Last updated · June 9, 2026
Privacy Policy
We built LifeOS because we were tired of social apps that treat people like ad inventory. This policy explains what we collect, why, and how you can control it.
Short version. We collect the minimum we need to run the service. We don't show ads, sell your data, or use it to train AI models. You own your content and can export or delete it any time.
1. Who we are
The data controller is LifeOS Ltd, registered in England and Wales. You can reach us at privacy@lifeos.app. For EU/UK users, our representative and DPO is reachable at the same address.
2. What we collect
- Account data. Email, display name, optional avatar, password hash, the locale your browser sends.
- Content. Posts, journal entries, media, circles, threads, replies, meetup RSVPs, favorites and folders — whatever you create.
- Settings. Your privacy and wellbeing toggles (view-count visibility, daily nudge, etc.).
- Operational logs. IP address, user-agent, error reports, and timestamps. We use these for security and reliability; we keep them for 30 days unless an incident is open.
- Billing data. Handled by our payment processor (Stripe or Paddle). We see your plan, status, and the last four digits of your card — never the full number.
We do not collect: precise location, contacts, device IDs, advertising identifiers, or behavioural data for ad targeting.
3. Why we use it
- To provide the service — show your posts to the people you share them with, deliver notifications, run the journal. Lawful basis: performance of contract.
- Security — detect abuse, fraud, and account takeover. Lawful basis: legitimate interest.
- Billing — collect payment for paid plans. Lawful basis: performance of contract.
- Legal compliance — respond to lawful requests, file taxes. Lawful basis: legal obligation.
- Service emails — confirmations, security alerts, plan changes. We don't send marketing email unless you opt in.
5. Your rights
Wherever you live, you can:
- Access a copy of your data (export from Settings → Your data).
- Correct anything that's wrong (edit it in-app or email us).
- Delete your account and all personal content (Settings → Close account).
- Object to processing based on legitimate interest.
- Lodge a complaint with your local data-protection authority (in the UK, that's the ICO).
If you're in California, the CCPA gives you similar rights — same email, same response time.
6. How long we keep things
Account and content data: until you delete it, then up to 30 days in backups. Operational logs: 30 days. Billing records: 7 years (tax law). Crash and abuse reports: 90 days unless an investigation is open.
7. Children
LifeOS is not for under-13s. In some jurisdictions (UK, EU) the minimum is 16 unless your guardian provides consent. If we learn a child has signed up without consent we'll delete the account.
8. International transfers
Your data may be processed in the EU, UK, and US. When data leaves the UK or EEA we rely on Standard Contractual Clauses or equivalent safeguards.
9. Security
We use TLS in transit and database-level encryption at rest, row-level security on every public table, and password hashing with bcrypt. End-to-end encryption for journal entries is on our roadmap. See our Security page for details and to report vulnerabilities.
10. Changes to this policy
We'll email you at least 14 days before any material change. Older versions are available on request.
11. Contact
Privacy questions or rights requests: privacy@lifeos.app.