← Home

Privacy

What we collect, and why.

This page is maintained by LivedThrough to answer common privacy questions. It describes the controls actually built into the product today. It is not legal advice and not an independent certification.

Last updated · June 2026

What we collect

  • Account: email, display name, password hash (or OAuth identity), age confirmation.
  • Seeker check-in: the stage / want / language fields and tag interests you provide.
  • Provider profile: story, headline, tags, rate, location at city/country resolution, optional age bracket, and a moderator-only ID document.
  • Session content: messages between you and your peer inside a booked session.
  • Operational: sign-in events, basic analytics, reports filed, moderator actions.

Why we collect it

To run the matching and booking flow, to keep the platform safe, to pay providers accurately, and to surface crisis resources when a session indicates risk. We don't sell your data and we don't use it to train third-party models.

Who can see what

  • You: your own account, your sessions, your messages.
  • Your peer: what you write inside the session you booked with them, and your display name.
  • Moderators: reports filed about a session and the messages inside that specific session.
  • Public: a provider's chosen story, tags, and city/country — nothing else.
  • Never public: seeker identities, intake answers, ID documents, message logs, ratings.

Retention

  • Account data: kept while your account exists.
  • Session messages: kept for 90 days after the session ends, then deleted from primary storage.
  • Reports: kept for 2 years for safety review history, then redacted.
  • Payment records: kept as long as tax & accounting law requires.

Your controls

  • Update or delete your profile from Account.
  • Export your data on request — email privacy@livedthrough.app.
  • Delete your account from Account → Danger zone. We hard-delete personal fields and anonymize past sessions.

Subprocessors

We rely on a small set of vendors: Supabase (database, auth, storage), Stripe (payments), Resend (transactional email), and Cloudflare (hosting and edge). Each one only sees the data necessary to do its job.

Children

LivedThrough is for adults. You must confirm you are 18+ at sign-up. We don't knowingly collect data from anyone under 18.

Changes

If we make a material change to this notice, we'll surface it in the app and email active accounts before it takes effect.