Security
Last updated: October 5, 2026
LifeOS holds some of the most personal things people write down, so it's built so that we can't read them. This page explains how, what we're still working on, and how to tell us if you find a problem.
How your data is protected
- End-to-end encryption. Everything is encrypted in your browser with AES-256-GCM using a random data key. That key is stored on our servers only in wrapped form: once with a key derived from your password (PBKDF2-SHA256, 600,000 rounds) and once with your recovery key.
- We never see your password. Sign-in uses a separate value derived from it, so our servers can't derive your data key.
- Attachments are encrypted with the same data key before upload and stored as unreadable blobs.
- Shared spaces each have their own key, wrapped to every member's public key (ECDH P-256). Invite links carry their secret in the part of the URL that's never sent to a server. Removing someone rotates the key. Members can compare a safety code to rule out a swapped key.
- Trip links are encrypted in your browser with a fresh random key before upload. The key sits in the part of the link after the # (never sent to a server), so we store only ciphertext. Anyone who has the whole link can read the parts you ticked — costs, confirmation numbers, booking links and notes are never included — and you can stop sharing at any time, which deletes our copy.
- Emergency access seals your data key to your trusted contact's public key. It's released only after they request it and your waiting period passes without you denying it.
- Passkey unlock uses the WebAuthn PRF extension. The data key is wrapped with a secret only your passkey can produce, and that wrapped copy never leaves your device.
- Account protection: optional two-step login (authenticator app), auto-lock after 30 minutes, a list of signed-in devices, a security log and "sign out everywhere". Row-level security in the database means each account can only reach its own rows.
- The site itself: a strict Content Security Policy with no third-party scripts, analytics or ads, HSTS, and no framing.
What isn't end-to-end encrypted
- Your email address, billing status and sign-in metadata.
- That a trip link exists, when it was last updated and when it expires (not what's in it), and the size of its encrypted copy.
- The calendar feed, if you turn it on, because other calendar apps have to read it. It's off by default and shows "busy" blocks only unless you choose otherwise.
- Reminder times for closed-app notifications (never what they're for), and who is a member of which shared space.
Independent audit
We plan to commission an independent review of the encryption design and code and to publish the full report here. It hasn't happened yet, and we won't claim it has until the report is up. The design and the browser code that runs it are readable by anyone in the app's source.
Report a vulnerability
Email bradyfitllc@gmail.com with "LifeOS security report" in the subject. Please include steps to reproduce and what an attacker could achieve. We'll reply within 3 business days, keep you updated, and credit you here if you'd like.
Bug bounty
We pay for valid, previously unknown issues, at our discretion based on impact:
- Critical: reading another user's decrypted data, or recovering data keys or passwords from what our servers store.
- High: account takeover, bypassing two-step login, cross-site scripting in the app, accessing another account's rows or files.
- Medium: bypassing the paywall or shared-space roles, leaking metadata beyond what this page lists.
Ground rules
- Only test against accounts you own. Never access, change or delete other people's data.
- No denial-of-service, spam, social engineering or physical attacks, and no automated scanning that degrades the service.
- Give us reasonable time to fix an issue before you disclose it publicly.
- Out of scope: missing best-practice headers with no real impact, self-XSS, rate limits on non-sensitive actions, and issues in third-party services (report those to them).
If you follow these rules, we won't pursue or support legal action against you for your research.