Privacy Policy
Effective Date: November 16, 2025
Thank you for using FinalSaying. We value your privacy and are committed to protecting your personal data. This Privacy Policy explains who we are, what information we collect, how we use and safeguard it, and your rights. FinalSaying is designed to let you write encrypted messages that will be delivered to your chosen recipients after your death, and we take privacy very seriously in providing this service.
Who We Are
FinalSaying (referred to as "we" or "us" in this Policy) is a personal project operated by an individual developer based in Germany. Because we operate in the European Union, we adhere to EU data protection laws, including the General Data Protection Regulation (GDPR). FinalSaying allows users (referred to as "you") to create secure, encrypted messages and have them delivered at a later time (for example, after the user's passing).
As an individually-run service, we strive to be transparent and respectful of your privacy. This Policy applies when you use the FinalSaying website or service.
What Data We Collect
We only collect the minimum personal information necessary to provide the FinalSaying service. Here is what we collect and what we do NOT collect:
- Google Account Information: When you sign up or log in via Google Sign-In, we receive your name and email address from your Google account. This is used to create and manage your FinalSaying account (so we know who you are and can authenticate you). We do not collect your Google password or any other Google account data beyond your name and email.
- Your Messages and Attachments: The content of the messages you write on FinalSaying – including any text and any files you choose to attach (such as photos or documents) – is collected and stored on our servers in encrypted form. This means your messages and attachments are encrypted such that they cannot be read by anyone without proper authorization. Even we, the service operators, cannot easily read your message content because of this encryption. We only decrypt and use this content at the time it needs to be delivered to your designated recipient(s) as part of the service.
- Recipients' Contact Information: If you provide contact details for the people who should receive your messages (for example, an email address for an intended recipient, or a phone number for WhatsApp delivery), we collect and store that information. We treat this data as confidential and, if possible, we store it encrypted alongside your messages. We use it solely to deliver your messages to those recipients at the appropriate time. (Please ensure you have the right to share any third-party contact information with us.)
- Payment Information: FinalSaying offers premium features available through a one-time payment. If you choose to make a payment, this will be handled by our third-party payment processor (Stripe). We do not collect or store your sensitive payment details (such as credit card numbers) on our servers. Stripe will collect payment information securely for processing transactions. We may receive and store basic information from Stripe, such as your premium status and payment confirmation, to know that your payment was processed. We do not receive your full credit card details or bank information.
- Customer Support Communications: If you contact us via email (for example, at our support email address), we will collect whatever information you choose to provide in that communication. This likely includes your email address and the content of your message. We will use this information to respond to your inquiry or request and to resolve any issues you reported.
No Cookies or Tracking Technologies: We do not use any cookies, analytics, or tracking pixels on the FinalSaying website or app. We do not track your behavior, clicks, or visits for marketing or advertising purposes. The only cookies that might exist would be strictly necessary ones (for example, for session management or authentication), and even those are minimized or not used if possible. In short, we do not use Google Analytics, Facebook pixels, or any similar tracking tools, and we do not profile you or your activity.
No Server Logs of Personal Data: FinalSaying itself does not keep identifying server logs. We do not store your IP address or device information in our application logs, and we do not record your usage patterns on the server side. (Please note, however, that when you use any internet service, your IP address is necessarily communicated; while we do not log or analyze this information on our end, it may be processed briefly by our hosting infrastructure or by third-party services in the background as part of normal operation. We ensure that we do not retain or use this data.)
No Advertising Data Collected: We do not collect any data for advertising or marketing purposes. We do not show ads in our service, and therefore we don't collect data such as ad preferences or tracking IDs. You will also not receive any marketing emails or newsletters from us — we will only contact you for service-related reasons (e.g. important updates to the service or your account, if ever necessary).
In summary, we collect only the information you provide directly (your account info and message content) and the bare minimum technical data to make the service work. We deliberately avoid collecting any extra personal data that is not needed.
How We Use Your Data
We use the personal data we collect only to provide and improve the FinalSaying service and to fulfill your requests. Specifically:
- Providing the Service: We use your Google account name and email to create your FinalSaying account and let you log in securely. Your email may be used to identify your account and, if needed, to communicate with you about service-related matters (for example, if there is an important update or if we need to inform you of something critical about your account). We use the information about your payment status (from Stripe) to enable access to premium features.
- Storing Your Messages: We use (store) the content you write (messages and attachments) in order to carry out the core purpose of FinalSaying — which is to hold these messages until the appropriate time and then deliver them to your chosen recipients. The storage is encrypted, as noted, and the content is essentially "locked away" until it's time to send it. We do not otherwise read or use the content of your messages for any purpose other than storing it and sending it to the intended recipient when the time comes.
- Delivering Messages to Recipients: When the conditions are met to send out your posthumous message (for example, we have been notified of your passing, or whatever mechanism FinalSaying uses to trigger delivery), we will decrypt the message content and use the recipient contact information you provided to deliver the message. If the delivery is via email, we will send an email through our email provider (Resend) to that recipient with your message. If the delivery is via WhatsApp, we will send the message via our WhatsApp integration (Twilio) to the recipient's phone number. Your data is used strictly to ensure your final messages reach the people you intended, in the manner you specified.
- Payments and Premium Access: If you purchase premium access, we use your data to manage your account. For example, we may use your email to send you a receipt or confirmation of payment (though Stripe usually handles receipts). We also rely on Stripe to inform us if your payment was successful, so we can grant access to premium features accordingly. We only use this information to manage the services you are paying for.
- Customer Support and Communication: If you reach out to us via the contact email for help or with questions, we will use your email address and the information you provided to respond to you. We will only use this information to assist you and resolve your support issue. We won't use support inquiry data for any other purpose.
- Service Improvements: Internally, we might review the usage of our service in general terms (e.g. how many users we have, or generic trends), but since we do not collect analytics or detailed logs, this is very limited. In general, if we ever look at data for improving the service, it would be non-personal or aggregated data. For example, we might keep track of how many messages in total are being stored (without reading them) or note if email deliveries succeed or fail to improve reliability. We do not examine personal data for analytics; we focus on maintaining a secure and functional service.
- Legal Compliance: If ever required by law (for instance, to comply with a valid court order or legal obligation), we may have to use or disclose certain data. This is not a routine use of data, but we mention it here for completeness. Unless we are prohibited from doing so, we would inform you if we ever had to disclose your information for legal reasons.
What We Do Not Do: We do not use your personal data for any kind of advertising, profiling, or marketing. We do not sell or rent your information to anyone. We do not send you promotional communications. We do not use automated decision-making or profiling that has legal or significant effects on you. All processing of your data is related directly to the service you have signed up for.
Legal Bases for Processing (GDPR)
For users in the European Union (and similar jurisdictions), we need to explain the legal grounds on which we process your personal data under the GDPR:
- Consent: By signing up for FinalSaying and providing your information, you are giving us consent to process your personal data for the purposes described above. For example, you consent to us storing your name and email by using Google Sign-In, and you consent to us processing the sensitive content you input (messages, attachments, recipient info) in order to carry out the service. You can withdraw your consent at any time (see "Your Rights" below), but note that if you withdraw consent for essential data, we may not be able to continue providing the service.
- Legitimate Interest: In certain cases, we rely on legitimate interests as our legal basis. Our legitimate interest is in operating a secure and reliable service that delivers users' final messages as intended. For instance, it is in our legitimate interest (and yours as well) that we securely store your messages and deliver them to recipients when the time comes. We also have a legitimate interest in using certain data to maintain the service (e.g., using your email to notify you of critical account issues, or using minimal payment information to manage premium access). When we process data based on legitimate interests, we ensure that this does not override your rights and freedoms – in other words, we only use data in ways you would reasonably expect when using FinalSaying.
In all cases, we handle your data in a manner that is compliant with GDPR and other applicable laws. If we ever need to process your data for a new purpose not described in this Policy, we will seek your consent or inform you of the new legal basis as required.
Data Sharing and Third-Party Services
We do not sell your data to anyone. We only share your information with a few trusted third-party service providers as necessary to operate FinalSaying. These providers are bound to handle your data securely and only for the purposes of providing their services to us (not for their own use). Here are the third parties we work with and what for:
- Google (Google LLC) – Authentication: We use Google Sign-In to allow you to log in to FinalSaying easily. When you use Google Sign-In, Google confirms your identity to us and shares your basic account info (name, email). We use that to log you in. Google may independently record the fact that you used Google to authenticate with our service (this could include logging your IP address or device info on their side, as part of their security measures). This data is handled according to Google's privacy policy. We do not send any of your FinalSaying data back to Google aside from the authentication request. In short, Google helps verify you, and we trust Google as a secure identity provider.
- Stripe (Stripe, Inc.) – Payments: If you subscribe or make payments on FinalSaying, we use Stripe to process those payments. When you enter payment information (like your credit card details) during a purchase, you do so via Stripe's secure checkout forms. That information goes directly to Stripe; we do not see or store your card number or bank info. Stripe will provide us with data like your name, email, and whether the payment was successful, as well as possibly the last four digits of your card or an expiration date (for reference and receipts). We may also send Stripe your user identifier or email to tie the payment to your account. Stripe might log transaction details (such as your IP at time of payment or a device identifier) to comply with anti-fraud and legal obligations on their side. Stripe is a GDPR-compliant company and will handle your data according to their privacy policy. We only use Stripe to ensure we can securely accept payments and manage subscriptions – no payment data is used outside of that purpose.
- Resend (Resend, Inc.) – Email Delivery: Resend is a third-party email sending service for developers. We utilize Resend to send out emails from FinalSaying, including the final messages you want delivered via email to your recipients (and possibly emails to you, such as account verification or notifications if we ever send those). This means that when a scheduled email needs to be sent (for example, your message to your loved one), the email content (including the recipient's email address, your email address as sender, and the message subject/body) is transmitted to Resend's system, which then actually delivers the email to the recipient's mail server. Resend may temporarily log information about email transactions – such as when the email was sent, whether it was delivered successfully, opens or bounces, and possibly the IP addresses involved in sending/receiving – as part of their service monitoring. These logs help ensure the email was delivered and help with troubleshooting. We only send the necessary information to Resend for sending the email (we do not give them any data unrelated to the email being sent). All content sent through Resend is handled under their security measures. We trust Resend as a privacy-conscious service (they advertise GDPR compliance and strong data protection). The emails sent via Resend will, of course, contain the message content you wrote (decrypted at send-time so the recipient can read it). Resend does not have the ability to decrypt anything that wasn't already in plaintext when we handed it to them (we only decrypt right when sending). They act purely as a conduit to deliver the message.
- Twilio (Twilio, Inc.) – WhatsApp Message Delivery: If you choose to have a final message delivered via WhatsApp, we integrate with Twilio's WhatsApp API to send that message. Twilio will handle sending the WhatsApp message to the phone number you provided for the recipient. To do this, we provide Twilio with the necessary data: the recipient's phone number and the message content (which we decrypt at the moment of sending so it can be delivered in readable form). Twilio then transmits that message through WhatsApp to the recipient. Twilio, as a communications platform, will likely log transactional details such as the phone number, the time the message was sent, delivery status, and possibly segments of the message or metadata needed for delivery. Twilio maintains its own privacy and security practices and is a reputable provider (also GDPR-compliant). We only use Twilio so that we can fulfill the WhatsApp delivery feature – we do not share any other data with Twilio beyond what is required to send the message.
In addition to the above, these general principles apply to our use of third parties:
- Necessary Sharing Only: We only share your data with the above providers for the specific purposes described. We do not share your personal information with any other third parties or individuals, unless it is required to carry out your requests or unless we are required by law (for example, responding to a lawful subpoena – which is rare and would be handled with care).
- No Third-Party Advertising or Marketing: We do not share, rent, or sell your information to advertisers or marketing companies. None of the limited data sharing we do is for commercial advertising purposes; it is all about providing the core service to you.
- Contractual Protections: We have agreements (to the extent applicable for a small project like this) with these service providers that require them to protect your data. For instance, using services like Google, Stripe, Resend, and Twilio implies agreement to their terms which include commitments to privacy and data protection. They are data processors or service providers for us, and they are only allowed to use your data to provide services to FinalSaying, not for their own independent use.
- International Data Transfers: Some of our third-party providers are based outside the EU (for example, Google, Stripe, Twilio, and Resend are U.S.-based companies, though they may have EU servers). This means your data might be transferred to or processed on servers located in the United States or other countries outside the European Economic Area. When we transfer data to these providers, we rely on legal mechanisms to ensure adequate data protection, such as the European Commission's Standard Contractual Clauses or the providers' certifications and compliance with GDPR. We only work with providers that we believe have strong data protection standards. By using FinalSaying, and specifically by opting to use features that involve these third parties, you understand that your data may be transferred to these services as needed to operate. We take steps to ensure any such transfer is done securely and in compliance with applicable laws.
In summary, your personal data is never shared arbitrarily – it is only passed along to trusted partners to perform essential functions like authentication, payment, or message delivery. We do not allow any third party to use your data for their own marketing or purposes not authorized by us and you.
Data Security
We understand that the data you entrust to FinalSaying is highly sensitive (personal messages, possibly final words, attachments, etc.). We take several measures to protect your data:
- Encryption: All messages and attachments you store with FinalSaying are encrypted at rest in our database. This means that even if someone were to gain unauthorized access to our storage, they would not be able to read your content without the encryption keys. The intention is that only authorized operations (like the final delivery process) can decrypt the content, and no one else (including the service operator in day-to-day operations) can casually browse or read your messages. In addition, we use HTTPS (TLS) for all data transmission between your device and our service, which means your data is also encrypted in transit over the internet. This prevents eavesdropping on your data as it travels to or from FinalSaying.
- Access Controls: As a small, individually-run service, access to systems that store personal data is extremely limited. The developer/operator of FinalSaying is the only person who administratively manages the servers and database. There are no employees or unrelated third parties accessing user data. Within the system, your data is segmented by user account, and proper authentication is required to access it (only you can access your own account data via your login). We follow the principle of least privilege, meaning even within our infrastructure, we only open up what's necessary for the service to function.
- No Unnecessary Data Stored: As described in the collection section, we intentionally do not collect data that we don't need. By not having things like extensive logs or tracking data, we reduce the risk of any such data being leaked or misused. The less data we have, the less can go wrong with it. This is a form of "data minimization," which is a core principle of privacy and security.
- Secure Infrastructure: We host FinalSaying on secure servers (for example, reputable cloud service providers or hosting services) that employ industry-standard security practices. We keep the server software and dependencies up to date with security patches to protect against vulnerabilities. We also monitor the system for any suspicious activities.
- Third-Party Security: When we use third-party services (Google, Stripe, Resend, Twilio), we choose companies that are known for high security standards. These companies invest heavily in security and have certifications (for instance, many are ISO certified or SOC compliant). While using them means some data passes through their systems, we trust their security measures. For example, Stripe is known for secure handling of payment data, and Twilio and Resend are reputable for communications.
- Backups and Encryption: We may keep encrypted backups of the database to prevent data loss (for example, if there's a hardware failure, we can restore your data). Any such backups would also be encrypted. In the event a backup restoration is needed, the same security controls apply.
- No Reading of User Content: Importantly, we (the operator) do not proactively read or access the content of your messages or attachments. The system might automatically handle them (e.g., encryption, storage, sending), but there is no routine where we look at your personal messages. We consider your content private and encrypted for your intended recipients only. In rare cases, if you request support that involves message content, we might need your permission to access it (for example, if you think there's a problem with how it was saved), but otherwise we leave it untouched.
- Breach Notification: While we strive to prevent any security breaches, no method of storage or transmission is 100% secure. In the unlikely event of a data breach that affects your personal data, we will notify you and the relevant authorities as required by law. We have procedures in place to quickly address and mitigate any security incident.
Our goal is to give you peace of mind that your sensitive messages are safe with us. We continually review our security practices to adapt to new threats and protect your privacy.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy, or as required by law. Here's how that works in practice:
- Account Data: We will keep your account information (name, email, and related info) as long as you remain a registered user of FinalSaying. If you choose to delete your account or if we close the service, we will delete this information (unless we are required to keep it for legal reasons, explained below).
- Messages and Attachments: We store the messages and files you have saved with FinalSaying until they are delivered to your recipients, or until you decide to delete them. The core purpose of FinalSaying is to hold onto your messages until the appropriate delivery time (which could be many years in the future, depending on circumstances). Therefore, by default, we will retain your encrypted message content indefinitely (potentially for the remainder of your lifetime) or until the conditions for delivery are met (e.g., notification of your passing triggers delivery). If you remove a specific message or attachment from your account, our system will delete that content from our storage (with the caveat that it may remain in secure backups for a short period, but will be purged from active use).
- After Delivery: If a message has been delivered (for example, sent via email or WhatsApp to the recipient), we may either delete the original stored message or retain it for a brief period in case of any issues. Our standard approach is to retain delivered messages for a short grace period (to verify delivery success and in case the delivery needs to be reattempted or verified) and then permanently delete them. We do not continue to store your personal messages longer than necessary after they've been delivered. Attachments would follow the same principle.
- Payment Records: If you have made payments, we may need to retain some basic payment records (amount, date, service provided) for accounting and tax purposes. For instance, under German or EU law, certain financial records might need to be kept for a number of years. These records would typically reside with Stripe as well, but we might keep invoice information or transaction IDs. This data will be minimal and only used for legitimate financial record-keeping.
- Account Deletion and Your Requests: If you decide to stop using FinalSaying, you have the option to delete your account and all associated data. You can do this by contacting us (see "Contact Information" below) and requesting account deletion. We will then erase your personal information from our live databases, including your profile info and all messages and attachments you had stored. We will also instruct our third-party processors to delete data they hold on our behalf where applicable (for example, tell Stripe to remove personal details if possible, though they may retain transaction records as required for their legal compliance). Backup copies might persist for a limited time but will also be purged according to our backup retention schedule. Similarly, if you only want to delete certain messages or attachments, you can remove them from your account interface (if functionality allows) or ask us to do so, and we will delete those items.
In summary, we keep your data only as long as you want us to (since the service is user-directed) or as long as needed to carry out the service. If you remove your data or request deletion, we honor that and do not hold on to your personal information longer than necessary. Our aim is not to accumulate data but simply to serve your needs with the FinalSaying service.
Your Rights Under GDPR
Because we operate in the EU (and even if you're elsewhere, we want to extend the same principles), you have certain rights regarding your personal data. We fully respect and uphold these rights. Under the GDPR (General Data Protection Regulation), you have the following rights:
- Right of Access: You have the right to request a copy of the personal data we hold about you. This means you can ask us to confirm if we're processing your data and provide you with a copy of that data, as well as information about how we use it. For example, you can ask us to send you a report of your account information and any messages or attachments you have stored (note: message content would be provided in an understandable format – if it's encrypted, we may need to work out a way to provide it in decrypted form to you securely, since it's your data).
- Right to Rectification: If any personal data we have about you is incorrect or incomplete, you have the right to have it corrected. In practice, this might mean if your name is spelled wrong in our records or your email has changed, you can update it (either via your Google account or by telling us). We want to make sure we have accurate data, so we will gladly correct any mistakes. For user-generated content like your messages, rectification could mean you editing those messages if you wish; you typically have control to update your own content while you are alive and have access.
- Right to Erasure: Also known as the "right to be forgotten." You can request that we delete your personal data. This isn't limited to account deletion — you can ask us to remove any or all personal information we have about you. For FinalSaying, this would most often mean deleting your account entirely (and thus removing your name, email, messages, attachments, etc. from our systems). We absolutely respect such a request and will carry it out, except in cases where we legally must keep certain data (as noted in the Data Retention section, e.g. transaction records). If you request erasure, please note this is irreversible – if your data is deleted, any final messages that were scheduled will not be delivered because we will no longer have that data. We will inform you of the consequences if you choose to delete data that would affect the service.
- Right to Object: You have the right to object to our processing of your data in certain circumstances. Given our no-marketing, no-tracking policy, the most relevant ground for objection in our case would be if we were processing your data under a "legitimate interest" and you have a particular situation that makes you want to object to that. For example, if for some reason you object to us holding your data for message delivery (perhaps you have changed your mind about using the service), you have the right to object. In practice, since we rely mostly on consent and minimal legitimate interest, an objection would likely be resolved by either us stopping that processing or by deleting your data (which is essentially the same outcome as a deletion request). You always have the right to object to any potential direct marketing use of your data – but we do not do any marketing with your data, so this is more a theoretical right in our context.
- Right to Data Portability: You have the right to obtain the personal data you provided to us in a structured, commonly used, machine-readable format, and you have the right to transmit that data to another service (or ask us to transmit it, where technically feasible). In simpler terms, you can ask for an export of your data that you could, for example, import into another application or just keep for your own records. For FinalSaying, this would likely mean we can give you a structured file (perhaps JSON or CSV or similar) containing your account info and the messages and attachments you saved (attachments could be provided in their original file form, and messages as text). We'll work with you to provide the data in a useful way if you need this. Portability applies to data you provided us directly or data generated by your activities, and since we don't generate much beyond what you provide, this largely overlaps with the Right of Access. Still, we are happy to help you port your data if needed.
- Right to Withdraw Consent: If we are processing any of your data based on your consent, you have the right to withdraw that consent at any time. For example, you consented to us using your Google account info when you signed up — you can later withdraw that consent by simply deleting your account (or contacting us to do so). Withdrawing consent will not affect the lawfulness of any processing we already did while we had your consent, but it will mean we stop processing your data going forward. In practice, withdrawing consent from FinalSaying would usually mean we have to deactivate or delete your account, since the service relies on the data you provided with consent. We will inform you if withdrawal will lead to service termination so you can make an informed choice.
- Right to Restrict Processing: In certain situations, you have the right to ask us to limit the processing of your data (essentially to just store it but not use it). This can be exercised, for example, if you believe your data is inaccurate (you can request restriction while we verify it), or if you have objected to processing and await verification of our grounds, or if you need us to preserve data for a legal claim while otherwise you'd want it erased. In our context, restricting processing might mean we keep your account and data but don't do anything with it until an issue is resolved. Since our default is not to use your data except for what you ask, restriction might rarely apply, but we will honor it if needed.
- Right to Lodge a Complaint: If you believe your privacy rights have been violated or you have a concern about how we handle your data, you have the right to lodge a complaint with a supervisory data protection authority. You can do this in the EU member state where you live, where you work, or where we are based (Germany). For example, in Germany the relevant authority is the Berliner Beauftragte für Datenschutz (Berlin Commissioner for Data Protection) since our operation is in Berlin. We would, however, appreciate the chance to address your concerns directly first – we're committed to privacy and will do our best to resolve any issues if you contact us.
We will not discriminate against you for exercising any of these rights. To exercise your rights, you can contact us at our email address provided below. We may need to verify your identity to fulfill certain requests (for example, to ensure that we don't give your data to someone else pretending to be you). Once your identity is confirmed, we will promptly act on your request. We aim to respond to all valid requests within one month, as required by GDPR, and usually sooner.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. If we make changes, we will post the updated policy on this page and update the "Effective Date" at the top. For significant changes, we may also notify users via email or a prominent notice on the site, so you are kept informed.
Some reasons we might update the policy include: adding new features (for example, if we add a new third-party provider or a new way of collecting data, we'll update the policy accordingly), changes in applicable law, or improvements in our security and privacy measures. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting the personal data you entrust to us.
If you continue to use FinalSaying after a Privacy Policy update, we will take that as acknowledgment of the changes. However, if any change requires new consent from you (for example, if we ever wanted to collect additional data or use it for a new purpose), we will obtain that consent explicitly.
Contact Information
If you have any questions, concerns, or requests regarding your privacy or this Privacy Policy, please do not hesitate to contact us:
Email: contact@finalsaying.com
This is the dedicated contact for privacy and data protection inquiries. Whether you want to request deletion of your data, exercise any of your rights, or just ask a question about how we handle personal data, you can reach us at that email address. We will respond as quickly as possible.
Data Controller: Because FinalSaying is operated by a private individual in Germany, that individual is the data controller responsible for your personal data. You can use the above contact information to reach the data controller (the operator of FinalSaying).
We are committed to the principles of transparency, fairness, and user control in privacy. Your trust is very important to us. If anything in this Policy is unclear, please contact us and we will gladly explain or provide more details.
Thank you for reading our Privacy Policy. We hope it gives you confidence that your data is handled with care. Enjoy using FinalSaying, knowing that your privacy is respected.
