Skip to content
LifeMuseum

The fine print

Privacy Policy

Last updated 10 September 2026

LifeMuseum is built so that almost nothing about you reaches us. Your museum lives in a database on your own phone. This policy explains the few, deliberate exceptions, in plain language and in full.

Who is responsible

LifeMuseum is published by DevTaskHub, Greece, which is the data controller for the limited personal data described below. Contact: devtaskhub@devtaskhub.com.

This policy applies to the LifeMuseum mobile application on iOS and Android and to the small set of servers behind its optional online features.

What stays on your device

Your exhibits, photographs, videos, dates, places, notes, tags, galleries, Before I Die list, collections, badges, statistics, time capsules, movies and posters are stored in a local database on your phone and in your own photo library.

None of it is transmitted anywhere by default. The app is fully usable with no account and no internet connection at all, and in that mode we can never see any of it.

Because this data lives on your device, it is covered by your device passcode and your own device backups. If you back your phone up to iCloud or Google, your museum goes with it, under Apple’s or Google’s terms rather than ours.

What leaves your device, and only when you ask

Publishing an exhibit uploads that one exhibit to your public museum: its title, description, place, date, tags and its own photographs. Nothing else is uploaded. Published content is visible to anyone using the app, and can be seen, screenshotted or copied by them. You can unpublish at any time, which deletes the stored copy and its files.

Creating a public profile stores an email address, a handle, a display name, an optional short bio and an optional profile picture, so other people can find your museum.

Turning on Cloud Sync copies your museum and its media to private, access-controlled storage so it can be restored onto another device. This happens only while the subscription is active and only after you switch it on.

In Couple Mode, an exhibit is shared only when you press Share on that specific exhibit. Its title, description, place, date and photographs then become readable by the one other person in your shared museum. The files are held in private storage and served through short-lived signed links. Removing the exhibit from the shared museum deletes that copy and its files. The rest of your museum is never visible to them.

Reporting content or a person sends us the report, what was reported and your account identifier, so the complaint can be acted on.

Why we are allowed to hold it

Where the GDPR applies, our legal basis for handling your account details, published content and shared content is performance of a contract with you: you asked for a public museum, a backup or a shared museum, and it cannot be provided without them.

Our basis for handling reports, blocks and moderation records is our legitimate interest, and our legal obligation, in keeping a user-generated-content service safe and lawful.

Location, camera, notifications and the daily reminder are handled on the basis of the permission you give, which you may withdraw at any time in your device settings.

Who else touches it

Supabase hosts the database and the file storage for every online feature. Data is stored in the European Union (Ireland).

Apple and Google process every payment, receipt and refund, and RevenueCat verifies those receipts so the app knows what you own. None of them receives your museum.

Expo delivers app updates. Checking for an update sends the usual technical request information, such as an IP address and the app version.

Resend delivers the emails the online features send: the sign-in link you ask for, to your own address, and the email a report generates, to our own inbox.

That is the complete list. There is no advertising network, no analytics SDK, no attribution SDK, no data broker and no social-media tracking pixel anywhere in this app.

What we never do

We do not show advertising, and we do not sell, rent, trade or share your data with advertisers or data brokers, for money or for anything else.

We do not read, scan, index, profile or train anything on your photographs, videos or writing. LifeMuseum contains no artificial intelligence or machine-learning feature, and nothing you put into it is sent to any AI service, ours or anyone else’s. If that ever changes, this policy will say so before the feature ships, and it will be something you switch on rather than something that happens to you.

We do not upload anything sealed in a time capsule or held in the Secret Vault, under any circumstances, including Cloud Sync and Couple Mode.

We do not build advertising profiles, track you across other apps or websites, or use your data to make automated decisions about you.

Permissions and why

Photo library: to let you choose the photographs and videos that become exhibits, and to save exported movies and posters back to your library.

Camera and microphone: only if you capture a moment directly into an exhibit.

Location: optional, and only when you tap “Use my location” while creating an exhibit. The coordinates are stored on your device with that exhibit.

Notifications: only for the daily reminder you can switch off, and to tell you when a time capsule you sealed is ready to open.

Every one of these can be refused, and refusing any of them leaves the rest of the app working.

Payments

In-app unlocks and the Cloud Sync subscription are processed by Apple or Google. They handle the payment, the receipt and any refund under their own terms and privacy policies.

We receive confirmation that a purchase is valid and an anonymous purchaser identifier. We never receive, store or transmit a card number, and we cannot charge you ourselves.

How long anything is kept

Published exhibits and your public profile are kept until you delete them or delete your account.

A Cloud Sync backup is kept while the subscription is active, and is deleted when you delete your account or switch the backup off and clear it.

Reports and moderation records are kept for up to twelve months so repeat abuse can be recognised, then deleted.

Deleting your account removes your profile, your published exhibits, your shared exhibits, your backup, your likes, your follows, every file you uploaded, and the login itself. This is immediate and cannot be undone.

Your rights

You can delete everything on your device at any time from Me → Empty the museum. This is immediate and irreversible.

You can unpublish anything you published, which deletes the stored copy and its files.

You can delete your entire account from Me → Delete account, inside the app, without asking us and without writing to anyone.

Under the GDPR you may also request a copy of the data we hold, correct it, object to or restrict processing, withdraw consent, and complain to your national data protection authority. Write to us and we will answer within 30 days.

Security

Everything that leaves your device travels over TLS. Private storage is reachable only through row-level rules bound to your own account, and shared files are served through links that expire.

No system is perfect, ours included. Keep your own copies of anything irreplaceable, and treat anything you publish as public permanently, because other people can copy it before you change your mind.

Children

LifeMuseum is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created a public profile, contact us and we will remove it.

Changes to this policy

If this policy changes materially, the app will say so before the change takes effect, and the date at the top will change. Continuing to use the app after that means the updated policy applies to you.

Questions, requests or complaints: devtaskhub@devtaskhub.com. Every message is read by a real person, usually answered within two working days.