Privacy Policy
Lifetimed is local-first: your data lives on your device, and nothing leaves it unless you sign in for encrypted backup & sync or use an online feature.
Last Updated: September 2, 2026
Lifetimed ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our application.
Data Storage
- • Local-First Architecture: All your personal data (tasks, moments, journal entries, connections, etc.) is stored locally on your device using IndexedDB and works fully offline.
- • You Own Your Data: Your data never leaves your device unless you sign in and enable cloud backup & sync, or explicitly use an online feature.
- • Account & Access: New installs require an account and an active subscription to use the app. You can personalize your setup and capture your first items locally before creating an account, and that data stays on your device until you sign in and enable cloud backup & sync. (Some earlier installs retain account-free access.)
Data We Collect
- If you sign in for Cloud Backup & Sync (optional):
- • Email address (used for sign-in and account recovery), and — if you sign in with Google or Apple — the name and profile picture your provider shares with us; Apple's Hide My Email relay addresses are supported
- • Transactional email delivery records (sign-in links, receipts, renewal notices) held by our email provider, Resend
- • A device record per synced device (random identifier, device name)
- • Encrypted backups (AES-256-GCM encrypted before upload) and encrypted sync changes
- • Photo and file attachments you sync, stored as-is in your account's private storage so they can be restored on your other devices
- • Subscription status and a random subscription identifier (managed by Stripe on the web and RevenueCat / Apple / Google on mobile — we never see payment details)
- If you use AI Features (optional):
- • Text, images, voice notes, files, or links you explicitly submit for AI analysis (e.g. Smart Capture, Drop Ingestion, Compass, photo-to-moment)
- • AI requests are processed by our AI providers (Google Gemini as primary, OpenAI as fallback) with data minimization, and only run when you trigger them
- • Live dictation while you record a voice note uses your device's speech recognition (Apple's on iOS), which may process audio on Apple's servers
- If you use Health features (optional):
- • Symptoms, medications, workouts, and check-ins you log stay on your device. With Cloud Backup & Sync on, they travel only inside your encrypted backups, and they are never sent to AI providers unless you explicitly submit them for analysis
- If you use Weather Features (optional):
- • The city you set, and — only if you grant location permission — your approximate device coordinates (or, as a fallback, IP-based location), which are sent to WeatherAPI to fetch local weather
How We Use Your Data
- • Cloud Backup & Sync: Store encrypted backups and sync your changes across your signed-in devices
- • AI Processing: Extract tasks, moments, and people, draft moments from photos, and generate summaries, reviews, and insights (e.g. Compass) from content you submit
- • Weather: Fetch current weather for the city you set (or, with your permission, your approximate location)
- • We do NOT sell, share, or monetize your personal data
- • We do NOT use your data for advertising
- • We do NOT train AI models on your data
Third-Party Services
- • Supabase: Authentication and encrypted cloud storage (EU/US data centers)
- • Google Gemini: Primary AI provider for text and image analysis (processed per Google's API data usage policy; not used to train its models)
- • OpenAI: Fallback AI provider for text and image analysis (processed per OpenAI's API data usage policy)
- • Apple Speech Recognition: On iOS, live dictation of voice notes is handled by the system speech recognizer; audio may be processed on Apple's servers under Apple's privacy policy
- • WeatherAPI: Weather data for the city you set, or your approximate coordinates when you grant location permission (used only to fetch current weather, not for ongoing tracking)
- • Stripe: Payment processing for web subscriptions (we don't store payment details)
- • RevenueCat: Mobile subscription management for iOS/Android (handles in-app purchases securely)
- • Apple/Google: In-app purchase processing on iOS/Android devices, and optional sign-in (Sign in with Apple, Google Sign-In)
- • Resend: Delivery of transactional email (sign-in links, receipts, account notices)
Every provider above processes your data only on our instructions, for the purpose listed, under a contract that requires at least the same level of protection this policy gives you. None of them may use your content for advertising or to train models.
Security Measures
- • Encryption: AES-256-GCM encryption for cloud backups; sync changes encrypted at rest
- • Transport Security: All data transmitted over TLS 1.3
- • Access Control: Authenticated, per-account access — your data is only readable by your signed-in devices
- • Rate Limiting: Protection against brute-force attacks
- • Input Validation: All inputs sanitized to prevent injection attacks
- • SSRF Protection: Server-side request forgery prevention
- • Security Headers: CSP, HSTS, X-Frame-Options, and more
Your Rights
- • Access: Export all your data at any time in multiple formats
- • Deletion: Delete all local data with one tap, or delete cloud account
- • Portability: Export to JSON, CSV, Markdown, or PDF
- • Control: Choose exactly what features to use and what data to share
Data Retention
- • Local data: Retained until you delete it
- • Cloud backups & sync changes: Retained until you delete them or your account (older backups are pruned automatically)
- • AI requests: Not retained by Lifetimed (see Google Gemini's and OpenAI's data policies)
- • Account, subscription and device records: kept while your account exists and deleted when you delete your account (Stripe / Apple / Google keep their own billing records for as long as tax law requires)
- • Email delivery logs: kept by Resend for up to 90 days for deliverability, then deleted
- • Withdrawing consent: turn off AI features in Settings › Privacy at any time (nothing further is sent), revoke location or notification access in your device settings, or delete your account to stop all cloud processing
- • Logs: Server logs retained for 30 days for security purposes
Contact Us
For privacy concerns or data requests, contact us at: hello@lifetimed.app
Positive Social Digital Limited
Nairobi, Kenya