Your data is stored on servers located in the European Union.
We process your data to run the Service, keep it safe, and meet our legal duties. We do not sell it,
and we do not use it for advertising profiles.
Conversations can be end-to-end encrypted: messages are then readable only on the
members' own devices, never by us. Other conversations are encrypted at rest. Calls are end-to-end
encrypted between clients that support it (section 6.2 and 6.3).
We keep a record of who called whom and when, but we never record the content of a call.
You can see, correct, export and delete your data, and object to some processing (section 10).
1. Who we are
One Live Network ("we", "us", "our") is a social network operated by One Live, established in the
European Union. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679,
"GDPR"), One Live is the controller of the personal data described in this policy,
except where this policy says otherwise.
This policy covers the One Live Network (sup.live.net.co), One Live Profile
(me.live.net.co), One Live Places (places.live.net.co and its member
sub-sites), voice and video calls, the embeddable One Live widget, the One Live apps for Windows, Windows
Phone and other platforms that connect to these services, One Live Sync file storage
(sync.live.net.co), and related services (together, "the Service"). One Live Sync does not
have a separate policy: this policy and the Terms of Use apply to it in full. One Live ID has its own
policy, linked where it applies.
You sign in to the Service with a One Live ID, an identity provider operated at
id.live.net.co. One Live ID manages your core account credentials (your sign-in name, primary
email address, password, passkeys and two-factor settings) under its own privacy policy. Changes to those
core credentials are made at One Live ID, not through the Service.
When you sign in, One Live ID sends the Service your account identifier, username, email address and any
role (such as moderator). To keep your name current, a signed-in browser is sent through a silent,
invisible check with One Live ID a few times a day; if you have renamed your account there, the new name
replaces the old one here. No new data is collected by that check.
Account and identity data received from One Live ID: a unique account identifier,
your username, email address, display name, and whether your account carries a moderator role.
Profile data you choose to add: status message, date of birth, gender, country,
state/region, city, "about me" text, interests, profile picture and selected theme.
Content you create: posts (text, images, videos and attached files), comments and
replies, likes on posts and comments, groups you create or join and group posts, and the activity
these generate in feeds ("What's new").
Edit history: when you edit a post or a message, the previous version is kept
alongside the new one so that readers can see what changed. The history of a post is visible to
everyone who can see the post; the history of a message is visible to the members of that
conversation. Deleting the post or message deletes its history.
Messages: the content of direct and group messages you send, attachments, replies
and read state. In an end-to-end encrypted conversation we hold only ciphertext we cannot read; in
other conversations message bodies and their edit history are encrypted at rest (section 6.2).
Encryption devices: for end-to-end encryption, a public key for each browser or app
you use, with a device name (for example "Chrome on Windows") and when it was last used. The matching
private key stays on your device and is never sent to us.
Calls: your call settings (who may call you, an allow list), and for each call a
record of the caller, the person called, whether it was audio or video, how it was carried, when it
started, was answered and ended, and how it ended (answered, declined, missed, failed). We do not
record or store the audio or video of a call.
One Live Places: the sub-site you build - its title and tagline, layout and modules,
custom style sheet, blog entries and their comments, lists, playlists, photo albums, guestbook
signatures you write on others' Places and others write on yours, and your Place's visibility
setting.
Files on One Live Sync: the files you upload for storage, their file name, type and
size, the folders you organise them in, the visibility you set for each file (private, public or
link-shared) and the share link token for link-shared files. For pictures we generate and keep a
small preview (thumbnail). Storage is subject to a per-member quota (10 MB per file and 10 MB in
total unless stated otherwise on the Service); when your storage is nearly full you may receive a
notification saying so.
Your network: the connections you make, invitations you send or receive, category
labels you apply to contacts, and people you block.
Reports: if you report content or a member, the report, your reason and any details
you add, kept with the moderation outcome.
Connected-service settings: if you connect a Bluesky account, your Bluesky handle and
an app password (encrypted at rest); the URLs of external RSS/Atom feeds you subscribe to; your One
Live Music preferences.
Preferences: presence status (online, away, busy, invisible), notification settings
including whether browser push notifications are on, feed settings, privacy setting (whether your
profile is private).
3.2 Data we collect automatically
Session data: a session cookie used to keep you signed in, with the sign-in tokens
issued by One Live ID (section 11). One Live Sync keeps its own session and a mirror of your account
(identifier, username, email, profile picture) in its own database.
Presence and connection data: whether you are currently connected and on which
devices, used to show your status to your network in real time over a WebSocket connection, and
"typing" indicators inside a conversation.
Push notification registrations: if you turn on notifications in a browser or app, the
push endpoint address and keys issued by your browser vendor or by Microsoft's Windows Notification
Service, the device name the app reports, and delivery success or failure (section 5.3).
Call connection data: to connect a call, your device and the other participant's
device exchange network addresses (IP addresses and ports) through our signalling server. For a
direct connection the other participant's device can learn your public IP address; using the relay
server hides it (section 6.3).
Technical and log data: your IP address, browser or app type and version, requested
pages and API calls, and timestamps, recorded in server logs for security, abuse prevention and
diagnostics. Rate-limit counters are kept in memory for at most an hour.
3.3 Data from third parties
One Live Music: your public music activity and
mutual follows, if you use One Live Music, may be shown in your feed and used to suggest contacts.
One Live Messenger (a Windows Live Messenger-compatible service operated by One Live):
if you use it, your status, profile picture and direct messages are mirrored between the Service and
your Messenger contacts, and your Messenger presence is shown on the Service.
Bluesky (AT Protocol): if you connect a Bluesky account, we retrieve your Bluesky
posts to display them, and send likes and replies you make through the Service back to Bluesky.
External feeds: if you subscribe to RSS/Atom feeds, we fetch content from those
publishers on your behalf.
We do not knowingly collect special categories of data (such as data revealing health, religion, sexual
orientation or political opinions). Please do not post such data about yourself or others unless you
intend it to be processed and shared with the audience you choose.
4. Why we process your data and our lawful bases
Purpose
Lawful basis (GDPR Article 6)
Creating and operating your account; showing your profile, posts, feeds, files, Place and
network; delivering messages, notifications and calls; keeping edit history and like lists
so the features work as described
Performance of a contract (Art. 6(1)(b))
Real-time presence, typing indicators and live updates
Performance of a contract (Art. 6(1)(b))
Keeping your username and role in step with One Live ID
Performance of a contract (Art. 6(1)(b))
Browser and Windows push notifications
Consent (Art. 6(1)(a)) - you switch them on, and can switch them off at any time
Connecting third-party services you choose (Bluesky, external feeds, One Live Music, One Live
Messenger)
Consent (Art. 6(1)(a)), which you may withdraw at any time by disconnecting the service
Keeping the Service secure; preventing abuse, fraud and spam; rate limiting; handling reports
and moderating content; keeping call and connection records for troubleshooting
Legitimate interests (Art. 6(1)(f)) in running a safe, working service
Complying with legal obligations and responding to lawful requests
Legal obligation (Art. 6(1)(c))
Maintaining essential session cookies
Performance of a contract / legitimate interests
Showing partnership announcements (section 12)
Legitimate interests (Art. 6(1)(f)); no personal data is used to select them
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms.
You may object to that processing (section 10).
5. Who your data is shared with
5.1 Other members and the public
Visibility you choose: Public posts and public profiles are visible to anyone,
including in public feeds (RSS, JSON and Windows Live formats) and in search. Network posts are
visible to your confirmed network. If you mark your profile private, your posts, activity and profile
details are visible only to people in your confirmed network.
Likes: the number of likes on a post or comment is visible to everyone who can see
it. The names of the people who liked it are visible only to the author of that post or
comment (and to moderators).
Edit history: as described in section 3.1.
Messages and calls: direct and group messages are visible to the members of that
conversation. Whether you are reachable for calls follows your call settings; a missed call is shown
to the person you called.
Presence: your online status is shown to your network unless you choose
"invisible".
Places: a Place is public, network-only or private according to its owner's
setting. Signing a guestbook on a public Place also appears in your own What's new feed.
Sync files: a private file is visible to you alone. A public file
can be opened by anyone who has its address, is listed in the photo strip on your profile and, the
first time you make it public, is announced in your What's new feed. A link-shared file can
be opened by anyone who has the link, including people who are not members; it is not listed on
your profile or in feeds. Files you attach to a post or message follow that post's or
conversation's audience instead.
5.2 One Live services
One Live ID (id.live.net.co): authentication and identity refresh.
One Live Sync (sync.live.net.co): stores the files you keep in Sync
on disks in the European Union, in its own database and file store, and answers the Network's and
Places' requests for the photos and files you have made public or shared.
One Live upload servers (upload1.onelive.me,
upload2.onelive.me): store post, group and message attachments.
One Live Music and One Live Messenger: as described in section
3.3.
One Live Places: mirrors your username, display name, profile picture, status,
presence and theme so your Place matches your profile.
5.3 Processors and other recipients
Hosting and infrastructure providers that run our servers and databases in the
European Union, under a data-processing agreement.
Cloudflare, Inc.: provides the network edge in front of the Service (so requests
pass through Cloudflare's network) and object storage for profile pictures
(u.onelive.me). Additonally, One Live Sync is served exclusively over the Cloudflare network using Cloudflared tunnels. Cloudflare acts as our processor.
G-Core Labs S.A.: provides the content delivery for theme artwork, emoji pictures and
announcement artwork (*.cdns.onelive.me). G-Core Labs acts as our processor.
Push notification services: when you turn notifications on, notification content
(for example "Alice likes your post" or the sender and a short preview of a message) is delivered
through your browser vendor's push service (Google, Mozilla or Apple, depending on your browser) or,
for the Windows apps, through Microsoft's Windows Notification Service. These providers carry the
notification to your device; browser push content is encrypted to your device so the push service
cannot read it.
Call relay (TURN) servers: used when a direct connection between two devices is not
possible. On the WebRTC path the relay carries only encrypted media it cannot decode.
Bluesky and the AT Protocol network (e.g. bsky.social): if you connect
Bluesky, your likes and replies made through the Service are published to Bluesky and are subject to
Bluesky's terms and privacy policy.
External feed publishers: when you subscribe to a feed, requests are made to that
publisher, which sees our server's address (not yours).
Embedding partner sites: if the One Live widget is embedded on an approved partner
site, the widget displays your account information within that site once you are authenticated. The
widget only operates on approved domains.
Authorities and legal successors: where required by law, to protect rights and
safety, or in connection with a merger or acquisition.
We do not sell your personal data, and we do not share it with advertisers.
6. Where your data is stored and how it is protected
6.1 Location
The Service's servers and databases - including One Live Sync's file store - are located in the European
Union. Attachments, profile pictures, public and link-shared Sync files and cached artwork are served
through Cloudflare's global network, and push notifications travel through the providers named in
section 5.3; those are the cases in which data may leave the EEA (section 7).
Public and link-shared Sync file bytes are served with long-lived caching headers, because a file's
address never changes once uploaded. When you delete such a file or make it private, copies already held
by a browser or by the content network may remain readable at the old address for a short time.
6.2 Messages
End-to-end encrypted conversations. Each browser or app you use generates its own key
pair and registers only the public half with us. A conversation can be end-to-end encrypted when every
member has such a device; new direct conversations between two members who both have one start
encrypted, and any member can turn the mode on or off from the conversation header. In this mode each
message is encrypted on the sender's device with a one-time key that is in turn encrypted for every
device of every member, and only ciphertext reaches our servers. We cannot read these messages, we
cannot restore them if you lose your key, and a device added later cannot read messages sent before it
existed unless you copy your key to it. Conversation previews and notifications then say only
"Encrypted message". Attachments (pictures and files) are not covered by this and are stored as
described in section 5.2. Encrypted conversations cannot be mirrored to One Live Messenger.
If you report an encrypted message, your device includes the text of that message, as
decrypted on your device, in the report so that a moderator can act on it. The report page tells
moderators that the text was disclosed by the reporter rather than read by us. Nothing else in the
conversation is disclosed.
Other conversations. Message bodies, message edit history and connected-service
credentials are encrypted at rest with a key held on our servers, so a copy of the database alone does
not reveal them. The Service decrypts these messages to deliver them, to show conversation previews and
notification text, and to mirror them to One Live Messenger if you use it. They are therefore
not end-to-end encrypted: our systems can technically read them, and we will do so only
where necessary to operate the Service, to handle a report you or another member made, or where the law
requires it.
6.3 Calls
Calls between modern browsers and the Windows 10 app use WebRTC. The audio and video travel directly
between the two devices (or through a relay server that cannot decode them) and are
end-to-end encrypted. Our servers only pass the connection set-up messages.
Calls with clients that have no WebRTC (the Windows 8.1 and Windows Phone 8.1 apps, browsers
without it) use relayed audio that passes through our server. Where both ends have an encryption
device, each audio frame is end-to-end encrypted with a key agreed between the two devices, and the
server forwards only ciphertext. With an app that does not yet support this, the relayed audio is
readable by the server while in transit. It is not stored in either case. The call screen shows a
lock while a call is end-to-end encrypted.
We never record calls, and we do not analyse their content.
On a direct WebRTC connection the other participant's device can learn your public IP address. If
you would rather not reveal it, decline calls from people you do not trust or use the call settings
to limit who may call you.
6.4 General measures
Encryption in transit (HTTPS and secure WebSockets) everywhere; content sanitising on write to stop script
injection; per-account rate limits; separation of file storage from the main database; access to
production systems limited to the people who run the Service; moderation actions logged. No system is
completely secure and we cannot guarantee absolute security.
6.5 If something goes wrong
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the
competent supervisory authority within 72 hours of becoming aware of it, and we will tell you directly
where the risk is high, as the GDPR requires.
7. International transfers
Some recipients - Cloudflare, the push notification providers (Google, Mozilla, Apple, Microsoft), the
Bluesky network and external feed publishers - may process data outside the European Economic Area
("EEA"), in particular in the United States. Where we transfer personal data outside the EEA we rely on
an appropriate safeguard under Chapter V of the GDPR: an adequacy decision (including the EU-U.S. Data
Privacy Framework for providers certified under it) or the European Commission's Standard Contractual
Clauses, with additional measures where needed. You may request a copy of the relevant safeguard using
the contact details in section 1.
8. How long we keep your data
Profile, content, Places, network, message and call-settings data are kept while your account is
active.
When you delete a post, comment, message, file or Place item, it is removed from the Service together
with its edit history, likes and attachments; backups, if any, are overwritten on a rolling basis
within 90 days. Deleting a Sync file removes the file and its thumbnail immediately; attachments are
deleted with the post or message they belong to.
Call records (section 3.1) are kept for 12 months, or until you delete your account, whichever is
sooner.
Push notification registrations are kept until you turn notifications off, the device stops
accepting them, or the registration expires.
Encryption device keys are kept until you remove the device, or it is replaced by a newer one (we
keep the ten most recently used per member), or your account is deleted.
Session records are kept for 30 days after last use; sign-in state used during the One Live ID
round trip is deleted within 15 minutes.
Reports and moderation records are kept for 12 months after the report is closed, so that repeated
behaviour can be recognised and appeals handled.
Server and security logs are kept for 90 days.
When your account is deleted, we delete or irreversibly anonymise your personal data within 90
days, except where we must retain certain data to comply with a legal obligation or to establish,
exercise or defend legal claims. Content you posted in other members' spaces (a comment on someone's
post, a guestbook signature) is removed or shown without your name.
9. Members outside the European Union
The Service is operated from the European Union and this policy applies to everyone who uses it. If your
local law gives you additional rights, contact us and we will honour them where they apply.
10. Your rights
Under the GDPR you have the right to:
Access the personal data we hold about you and receive a copy.
Rectification of inaccurate or incomplete data. Your profile can be corrected on the
Edit profile page; posts and messages can be edited (the earlier version stays in the edit history
until the item is deleted); core One Live ID details are changed at id.live.net.co.
Erasure ("right to be forgotten") of your data in certain circumstances. You can
delete individual posts, comments, messages and Place content yourself at any time, and request
deletion of your whole account.
Restriction of processing in certain circumstances.
Data portability: to receive certain data in a structured, commonly used,
machine-readable format. Your public activity is available via the feed links on your profile (RSS,
JSON and Windows Live formats); for a full export contact us.
Object to processing based on our legitimate interests.
Withdraw consent at any time where processing is based on consent - for example by
turning notifications off, or by disconnecting a linked Bluesky account or removing a subscribed
feed. Withdrawal does not affect processing carried out before withdrawal.
Not be subject to automated decisions with legal or similarly significant effects
(section 13).
Lodge a complaint with a supervisory authority, in particular in the EU member state
of your habitual residence, place of work or place of the alleged infringement. A list of authorities
is at edpb.europa.eu.
To exercise these rights, contact us using the details in section 1. We will respond within one month, as
required by the GDPR (extendable by two further months for complex requests, in which case we will tell
you). We may need to verify your identity first, normally by asking you to write from the email address
on your One Live ID. Exercising your rights is free of charge unless a request is manifestly unfounded or
excessive.
11. Cookies and similar technologies
We use a small number of first-party cookies and storage entries that are strictly necessary to operate
the Service:
Session cookies (onelive_session on the Network, Profile and Places;
onelivesync_session on Sync, which has its own session store): keep you signed in.
Essential; the Service cannot function without them.
Sign-in state: a short-lived record used to complete the One Live ID sign-in and the
silent identity check safely.
Preference storage: your browser may remember settings such as your selected theme,
recently used emoji and skin tone, and whether you dismissed a notice. These live in your browser only.
Service worker: if you turn on browser notifications, a small script is installed in
your browser to display them. Turning notifications off removes the subscription.
Because these are strictly necessary or functional, they do not require consent under the applicable
ePrivacy rules. We do not use advertising or third-party tracking cookies, and we do not run analytics
scripts.
12. Announcements
The Service shows a small number of partnership announcements in fixed slots. They are static pictures
served from our own content network, chosen for everyone alike; no personal data, browsing history or
profile information is used to select them, and no tracking cookie is set. Clicking one opens the
partner's page in a new window, where the partner's own policies apply.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on
automated processing. Automated rate-limiting and duplicate filters may temporarily restrict actions;
moderation decisions (removing content, suspending accounts) are made by people. You can contact us if
you believe a restriction was applied in error.
14. Children
The Service is not directed to children under 16 years of age (or the minimum age permitted in your
country under Article 8 GDPR). We do not knowingly process the data of children below that age. If you
believe a child has provided us with personal data, contact us and we will take appropriate steps.
15. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the "Last
updated" date. Where changes are material, we will provide additional notice on the Service before they
take effect.