record (rl_consent)Stored in your browser; re-confirmation suggested after 12 months
Advertising / analytics cookiesSee the Cookie Policy; up to 24 months

9. Your rights under the GDPR

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:

In practice: because there are no accounts, we are generally unable to link a line in a server log to a particular person (Art. 11 GDPR). If you would like us to look, please provide details that make identification possible, such as the approximate time of your visit and the IP address used. As for the content you wrote on the site, the fastest way to exercise your rights is to clear this site's data in your browser — that is the only place it exists.

To exercise any right, write to privacy@stilltimeto.com. We respond within one month; where a request is complex we may extend that by two further months and will tell you if we do.

10. United States residents

California (CCPA/CPRA): in the past 12 months the only categories of personal information collected have been "internet or other electronic network activity information" and "identifiers" (IP address, device and cookie identifiers), obtained from your device, for the purposes of providing the site, keeping it secure and — where you consent — showing advertising. We do not sell personal information and do not "share" it for cross-context behavioural advertising unless you consent to the "Advertising" category, in which case the disclosure of identifiers to advertising partners may amount to "sharing" under the CPRA.

You can decline through Cookie settings in the footer, which serves as our "Do Not Sell or Share My Personal Information" mechanism. We also honour Global Privacy Control (GPC): if your browser sends the signal, advertising and analytics are set to denied automatically.

You also have the right to know, delete, correct, and not to be discriminated against for exercising these rights. We do not collect "sensitive personal information" as defined by the CPRA, do not use personal information for purposes beyond those described here, and do not knowingly collect or sell the personal information of anyone under 16.

Other states: residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have comparable rights and may use the same address.

11. Children

The site is intended for people aged 15 and over and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or under 13 to 16, depending on how the relevant Member State implements Art. 8 GDPR), nor from children under 13 within the meaning of the US COPPA. If you believe a child has provided us with data, please contact us and we will delete it.

12. Security

The site is served over HTTPS with modern transport encryption. Since we keep none of your content on a server, the main risk to that content is your own device: be mindful of shared computers, lost devices and the permissions you grant to browser extensions.

13. Changes to this policy

We may update this policy as features or legal requirements change. Material changes are reflected in the date at the top of this page and announced on the site where significant. Earlier versions are available on request.

14. Contact and complaints

Privacy matters: privacy@stilltimeto.com. You may also lodge a complaint with the data protection authority in your country at any time. Our own supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, Hoge Nieuwstraat 8, 2514 EL Den Haag, Netherlands — autoriteitpersoonsgegevens.nl).