Privacy Policy
Last updated: 11 May 2026
This notice describes transparently how LifeSkills processes personal data when you browse the site or use the account area.
Data controller
The data controller is the LifeSkills team, reachable by email. As an early-stage student-led project we have not appointed a Data Protection Officer (DPO).
Privacy contact email: lifeskills.project@gmail.com
Scope
This policy applies to lifeskill-web.com and all its sub-pages, including the Italian, Spanish and French localized areas.
The site offers public informational content (country and US state guides) and an optional account area to save profile, avatar and personal trackers.
Data we process
We process the following categories of data, separating anonymous browsing from account usage:
-
Technical browsing data
IP address, user-agent, request timestamps, visited pages. Stored in application server logs and security services (rate limiting, abuse mitigation).
-
Account registration data
Email, password (stored as Argon2id hash, never in plain text), nickname/username, optional avatar. Email verification is planned for the next release.
-
Session data
Technical cookie __Host-ls_session (httpOnly, SameSite=Lax, 7 days). The CSRF token for mutating requests lives on the server and in browser memory after login (no CSRF cookie). Session tokens and CSRF identifier stored in the database; 30-minute idle timeout.
-
Account security data
Login attempts (email + IP), audit events (login, logout, signup, password reset, profile changes, account deletion, MFA TOTP enrollment), TOTP secrets encrypted with AES-256-GCM.
-
Interactive tools data
Some tools (visa tracker, calculators, theme preferences) store data only in your browser via localStorage; if logged in, some state is saved server-side to your account.
-
Traffic measurement
Google Analytics 4 (with Consent Mode v2). Without your consent GA only sends "cookieless pings" without identifiers; with consent the _ga / _ga_* cookies are set. IP is anonymized.
Purposes
We process your data for the following purposes:
- Serve the site and informational guides. — Service performance.
- Run registration, login, session and account features. — Contract performance.
- Ensure security (rate limiting, audit, MFA, new login alerts). — Legitimate interest.
- Send transactional email (password reset, security alerts, confirmations). — Service performance / legitimate interest.
- Measure traffic in aggregate via Google Analytics. — Consent.
- Comply with legal obligations or respond to authority requests. — Legal obligation.
Retention
- User accounts: retained while the account is active. You can request deletion from your account area or by email; deletion is effective within 30 days.
- Sessions: max 7 days, 30-minute idle timeout.
- Security and audit logs: retained up to 12 months for security and abuse prevention.
- Failed login attempts: 15-minute rolling window, then deleted.
- Password reset tokens: 20 minutes, single-use, then invalidated.
- Transactional emails sent via Gmail SMTP (Google): copies remain in the sender mailbox under Google’s retention policies.
Recipients and processors
To run the service we rely on external providers acting as processors (art. 28 GDPR):
-
Vercel Inc.
Application hosting, edge network, access logs, avatar storage (Vercel Blob).
-
Neon Inc.
Managed PostgreSQL database (accounts, profiles, sessions, audit logs).
-
Upstash Inc.
Serverless Redis for distributed rate limiting (temporary keys with hashed IP).
-
Google LLC (Gmail SMTP)
Transactional email delivery (email verification, password reset, security alerts).
-
CookieYes Ltd.
Cookie consent management (Consent Management Platform).
-
Google Ireland Ltd. (Google Analytics 4)
Traffic measurement — only with consent, IP anonymized, Consent Mode v2 active.
-
Open-Meteo / ipapi
Weather API and IP geolocation for login alert security logic.
Non-EU transfers
Some of the providers above are based in the United States or in non-EU countries. Transfers rely on the European Commission Standard Contractual Clauses (SCC) and, where applicable, on the EU-US Data Privacy Framework.
Your rights
- Access your data (art. 15 GDPR).
- Rectify it if inaccurate (art. 16 GDPR).
- Request its erasure (art. 17 GDPR — "right to be forgotten").
- Restrict its processing (art. 18 GDPR).
- Receive it in a portable format (art. 20 GDPR).
- Object to processing based on legitimate interest (art. 21 GDPR).
- Withdraw consent whenever the processing relies on it (art. 7 GDPR).
- Lodge a complaint with your data protection authority.
To exercise your rights, write to the email above: we reply within 30 days, extendable by 60 in complex cases.
Security measures
We adopt appropriate technical and organizational measures: forced HTTPS (1-year HSTS), security headers (CSP, X-Frame-Options DENY, Referrer-Policy, Permissions-Policy), passwords stored only as Argon2id hashes, TOTP MFA for admin accounts, rate limiting, audit log of sensitive events, email alerts on logins from unseen IPs, httpOnly sessions with SameSite=Lax and double-channel CSRF tokens.
Minors
The service targets an adult audience and university students. We do not knowingly collect data from users under 16; if you believe this happened, contact us and we will delete it.
Changes to this notice
We may update this policy to reflect new features or regulatory changes. We will publish the last-updated date here. For material changes we will email registered users.
Contact
For any privacy-related request, you can write to: