Skip to content

For Customers

Security Policy

We are committed to ensuring the security, confidentiality, and integrity of our customers' data.

As of last update on July 28, 2026, at Longtime Friends, LLC we are committed to ensuring the security, confidentiality, and integrity of our customers' data. As part of our commitment to providing secure services, this Security Policy outlines the measures and practices we implement to protect data from unauthorized access, disclosure, alteration, and destruction.

1. Data Protection & Encryption

We take all reasonable precautions to ensure that all sensitive customer data is encrypted and protected. These measures include:

  • Data Encryption in Transit: All data transmitted between users and our service is encrypted using HTTPS (SSL/TLS) to ensure secure communication channels.
  • Data Encryption at Rest: All sensitive data stored in our systems is encrypted using industry-standard encryption protocols, ensuring that data is protected even in the event of unauthorized access to storage.

2. Access Control

To safeguard against unauthorized access, we implement strict access control measures:

  • Authentication: Our services require secure authentication methods, such as username/password and multi-factor authentication (MFA), to access the system.
  • Least Privilege: Administrative access to production systems is held by a single person — the operator of Longtime — and is used only to run or repair the service. No one else holds standing access to your information.
  • Separation: Within Longtime, the information in your Space is reachable only by you. Our diagnostic tools receive personal information only after it has been scrubbed.

3. Network Security

Our infrastructure is protected by a variety of network security measures:

  • Platform Network Controls: Longtime runs on a managed hosting platform, and we rely on the network-level protections that platform and its underlying infrastructure provider offer, including firewalling, traffic filtering, and denial-of-service mitigation.
  • Dependency and Platform Updates: We track security advisories for the software Longtime is built on and apply security updates promptly.
  • Assessments: We review our own configuration and dependencies for weaknesses. We do not currently commission third-party penetration tests, and we will say so here if that changes.

4. Incident Response & Monitoring

We monitor our systems for potential security incidents and respond to them as follows:

  • Continuous Automated Monitoring: Errors and anomalies are captured automatically and around the clock by our monitoring and logging tools, which alert us when something goes wrong.
  • Response: Longtime is operated by one person, so we do not staff a 24-hour response rotation. Alerts are reviewed and acted on as promptly as we are able, and we would rather tell you that than imply a night shift that does not exist.
  • Incident Response Plan: We maintain a written incident response plan covering how we identify, contain, and investigate a security incident, what evidence we preserve, and who we are obliged to notify and within what time.
  • Breach Notification: If a security breach affects your information, we will notify you in a timely manner and in accordance with applicable laws, whether the failure occurred in our own systems or in those of a service provider.

5. Data Backup & Recovery

To protect against data loss and system failure, we maintain:

  • Automated Backups: Our hosting platform takes automated backups of the database on a continuous schedule. We keep them enabled, and the platform stores and encrypts them.
  • A Second, Independent Copy: We also keep our own encrypted copy of the database in separate storage, so that a problem at our hosting provider cannot put your information out of reach. It is encrypted before it leaves Longtime, using a key held outside the service — which means the storage provider cannot read it, and neither can Longtime itself. Both sets of backups are kept for thirty days and then deleted.
  • Recovery: Those backups exist so that Longtime can be restored after data loss or system failure. We do not offer a contractual recovery-time guarantee.
  • Your Own Copy: You can export your information from Longtime at any time, and we encourage you to keep your own copy of anything you would not want to lose.

6. User Responsibilities

In addition to our own security measures, users are responsible for maintaining the security of their accounts. We recommend the following best practices for our users:

  • Strong Passwords: Users should create strong, unique passwords for their accounts and avoid reusing passwords across different platforms.
  • Multi-Factor Authentication (MFA): We strongly encourage users to enable multi-factor authentication (MFA) to add an additional layer of security.
  • Account Monitoring: Users should regularly monitor their accounts for any suspicious activity and report any potential security concerns to us immediately.

7. Compliance with Industry Standards and Regulations

We strive to comply with relevant security standards and regulations, including but not limited to:

  • General Data Protection Regulation (GDPR): We comply with the GDPR for customers located in the European Union and provide appropriate safeguards for data privacy.
  • Payment Card Industry Data Security Standard (PCI DSS): We require our payment processing providers to implement PCI DSS-compliant processes for the secure handling of payment card information.

8. Who Has Access

Longtime is built and operated by one person. There are no employees and no contractors, so the list of people who can reach your information is one name long.

That means we do not run the security training programs, insider-threat policies, and access reviews that a larger company would need. It also means there is no one to train, and no one else who could look. We would rather tell you which of those trade-offs you are getting than describe a security organization that does not exist.

9. Third-Party Security

We keep the number of outside services to a minimum, and we choose them for their security and privacy commitments rather than for convenience. Before adopting a provider, we review its published security practices, data protection terms, and transfer safeguards.

Each provider that processes information on our behalf is bound by data protection terms. For most, those terms are incorporated into the agreement we accept as their customer; for others, we execute a separate data processing agreement. Where a service is a public resource with no customer relationship to contract through, we say so plainly rather than imply a contract exists.

Our Subprocessors notice lists every provider, what it handles, and any exception of that kind.

10. Changes to This Security Policy

We may update or modify this Security Policy from time to time to reflect changes in security practices or regulatory requirements. Any changes will be posted on this page, and the “Last Updated” date will be revised accordingly. We encourage you to check this page periodically for updates.

11. Contact Us

If you have any questions about this Security Policy, please feel free to contact us at support@longtime.app.