Last updated: 2026-09-21
1. At a glance
- There are no accounts. We never ask for your name, email or phone number.
- The age, names, lists, letters and photos you enter are stored in your own browser and never transmitted to us.
- The only personal data we can reach is: server access logs, emails you choose to send us, and data generated by advertising or analytics cookies after you consent.
- We do not sell or trade personal data.
2. Who is the controller
For the processing described here, the controller within the meaning of Art. 4(7) GDPR is:
Jun Li
Utrecht, Netherlands
This is a personal, non-commercial project. Written correspondence is handled by email; a full postal address is provided on request and will be published here if the site ever carries advertising or takes payment.
Email: privacy@stilltimeto.com
EU representative (Art. 27 GDPR, where applicable): Not applicable — the operator is established in the European Union (Netherlands).
We have not appointed a Data Protection Officer: the processing carried out by this site does not meet the thresholds of Art. 37 GDPR. Please send all privacy matters to the address above.
3. What stays on your device, where we cannot see it
The core of the site runs entirely in your browser. The following is kept in local storage (localStorage and IndexedDB) and is sent neither to us nor to any third party:
- the age, life expectancy, language and display settings you choose;
- the names and meeting frequencies in your list of people;
- weekend plans, unsent letters, letters to yourself, promises you have kept;
- photos you attach to a kept promise;
- the numbers and names you type into any of the calculators.
Because this content never reaches us, it is not personal data that we process. By the same token we cannot retrieve, export or delete it for you — the way to delete it is to clear this site's data in your browser, or use the clear button on the page.
Photos: when you choose an image, the browser resizes it and re-encodes it as JPEG locally. That process discards the EXIF metadata of the original file, including location and device information. The result is stored in IndexedDB on your machine. Photos are never uploaded.
A note on shared devices: because the content sits in the browser, anyone who can use that device and browser profile may be able to see it. On a public computer, use a private window or clear the data before you leave.
4. Data we do process
4.1 Server access logs
Like any website, the pages are delivered by a hosting provider (Cloudflare, Inc. (Cloudflare Pages), 101 Townsend St, San Francisco, CA 94107, USA). Its servers automatically record, for each request: IP address, time of access, the page requested, HTTP status code, bytes transferred, referrer and browser user-agent string.
- Purpose: delivering the pages, security, troubleshooting, and defending against attacks and abuse.
- Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating the site securely and reliably.
- Retention: kept by the hosting provider under its default policy, typically no longer than 30 days, then deleted or anonymised.
4.2 Emails you send us
If you write to us we process your email address, your name if you give one, and the content of your message.
- Purpose: answering your question or handling your rights request.
- Legal basis: Art. 6(1)(b) (steps taken at your request) or Art. 6(1)(f) (legitimate interest in responding to enquiries); Art. 6(1)(c) (legal obligation) where a data subject request is involved.
- Retention: up to 24 months after the exchange ends; correspondence about rights requests is kept as long as needed to evidence compliance.
4.3 Cookies and similar technologies
Beyond what is strictly necessary, cookies and similar technologies (advertising, analytics) are set only after you consent through the banner at the bottom of the page. The legal basis is Art. 6(1)(a) GDPR together with Art. 5(3) of the ePrivacy Directive; consent is obtained before any non-essential storage is written or read. You can withdraw consent at any time through Cookie settings in the footer, as easily as it was given, without affecting the lawfulness of processing carried out beforehand. The full list is in the Cookie Policy.
4.4 Share links and share cards
Share cards are images drawn in your browser and saved to your device; who you send them to is entirely your decision. Share links may carry the nickname and numbers you entered as URL parameters. Once you send such a link, that content appears on the recipient's device and may be recorded in their browser history and in the server logs of sites they visit. Please do not type anything into those fields that you would not want another person to see.
5. What we do not do
- We do not build user profiles and do not track you across sites (for what advertising partners do after your consent, see section 6).
- We do not sell, rent or trade personal data.
- We do not send marketing email — we do not have your address.
- We carry out no automated decision-making or profiling producing legal or similarly significant effects (Art. 22 GDPR).
6. Third parties
6.1 Google Fonts
Typefaces are loaded from Google's servers (fonts.googleapis.com, fonts.gstatic.com). Your browser makes a request to Google for them, and Google therefore receives your IP address and user-agent. Legal basis: Art. 6(1)(f) — our legitimate interest in a consistent presentation. If you prefer to avoid this, a browser extension that blocks third-party requests will do so; the pages remain usable without the fonts.
6.2 Google AdSense (if enabled)
The site may display advertising served by Google Ireland Limited / Google LLC. Only if you have consented to the "Advertising" category will Google and its partners set or read cookies and advertising identifiers on your device for ad delivery, frequency capping, invalid-traffic detection and measurement. In that processing Google acts as an independent controller for its own purposes.
We have implemented Google Consent Mode v2: before you make a choice, advertising and analytics storage default to denied.
Further information: How Google uses cookies in advertising, Google Privacy Policy, Google Ads Settings.
6.3 Analytics (if enabled)
We may use a privacy-focused analytics tool or Google Analytics to understand how many people visit which pages. Those cookies are likewise set only after you consent to the "Analytics" category.
6.4 Hosting provider
Cloudflare, Inc. (Cloudflare Pages), 101 Townsend St, San Francisco, CA 94107, USA provides hosting and content delivery as our processor under Art. 28 GDPR and processes the log data described in section 4.1 on our behalf, under a data processing agreement.
7. International transfers
Some of the providers above are located outside the European Economic Area, principally in the United States. Such transfers take place on the basis of the European Commission's Standard Contractual Clauses and, where the provider participates, the adequacy decision for the EU–U.S. Data Privacy Framework. Google LLC is certified under that framework. You may request a copy of the relevant safeguards at the address above.
8. Retention at a glance
| Data | Retention |
|---|---|
| Local browser content (lists, letters, photos) | Under your control, until you clear your browser data |
| Server access logs | Typically ≤ 30 days |
| Email correspondence | ≤ 24 months |
| Consent record (rl_consent) | Stored in your browser; re-confirmation suggested after 12 months |
| Advertising / analytics cookies | See the Cookie Policy; up to 24 months |
9. Your rights under the GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:
- access (Art. 15) — find out whether and what personal data we process about you;
- rectification (Art. 16) — have inaccurate data corrected;
- erasure (Art. 17) — have data deleted where the conditions are met;
- restriction of processing (Art. 18);
- data portability (Art. 20) — receive the data you provided in a structured, commonly used, machine-readable format;
- object (Art. 21) to processing based on legitimate interests;
- withdraw consent (Art. 7(3)) at any time via Cookie settings in the footer, as easily as it was given;
- lodge a complaint (Art. 77) with the supervisory authority of your habitual residence, place of work or place of the alleged infringement.
In practice: because there are no accounts, we are generally unable to link a line in a server log to a particular person (Art. 11 GDPR). If you would like us to look, please provide details that make identification possible, such as the approximate time of your visit and the IP address used. As for the content you wrote on the site, the fastest way to exercise your rights is to clear this site's data in your browser — that is the only place it exists.
To exercise any right, write to privacy@stilltimeto.com. We respond within one month; where a request is complex we may extend that by two further months and will tell you if we do.
10. United States residents
California (CCPA/CPRA): in the past 12 months the only categories of personal information collected have been "internet or other electronic network activity information" and "identifiers" (IP address, device and cookie identifiers), obtained from your device, for the purposes of providing the site, keeping it secure and — where you consent — showing advertising. We do not sell personal information and do not "share" it for cross-context behavioural advertising unless you consent to the "Advertising" category, in which case the disclosure of identifiers to advertising partners may amount to "sharing" under the CPRA.
You can decline through Cookie settings in the footer, which serves as our "Do Not Sell or Share My Personal Information" mechanism. We also honour Global Privacy Control (GPC): if your browser sends the signal, advertising and analytics are set to denied automatically.
You also have the right to know, delete, correct, and not to be discriminated against for exercising these rights. We do not collect "sensitive personal information" as defined by the CPRA, do not use personal information for purposes beyond those described here, and do not knowingly collect or sell the personal information of anyone under 16.
Other states: residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have comparable rights and may use the same address.
11. Children
The site is intended for people aged 15 and over and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or under 13 to 16, depending on how the relevant Member State implements Art. 8 GDPR), nor from children under 13 within the meaning of the US COPPA. If you believe a child has provided us with data, please contact us and we will delete it.
12. Security
The site is served over HTTPS with modern transport encryption. Since we keep none of your content on a server, the main risk to that content is your own device: be mindful of shared computers, lost devices and the permissions you grant to browser extensions.
13. Changes to this policy
We may update this policy as features or legal requirements change. Material changes are reflected in the date at the top of this page and announced on the site where significant. Earlier versions are available on request.
14. Contact and complaints
Privacy matters: privacy@stilltimeto.com. You may also lodge a complaint with the data protection authority in your country at any time. Our own supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, Hoge Nieuwstraat 8, 2514 EL Den Haag, Netherlands — autoriteitpersoonsgegevens.nl).