One Live Network Privacy Policy

This service is in Preview.

Last updated: September 14, 2026

Summary

1. Who we are

One Live Network ("we", "us", "our") is a social network operated by One Live, established in the European Union. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), One Live is the controller of the personal data described in this policy, except where this policy says otherwise.

This policy covers the One Live Network (sup.live.net.co), One Live Profile (me.live.net.co), One Live Places (places.live.net.co and its member sub-sites), voice and video calls, the embeddable One Live widget, the One Live apps for Windows, Windows Phone and other platforms that connect to these services, One Live Sync file storage (sync.live.net.co), and related services (together, "the Service"). One Live Sync does not have a separate policy: this policy and the Terms of Use apply to it in full. One Live ID has its own policy, linked where it applies.

Data protection contact: privacy@onelive.me. General support: support@onelive.me.

2. One Live ID

You sign in to the Service with a One Live ID, an identity provider operated at id.live.net.co. One Live ID manages your core account credentials (your sign-in name, primary email address, password, passkeys and two-factor settings) under its own privacy policy. Changes to those core credentials are made at One Live ID, not through the Service.

When you sign in, One Live ID sends the Service your account identifier, username, email address and any role (such as moderator). To keep your name current, a signed-in browser is sent through a silent, invisible check with One Live ID a few times a day; if you have renamed your account there, the new name replaces the old one here. No new data is collected by that check.

See the One Live ID Privacy Policy and Terms of Use.

3. Personal data we process

3.1 Data you provide

3.2 Data we collect automatically

3.3 Data from third parties

We do not knowingly collect special categories of data (such as data revealing health, religion, sexual orientation or political opinions). Please do not post such data about yourself or others unless you intend it to be processed and shared with the audience you choose.

4. Why we process your data and our lawful bases

Purpose Lawful basis (GDPR Article 6)
Creating and operating your account; showing your profile, posts, feeds, files, Place and network; delivering messages, notifications and calls; keeping edit history and like lists so the features work as described Performance of a contract (Art. 6(1)(b))
Real-time presence, typing indicators and live updates Performance of a contract (Art. 6(1)(b))
Keeping your username and role in step with One Live ID Performance of a contract (Art. 6(1)(b))
Browser and Windows push notifications Consent (Art. 6(1)(a)) - you switch them on, and can switch them off at any time
Connecting third-party services you choose (Bluesky, external feeds, One Live Music, One Live Messenger) Consent (Art. 6(1)(a)), which you may withdraw at any time by disconnecting the service
Keeping the Service secure; preventing abuse, fraud and spam; rate limiting; handling reports and moderating content; keeping call and connection records for troubleshooting Legitimate interests (Art. 6(1)(f)) in running a safe, working service
Complying with legal obligations and responding to lawful requests Legal obligation (Art. 6(1)(c))
Maintaining essential session cookies Performance of a contract / legitimate interests
Showing partnership announcements (section 12) Legitimate interests (Art. 6(1)(f)); no personal data is used to select them

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to that processing (section 10).

5. Who your data is shared with

5.1 Other members and the public

5.2 One Live services

5.3 Processors and other recipients

We do not sell your personal data, and we do not share it with advertisers.

6. Where your data is stored and how it is protected

6.1 Location

The Service's servers and databases - including One Live Sync's file store - are located in the European Union. Attachments, profile pictures, public and link-shared Sync files and cached artwork are served through Cloudflare's global network, and push notifications travel through the providers named in section 5.3; those are the cases in which data may leave the EEA (section 7).

Public and link-shared Sync file bytes are served with long-lived caching headers, because a file's address never changes once uploaded. When you delete such a file or make it private, copies already held by a browser or by the content network may remain readable at the old address for a short time.

6.2 Messages

End-to-end encrypted conversations. Each browser or app you use generates its own key pair and registers only the public half with us. A conversation can be end-to-end encrypted when every member has such a device; new direct conversations between two members who both have one start encrypted, and any member can turn the mode on or off from the conversation header. In this mode each message is encrypted on the sender's device with a one-time key that is in turn encrypted for every device of every member, and only ciphertext reaches our servers. We cannot read these messages, we cannot restore them if you lose your key, and a device added later cannot read messages sent before it existed unless you copy your key to it. Conversation previews and notifications then say only "Encrypted message". Attachments (pictures and files) are not covered by this and are stored as described in section 5.2. Encrypted conversations cannot be mirrored to One Live Messenger.

If you report an encrypted message, your device includes the text of that message, as decrypted on your device, in the report so that a moderator can act on it. The report page tells moderators that the text was disclosed by the reporter rather than read by us. Nothing else in the conversation is disclosed.

Other conversations. Message bodies, message edit history and connected-service credentials are encrypted at rest with a key held on our servers, so a copy of the database alone does not reveal them. The Service decrypts these messages to deliver them, to show conversation previews and notification text, and to mirror them to One Live Messenger if you use it. They are therefore not end-to-end encrypted: our systems can technically read them, and we will do so only where necessary to operate the Service, to handle a report you or another member made, or where the law requires it.

6.3 Calls

6.4 General measures

Encryption in transit (HTTPS and secure WebSockets) everywhere; content sanitising on write to stop script injection; per-account rate limits; separation of file storage from the main database; access to production systems limited to the people who run the Service; moderation actions logged. No system is completely secure and we cannot guarantee absolute security.

6.5 If something goes wrong

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will tell you directly where the risk is high, as the GDPR requires.

7. International transfers

Some recipients - Cloudflare, the push notification providers (Google, Mozilla, Apple, Microsoft), the Bluesky network and external feed publishers - may process data outside the European Economic Area ("EEA"), in particular in the United States. Where we transfer personal data outside the EEA we rely on an appropriate safeguard under Chapter V of the GDPR: an adequacy decision (including the EU-U.S. Data Privacy Framework for providers certified under it) or the European Commission's Standard Contractual Clauses, with additional measures where needed. You may request a copy of the relevant safeguard using the contact details in section 1.

8. How long we keep your data

9. Members outside the European Union

The Service is operated from the European Union and this policy applies to everyone who uses it. If your local law gives you additional rights, contact us and we will honour them where they apply.

10. Your rights

Under the GDPR you have the right to:

To exercise these rights, contact us using the details in section 1. We will respond within one month, as required by the GDPR (extendable by two further months for complex requests, in which case we will tell you). We may need to verify your identity first, normally by asking you to write from the email address on your One Live ID. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

11. Cookies and similar technologies

We use a small number of first-party cookies and storage entries that are strictly necessary to operate the Service:

Because these are strictly necessary or functional, they do not require consent under the applicable ePrivacy rules. We do not use advertising or third-party tracking cookies, and we do not run analytics scripts.

12. Announcements

The Service shows a small number of partnership announcements in fixed slots. They are static pictures served from our own content network, chosen for everyone alike; no personal data, browsing history or profile information is used to select them, and no tracking cookie is set. Clicking one opens the partner's page in a new window, where the partner's own policies apply.

13. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Automated rate-limiting and duplicate filters may temporarily restrict actions; moderation decisions (removing content, suspending accounts) are made by people. You can contact us if you believe a restriction was applied in error.

14. Children

The Service is not directed to children under 16 years of age (or the minimum age permitted in your country under Article 8 GDPR). We do not knowingly process the data of children below that age. If you believe a child has provided us with personal data, contact us and we will take appropriate steps.

15. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the "Last updated" date. Where changes are material, we will provide additional notice on the Service before they take effect.

16. Contact

Questions about this policy or your data: privacy@onelive.me. General support: support@onelive.me.


One Live Network - One Live, 2026.