Privacy Policy
Last updated September 2026
Beyond My Time is a place to keep a life's story with the people who share it. This page says, in plain words, what we store, who can see it, what we do with it, and what we never do. Questions: hello@beyondmytime.life.
What we store
Your account. Your name, your email address, your password (stored only as a one-way hash), your chosen language, and — if you use them — the Google or Apple sign-in you connected and the authenticator you set up for two-step verification. We never store your date of birth: when you create an account we ask your birth month and year on your device, and keep only that you answered and were 16 or older.
What you add. The Life Pages, memories, photos, videos, notes, sayings, words, letters, things passed down, tributes and people lists you and your invited contributors add, with your name on what you added. Photos are shrunk for the page and the original is kept; the exact location a photo carries is removed before it is stored (see Places below). For each photo we also keep a fingerprint of the original so From my photos can tell you which ones a page already has; it identifies the file, not you.
How you're connected. Who belongs to which page and in what role; invitations you send and accept; the people you place in a page's Family & friends and the pages you link; who you have blocked; requests you make and answer. A photo tag is a name on a photo, never a face: we have no face recognition and store no biometric data.
Protecting your account. When you sign in, we note the kind of device and browser you used and the network address it came from, so we can email you if your account is opened from a device we haven't seen before, and so you can see under Account where you're signed in and end any of those sessions. A device we haven't seen in 180 days is forgotten. If an email we send bounces or is reported as spam, we remember that address and don't write to it again. If someone reports an invitation or a page, we keep the report and what was done about it so the people who look after Beyond My Time can act on it; the person who reported it is never named to the page. Records of these security events are kept for one year and then removed.
On your device only. Some things never leave your phone or browser: your appearance setting (light or dark), when you last opened each page (which is how your dashboard says “new since you looked”), a memory you were writing when the connection dropped, and files you shared into the app from another app until you save them.
Analytics. We record product events (for example, that a Life Page was created or an invitation was opened) to understand whether the product is working. These are stored in our own database, are not shared with third-party ad networks, and there are no tracking pixels. We do not use cookies for advertising.
Who can see what
Pages. Each Life Page is for its owner alone (Just me) or for the people they invite. One switch lets anyone who has the page's address read it — read, not add — and a page can be made Public when that is offered. A page's owner and trusted people can restrict any memory to the page's people; a contributor can keep everything they added for the page's people with a switch only they control. A memory kept to yourself is readable by nobody but you, not even the page's owner, until you add it to the page. An archived memory or page is out of sight for everyone but the people who look after it.
Links you make. A link to one memory, an invitation link, a page's address and a handover link each open exactly what they name for whoever holds them. Every one can be revoked from the page's Access panel, and an invitation stops working if the person who sent it leaves the page or is limited. We never tell anyone when a link is opened, and we don't count openings.
What the people who run Beyond My Time can see. We can't see a private page unless you switch on support access in that page's settings, and it turns itself off after seven days. A page whose owner has switched on reading by link, or made public, is readable by anyone with the link, us included. Your note to trusted people and any sealed letter are never visible to us. When you ask for help, we work from account details and technical logs, not your memories, and every time one of us opens a page you've let us into, it is recorded. When something is reported to us we look at the thing reported and the account behind it, and act on the account — never by reading a private page.
Letters for later. A member of a page can seal a letter to open on a chosen day, when the person it's for says the day has come, or after the writer's time. Sealed letters can't be read on the page by anyone — not family, not trusted people, not the page's owner — until they open, and only the people a letter is for can read it then. Like everything here they are stored on our servers, so the people who run Beyond My Time could technically read them; we never will, and they are never part of support.
A page in an organisation's care. A funeral home, cemetery or hospice that starts a page for you, or that you ask to care for yours, can read the page and keep its service details until you take the page or end their care — every change they make is listed for you. They can never add or change a memory. If they started the page they gave us your name and email to invite you, and the invitation says so. When care ends they keep a card of what they entered about the service they performed, never a word of yours. Whether the page appears on their own page, and how much of it, is your switch alone.
Young people
Sixteen and older. Accounts are for people 16 and older. If we learn that an account belongs to someone younger, we close it and everything in it is removed within seven days; the person can ask us to undo a mistyped year within those days. A younger person appears on a page as a person — named, pictured, with memories added in their name by an adult from that adult's account.
Under a parent's wing. A parent or legal guardian can open a supervised profile for someone under 16 under their own account. We collect nothing from the young person: no email address and no date of birth (we keep only the month supervision ends). The parent is the account holder, gives consent, sees everything the young person adds, and approves anything that would reach another person. The parent can change the passcode, adjust what asks for approval, and close the profile at any time, after which it is removed within seven days. The month the young person turns 16 the supervision ends and they choose an email and password of their own.
Places and third parties
Places and photo locations. A Life Page can show a map of the places behind its memories. Places are stored at the level of a town or neighbourhood — or a named public place like a park or a church — never a street address. When you add a photo that carries a location, we offer to use the town it was taken in and remove the exact coordinates from the photo before it is stored. An occasion or a resting place can carry an exact address because that is where people need to go; a resting place is shown to the page's people only unless its managers choose otherwise. Maps and place suggestions on the site are provided by Google Maps; loading a page with a map sends your browser's request to Google, subject to Google's privacy policy. Page owners can turn the map off in Settings. The map inside a PDF you save is drawn from OpenStreetMap.
Services we rely on. Beyond My Time runs on Supabase (database, authentication and file storage) and Amazon Web Services (the web servers). Email is sent through Resend; notifications on the phone apps go through Apple's and Google's push services; signing in with Google or Apple sends the sign-in itself to them. Each of these handles only what its job needs, under its own privacy terms. We share nothing with anyone else.
What we don't do
Ever. We do not sell your data, show advertising, or train AI models — ours or anyone's — on your memories. We don't scan your photos to recognise faces. We don't post anywhere on your behalf. We don't handle money: a fundraiser on a page is a name and an organiser, never a payment.
Your copies, and deleting
Keeping it safe. We keep a nightly copy of everything outside the platform it runs on, encrypted with a key only we hold. You can take a copy of any page you own at any time from Settings (Download a copy), and anyone on a page can save its Timeline, Calendar or Places as a PDF. If we ever close, you get six months' notice and the Download button stays on until the last day.
Deleting. Page owners can delete a Life Page and all of its content at any time from Settings, or archive it to keep it out of sight without deleting it. You can delete your account from the app: it is scheduled for 90 days, during which signing back in keeps it, and then your profile is removed, pages with a trusted person pass to them, pages without one are deleted with their contents, and what you added to other people's pages is removed. Tributes you left stay, without your name. Open memory links you made stop working.
Changes. When this policy changes we update the date at the top, and for anything that matters we tell you in the app.
Contact. Questions about privacy, and requests to see, correct or remove what we hold about you: hello@beyondmytime.life.