Privacy Policy
Last updated · June 25, 2026
TheLifeOS is local-first: your daily entries live on your device, and — when you're signed in — sync securely to your account so they follow you across devices. We collect the minimum we need, and we never sell your data.
Who we are
TheLifeOS ("we", "us") operates the app and the website at thelifeos.org and is the data controller for the personal data described here. Contact us anytime at privacy@thelifeos.org.
The short version
- Your check-ins, wins, journal and other entries are stored on your device, and synced to your account when you're signed in.
- We don't sell your data. Ever.
- We collect the minimum needed to run the service, take payment, and measure the ads that bring people here.
- You can export or permanently delete everything at any time.
What we collect
Data you create
Check-ins, habits, goals, wins, journal entries, workouts, revenue notes and similar content you enter. It's stored locally on your device for speed and offline use. When you're signed in, an encrypted copy syncs to our database (Supabase), protected by row-level security so only you can read it — so it follows you across devices and isn't lost.
Account data
When you create an account we store your email address and basic authentication details (via Supabase) so you can sign in and recover access. You can sign in with email, a one-time code, or Google — if you use Google we receive only your name and email, never your Google password.
Payment data
Payments are processed by Stripe. We never see or store your full card number — Stripe handles that. We keep a record of which plan you're on and your Stripe customer/subscription identifiers so we can unlock the app and manage renewals.
Advertising & measurement
We advertise on Meta (Facebook/Instagram). The Meta Pixel on our site reports a few events to Meta — page views, sign-ups and purchases (with their value) — so we can measure which ads work. It never sends the contents of your entries. See our Cookie Policy for what it sets and how to opt out.
Usage & diagnostics
We keep a simple, first-party count of site visits and limited aggregated diagnostics to keep TheLifeOS reliable. This never includes the contents of your entries.
Connected services
If you connect a third-party account, we access only the data you authorize, only to show it back to you. You can disconnect at any time, which revokes our access.
How we use your data & our legal bases
- To provide the app, your dashboard and cross-device sync — to perform our contract with you.
- To take payment and manage subscriptions — to perform our contract.
- To send essential account emails (sign-in codes, password resets, receipts) — to perform our contract.
- To keep the service secure and working, and to measure and improve our advertising — our legitimate interests (and, for the Meta Pixel, your consent where required).
- To comply with the law where we're obliged to.
Sharing
We do not sell or rent your personal data. We share data only with the service providers (sub-processors) that help us run TheLifeOS, under contracts that require them to protect it — or when required by law:
- Vercel — website hosting.
- Supabase — accounts, database and cross-device sync.
- Stripe — payment processing.
- Resend — sending account and sign-in emails.
- Meta — measuring our ads via the Pixel.
International transfers
Some of these providers process data in the United States and other countries. Where personal data is transferred outside your region, we rely on appropriate safeguards (such as the providers' Standard Contractual Clauses) to protect it.
Security
We protect your data with measures including encryption in transit (HTTPS), row-level security so accounts can only read their own synced data, hashed credentials handled by our authentication provider, and scoped server-side keys. No system is perfectly secure, but we work to keep yours safe.
Your rights & controls
- Export — download all your data as JSON from Settings.
- Delete — wipe your local data from Settings, or contact us to delete your account and synced data.
- Depending on where you live (e.g. the EU/UK under GDPR, or California under the CCPA), you may have rights to access, correct, delete, port, or object to / restrict processing of your data, and to withdraw consent. We don't sell personal information.
- You also have the right to complain to your local data-protection authority.
To exercise any of these, email privacy@thelifeos.org.
Children
TheLifeOS isn't intended for anyone under 16, and we don't knowingly collect data from children. If you believe a child has given us data, contact us and we'll delete it.
Data retention
Local data persists until you clear it. Synced and account data is kept while your account is active and deleted within 30 days of an account deletion request, except where we must retain limited records (such as payment history) for legal or accounting reasons.
Changes to this policy
We may update this policy as TheLifeOS evolves. If changes are material, we'll update the date above and, where appropriate, notify you in the app or by email.
Contact
Questions about privacy? Email privacy@thelifeos.org or use our contact form.
This is a good-faith, plain-language policy, not bespoke legal advice. For a regulated business or at scale, have counsel review it.