Privacy

Last updated 3 August 2026. This explains what Liferafts stores about you, why, and what you can ask us to do about it.

Who is responsible

Liferafts is run by Elliot Smith, based in Victoria, Australia, who is responsible for everything described here. To ask a question, get a copy of your data, or have it deleted, email privacy@theliferafts.com.

We handle your information according to the Australian Privacy Principles. If you are in the United Kingdom or the European Union, the section on your rights below covers the extra protections you have.

What we store, and why

Your account
Your email address, the display name you choose, your timezone, and a hashed version of your password. We need these to sign you in, to show your name to the people in your groups, and to send reminders at the right hour. We never store your password itself.
What you write and track
Your goals, the numbers you record against them, your weekly posts, comments, likes and any images you attach. This is the service. It is visible to the active members of the groups you share it with, and to nobody else.
Your groups
Which groups you belong to, whether you administer them, and the notification settings you have chosen for each one.
Connected services
If you connect Strava, we store the access tokens it gives us, encrypted, along with the activity figures you have asked us to record. Disconnecting deletes the tokens. If you create an API key we store only a hash of it, so we cannot read it back to you or to anyone else.
Health-related numbers, if you track them
Things like bodyweight, resting heart rate, hours of sleep or days without a drink count as health information, which the law treats as sensitive and protects more strictly. We only ever have these because you typed them in or connected a service that supplies them, which is you consenting to us holding them. You can delete any of them at any time, and you decide whether your group sees them at all.
Things other people tell us about you
If someone invites you to a group by email, we hold that address so we can send the invitation, before you have an account and before you have told us anything. If you do not accept, tell us and we will delete it. Anything a member of your group writes about you in a post or comment is theirs, and we hold it the same way we hold everything else they write.
Technical logs
Ordinary server logs, which include IP addresses and browser user agents, kept so we can find faults and abuse.

Cookies and analytics

We do not use tracking cookies, and there is no consent banner because there is nothing to consent to. Our analytics provider is configured to store nothing at all on your device: no cookies, no local storage, no session storage. Visitors are counted using a hash generated on the server that changes every day and cannot be traced back to a person.

The only cookies Liferafts sets are the ones that make signing in work: a session cookie and a security token to protect forms you submit. Both are strictly necessary and neither is used to track you.

Once you are signed in we record which features get used, so we know what to improve. Those records are keyed to your account's internal ID number. Your email address and your name are never sent to our analytics provider, and the contents of your posts, comments and metrics never are either.

Who else sees it

We do not sell your data and we do not share it for advertising. A small number of companies process it on our behalf so the service can run:

  • PostHog (United States), for the usage analytics described above.
  • SendGrid (United States), to deliver email. It sees your address and the contents of the emails we send you, which includes the posts in your groups if you have those notifications switched on.
  • Strava (United States), only if you connect it, and only to read the activities you have asked us to read.
  • Binary Lane (Australia), who host the servers holding the database and the backups.
  • Backblaze (United States), which stores the images you attach to posts.

Liferafts is run from Australia, and your account, your posts and your numbers live on Australian servers. Some things do leave the country: any image you upload is stored in the United States, as are the emails we send you, the usage analytics described above, and your Strava activities if you connect it. We take reasonable steps to make sure anyone handling your information protects it to the standard we are held to, and we require it of them by contract. We will hand data to the authorities only when we are legally required to.

How we protect it

Everything travels over an encrypted connection, and browsers are told to refuse an unencrypted one for a year at a time. Your password is stored only as a hash, using the algorithm Django ships and recommends, so nobody here can read it. API keys are stored the same way, as a hash, which is why we can only show you a new one once. The access tokens for a connected service such as Strava are encrypted before they are written down, with a key kept separately from the database.

Access to your content is checked on every request against the groups you actually belong to. Sign-in cookies are marked secure and are not readable by scripts. Backups are taken nightly and are held on the same Australian servers as the live database.

No system is completely secure.

Automated decisions

We do not use artificial intelligence or automated profiling to make decisions about you. The only automated judgements here are anti-spam checks when an account is created or an integration is requested, which can refuse a submission that looks like a bot. If that happens to you and you are a person, email us and we will sort it out.

Age

Liferafts is for adults. You confirm you are 18 or over when you create an account, and we do not knowingly collect anything from anyone younger. If you believe someone under 18 has an account, tell us and we will remove it.

How long we keep it

Your account and everything in it stays until you delete it, which you can do yourself at any time. If you leave a group without deleting your account, your posts stay with the group unless you remove them, and you keep access to your own history. Backups are kept for a short rolling window and are overwritten in turn, so deleted data can persist there for a little while before it ages out.

If something goes wrong

If there is a breach that we think could seriously harm you, we will tell you and the Office of the Australian Information Commissioner. We will say what happened, what was affected, and what you should do about it.

Your rights

You can delete your account yourself, from your profile page, without asking anyone. It takes your goals, your numbers, your images, and every post and comment you have written, including the ones in other people's groups. It is immediate and permanent, and we cannot undo it for you, so take a copy of anything you want to keep first.

Plenty else you can do without asking too. Export any number as a spreadsheet, read everything through the API, edit or delete individual posts, and change what your group can see, all from inside the app.

You can also ask us for a copy of what we hold about you, or to correct anything that is wrong. Email privacy@theliferafts.com and we will get back to you within 30 days.

We only collect what we need to run the service and improve it. If you are unhappy with how we have handled your information, tell us first and we will try to fix it. If you are still unhappy you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

If you are in the United Kingdom or the European Union you have further rights, including to object to or restrict how we use your information and to have it sent to another provider. We rely on our agreement with you for the parts needed to run your account, on our legitimate interest for security logs and usage analytics, and on your consent for anything you switch on yourself, such as connecting Strava. You can complain to your national data protection authority, which in the UK is the Information Commissioner's Office at ico.org.uk.

Changes

If we change what we collect, this page changes in the same release, and the date at the top changes with it. We also read it through once a year whether anything has changed or not. If a change materially affects you, we will tell you rather than quietly editing this page.