Privacy
Last updated · 28 April 2026
The short version
Annum is an archive of your year. To run that archive, we store the things you save (traces, photos, notes, ratings), the account you use to sign in, and the small amount of metadata needed to keep the service working. We don’t sell your data, we don’t serve ads against it, and we don’t train models on it.
Who's behind Annum
Annum is operated from Munich, Germany. The data controller within the meaning of Art. 4 (7) GDPR is Jonathan Magnis. Postal and contact details are on the Impressum page.
What we store, and why
- Account identity. Email address (or Apple Relay address) and the OAuth provider you signed in with. Required to keep your archive yours.
- Profile. Display name, username, optional bio, avatar, and chosen appearance palette. Public profile fields are visible to anyone who visits annum.life/{username}.
- Traces and entries. Everything you write, upload, or import — titles, descriptions, photos, ratings, dates, tags. This is the archive itself.
- Imports. When you upload a CSV from Letterboxd, Goodreads, or similar, the file is parsed into traces and the original CSV is discarded.
- Cookies and session. A small set of cookies needed to keep you signed in (Supabase auth) and to remember your appearance preference. No tracking pixels, no third-party advertising cookies.
- Time zone. Which time zone your device reports (e.g. “Europe/Berlin”), for the last 35 days, one entry per day. Used to work out when to say “good morning” and to ask whether you were away when the clock changed for a stretch of days. No location permission is requested and no location API is called — a time zone is not a location, and Annum cannot tell a city from one. Entries older than 35 days are deleted automatically.
- Logs. Standard server logs (IP, user agent, timestamps) retained for a short window for debugging and abuse prevention.
Who we share it with
We use a small set of subprocessors to run the service. Each is bound by a Data Processing Agreement and only handles the data necessary to do its job:
- Supabase. Database, authentication, file storage. Hosted in the EU (Frankfurt).
- Vercel. Application hosting and edge delivery.
- Resend. Transactional email (magic links, notifications).
- Stripe. Payment processing for paid plans. Receives billing details and payment method data directly; we never see or store your card number.
We do not transfer your data to third parties for marketing, analytics, or model training.
Services you connect
Nothing here is on by default, and none of it writes to your archive. If you connect a service under Settings → Connected services, Annum reads a narrow slice of it to suggestthings you might want to keep. A suggestion becomes a trace only when you say so.
- Spotify. If you connect it, Annum requests one permission — “recently played” — and reads which albums you listened through in the last seven days, in order to suggest them. It never requests now-playing, playback control, or anything about your library or playlists. Your listening history is not stored: it is read when you open Found and discarded with the request. Spotify learns that Annum asked, on your behalf, for as long as the connection lasts.
- Last.fm. If you connect it, you give Annum your Last.fm username, which is public. Annum asks Last.fm’s public API which albums you scrobbled in the last seven days, in order to suggest them. No Last.fm login or password is involved and no permission is granted to us. Scrobble history is not stored: it is read when you open Found and discarded with the request.
- Steam. If you connect it, you give Annum your public Steam profile ID. Annum asks Steam’s public Web API which games you played in the last two weeks, in order to suggest them. No Steam login, password or permission is involved, and Steam grants Annum nothing. Play history is not stored.
- Google Timeline. Not a connection. If you import a Timeline export, the file is read in your browser and never uploaded — only the trips you choose to keep are saved. Google is not contacted at any point.
Disconnecting a service in Settings deletes what Annum stored to reach it — for Spotify the access and refresh tokens, for Steam the profile ID — immediately and permanently. You can also revoke Annum’s access from your Spotify account page at any time. Nothing derived from a connected service outlives the suggestion it was read for.
Your rights under GDPR
Because we operate in the EU, you have the rights set out in Articles 15–22 of the GDPR — access, rectification, erasure, restriction, portability, and objection. You can:
- Export. Download your full archive as JSON from Settings → Export.
- Edit. Edit or delete any individual trace, profile field, or photo at any time.
- Delete account. Delete your account from Settings → Danger Zone. This removes your traces, photos, and profile from our systems within 30 days, except where law requires longer retention (e.g. invoicing records).
- Object or restrict. Email the contact address on the Imprint page if you want to restrict or object to a specific processing activity.
You also have the right to lodge a complaint with a supervisory authority. In Germany the relevant authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
How long we keep things
Traces and profile data are kept for as long as your account exists. After deletion, they are removed within 30 days from primary storage and within 90 days from encrypted backups. Email and billing records are retained for the period required by German tax and commercial law (currently up to 10 years).
Two things expire on their own, whatever else happens: the daily time-zone entries described above are deleted after 35 days, and anything read from a connected service is discarded with the request that read it.
Children
Annum isn’t designed for people under 16. If we learn that someone under 16 has signed up without parental consent, we will delete the account.
Changes
When this notice changes materially we’ll surface a banner in the app and update the date at the top. The previous version remains available on request.
Contact
Questions about anything on this page: see the contact details on the Impressum page.