Actus Humani

Privacy

What we can and cannot see

Last updated 28 August 2026. The short version: your ends, acts, tags and time logs are encrypted before they leave your browser, and we cannot read them.

If you never sign in

Nothing about your content reaches us at all. The application runs entirely in your browser and stores everything locally on your device. There is no analytics script, no advertising network, and no third-party tracker on the site.

If you enable sync

What we store:

  • Your email address, to identify the account and send sign-in codes.
  • Encrypted blobs of your ends, acts and time logs. These are AES-256 ciphertext. Titles, tags, notes, estimates and even the shape of your outline are inside the encryption — not visible to us.
  • Sync metadata we cannot avoid: how many records exist, when each changed, which device wrote it, and per-account storage totals.
  • Session records so you stay signed in, and short-lived hashed sign-in codes.

The encryption key is generated in your browser and never transmitted to us. This is not a promise about our intentions; it is a property of the design. Even under legal compulsion we could produce only ciphertext.

What we do not do

  • No advertising, and no selling or sharing of personal data.
  • No behavioural analytics or third-party tracking scripts.
  • No reading of your content, for product improvement, machine learning, or any other purpose. We cannot.

Processors we rely on

  • Cloudflare — hosting, storage of the encrypted data, and delivery of sign-in emails.
  • Stripe — payment processing for subscriptions. Card details go directly to Stripe; we never receive them. Stripe tells us only that a subscription is active and when it renews.

Cookies

One cookie, set only after you sign in, holding your session. It is HttpOnly and same-site, exists so you are not asked to sign in repeatedly, and is not used for tracking. There are no analytics or advertising cookies, which is why the site has no cookie banner.

How long things are kept

Encrypted data is kept while your account exists, including through a lapsed subscription, so nothing is lost if you come back. Sign-in codes expire in ten minutes. Deleted records are retained as tombstones for a period so that deletions propagate to your other devices, then purged.

Your rights

You can export everything at any time from within the application, and you can delete your account, which removes your encrypted data and your email address from our systems. If you are in the UK, EU, or a comparable jurisdiction, you have rights of access, correction, deletion and portability — practically speaking, export and deletion are available to you directly, and we will answer any other request sent to the address below.

One honest limitation: because we cannot read your data, we also cannot correct or retrieve it on your behalf. Everything meaningful about your content is under your control alone.

Children

The Service is not directed at children under 13, and we do not knowingly collect their data.

Changes and contact

Material changes will be posted here with a new date. Questions:[email protected].