Privacy
Last updated 24 August 2026
This page is about your data — what we hold if you have an account, how long we keep it, and who else sees it. What we collect from brand accounts is covered in the terms.
Who is responsible
MARNETTE.MEDIA, Société en commandite (SComm), company number 0722.977.820, Rue St-Pierre 43, Boîte 7, 4500 Huy, Belgique. Contact: hello@twentyfourever.com.
[ to be confirmed — whether a data protection officer is required, and if so who — depends on the legal review ]
What we hold about you
If you have an account: your email address, a hash of your password (never the password itself), your first and last name if you gave them, your occupation if you gave it, your display preferences, and the date you signed up.
What you create: the sequences you save, the notes you write on them, the collections you build and the client boards you organise.
If you subscribe: your Stripe customer and subscription identifiers, your plan and its status. We never see or store your card. It is handled by Stripe and never reaches our servers.
When we send you an email: we record that we sent one, with a hash of the address and a hash of the IP — never the address or the IP themselves. It exists only to stop the sign-up form from being used to send mail to arbitrary people.
How long we keep it
| Your account | until you delete it — deletion is immediate |
| Sign-in and reset links | 7 days after they expire or are used |
| Email sending log (hashed) | 30 days |
| Database backups | 90 days |
One consequence we would rather state than hide: when you delete your account, the row is removed at once — but backups taken before that date still contain it, and they expire after 90 days. Your data is therefore fully gone within 90 days, not instantly.
Who else sees it
| Who | What for | What they see | Outside the EU |
|---|---|---|---|
| Amazon Web Services | hosting, media storage, delivery | everything that passes through the site | — |
| Amazon Web Services (RDS) | database | accounts, collections, notes | — |
| Resend | transactional email delivery | the recipient address | — |
| Stripe | payment and subscriptions | billing identity, payment method | standard contractual clauses |
| Meta | advertising audience measurement | browsing, hashed address | not verified |
| Apify | collection of public stories | no subscriber data | not applicable — no subscriber personal data |
| Anthropic | automated reading of sequences | no subscriber data — brand images only | standard contractual clauses (decision 2021/914, modules 2 and 3) |
Three of them process data outside the European Union. Anthropic and Stripe do so under the European Commission's standard contractual clauses. Apify never receives any subscriber data — only public brand images — so no personal transfer takes place.
For Meta: [ to be confirmed — we have not been able to verify, at Meta's own source, which transfer mechanism applies — their data processing terms point to an addendum we cannot read without an account. We would rather say so than name a mechanism we have not read ]
The site, the database and the images are all hosted by Amazon Web Services in Frankfurt (eu-central-1), inside the European Union.
Cookies
| twf-theme | light or dark theme | one year |
| next-auth / authjs | sign-in session | the session |
| _fbp, _fbc | Meta measurement | three months — advertising measurement |
The last two are set by Meta and are not necessary to use the site. [ to be confirmed — a consent banner is required before these load, and there is none today — this is a gap, not an omission in the text ]
What you can ask for
A copy of your data, a correction, or its deletion. Write to hello@twentyfourever.com. You can delete your account yourself from your settings, which is faster than asking us.
[ to be confirmed — the right to lodge a complaint with a supervisory authority — which one depends on where the operator is established ]
Changes
If we change this policy, the date at the top changes with it.
Questions about this text: hello@twentyfourever.com