Privacy and security
Plain answers about your data.
Life OS holds the most personal things you track. Here is what happens to them.
What is stored, and where
Only what you put in: your accounts and entries, workouts, habits, journal, content ideas, notes, reminders, and your profile settings. It lives in a Supabase database. The website itself runs on Vercel.
There are no third-party trackers and no analytics on this site or in the app. Fonts are served from the same site.
Who can see it
You can. A household partner you invite can see shared Finance, and only that. Fitness, Content, Habits and Journal are personal: your partner sees none of it, and you see none of theirs.
This is enforced in the database with row-level security on every table, not just in the screens you see.
What AI sees
AI features use Google’s free Gemini tier, and only when you press a button. They send the text you are working on: for example a content idea, its title and your channel’s voice note, or an Inbox note you ask to sort.
Money, body and journal data never go to a free model. Finance, Fitness, Habits and Journal have no AI features, and Sort with AI never sends a note that a Finance, Fitness, Habits or Journal shortcut would claim, or one that looks like money, body, health or feelings.
Content trend research, when you press Research, sends a channel’s topic words to a web search service. Nothing else about you goes with it.
Prefer your own tools? Copy prompt gives you the exact text so you can use any chatbot and paste the reply back.
The demo
The demo is a separate account filled with fictional data, refreshed every night. It is read-only. Nothing in it is anyone’s real life.
Backups and deletion
Each module has a download in Settings: Finance as JSON or CSV, and Fitness, Content, Habits and Journal as one file each. The free database tier keeps no automatic backups for you, so download a copy now and then.
You can delete almost anything: single items (with Undo), or a whole module with Start over, which asks you to type a confirmation.
How it is protected
- Row-level security on every table, and an automated database test that sweeps every schema to prove it.
- A strict content security policy with a fresh nonce on every page load, and HSTS.
- Sessions in httpOnly cookies that scripts on the page cannot read.
- Per-account sign-in limits, so guessing passwords gets nowhere. A rejected sign-in looks the same whether or not the account exists.
- Recording mode, which blurs amounts, bodies and names when you share your screen.
Questions
Questions about your data: ask the person who runs this Life OS for you.