inside.live ← Back

Privacy Notice

Last updated: 7 August 2026

This page is a draft. It is not in force and it has not been checked by a lawyer. Draft revision 13 August 2026. The version currently in force is the one dated 7 August 2026 above.

It was written by the person who builds inside.live, not by a solicitor, and its main purpose is to correct the previous version: that one said our analytics were cookieless, which is only true of these marketing pages and not of the pages your visitors actually land on. The section below headed Visitors to inside.live pages describes what the code does today. Sections tagged new or corrected have changed. Boxes marked For legal review are open questions we've chosen not to answer ourselves.

Anything here that looks wrong to you probably is — tell us: max@inside.live.

inside.live is operated by Shoroye Studios / Max Shoroye. This notice explains what we collect, why, and your rights — including under UK and EU data-protection law (GDPR). Contact us any time at max@inside.live.

Two different roles new

It matters which one you are, because we're responsible for different things in each case.

What we collect from account holders corrected

Visitors to inside.live pages new

This is the section the previous version was missing, and it's the one to read if you've just opened someone's page.

We use PostHog (EU region) to understand how pages are used. On a published page — anything at inside.live/someone — PostHog does three things: it stores an identifier on your device so repeat visits are recognised, it automatically records the taps and interactions you make with the page, and it captures a replay of your session on the page. Alongside that it receives your IP address, an approximate location worked out from it (roughly city level), your device and browser type, and which page you were on.

On our own marketing pages — the homepage, sign-up and sign-in — it's set up differently and deliberately more lightly: nothing is stored on your device, and there's no session replay.

We don't run advertising trackers, we don't sell any of this, and page owners see aggregate numbers about their page rather than a list of who visited.

For legal review — consent for analytics on published pages. Storing an identifier on a visitor's device and recording their session are not the same as counting page views, and PECR generally treats non-essential storage as needing consent. There is no cookie banner on any inside.live page today. There are two honest ways out and we haven't picked one: make the published pages match the marketing pages (no device storage, no replay, which is a code change and probably the simpler answer), or keep replay and build a consent mechanism. This notice describes what the code does right now so that at least the description is true while that gets decided.

Mailing-list signups on a creator's page new

Some pages have a tile that invites you to join the page owner's mailing list. If you use it, your email address is stored in our email provider (Resend), tagged to that page, and the page owner is notified that someone signed up. The point of the tile is that the page owner can email you later — so treat it as giving your address to them, not to us. We don't email you ourselves when you use it.

To be taken off a list, the fastest route is the page owner. If you can't reach them, email us at max@inside.live and we'll remove you.

For legal review — two things. Who is the data controller for these addresses: the page owner (with us as their processor, which would need a written agreement with every page owner — we have none today), both of us jointly, or us. And separately: the notification we send the page owner currently includes the subscriber's IP address. That isn't needed for the feature to work and we'd suggest removing it regardless of what the legal answer turns out to be.

Why we're allowed to new

Data-protection law asks us to name a lawful basis for each thing we do. Ours:

Storage on your device corrected

When you're signed in we store an auth session token in your browser's localStorage. It's necessary to keep you logged in — it isn't an advertising cookie and isn't used for tracking.

Separately, on published pages our analytics store an identifier on your device, as described above. That one isn't necessary to make the page work; it's there so we can tell a returning visitor from a new one.

Who processes it corrected

We use a small set of processors to run the service:

Each processes data only on our instructions to provide their service.

Where your data goes new

Our database, file storage and analytics are hosted in the EU. Some of the others — payments, email, hosting — are US companies and may process data in the United States or elsewhere. Where that happens, transfers rely on the standard safeguards those providers publish, such as the European Commission's standard contractual clauses and the UK addendum to them.

For legal review. That paragraph describes the shape of the arrangement rather than verified specifics. Someone should check each provider's current transfer mechanism and whether we need a transfer risk assessment on file, before this sentence is relied on.

How long we keep things new

For legal review — numbers, not adverbs. "Shortly afterwards" and "as long as retention settings hold them" are placeholders. Backup windows and the analytics retention setting need to be looked up and stated as periods. The 14-day hold also needs its basis confirmed: it means keeping the email address of someone who has just asked to be erased, for a fortnight, in order to refuse them service.

Your rights corrected

Under the GDPR you can ask for access to your data, rectification, erasure, portability, or object to processing. Email max@inside.live and we'll act on it. You also have the right to complain to the ICO or your local supervisory authority — in Ireland, the Data Protection Commission.

You don't have to email us to be erased: account settings in the editor has a delete button that does it in full — pages, uploads, account, login. Read Ending your account in our Terms of Service first, because it can't be undone and it cancels any paid plan on the spot.

Children new

inside.live isn't built for children, and we don't knowingly collect data from them. If you think a child has an account or has given us their details, email max@inside.live and we'll remove it.

For legal review — this paragraph is a placeholder. It states no age, on purpose, and it needs to match whatever minimum age the Terms end up setting. Two things a solicitor should weigh: the UK Age Appropriate Design Code, if a service is likely to be accessed by children whoever owns the accounts; and the fact that promoter pages are public, so under-18s visit them and get the analytics described above regardless of who signed up.

Changes

If this notice changes in a way that matters, we'll flag it on the site or by email, and update the date at the top.