Legal
Privacy Policy
LifeOS holds things people don't usually write down — how you slept, how you felt, what you journalled. This explains exactly what is stored, who it reaches, and what you can do about it.
Last updated 25 August 2026
What we collect
Account details. Your name, email address, and timezone. Your password is stored only as a bcrypt hash — we never hold the plaintext and cannot recover it for you. Your timezone is detected from your browser because every streak, reminder and daily total is calculated against your local midnight rather than UTC.
Google sign-in. If you sign in with Google, Firebase passes us the email address, name and account identifier on your Google profile. No password is created for that account.
What you track. Mood ratings and notes, sleep hours, water intake, workouts, habits and their check-ins, and journal entries. Journal entries and mood notes are free text, so they are as personal as you choose to make them.
AI conversations. Messages you send to the assistant and the replies it returns, kept so a conversation survives a page reload.
Preferences and progress. Daily goals, reminder times, whether email reminders are on, and your XP, level and challenge progress.
Notification subscriptions. If you turn on browser notifications, the push endpoint and keys your browser issues.
Technical logs. Our hosting providers keep standard server request logs, including IP address and browser user-agent, for operating the service and preventing abuse.
Product analytics
We use Amplitude to understand how the app is used — which pages get opened, which buttons get pressed, and where people get stuck. It records the interaction: the page you were on and the element you clicked, along with a device identifier, your approximate location derived from your IP, and your browser and operating system.
It does not capture what you write. The contents of your journal entries, mood notes, sleep notes and AI conversations are never sent to Amplitude. We do not use session recording or session replay, which would capture the screen itself; the analytics-only SDK we ship contains no recording code at all.
Amplitude stores a device identifier in your browser to tell one visit from the next. You can stop this at any time with your browser's “Do Not Track” or tracking-protection setting, or by blocking amplitude.com; the app works normally either way.
What we don't do
- No advertising trackers. There is no ad SDK, no advertising pixel and no cross-site profiling in the app.
- No session recording. Nothing captures your screen, your keystrokes or the text of your entries.
- We do not sell your data or share it for advertising.
- We do not read your journal entries or chat history, except where an AI feature you invoked sends them onward as described below.
Cookies
Only the two needed to keep you signed in. access_token is a short-lived session cookie that expires after 15 minutes, and jid is a refresh cookie lasting 7 days that renews your session without making you log in again. Both are httpOnly, so JavaScript cannot read them, and both are marked Secure in production.
Your light/dark theme preference is kept in your browser's local storage and never sent to us. Amplitude keeps a device identifier in browser storage, as described under Product analytics above. There are no advertising cookies and no cross-site tracking.
AI features — what leaves the app
Three features send your data to Anthropic's Claude API for processing. This is the only place your entries leave our own infrastructure in a form tied to what you wrote:
- Assistant chat — your recent mood, sleep, water, fitness, habit and journal entries are summarised into the prompt so the assistant can answer with context about you.
- Journal analysis — the full text of the entry you ask it to analyse.
- Weekly insights — your aggregated statistics for the week.
Anthropic processes this to generate a response and returns it to us. Under Anthropic's commercial terms, API inputs and outputs are not used to train their models. If you would rather nothing left the app at all, simply don't use chat, journal analysis or insights — every tracker works without them.
Who else processes your data
Each of these is a service provider acting on our instructions, not an independent recipient free to reuse your data:
- MongoDB — the database where your account and entries are stored.
- Render — hosts the backend API.
- Vercel — hosts the web app.
- Google Firebase Authentication — verifies the token issued when you sign in with Google.
- Anthropic — powers the AI features described above.
- Resend — delivers verification and reminder emails.
- Amplitude — receives the product-analytics events described above. It never receives your entries.
- Your browser's push service (Google, Apple or Mozilla, depending on your browser) — delivers notifications if you enable them.
We may also disclose data where the law requires it, or where it is necessary to investigate a security incident or abuse of the service.
How long we keep it
Your entries stay for as long as your account exists, or until you delete them individually in the app. Refresh tokens are replaced each time your session renews and cleared when you log out. Email verification tokens expire on their own. When you ask us to delete your account, we remove your account record and the entries attached to it.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you can exercise the following — and most of them don't require asking us at all:
- Access and portability. Settings → Export all data gives you your entire history as JSON or CSV, immediately, with no request needed.
- Correction. Every entry can be edited or deleted in the app, and your name, goals and reminders in Settings.
- Erasure. There is no self-serve delete button yet. Email us from your registered address and we will delete your account and its data.
- Withdrawing consent. Turn off email reminders and push notifications in Settings, and stop using the AI features, at any time.
- Grievance redressal. Write to us at the address below. We aim to respond within 30 days.
Security
Passwords are hashed with bcrypt. Session cookies are httpOnly, Secure and sent over HTTPS, and access tokens expire after 15 minutes. Authentication and AI endpoints are rate-limited per account, and state-changing requests are checked against an allowlist of permitted origins.
To be straightforward with you: this is a small, independently run service. No system is perfectly secure, and we can't promise your data will never be exposed. Please use a password you don't reuse anywhere else.
Children
LifeOS is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If this policy changes materially, we will tell you by email or in the app before the change takes effect. The date at the top always reflects the current version.
Contact
For any privacy question, data request or account deletion, email mayanksaini0416@gmail.com from the address on your account.