Pastpond — Privacy Policy

Last updated: 2026-07-18. Provisional v0.6.

This describes what personal data Pastpond collects, why, where it lives, and what your rights are.

Data we collect

You give us:

  • Your email address (for sign-in and notifications).
  • Your sign-in method. You can sign in three ways: a one-time link sent to your email, your Google account, or a passkey.
    • If you sign in with Google, we receive the email address on your Google account, and the name and avatar image if your account has them. We never receive your Google password.
    • If you add a passkey: its public-key credential record — the credential ID, public key, signature counter, transports, device type, and whether it is backed up (synced). This is verification material used only to confirm sign-in; it cannot decrypt your capsule. Your biometrics never leave your device — we never receive them.
  • Your encryption passphrase (only at the moment of derivation in your browser; we never receive or store it).
  • File contents you upload — photos, videos, documents, and letters — encrypted on your device before upload.
  • Names and email addresses of the beneficiaries you designate, and the release conditions you configure for each. If you set a release to happen at a beneficiary's chosen age, that includes the beneficiary's date of birth.

We collect automatically:

  • Check-in timestamps. Using the app records that you were active (at most once every few hours). These "proof of life" timestamps are what the release safeguard reads — see How your capsule is released below.
  • IP address (used only for security logs and abuse prevention). Where an IP is stored for abuse prevention — for example, to rate-limit the pre-launch waitlist form — it is kept only as a salted, one-way hash, never as a raw address.
  • Browser/device user-agent string.
  • Server logs (retained 30 days).

We do not collect the plaintext of any file you upload, with one transient exception: photo bytes pass through our server in memory on their way to Anthropic for description (see AI processing below) and are discarded immediately. Nothing is written to disk in plaintext. We never receive your passphrase or any key derived from it. We run no third-party analytics or advertising trackers, and we do not build a behavioral profile of you.

How we use it

  • To run the service: storing your encrypted capsule, charging you, sending transactional emails.
  • To operate the release safeguard: recording your check-ins and, if you configure an inactivity-based release, acting on prolonged inactivity exactly as you instructed.
  • For security: detecting abuse, fraud, and unauthorized access.
  • For legal compliance: responding to lawful requests.

We do not sell or share personal data with third parties for advertising.

AI processing — Anthropic Claude for photos

Photos. When your capsule organizes itself, each photo is decrypted on your device and sent, via our server (held in memory only, never written to disk), to Anthropic's Claude, which returns a description and tags. Anthropic is our only AI sub-processor: API data is retained by Anthropic for at most 7 days, is never used to train models, and is covered by our data processing agreement. The returned description is encrypted on your device with the same per-item key that protects the photo itself before it is stored — we cannot read your descriptions afterwards.

Beneficiaries you grant access to can read these descriptions, because their release code unlocks the same per-item keys.

The encrypted-at-rest copy of your file in storage is never decrypted on our infrastructure.

Cross-connections — optional, off by default

Settings has a "Let Pastpond's AI find connections" switch. It is off by default. When you turn it on, you authorize Pastpond's AI to use facts extracted from your capsule (names, places, dates from descriptions) to suggest possible family or professional connections to you, as those features launch. No suggested connection is ever revealed to another person without your explicit confirmation of that specific connection. Turning the switch off withdraws the authorization going forward. While it is off, nothing in your capsule is used for matching.

How your capsule is released

Pastpond exists to pass your capsule to the people you choose. For each beneficiary you set one release condition:

  • A fixed date — the capsule is released to them on that day.
  • A beneficiary's age — released when they reach the age you chose (this is why an age-based release stores their date of birth).
  • Prolonged inactivity — the check-in safeguard. Because using the app records a check-in, staying active keeps everything private to you. If you configure an inactivity-based release and then stop checking in, we email you a reminder after about 9 months, and after 12 months of silence a further escrow period you set (a year by default) begins, with another notice. Only if that whole window passes with no check-in do we email your designated beneficiaries a link to open the capsule. Any single check-in resets the clock.

A release email only delivers a link. Beneficiaries still need the release code you shared with them separately (by text or in writing) to decrypt anything — without it the items cannot be read, and we cannot decrypt them for anyone.

Where your data lives

  • Encrypted file contents: Cloudflare R2.
  • Database metadata: Supabase.
  • Backups: encrypted backups within our providers' infrastructure (Supabase database backups; Cloudflare's replicated storage). A second cloud and a cold-tier archive in a second jurisdiction are planned, not yet live.

Sub-processors

Cloudflare, Supabase, Stripe, Postmark, Vercel, Google (sign-in only — when you choose to sign in with Google), Anthropic (photo description only — ≤7-day retention, no training on your data).

Cookies

We use only the essential cookies that keep you signed in and maintain your session. We set no advertising cookies and no third-party tracking cookies.

Your rights

You may have rights to access, correct, delete, export, object to or limit processing of your data, and to file a complaint with your local data protection authority. You can export everything we hold on you (profile, capsule metadata, items, beneficiaries, subscriptions, and check-ins) and delete your account from Settings at any time. To exercise any other right, email hello@pastpond.com.

Because we are encrypted client-side, our ability to honor some requests depends on the passphrase you still control. We cannot decrypt and produce plaintext of your files on demand. We can confirm what we hold and we can delete it.

Retention

  • Active capsule: as long as your storage plan is active.
  • Check-in timestamps: kept while your account is open, because the release safeguard depends on them.
  • Server logs: 30 days.
  • Backups: 90 days after capsule deletion.

Children

Pastpond is not for users under 18. We do not knowingly collect data from minors.

International transfers

Your data may be stored or processed outside your country of residence. We rely on standard contractual clauses and equivalent mechanisms where required.

Changes

We will email you at least 30 days before material changes take effect.

Contact

hello@pastpond.com