← Back to Make Their Days

Privacy Policy

Version 0.1 (review draft) · Last updated 2026-09-29

This document is a review draft. It describes how the service works today, but the operator details and some legal decisions are still being confirmed.

Make Their Days lets someone build a calendar of doors for another person, who opens one door a day through a personal link. This policy explains what that involves for your information.

Who is responsible

The operator of Make Their Days is responsible for your personal data (the “controller”). The operator’s name and contact details are listed on the Legal & contact page once confirmed.

The people involved

  • Creators have an account and build calendars.
  • Recipients open a calendar through a personal link, without an account, and may answer challenges.
  • Viewers of a shared calendar see a frozen, view-only copy the recipient chose to share.
  • Platform administrators run the service and have technical access described below.

What we collect and why

  • Account details (email address, password stored only as a secure hash) — to let creators sign in.
  • Calendar content (titles, challenge texts, design choices, recipient names and optional email addresses) — to build and deliver the calendar.
  • Answers and photos from recipients — to show them to the calendar’s creator.
  • Draft progress (last saved step and time) — so creators can continue where they left off.
  • Technical records (e.g. when a link was used, delivery status of invitation emails) — to keep the service secure and working.
  • Optional analytics, only with your consent — see Cookies.

An email address is needed for a creator account. Everything else is up to you; leaving it out just means that part of the service is not used.

Legal basis

Running the service a user has asked for is the main reason we process this information. Optional analytics rely on your consent, which you can withdraw at any time. The exact legal bases are being confirmed by the operator and will be stated here in the final version.

Sensitive content

Some calendars — especially the bolder partner calendars — can contain very personal material, including about relationships and intimacy. Please only include what the other person is comfortable with. We do not use calendar content for advertising or profiling.

Who can see what

  • Answers and photos can be seen by the recipient who gave them and by the calendar’s creator.
  • Platform administrators can technically access calendars, answers and photos. They do so only when needed to run the service, help with support or investigate abuse.
  • Shared calendars: if a recipient shares a calendar, anyone with that share link can see the frozen copy it contains. Later changes are not added to it.
  • We do not sell personal data.

Personal links

A personal link works like a key: anyone who has it can open that calendar. Links are stored only in a scrambled (hashed) form, so we cannot read them back. If a link gets into the wrong hands, the creator can revoke it and create a new one.

Replacing a photo

When a recipient replaces a photo, the new photo is shown, but earlier versions are kept as version history. They remain visible to the creator and platform administrators until the calendar is deleted.

Service providers

We use providers to host the website, store the database and files, and send invitation emails. They process data on our behalf only. The list of providers, where they store data and the safeguards for any transfer outside the EU/EEA are being confirmed and will be listed here in the final version.

How long we keep information

  • Calendars, answers, photos and their version history are kept until the creator deletes the calendar or account.
  • Detailed analytics events are kept for up to 90 days, then reduced to anonymous daily totals kept for up to 12 months.
  • Deleted information may remain in backups for a limited period before it is overwritten. Exact backup periods are being confirmed.

Your rights

You can ask for access to your data, correction, deletion, restriction, a copy to move elsewhere (portability), and you can object to certain processing. Where we rely on consent, you can withdraw it at any time without affecting earlier processing. We do not make automated decisions with legal or similarly significant effects about you.

To exercise your rights, contact the operator using the details on the Legal & contact page. You can also complain to the Swedish Authority for Privacy Protection (IMY), imy.se.

Changes

If this policy changes in a meaningful way, we will update the version and date above and, where appropriate, let you know.