Privacy Policy
Last updated: 2 August 2026
This policy explains what personal data Adventurelist collects, why we collect it, and the rights you have over it under the General Data Protection Regulation (GDPR).
1. Who we are
The data controller responsible for your personal data is Björn Höglund. For any privacy questions or to exercise your rights, contact us at bjorn@hoglund.eu.
2. What we collect
- Account details — your email address (also your sign-in identifier) and a display name.
- Password — stored only as a salted cryptographic hash. We never store or can see your actual password.
- Your activity — the experiences you mark as completed, the date you completed them, and any personal notes you choose to add.
- Security metadata — limited data used to protect your account, such as failed sign-in counts, temporary lockout status, and password-reset request timestamps.
- Technical — a single strictly-necessary cookie that keeps you signed in.
We do not collect special-category data, we do not use advertising or analytics trackers, and we do not build behavioural profiles or sell your data.
3. Why we use it (legal basis)
- Performance of a contract — creating your account and providing the features you signed up for (tracking progress, notes, dashboard).
- Legitimate interests — keeping the service secure and functioning (e.g. authentication and password resets).
4. Who we share it with
We use a small number of processors to run the service. Your account data is never sold or shared for marketing.
- Microsoft Azure — hosting, database storage (Azure Cosmos DB), and delivery of transactional emails such as password-reset links (Azure Communication Services). Your account and activity data is stored here, and your email address is used to send these account/security emails.
- Anthropic (Claude) — generates the informational descriptions shown on experience pages. Only the experience name and category name are sent; no user personal data is sent.
- Unsplash — supplies illustrative photos. Only search terms (experience and category names) are sent; no user personal data is sent.
Where a processor stores data outside your region, transfers are covered by that provider's standard contractual clauses and safeguards.
5. Cookies
Adventurelist uses only one cookie: a strictly-necessary authentication cookie that keeps you logged in. Because it is essential to a service you actively requested, no consent banner is required for it. We use no analytics, advertising, or third-party tracking cookies.
6. How long we keep it
We keep your account and activity data for as long as your account is active. If you ask us to delete your account, we remove your personal data without undue delay (see your rights below).
7. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct inaccurate data, such as your display name or email.
- Erasure — have your account and personal data deleted ("right to be forgotten").
- Restriction & objection — limit or object to how we process your data.
- Portability — receive your data in a portable, machine-readable format.
To exercise any of these, email bjorn@hoglund.eu. You also have the right to lodge a complaint with the Swedish data protection authority, Integritetsskyddsmyndigheten (IMY).
8. Children
Adventurelist is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date at the top of this page.