You are telling this thing what you want out of your life. That is about as personal as data gets, and the honest version of this page is more useful to you than a careful one.
Your own words are encrypted before they are stored. Answers, comments, reasons and feedback are unreadable from the database.
Your answers are sent to OpenAI to write your cards. That is the one place your words leave our systems, it is what makes the product work, and OpenAI does not train on them.
There is no tracking of any kind. No analytics, no advertising, no pixels, no third party cookies, no session recording. None of it, anywhere on the site. You can check.
Under the GDPR that makes him the data controller. There is no data protection officer, because there is one person and he is it.
| Your email | To sign you in, to get you back in if you forget your password, and to reach you about your account. |
|---|---|
| Your password | Stored hashed by Supabase, our authentication provider. It is never stored in a form anybody can read, including us. |
| Your answers | What you write in the interview. Encrypted at rest. |
| Your cards | The title, the reason, the photograph and the category. Written by us, so stored as plain text. |
| Your rulings | Yes or no on each card, and the body read: warm, tight, flat, boring. Reasons and comments you type are encrypted at rest. |
| Your settings | How many cards a day, your timezone, your theme. The timezone is how the cards arrive at 11:11 where you are rather than somewhere else. |
| Your plan | Whether you are on the free days or subscribed, and the identifiers Stripe uses for you. Never your card number. |
That is the whole list. There is no profile built about you beyond your own board, no inference about your age, income, location or anything else, and nothing is bought in from anywhere.
It makes your words useless from a database. A stolen key to the database, a leaked backup, somebody with a database login: all of it is ciphertext. What it does not do is make the operator unable to read anything, because the cards are written on a server while you sleep and the words have to exist in the clear at that moment. Reading somebody's board is therefore a deliberate act of deploying code, which is a thing a person notices themselves doing, rather than something that can happen by browsing a table.
These are the only other companies involved. Each one gets the least it needs to do its job.
| Supabase | The database and the sign in. Hosted in the EU. Holds everything in the table above. |
|---|---|
| Cloudflare | Serves the site, runs the code, and holds the nightly backup. Sees the request, including your IP address, as any web host does. |
| OpenAI | Your interview answers and your rulings are sent here to write your cards, and to draw an image where a photograph cannot be found. Via the API, where OpenAI does not train on what is sent. United States. |
| Stripe | Takes the payment and is the merchant of record. Gets your email and your card details, which go to Stripe directly and never reach us. |
| Pexels | Where the photographs on cards come from. Gets a search phrase, such as two or three words describing an object. Never your words. |
| Resend | Sends the few emails there are. Gets your address and the message. |
OpenAI, Cloudflare and Stripe are in or operate from the United States. Transfers there rely on the European Commission's adequacy decision for the EU and US Data Privacy Framework, and on standard contractual clauses.
| To run it | Performing the contract you entered when you signed up. Your email, your answers, your cards, your settings. |
|---|---|
| To charge you | Performing the contract, and a legal obligation to keep accounting records. |
| To keep it working | Legitimate interest in security, backups and stopping abuse. |
Your board is kept for as long as you have an account, including after you stop paying, because nothing anyone makes is ever thrown away. If you ask for your account to be deleted it goes, permanently, including from the backups on their next cycle. Backups are taken nightly and kept for a rolling period. Records of what you paid are kept for as long as Romanian tax law requires, which is currently ten years, and those are held by Stripe as the merchant of record.
Under the GDPR you can ask for a copy of everything held about you, ask for something wrong to be corrected, ask for all of it to be deleted, ask for it in a portable form, object to a use of it, or ask for a use of it to be restricted.
Email paul@1111board.com and say which one. There is no form. You get an answer within thirty days and usually within a day, and it costs nothing.
If you are not happy with the answer, you can complain to a data protection authority. In Romania that is the ANSPDCP, at dataprotection.ro. If you live elsewhere in the EU you can go to the authority in your own country.
11:11 is for adults and accounts are for people 18 or over. Nothing here is built for or aimed at children, and if we find out an account belongs to one it gets deleted.
If there is a breach that puts your data at risk, you will be told, plainly, what happened and what it means for you, and the authority will be notified within seventy two hours as the law requires. You will not find out about it from a footnote.
If what is done with your data changes, this page changes and the date at the top changes with it. If the change is significant, you get an email rather than a quiet edit.