Dieses Dokument ist nur auf Englisch verfügbar. · เอกสารนี้มีให้บริการเฉพาะภาษาอังกฤษเท่านั้น
The short version
- Your memories are yours. We don't sell them, mine them, or show you ads.
- Your database lives in the EU (Ireland), not the US.
- Vault entries are encrypted on your device — we cannot read them.
- AI features only send content when you actively trigger them, and only with your separate consent — which you can withdraw anytime.
- You can export everything, or delete your account and all data, from inside the app.
This summary is for convenience — the full policy below is what governs.
1. Who We Are and How to Contact Us
Lifebook AI ("we", "us", "our") is a personal memory journaling application operated by an individual developer, available at mylifebookapp.com.
Contact for privacy matters:
Email: info@mylifebookapp.com
We respond to all privacy requests within 30 days.
This Privacy Policy applies to all users worldwide. Where specific regional rights apply (EU/EEA, Switzerland, California), we indicate these clearly below.
2. What Data We Collect
| Category | Data | Why We Collect It |
|---|---|---|
| Account | Name and email address, plus either a password (stored only as a bcrypt hash by Supabase Auth — never in plaintext) or, if you choose Sign in with Google, the name, email address, and profile picture Google shares with us (no password is created) | To create and manage your account |
| Memory content | Text you write, photos, voice recordings, dates, mood, and tags. Memories are one of four types: journal, photo, voice, or event. | Core service — preserving your memories |
| Photo metadata (EXIF) | GPS coordinates and timestamp embedded in photos you upload | Auto-filling the date and location so you don't type them manually |
| Location data | Coordinates and place names you attach to memories. Place searches are sent to OpenStreetMap Nominatim. | Showing memories on your Life Map |
| People data | Names, relationships, and family-tree entries you type in. Optional avatar photos you choose to upload. | People screen, family tree, and filtering memories by person |
| AI-derived content | Text embeddings (numerical vectors of your memory text) stored in our own Supabase database using pgvector; AI-generated titles, descriptions, summaries, and life stories | Semantic search and Memory AI Chat |
| Vault entries | Content you place in the Vault, encrypted on your device before it reaches us (see Section 7) | Private entries only you can read |
| Profile | Optional: date of birth, occupation, and other personal details you choose to enter | Personalisation features you enable |
| Payment | Billing email and subscription status. We never see or store card numbers — payments are handled by Stripe (web) or Google Play / Apple via RevenueCat (mobile). | Managing premium subscriptions |
| Usage events | Event name (e.g. "memory_added"), timestamp, and your user ID — no memory content. Stored in our own database, not sent to any analytics company. | Understanding which features are used, to improve the app |
| Diagnostics | Crash and error reports (stack traces, device/OS type) via Sentry | Finding and fixing bugs |
| Technical logs | IP address, browser/device type (Supabase infrastructure logs) | Security, abuse prevention, and reliability |
2a. Data About Other People in Your Memories
Your memories may contain information about other people — family, friends, colleagues — who have not signed up themselves. You are responsible for having an appropriate basis to record this information. We process it solely to provide the Service to you. We do not contact, profile, or build any independent record of people named in your memories.
3. What We Never Do
- No advertising. No ad networks, no ad SDKs, no tracking pixels.
- No selling or sharing your data for anyone else's marketing.
- No face recognition, no biometric data. We do not analyse faces or derive facial geometry from your photos.
- No third-party analytics. Usage events stay in our own database — no Google Analytics, Meta, Mixpanel, or similar.
- No training AI on your memories. Your content is not used to train any model, ours or anyone else's.
- No reading your Vault. It is encrypted with a key derived from your password — or, for Google sign-in accounts, a separate Vault passphrase you set — which we never hold.
4. Legal Basis for Processing (GDPR / nFADP)
For users in the EU/EEA and Switzerland, we process your data on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Creating and operating your account | Performance of contract (Art. 6(1)(b) GDPR) |
| Storing your memories and files | Performance of contract (Art. 6(1)(b) GDPR) |
| AI features (Chat, descriptions, life stories, prompts, semantic search) | Your explicit consent (Art. 6(1)(a) GDPR), and — because your memories may reveal special-category data — Art. 9(2)(a) GDPR. You give this separately from the Terms, before any AI processing, and can withdraw it anytime in Settings. |
| Processing payments | Performance of contract (Art. 6(1)(b) GDPR) |
| On This Day email digests | Consent (Art. 6(1)(a) GDPR) — opt-in, withdrawable anytime in Settings |
| Usage events and crash diagnostics | Legitimate interests (Art. 6(1)(f) GDPR) — keeping the app working and improving it |
| Security and abuse prevention | Legitimate interests (Art. 6(1)(f) GDPR) |
5. Where Your Data Lives and International Transfers
Your memories, photos, and voice recordings are stored at rest in our Supabase project hosted in eu-west-1 — Ireland, EU. We keep your core data in the EU by design.
Some processing necessarily involves a transfer of personal data outside the EU/EEA — most importantly to OpenAI in the United States when you use an AI feature. Where we transfer personal data to a country without an EU adequacy decision, we rely on one or more of the safeguards permitted under Chapter V GDPR:
- Standard Contractual Clauses (Art. 46(2)(c) GDPR) with the provider, and
- the provider's certification under the EU–US Data Privacy Framework where it holds one (an adequacy mechanism under Art. 45 GDPR), and
- supplementary technical and organisational measures — encryption in transit and at rest, data minimisation (only the content a feature needs is sent), and access controls.
We have assessed the risks of these transfers, including the possibility that a US-incorporated provider may be subject to US legal process (such as the CLOUD Act) even where it stores data in an EU region. Supabase, Inc., though it hosts your data in Ireland, is a US-incorporated company and is treated on that basis; the same SCC and technical safeguards apply. You may request a copy of the transfer safeguards (e.g. the SCCs) by emailing us.
Our sub-processors, what each receives, and the safeguard we rely on:
| Provider | Role & what it receives | Location / safeguard |
|---|---|---|
| Supabase, Inc. | Processor — database, authentication, file storage (your memories and account) | Data at rest in EU (Ireland, eu-west-1); provider US-incorporated — SCCs + EU-hosted data |
| OpenAI, L.L.C. | Processor — only the memory content needed for an AI feature you actively trigger | United States; SCCs. Per OpenAI's API Data Processing Addendum, API-submitted data is not used to train its models. |
| Sentry (Functional Software, Inc.) | Processor — crash and error reports; no memory content | EU (Germany) region; SCCs for any provider-side US access |
| Resend | Processor — your email address and the message, to deliver account and digest emails | Sends via EU infrastructure (eu-west-1); SCCs |
| Stripe, Inc. | Independent controller — billing email and payment details you enter directly with them (web) | United States; SCCs and, where applicable, EU–US DPF |
| RevenueCat, Inc. | Processor — subscription status and an anonymous app user ID (mobile) | United States; SCCs |
| Google LLC | Independent controller — Sign in with Google: if you choose it, Google authenticates you and shares your name, email address, and profile picture | United States; governed by Google's Privacy Policy and its transfer safeguards |
| Google Play / Apple | Independent controllers — purchase and subscription handling on mobile | Governed by their own privacy policies and transfer safeguards |
| Vercel, Inc. | Processor — serves the web app; standard web request logs | United States; certified under the EU–US Data Privacy Framework |
| OpenStreetMap / Nominatim | Independent controller — place-name searches and coordinates when you use map or location features | OpenStreetMap Foundation (UK) — OSMF Privacy Policy |
We review this list and each provider's current transfer status (including its EU–US Data Privacy Framework listing at dataprivacyframework.gov) from time to time and will update it as providers change. Questions about any of these? Email info@mylifebookapp.com.
6. AI Features and Automated Processing
When you use an AI feature — Memory AI Chat, photo descriptions, life stories, daily prompts, or semantic search — the relevant content from your memories is sent to OpenAI's API for processing, and the result is stored in your account.
Explicit consent. Because personal memories may reveal special-category data under Art. 9 GDPR (for example health, religious or philosophical beliefs, political opinions, or sexual orientation), we ask for your separate, explicit consent before any AI feature processes your memory content. This consent is distinct from accepting the Terms, is requested the first time you use an AI feature, and can be withdrawn at any time in Settings → AI processing. If you withdraw it, AI features are disabled but none of your memories are deleted, and you can continue to use every non-AI part of the app.
- AI features are triggered by you. Nothing is sent for AI processing in the background.
- Only what's needed is sent — not your whole account.
- Your content is not used to train models.
- AI output is checked by an automated moderation step before it is shown, and you can report content you consider inappropriate.
- No automated decisions producing legal or similarly significant effects are made about you (GDPR Art. 22). AI output is a suggestion you can edit or delete.
- You can delete AI-generated content at any time by editing or deleting the memory.
AI-generated text is for personal use and can be wrong. Don't rely on it for legal, medical, financial, historical, or official purposes.
7. Security
- In transit: TLS/HTTPS on every connection.
- At rest: AES-256 encryption at the infrastructure level (Supabase / AWS).
- Row-level security (RLS): enforced in the database so one account cannot read another's rows.
- Private storage: your photos and recordings are not publicly accessible.
- Passwords: stored only as bcrypt hashes by Supabase Auth — never in plaintext, and never visible to us.
Vault — encrypted on your device
Content you place in the Vault is encrypted on your device before it is uploaded, using envelope encryption: an AES-256 data key is itself wrapped with a key derived via PBKDF2-HMAC-SHA256 (100,000 iterations) from your account password — or, for accounts that sign in with Google, from a separate Vault passphrase you set (since there is no password). We store only the wrapped key and the encrypted content.
This means we cannot read your Vault entries, and neither can anyone who obtained a copy of our database. It also means that if you forget your password (or Vault passphrase), Vault content cannot be recovered by us.
Data breach notification: if a breach poses a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Art. 33 and nFADP Art. 24.
8. Data Retention
| Data Type | Retention |
|---|---|
| Account, memories, files, people, usage events | Kept until you delete your account, then removed |
| Crash/error diagnostics (Sentry) | Per Sentry's retention schedule (typically 90 days) |
| Infrastructure/security logs | Short-term, per our hosting providers' schedules |
| Payment and tax records | Retained by Stripe / Google / Apple as their legal obligations require (commonly up to 10 years) |
When you delete your account in Settings → Delete Account, your account and associated data are removed from our systems. Backups roll off within 30 days. Records that a payment provider must keep by law remain with that provider.
9. Cookies and Local Storage
Lifebook AI uses browser/device local storage, not advertising cookies. It holds your preferences (theme, language, notification settings) and your Supabase session token so you stay logged in. This is strictly necessary for the app to work.
We do not use advertising cookies, tracking pixels, or third-party analytics cookies — so there is nothing to consent to and no tracking to opt out of.
10. Your Rights
Everyone — available right now in the app
- Export your data — Settings → Export My Data (downloads everything as a ZIP)
- Delete your account and all data — Settings → Delete Account
- Correct your data — edit any memory or profile field directly
- Turn off emails — Settings → Reminders → On This Day email digest
EU/EEA users (GDPR)
- Right of access (Art. 15), erasure (Art. 17), and portability (Art. 20)
- Right to rectification (Art. 16) and restriction (Art. 18)
- Right to object to legitimate-interest processing (Art. 21)
- Right to withdraw consent at any time, without affecting prior processing
- Right to lodge a complaint with your national supervisory authority
Swiss users (nFADP)
- Right to information about processing (Art. 25)
- Right to data portability (Art. 28)
- Right to rectification and erasure (Art. 32)
- You may complain to the Federal Data Protection and Information Commissioner (FDPIC)
California users (CCPA/CPRA)
- Right to know what personal information we collect and why
- Right to delete your personal information
- Right to correct inaccurate personal information
- We do not sell or share personal information as those terms are defined by the CCPA/CPRA — there is nothing to opt out of
- Right not to be discriminated against for exercising your rights
Most rights are self-service in the app. For anything else, email info@mylifebookapp.com — we respond within 30 days.
11. Children's Privacy
Lifebook AI is not directed at children and is intended for adults. The minimum age to use the Service is:
- 13 years — United States (COPPA)
- 16 years — EU/EEA (GDPR Art. 8; some member states set 13)
- 16 years — Switzerland (nFADP)
We ask for the account holder's date of birth at sign-up and do not knowingly create an account for anyone below the applicable age. If we learn that an underage person holds their own account, we will delete it. Contact info@mylifebookapp.com if you believe this has happened.
Children documented by a parent. A parent or legal guardian may record memories about their own child within the parent's account. In that case the parent is the account holder and data controller-side user, and the child's information is processed as part of the parent's family memories on the basis that the parent has parental responsibility. This is different from a child operating their own account, which we do not offer. A parent may exercise the data-protection rights in this policy on behalf of their child, and may export or delete that content at any time.
12. Changes to This Policy
We may update this Privacy Policy as the app changes. For material changes we will notify account holders by email and update the "Last updated" date above. If you don't accept a change, you can export your data and delete your account.
13. Supervisory Authority
If you are in the EU/EEA and believe we are processing your data unlawfully, you may lodge a complaint with your local data protection authority. In Switzerland, contact the FDPIC.