Privacy
Last updated: 2026-10-02
This is a plain-language summary of how LiferList handles your data, not legal advice. LiferList (contact@lifer-list.com) runs the site. Anyone can create an account when sign-ups are open.
What we keep, and why
- Your sign-in email and password, in Amazon Cognito. We never see your password.
- Your life list, outings, sightings, places (with the exact spot only when you choose to save one), notes and count overrides.
- Your photos, videos and recordings at full resolution, with location data, serial numbers and owner names removed from the files themselves. Their capture time and GPS location are kept privately in our database to suggest outings and places; we never show them to anyone else.
- What you imported from eBird (see below).
- Your share links; the name, picture and About you text you choose to show on shared pages (see Sharing); your light / dark appearance choice; and any feedback you send us (see below).
- An upload API key, if you make one (More → API access): only a one-way fingerprint of it, when it was made and last used, and how many uploads it made today. Revoking it or deleting your account removes it.
- If you have a paid plan: which plan, its status and renewal or end dates, and a reference to your customer record at Stripe. Your card details go straight to Stripe; we never see or store them.
- If you sign in with Google: your email address and that Google verified it (nothing else from your Google account).
"Use my location"
When you use "Use my location", the point is looked up on our own server to name your county. We don't store it unless you save it as a place's exact spot, and nothing is sent to a map service.
In the Android app
In the Android app, when you use Take photo and the photo has no location of its own, the app reads your phone's location once (only if you allowed location) to pick one of your saved places; that location is sent to LiferList only to find the place and isn't stored. Photos and videos you take in the app are also saved to your phone's gallery, in a LiferList folder. In the Android app, HEIC photos are converted to JPEG on your phone before they are uploaded, keeping their date, time and location.
Your eBird export
You upload your own "Download My Data" file from eBird. We read it and keep the outings and sightings it contains; the file itself is deleted automatically about 31 days after you upload it (30 days, plus a 1-day recovery copy the storage service removes on its own schedule). LiferList doesn't use eBird's API and isn't affiliated with eBird or the Cornell Lab of Ornithology.
Who else sees your data (processors)
- Amazon Web Services hosts the app at app.lifer-list.com: your data lives in the US East (Ohio) Region, and Amazon CloudFront delivers the app and your media from edge locations worldwide.
- Amazon Cognito signs you in.
- Stripe processes payments for paid plans. When you pay, Stripe receives your email address, your name and billing address if you give them, and your payment details, under its own privacy policy. Stripe's checkout and billing pages are on stripe.com and set Stripe's own cookies.
- Amazon Simple Email Service sends LiferList's emails (sign-up codes, password-reset codes, email-change codes) from no-reply@lifer-list.com.
- Google signs you in if you choose Continue with Google.
- Cloudflare runs the DNS for lifer-list.com and hosts its front page, which has no cookies, scripts or analytics; like any web host, it sees your IP address and browser details when you open that page.
- Cloudflare Email Routing receives messages sent to contact@lifer-list.com and forwards them on; Cloudflare doesn't store the message content, but keeps a record of each one's sender, recipient, subject and delivery result for about a month.
- Mail sent to contact@ — and our replies — end up in the owner's personal Gmail mailbox. That's a consumer Google account, not a contracted data processor, so it isn't listed as one here; it's simply where that mail is kept.
- Feedback you send from More → Send feedback is kept with the screen you came from, the app version and your browser; an automatic alert tells us new feedback arrived (just which kind — bug, idea or other — never its content), and the feedback itself is deleted with your account.
No advertising, no analytics, no third-party scripts, no selling or sharing of your data.
Species information
Species names come from AviList (CC BY 4.0). Species text comes from Wikipedia, and images from Wikimedia Commons and iNaturalist contributors. We store all of it on our servers ahead of time, so your browser never contacts those sites and nothing about you is sent to them.
Sharing
Nothing about your list is public unless you share it. You make share links under More → Sharing. Anyone who has one of your links can see, without signing in, your life list, species pages, outings, single sightings and every photo, video or recording you filed with a bird (or as "Unknown bird"), with its caption — photos at preview size; videos and recordings as the full file we keep (the one described above, location data removed), which a viewer can play and, when their browser can't play it, download — until you turn that link off, hide the item, or turn off sharing for that outing or sighting.
- Places show only as county, state and country — never exact spots, GPS, place names, notes or eBird IDs — and dates without times.
- Birds eBird treats as sensitive show only the year where and when they're sensitive, without a place or an outing, and their photos, videos and recordings aren't shared.
- The name, picture and About you text you set on the Sharing screen are shown on shared pages (the picture without its location or camera data); they are deleted with your account. A link's label is only for you.
- Names you give your outings are shown on shared pages; your notes never are.
- Turning a link off stops its pages at once. Photo addresses already opened through it keep working for up to 15 minutes, video and recording addresses for up to an hour, and a messaging app may keep the preview picture it made of the link.
A public profile is optional, off by default, and not available yet.
Reports and the law
- If someone reports content shared from your account (abuse@lifer-list.com), we may look at what was shared to decide what to do.
- We report apparent child sexual abuse material to the National Center for Missing & Exploited Children, as US law requires, and keep what the law requires us to keep (one year).
- Copyright notices are handled as the Copyright page describes.
Cookies and browser storage
- Your sign-in tokens, in your browser's local storage.
- Short-lived, HttpOnly cookies that let your browser load your own private photos, videos and recordings.
- Upload-resume notes in your browser, removed when you sign out or delete your account.
- The Amazon Cognito sign-in page sets its own short-lived sign-in cookies (about an hour) while you're signing in.
- Your light / dark appearance choice, in your browser's local storage (
ll.theme).
Nothing here is used for tracking.
How long we keep things
- Your data, until you delete it or your account.
- Deleting your account removes everything from the app within a few hours.
- Database backups keep a copy for up to 14 days.
- Deleted photos, videos and recordings stay recoverable by us for about 30 days, then the storage service removes them.
- Raw uploads (with location data still in the file) are removed about 4 days after upload.
- Server logs (request details, including IP address and browser type) are kept for 30 days.
- Messages you send us: in our mailbox until we delete them.
- AWS keeps its own records of sign-ins and account changes — the time, the IP address and an internal user ID, never your password — for 90 days (AWS CloudTrail).
- Copies of your media cached at CloudFront's edge locations can't be opened without your sign-in or a share link's photo address (which stops working within 15 minutes, or an hour for videos and recordings), and expire on their own.
- Payment records stay with Stripe for as long as Stripe and tax law require. When you delete your account we delete your customer record at Stripe, which ends any paid plan.
Your choices
You can see, correct and delete your data in the app: single items, or your whole account (see deleting your account). There's no self-service export yet; ask us for a copy, or anything else, at contact@lifer-list.com.
Children
LiferList isn't for children under 13.
Security
Your data is encrypted in transit and at rest. Sign-in emails are signed (DKIM) so your mail provider can tell they really came from us.
Changes
We'll update this page, and its date, when anything here changes.