Privacy Policy
Last updated: October 1, 2026. This English version governs.
This policy explains how SHLF ("SHLF", "we", "us"), operated by [Company legal name], [registered address], handles personal data when you use shlf.live and related services (the "Service").
1. Data we collect
- Account data: name, email address, profile picture, and sign-in details (including from Google if you use Google sign-in).
- Content: files, links, notes, embeds, comments and shelf settings you add.
- Billing data: plan, subscription status and payment history. Card details are handled by our payment processor; we never see or store full card numbers.
- Usage data: log data such as IP address, browser type, pages visited and timestamps, used for security and reliability.
2. How we use it
- To provide the Service: store your shelves, show them to the people you share them with, and keep version history.
- To process payments and manage subscriptions.
- To send service emails (account, security, billing). We send marketing only with your consent.
- To keep the Service secure, prevent abuse and fix problems.
Legal bases (EEA/UK): performance of our contract with you, our legitimate interests in running a secure service, compliance with law, and your consent where required.
3. AI features
AI features (Executive Brief, Ask AI) run only when you use them and only on shelves you can already access. The relevant content is sent to our AI provider to produce the answer. We do not use your content to train AI models, and our providers may not use it to train theirs.
4. Sharing
We don't sell your personal data. We share it only with:
- People you choose: team members and anyone with a public link you create.
- Sub-processors who run the Service for us: cloud hosting and database (United States), payment processing (Stripe), AI model providers, and email delivery.
- Authorities, when required by law or to protect rights and safety.
- A buyer or successor in a merger or acquisition, under this policy.
5. Where data is stored and security
Your data is stored in the United States (US East region) on enterprise-grade cloud infrastructure. Data is encrypted in transit (TLS) and at rest. Access is controlled per shelf with row-level security. Where data is transferred from the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards.
6. Retention
We keep your content while your account is active. Earlier versions are kept so the timeline stays complete until you delete the item or shelf. When you delete your account, we delete your content within 30 days, except where we must keep records (for example billing records) by law.
7. Your rights
Depending on where you live (including under GDPR and CCPA/CPRA), you may access, correct, export or delete your data, object to or restrict processing, and withdraw consent. We do not "sell" or "share" personal information for cross-context behavioral advertising. To exercise your rights, email privacy@shlf.live. You can also complain to your local data protection authority.
8. Cookies
We use only essential storage needed to keep you signed in and remember your language and currency. We don't use advertising cookies.
9. Children
The Service is not intended for children under 16, and we don't knowingly collect their data.
10. Changes
We'll post updates here and notify you of material changes by email or in the app before they take effect.
11. Contact
privacy@shlf.live ยท [Company legal name], [registered address]