Privacy Policy
Last updated: October 6, 2026
LifeOS is operated by Brady Groft, a sole proprietor based in Pennsylvania, USA ("LifeOS", "we", "us"). Questions: bradyfitllc@gmail.com.
The short version: your LifeOS content is end-to-end encrypted on your device. We can't read it, we don't sell anything, and we don't track you.
What we cannot see
Everything you put in LifeOS (tasks, journal, money, health, vault, and so on) is encrypted in your browser with AES-256-GCM before it is stored or synced. The key comes from your password, and your password never leaves your device. Our servers store only ciphertext, and we have no way to decrypt it.
What we do store
- Account: your email address, a login proof derived from your password (not the password), sign-in timestamps, and two-step-login settings if you enable them.
- Encrypted data: your encrypted LifeOS data and your encrypted ("wrapped") data keys.
- Billing: your subscription plan and status and your Stripe customer ID. Card details are collected and stored by Stripe, never by LifeOS.
- Closed-app reminders (only if you turn them on): your device's push address from your browser's push service and the times of your upcoming reminders, so we can send a notice at the right moment. We never receive what a reminder is for: the notice just says "You have a reminder". Sent times are deleted after a day, and everything is removed when you turn reminders off on every device or delete your account.
- Calendar links (only if you add one): to show a Google, Apple or Outlook calendar, our server fetches its link for you and passes the calendar straight to your device. Neither the link nor the calendar is kept on our servers; your copy is stored end-to-end encrypted.
- Attachments (only if you add files): photos and documents are encrypted on your device with your data key before upload, so we store only unreadable blobs. Their names and types are inside your encrypted data.
- Calendar feed (only if you turn it on): this is the one opt-in exception to end-to-end encryption. To let Google, Apple or Outlook show your Life OS calendar, we store a readable copy of the events you choose (or just "busy" blocks, the default) behind a secret link. Turning the feed off deletes it.
- Emergency access (only if you set it up): which accounts you've nominated as trusted contacts, your waiting period, and a copy of your data key sealed so that only that contact's device can open it. We hand it over only after a request and your waiting period, and we still can't read it.
- Shared spaces: who is in each space and its encrypted content. When someone changes a space we may send the other members' devices a notice that says nothing about what changed.
- Basic logs: our hosting and database providers keep standard technical logs (such as IP addresses and request times) for security and reliability.
What we don't do
- No advertising, no data sales, no data brokers.
- No analytics, advertising or tracking cookies or scripts on this site or in the app. We only use your browser's local storage to keep you signed in and remember your settings, which is why there is no cookie banner.
- No reading, scanning or "training" on your content. It is encrypted, so we couldn't if we wanted to.
- Voice capture, location reminders and health imports run on your device. If your browser can't recognise speech on-device, we ask before it uses the browser's own speech service (e.g. Google or Apple); Life OS never receives the audio.
Service providers
We use Supabase (database and authentication), Vercel (website hosting), Stripe (payments), Anthropic (the AI features above) and, if you turn on closed-app reminders, your browser's push service. They process data only to provide those services, and some may process it in the United States or other countries. We don't sell or share your personal information for advertising.
AI features (travel guide and fuel prices)
These are the exceptions to "we never see your content". When you use the AI travel guide, the details you type into it (destination, dates, trip length, travellers, budget, home region, interests and notes) are sent through our server to Anthropic, which generates the answer. The fuel-price lookup sends only the place name you enter. Don't put sensitive personal information in these fields. None of your other encrypted LifeOS data is sent. We don't store these requests, and Anthropic processes them under its own terms and privacy policy.
Chat
The chat bubble on the website and in the app lets you ask questions and message the owner. Unlike your LifeOS data, chat messages are not end-to-end encrypted: they are stored on our server so the owner can read and answer them, and the assistant that replies first is an AI (Claude, by Anthropic), so what you type in chat is sent to it. Chat is optional, we only keep the conversation and, if you give one, your email address (or your account email if you are signed in) so we can reply. Never put passwords, recovery keys or card numbers in chat. Ask the owner to delete a conversation at any time.
Forge Coaching (Forge Elite)
If you have Forge Elite and connect a Forge Coaching account, LifeOS copies the categories you switch on (habits and check-ins, food logs, weight, sleep, steps, water and workouts, from a week before you connected) to Forge, and copies your coach's plan, targets, messages and check-ins back into LifeOS. Data in Forge is not end-to-end encrypted, because your coach needs to read it; Forge's own privacy policy applies to it. You can turn each category off or disconnect at any time under Forge → Settings. LifeOS never stores your Forge password.
Your choices
- Export: download your data at any time, encrypted or plain.
- Delete: Account → Delete account permanently removes your account, encrypted data, keys and subscription. Stripe may keep payment records it is legally required to keep.
- Questions or requests: email bradyfitllc@gmail.com. We reply within a few business days.
How long we keep data
We keep your account and encrypted data until you delete your account, which removes it permanently. Reminder times are deleted after a day. Stripe and our hosts may keep payment and security records for as long as the law requires.
Your rights (GDPR, UK GDPR, CCPA/CPRA and similar laws)
Depending on where you live you may have the right to access, correct, delete, export or restrict the use of your personal data, to object to processing, and to complain to your local data protection authority. California residents can also ask what we collect and have it deleted; we don't sell or share personal information for cross-context advertising, so there is nothing to opt out of, and we won't treat you differently for using your rights. Email bradyfitllc@gmail.com to make a request, or use the export and delete tools in the app. Where the GDPR applies, we process your data to provide the service you signed up for (contract), to keep it secure and prevent abuse (legitimate interests), to meet legal obligations, and, for optional features such as reminders, with your consent, which you can withdraw at any time.
Children
LifeOS is for people 18 and over. We don't knowingly collect data from anyone under 18. If you think a child has an account, email us and we'll delete it.
Health information
Health, cycle and nutrition entries you make are inside your end-to-end encrypted data, so we can't read them. If you connect Forge Coaching and switch on health categories, that copy is readable by your coach (see above). We don't use health data for advertising or share it with anyone else.
Security
Besides end-to-end encryption, we use two-step login (enforced by the database), strict security headers and per-user database access rules. No system is perfect. If you find a vulnerability, please tell us privately at bradyfitllc@gmail.com.
Changes
If we change this policy in a meaningful way, we'll tell you by email or in the app before the change takes effect.