← Back to Lifebook AI

Privacy Policy

Last updated: July 24, 2026 · Effective: July 24, 2026

Language notice. This document is available in English only. The English version is the authoritative text.
Dieses Dokument ist nur auf Englisch verfügbar.  ·  เอกสารนี้มีให้บริการเฉพาะภาษาอังกฤษเท่านั้น

The short version

This summary is for convenience — the full policy below is what governs.

1. Who We Are and How to Contact Us

Lifebook AI ("we", "us", "our") is a personal memory journaling application operated by an individual developer, available at mylifebookapp.com.

Contact for privacy matters:
Email: info@mylifebookapp.com
We respond to all privacy requests within 30 days.

This Privacy Policy applies to all users worldwide. Where specific regional rights apply (EU/EEA, Switzerland, California), we indicate these clearly below.

2. What Data We Collect

CategoryDataWhy We Collect It
AccountName and email address, plus either a password (stored only as a bcrypt hash by Supabase Auth — never in plaintext) or, if you choose Sign in with Google, the name, email address, and profile picture Google shares with us (no password is created)To create and manage your account
Memory contentText you write, photos, voice recordings, dates, mood, and tags. Memories are one of four types: journal, photo, voice, or event.Core service — preserving your memories
Photo metadata (EXIF)GPS coordinates and timestamp embedded in photos you uploadAuto-filling the date and location so you don't type them manually
Location dataCoordinates and place names you attach to memories. Place searches are sent to OpenStreetMap Nominatim.Showing memories on your Life Map
People dataNames, relationships, and family-tree entries you type in. Optional avatar photos you choose to upload.People screen, family tree, and filtering memories by person
AI-derived contentText embeddings (numerical vectors of your memory text) stored in our own Supabase database using pgvector; AI-generated titles, descriptions, summaries, and life storiesSemantic search and Memory AI Chat
Vault entriesContent you place in the Vault, encrypted on your device before it reaches us (see Section 7)Private entries only you can read
ProfileOptional: date of birth, occupation, and other personal details you choose to enterPersonalisation features you enable
PaymentBilling email and subscription status. We never see or store card numbers — payments are handled by Stripe (web) or Google Play / Apple via RevenueCat (mobile).Managing premium subscriptions
Usage eventsEvent name (e.g. "memory_added"), timestamp, and your user ID — no memory content. Stored in our own database, not sent to any analytics company.Understanding which features are used, to improve the app
DiagnosticsCrash and error reports (stack traces, device/OS type) via SentryFinding and fixing bugs
Technical logsIP address, browser/device type (Supabase infrastructure logs)Security, abuse prevention, and reliability

2a. Data About Other People in Your Memories

Your memories may contain information about other people — family, friends, colleagues — who have not signed up themselves. You are responsible for having an appropriate basis to record this information. We process it solely to provide the Service to you. We do not contact, profile, or build any independent record of people named in your memories.

3. What We Never Do

4. Legal Basis for Processing (GDPR / nFADP)

For users in the EU/EEA and Switzerland, we process your data on the following legal bases:

Processing ActivityLegal Basis
Creating and operating your accountPerformance of contract (Art. 6(1)(b) GDPR)
Storing your memories and filesPerformance of contract (Art. 6(1)(b) GDPR)
AI features (Chat, descriptions, life stories, prompts, semantic search)Your explicit consent (Art. 6(1)(a) GDPR), and — because your memories may reveal special-category data — Art. 9(2)(a) GDPR. You give this separately from the Terms, before any AI processing, and can withdraw it anytime in Settings.
Processing paymentsPerformance of contract (Art. 6(1)(b) GDPR)
On This Day email digestsConsent (Art. 6(1)(a) GDPR) — opt-in, withdrawable anytime in Settings
Usage events and crash diagnosticsLegitimate interests (Art. 6(1)(f) GDPR) — keeping the app working and improving it
Security and abuse preventionLegitimate interests (Art. 6(1)(f) GDPR)

5. Where Your Data Lives and International Transfers

Your memories, photos, and voice recordings are stored at rest in our Supabase project hosted in eu-west-1 — Ireland, EU. We keep your core data in the EU by design.

Some processing necessarily involves a transfer of personal data outside the EU/EEA — most importantly to OpenAI in the United States when you use an AI feature. Where we transfer personal data to a country without an EU adequacy decision, we rely on one or more of the safeguards permitted under Chapter V GDPR:

We have assessed the risks of these transfers, including the possibility that a US-incorporated provider may be subject to US legal process (such as the CLOUD Act) even where it stores data in an EU region. Supabase, Inc., though it hosts your data in Ireland, is a US-incorporated company and is treated on that basis; the same SCC and technical safeguards apply. You may request a copy of the transfer safeguards (e.g. the SCCs) by emailing us.

Our sub-processors, what each receives, and the safeguard we rely on:

ProviderRole & what it receivesLocation / safeguard
Supabase, Inc.Processor — database, authentication, file storage (your memories and account)Data at rest in EU (Ireland, eu-west-1); provider US-incorporated — SCCs + EU-hosted data
OpenAI, L.L.C.Processor — only the memory content needed for an AI feature you actively triggerUnited States; SCCs. Per OpenAI's API Data Processing Addendum, API-submitted data is not used to train its models.
Sentry (Functional Software, Inc.)Processor — crash and error reports; no memory contentEU (Germany) region; SCCs for any provider-side US access
ResendProcessor — your email address and the message, to deliver account and digest emailsSends via EU infrastructure (eu-west-1); SCCs
Stripe, Inc.Independent controller — billing email and payment details you enter directly with them (web)United States; SCCs and, where applicable, EU–US DPF
RevenueCat, Inc.Processor — subscription status and an anonymous app user ID (mobile)United States; SCCs
Google LLCIndependent controller — Sign in with Google: if you choose it, Google authenticates you and shares your name, email address, and profile pictureUnited States; governed by Google's Privacy Policy and its transfer safeguards
Google Play / AppleIndependent controllers — purchase and subscription handling on mobileGoverned by their own privacy policies and transfer safeguards
Vercel, Inc.Processor — serves the web app; standard web request logsUnited States; certified under the EU–US Data Privacy Framework
OpenStreetMap / NominatimIndependent controller — place-name searches and coordinates when you use map or location featuresOpenStreetMap Foundation (UK) — OSMF Privacy Policy

We review this list and each provider's current transfer status (including its EU–US Data Privacy Framework listing at dataprivacyframework.gov) from time to time and will update it as providers change. Questions about any of these? Email info@mylifebookapp.com.

6. AI Features and Automated Processing

When you use an AI feature — Memory AI Chat, photo descriptions, life stories, daily prompts, or semantic search — the relevant content from your memories is sent to OpenAI's API for processing, and the result is stored in your account.

Explicit consent. Because personal memories may reveal special-category data under Art. 9 GDPR (for example health, religious or philosophical beliefs, political opinions, or sexual orientation), we ask for your separate, explicit consent before any AI feature processes your memory content. This consent is distinct from accepting the Terms, is requested the first time you use an AI feature, and can be withdrawn at any time in Settings → AI processing. If you withdraw it, AI features are disabled but none of your memories are deleted, and you can continue to use every non-AI part of the app.

AI-generated text is for personal use and can be wrong. Don't rely on it for legal, medical, financial, historical, or official purposes.

7. Security

Vault — encrypted on your device

Content you place in the Vault is encrypted on your device before it is uploaded, using envelope encryption: an AES-256 data key is itself wrapped with a key derived via PBKDF2-HMAC-SHA256 (100,000 iterations) from your account password — or, for accounts that sign in with Google, from a separate Vault passphrase you set (since there is no password). We store only the wrapped key and the encrypted content.

This means we cannot read your Vault entries, and neither can anyone who obtained a copy of our database. It also means that if you forget your password (or Vault passphrase), Vault content cannot be recovered by us.

Data breach notification: if a breach poses a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Art. 33 and nFADP Art. 24.

8. Data Retention

Data TypeRetention
Account, memories, files, people, usage eventsKept until you delete your account, then removed
Crash/error diagnostics (Sentry)Per Sentry's retention schedule (typically 90 days)
Infrastructure/security logsShort-term, per our hosting providers' schedules
Payment and tax recordsRetained by Stripe / Google / Apple as their legal obligations require (commonly up to 10 years)

When you delete your account in Settings → Delete Account, your account and associated data are removed from our systems. Backups roll off within 30 days. Records that a payment provider must keep by law remain with that provider.

9. Cookies and Local Storage

Lifebook AI uses browser/device local storage, not advertising cookies. It holds your preferences (theme, language, notification settings) and your Supabase session token so you stay logged in. This is strictly necessary for the app to work.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies — so there is nothing to consent to and no tracking to opt out of.

10. Your Rights

Everyone — available right now in the app

EU/EEA users (GDPR)

Swiss users (nFADP)

California users (CCPA/CPRA)

Most rights are self-service in the app. For anything else, email info@mylifebookapp.com — we respond within 30 days.

11. Children's Privacy

Lifebook AI is not directed at children and is intended for adults. The minimum age to use the Service is:

We ask for the account holder's date of birth at sign-up and do not knowingly create an account for anyone below the applicable age. If we learn that an underage person holds their own account, we will delete it. Contact info@mylifebookapp.com if you believe this has happened.

Children documented by a parent. A parent or legal guardian may record memories about their own child within the parent's account. In that case the parent is the account holder and data controller-side user, and the child's information is processed as part of the parent's family memories on the basis that the parent has parental responsibility. This is different from a child operating their own account, which we do not offer. A parent may exercise the data-protection rights in this policy on behalf of their child, and may export or delete that content at any time.

12. Changes to This Policy

We may update this Privacy Policy as the app changes. For material changes we will notify account holders by email and update the "Last updated" date above. If you don't accept a change, you can export your data and delete your account.

13. Supervisory Authority

If you are in the EU/EEA and believe we are processing your data unlawfully, you may lodge a complaint with your local data protection authority. In Switzerland, contact the FDPIC.