Privacy
What we know about you and about the people you love, why we know it, and what we do with it. Written to be read, not to satisfy a formality.
August 12, 2026
Who the controller is
The controller is Ing. Martin Polak, a sole trader, company number 29812798, registered office Nebovidy 151, 664 48 Nebovidy, entered in the Czech trade register.
You can write to us at info@saylastword.com. A person answers, not a robot.
What we store
- Your account: e-mail address, the name signed under your messages, your language and an identifier from sign-in.
- Your messages: text, voice and video recordings, and a transcript where one was made.
- Your life timeline: dated milestones of your life with a title and text — and so, inevitably, mentions of the people who were in it.
- Share links for the timeline: a random token (we keep only its hash), your own label, and when the link was made and revoked.
- Your loved ones: name, relationship, e-mail, phone, postal address and your private note. You give us these — they do not.
- Your trusted contacts: name, e-mail, phone and language.
- Life check: when you last confirmed you are here, and how often we should ask.
- Payments: your Stripe customer and subscription identifiers, currency and payment status.
- Operational logs: IP address and technical details of requests to the server.
We never see or store your card number. Stripe handles the whole payment on its own pages; all that comes back to us is that it succeeded, and the last four digits.
We do not read the contents of messages. We have no reason to and no interest in it — the only things we do with them are keep them and, at the right moment, deliver them.
Why we process it
| What | Why | Legal basis |
|---|---|---|
| Account and messages | To provide the service at all | Contract |
| Life timeline and its share links | Keeping your life story, and showing it to whoever you decide to show it to | Contract |
| Data about loved ones and trusted contacts | To deliver a message and to verify a death | Legitimate interest (see below) |
| Payment data | Processing payments and bookkeeping | Contract, legal obligation |
| Operational logs | Security and debugging | Legitimate interest |
The people who have never heard of us
This is the most important part, and most services like ours quietly skip it. We hold the name, e-mail and phone number of your loved ones and your trusted contacts — and they have no idea. We got those details from you, not from them.
The GDPR (Article 14) says we should normally tell such people. We do not tell them in advance, and that is a deliberate decision.
If we wrote to your loved ones ahead of time to say “someone has prepared a message for you”, we would give away precisely what is meant to stay quiet until you die. For some messages that would be worse than awkward: there are letters written exactly so that nobody else ever learns of them.
We rely on the exemption in Article 14(5)(b) — informing them in advance would render the very purpose of the processing impossible. Instead we inform them at the first communication, which is the delivery itself, and this text is publicly available to anyone before then.
Until that moment we do not contact your loved ones. Ever. Not to test, not to “verify an address”.
We approach trusted contacts in two cases only: when you have stopped answering the life check and we ask them what happened, or when a message could not be delivered and you expressly allowed us to ask them for help with that message. Even then we tell them who it was for — and never what it said.
If you have arrived here as someone's loved one or trusted contact and do not want this, write to info@saylastword.com and we will delete your details. It means we will not be able to deliver the message to you — and it is right that this decision is yours.
Who else touches the data
We do not sell it or pass it on for anyone else's purposes. These four processors can technically reach it, and no others:
| Who | For what | Where |
|---|---|---|
| Hetzner Online GmbH | The server — database, recordings, sign-in | Germany |
| Websupport s.r.o. | Outgoing e-mail and bounces | Slovakia |
| Stripe Payments Europe, Ltd. | Payments | Ireland |
| seven communications GmbH | SMS after a verified death | Germany |
The database, the recordings and the sign-in system all run on one server in Germany. We do not use a third-party cloud for file storage or a third-party sign-in service.
Stripe may process some data outside the EU, under standard contractual clauses approved by the European Commission. That concerns payments, not the contents of your messages.
We may also hand data to public authorities where the law requires it. Nothing else will compel us.
When you share your timeline while alive
Messages leave only after a death has been verified. The life timeline is the single exception — and you are the one who makes it. You can create a link and send it to anyone; whoever holds that link reads the timeline straight away, without an account.
- The link contains a random token. All that stays with us is its hash, so we cannot show it to you again or send it on your behalf.
- You can revoke it whenever you like. From that moment it works for nobody who has it.
- The link cannot reach your messages. It opens the timeline and nothing else.
- We do not record who opened it. So we cannot tell you who has read it.
A link can be forwarded. Whoever receives it also receives access — so expect that people you did not send it to may come to know your timeline. If that stops feeling right, revoke the link and make a new one.
A life story inevitably speaks of other people — partners, children, parents. You write it and you decide who receives it; we do not read it, moderate it or publish it anywhere. If you are named in someone's timeline and object to it, write to the address below and we will take it up with you.
After your death, a link you already made keeps working. That is deliberate: a family who read your timeline while you were alive should not lose it at the moment it matters most to them.
What we do not do
- We have no analytics — not Google Analytics, not any other.
- We have no advertising or tracking scripts. None.
- We do not sell data or share it with advertisers.
- We do not load third-party fonts at run time — fonts come from our own server, so nobody else learns of your visit.
- We do not profile you and make no automated decisions about you.
That is why this site has no cookie consent banner. There is nothing to consent to.
How long we keep it
We keep your account and messages until you delete them or close the account. There is a deliberate exception here, and it is only fair to say it plainly:
We keep messages for the long term because that is the point of the service. Even if you stop paying, your messages stay stored and deliverable. If we deleted them after a year, the whole product would be a lie.
- Delivered messages: the recipient's link keeps working, so they can come back to it.
- Payment records: 10 years, as accounting law requires.
- Operational logs: a matter of months.
- When you delete your account we delete the messages, recordings, loved ones and trusted contacts. Only the accounting records we are obliged to keep remain.
After death
The GDPR does not apply to the data of deceased people. We handle it just as carefully anyway — your messages stay private, we do not read them, and we make them available to nobody except the people you chose yourself.
The data of your loved ones and trusted contacts stays protected in every case, because they are still living.
Your rights
- To know what we hold about you, and get a copy.
- To have what is wrong corrected.
- To have it deleted.
- To restrict what we do with it.
- To take your data elsewhere in a machine-readable form.
- To object to processing based on legitimate interest.
Write to info@saylastword.com. We will come back to you within a month.
If you think we are handling your data badly, you can complain to the Czech data protection authority (uoou.gov.cz) or to the authority where you live. We would rather you wrote to us first.
Security
- Connections are always encrypted (HTTPS), with certificates renewed automatically.
- Access links for recipients and trusted contacts are stored only as a hash — they cannot be read back out of the system.
- Recordings are not publicly reachable; links to them are short-lived.
- Only the service administrator has access to production data.
If a breach happened that could put you at risk, we will tell you — and report it to the authority as the law requires.
Changes
When something material changes we will update this text and the date at the top. If the change affects you, we will write to you.