Privacy Policy
Overview
LifeOS is a personal productivity application operated as a SaaS service ("we," "us"). This Privacy Policy explains how LifeOS collects, uses, stores, and protects your information. Operator acknowledgments are listed on the Credits page.
Information We Collect
- Account data: Username, email address, and a securely hashed password when you register.
- Productivity data you enter: Tasks, calendar events, habits, goals, expenses, income, savings goals, memories, attachments, and application settings.
- User-generated files & uploads: Memory attachments, profile photos, wallpapers, and other media you choose to upload.
- Voice & audio data: Voice commands you initiate, optional voice library recordings you save, and related metadata. Browser or device speech recognition may be handled by your operating system or browser; only the resulting text or saved recordings you choose to store are processed by LifeOS as described here.
- Planner, calendar & finance data: Tasks, events, budgets, transactions, and related entries you create in those modules.
- Security data: Hashed Hidden Vault PIN, vault lockout timestamps, and session authentication metadata.
- Payment & billing data: When you purchase a plan or booster, we store order identifiers, payment status, transaction references, purchased SKU, and amounts for billing records and support. We do not store full card numbers or UPI PINs — those are handled by Razorpay or the applicable app store.
- Technical data: Standard server logs (request path, timestamp, and IP address as needed for security and abuse prevention).
- Communication data: Messages you send to support (for example, email content and metadata).
Purpose of Collection
Your data is used solely to operate LifeOS features you choose to use: scheduling, reminders, finance tracking, memory journaling, voice assistance, account security, billing, support, and optional cloud sync or backup. We do not sell your personal data. We do not use your task, finance, or diary content for advertising.
Legal Bases (EEA / UK)
Where the GDPR or similar laws apply, we process personal data on these bases:
- Contract: To provide the LifeOS service you signed up for (account, sync, purchased features).
- Legitimate interests: Security, fraud prevention, abuse detection, and service reliability, balanced against your rights.
- Legal obligation: Where we must retain or disclose data to comply with law.
- Consent: Where required for optional processing beyond what is necessary to provide the service (for example, non-essential communications if offered separately).
AI Processing
Voice commands and recognized LifeOS intents (planner, calendar, finance, and related modules) are processed by LifeOS on the server. Optional Ask LifeOS general-knowledge replies are controlled by your AI privacy setting in Settings → Privacy. External AI processing occurs only when both the operator has configured a supported provider (for example, DeepSeek and/or Google Gemini) and you have enabled external AI in that setting.
When external AI is enabled, LifeOS may send your question text and, if you also enable memory context, short non-vault memory snippets and recent voice conversation context to the configured provider. Vault-protected (hidden) memories, raw task/calendar/finance rows, and raw voice audio are not sent to external AI providers. AI responses may be inaccurate; you remain responsible for decisions you make based on them.
Payment Processing
Web purchases (Premium, Pro, storage boosters, AI boosters, and voluntary support donations) are processed through Razorpay when enabled. Razorpay collects payment credentials according to its own privacy policy. LifeOS receives confirmation of payment, order IDs, and amounts needed to activate your purchase and maintain billing records. Purchases through Google Play or the Apple App Store are processed by those platforms; we receive purchase tokens or receipts needed to grant entitlements.
Email Services
We use your email address for account-related messages such as password reset, email verification, security notices, billing receipts when enabled, and other essential service communications. These transactional messages are necessary to operate your account and are sent regardless of optional marketing preferences.
Marketing and promotional email (for example, product updates, feature announcements, or special offers) is optional. We send it only if you explicitly opt in — for example by checking the optional box at signup or enabling “Product updates and promotional emails” in Settings → Privacy. You can withdraw marketing consent at any time in Settings or via an unsubscribe link included in promotional emails. Withdrawing marketing consent does not stop account-related or security email.
Transactional email is sent via the configured email provider (for example, Resend). We do not sell your email address or use your productivity content for third-party advertising.
Storage
Application data is stored in the configured production database (PostgreSQL in production deployments). Uploaded media (memory attachments, profile photos, wallpapers, voice library files) are stored in protected server storage or an operator-configured durable object store (for example, Cloudflare R2 when enabled). Media is accessible only to your authenticated account unless you choose to export or share it yourself.
Third-Party Services
LifeOS may use the following categories of service providers to operate the product. Each processes data only as needed for its function. See our Subprocessors & Infrastructure Providers page for an implementation-accurate list with Active, Conditional, and Dormant status:
- Hosting & database: Railway hosting with PostgreSQL and a durable media volume in production deployments.
- Email: Resend for transactional email in production when configured.
- Payment (conditional): Razorpay and/or Stripe for web checkout when payments are enabled; Google Play / Apple App Store for mobile purchases when configured.
- AI (conditional): DeepSeek and/or Google Gemini when configured by the operator and enabled in your AI privacy settings.
- Cloud storage (dormant unless enabled): Cloudflare R2 or similar object storage when explicitly configured.
- Error monitoring (conditional): Sentry or similar tooling when enabled by the operator.
- Cache/coordination (dormant unless enabled): Redis when configured.
We do not authorize these providers to use your productivity content for their own marketing purposes.
Analytics & Cookies
LifeOS does not use third-party advertising analytics trackers, advertising cookies, or cross-site advertising pixels. Operators may collect aggregate operational metrics on the server (for example, error rates, uptime, and abuse signals) for reliability and security. No advertising profile is built from your productivity content.
LifeOS uses one essential first-party session cookie (lifeos_session) for sign-in and security. The product also uses browser storage (localStorage, sessionStorage, and service-worker Cache Storage) for workspace preferences and offline support — not for advertising. Razorpay may set its own cookies when you open the payment checkout. See our Cookie & Storage Policy for a complete, implementation-accurate list. We do not claim global cookie-law compliance; if we introduce non-essential analytics that require consent in your region, we will update these policies and the product before enabling them.
Data Retention
We retain your account and content while your account remains active. Enforced time limits (for example, session lifetime, password-reset tokens, and email-verification tokens) and longer-lived data categories are described in our Data Retention & Lifecycle Policy. If you permanently delete your account when eligible, associated personal data is removed from the active LifeOS datastore according to our Account Deletion Policy. Infrastructure backups may retain residual copies until their operator-configured expiry. Accounts with successful paid billing history may have deletion restrictions — see Account Termination in our Terms of Service.
Data Export & Deletion
You may export expense and income data to CSV from Settings → About. Every authenticated user can download a personal-data JSON export from Settings → Privacy (data export). If your plan includes Backup & Sync, you can also download a JSON workspace backup from Settings → Backup & Sync.
You may permanently delete your account from Settings → Security (Account Management) when eligible. Accounts with successful paid billing history cannot be permanently deleted from Settings; you may deactivate instead or contact support@lifeos.vision. See the Account Deletion Policy and Data Retention & Lifecycle Policy for details.
Your Rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data; export available data; object to or restrict certain processing; and withdraw consent where processing is consent-based. In the app, use Settings → Privacy to export your data or submit an access, correction, or deletion request. You may also contact support@lifeos.vision with the subject "Privacy Request." We may need to verify your identity before fulfilling a request.
If you are in the European Economic Area or UK, you also have the right to lodge a complaint with your local data protection supervisory authority. We do not sell personal data as defined under applicable U.S. state privacy laws.
International Data Transfers
LifeOS is accessible to users globally. The service is operated as a SaaS application with hosting, database, and media storage on Railway in the current production deployment at lifeos.vision. Production readiness checks report PostgreSQL and a durable media volume as active infrastructure components.
Depending on how you use LifeOS, personal data may be processed in or transferred to countries where our infrastructure and subprocessors operate. Categories that may involve cross-border processing include hosting and database services, transactional email (Resend), payment processors (Razorpay, Stripe, or app stores when used), optional external AI providers (DeepSeek and/or Google Gemini when enabled), and optional error monitoring (Sentry when configured).
Applicable transfer safeguards depend on the operator’s vendor contracts, the jurisdictions involved, and applicable law. LifeOS does not claim that a specific legal transfer mechanism (such as standard contractual clauses, adequacy decisions, or India DPDP transfer approvals) applies to every subprocessor on this page. Additional jurisdiction-specific contact details will be provided where legally required.
For the current implementation-accurate provider list, see Subprocessors & Infrastructure Providers.
Hidden Vault
Hidden memories and vault content are protected by your vault PIN, which is stored as a one-way hash. LifeOS staff cannot read your PIN. Hidden content is never exposed through voice commands unless you successfully unlock the vault in your active session.
Children's Privacy
LifeOS is not directed at children under 13. During signup, you must confirm that you are at least 13 years old; we record that age attestation with your account. We do not collect date of birth or government ID for age verification. If you believe a child under 13 has created an account or provided personal data, contact us to request deletion.
Security
We use industry-standard measures including HTTPS transport, hashed passwords, access controls, and user data isolation. No method of transmission or storage is completely secure; you are responsible for protecting your password and vault PIN.
If you believe you have found a security vulnerability, please report it responsibly to support@lifeos.vision (subject: Security Report). Do not publicly disclose exploit details before we have had a reasonable opportunity to investigate and remediate. See Contact for reporting guidance.
Changes
We may update this policy as LifeOS evolves. Material changes will be noted in Release Notes and by updating the effective date on this page.
Privacy Contact & Complaints
For privacy questions, data-subject requests, or complaints about how LifeOS handles personal data, contact:
- Email: support@lifeos.vision (subject: Privacy Request, Privacy Inquiry, or Account Deletion Request as applicable)
- In-app: Settings → Privacy (data export and access/correction/deletion requests)
- Web: Contact page
If you are in the European Economic Area or UK and wish to lodge a complaint with a supervisory authority, you may contact your local data protection authority. Additional jurisdiction-specific privacy contacts (for example, EU/UK representative, India grievance officer, or data protection officer details) will be provided where legally required.
Contact
General inquiries: support@lifeos.vision · Contact page
Related: Terms of Service · Subprocessors · Data Retention Policy · Refund Policy · Copyright / DMCA