Privacy Policy

Your privacy is important to us. This policy explains what we collect, why, and how we protect it.

Last updated: March 21, 2026

1. Introduction

ALife ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use our Service.

This policy applies to all users of ALife, including visitors, registered users, and subscribers, across all platforms (web, mobile app, and any future integrations).

We comply with the General Data Protection Regulation (GDPR) for users in the European Union and the European Economic Area, and take a privacy-first approach for all users globally.

Data Controller: ALife (Independent) — contact: privacy@alife.app

2. Data We Collect

We collect the following categories of personal data:

Account Data • Email address (required for registration and communication) • First name (optional, used for personalization) • Timezone and language preference • Account creation date and last login

Planning & Productivity Data • Annual and monthly goals (titles, categories, priorities, progress, status) • Weekly and daily tasks (titles, due dates, priorities, status, notes, subtasks) • Habit definitions and daily/weekly completion logs • Personal notes written in the weekly planner • Shared list contents and collaborator email addresses • Templates created or used (public templates are accessible to all users) • Tags applied to tasks

Settings & Profile Data • Focus areas (e.g., career, health) • Planning style, discipline level, energy peak preferences • Notification preferences and reminder times • Google Calendar connection status and OAuth tokens (encrypted)

Usage & Technical Data • Device type, browser type, operating system • IP address (used for country detection and security) • Pages visited and features used within the Service • Error logs and crash reports (anonymized where possible)

Payment Data • Subscription plan and billing history • Last 4 digits of card (stored by Stripe, not by us) • Country for tax purposes • We do NOT store full credit card numbers, CVV codes, or complete card details.

Integration Data • Google Calendar: OAuth tokens (encrypted), synced event IDs • We do not store your Google account password.

3. How We Use Your Data

We use your personal data for the following purposes:

Providing the Service • Creating and maintaining your account • Storing and displaying your planning data across devices • Processing payments and managing subscriptions • Syncing data with Google Calendar (when authorized)

Personalization • Detecting your preferred language based on your location • Tailoring dashboard layout and suggestions to your focus areas • Showing relevant templates based on your goals and activity

Communication • Sending account-related emails (verification, password reset, subscription receipts) • Notifying you of material changes to these policies • Sending habit and task reminders (only if enabled in settings) • Sending product updates and newsletters (only with your explicit consent; unsubscribe at any time)

Security & Fraud Prevention • Detecting and preventing unauthorized access to your account • Monitoring for abuse, spam, or Terms violations • Maintaining audit logs for security investigations

Analytics & Improvement • Understanding how features are used to improve the product • Identifying and fixing bugs and performance issues • Measuring feature adoption to prioritize development

Legal Compliance • Fulfilling legal obligations under applicable law • Responding to lawful requests from authorities

We do NOT sell your personal data to third parties, and we do NOT use your planning content (goals, tasks, habits, notes) for advertising purposes.

4. Data Sharing & Disclosure

We share your data only in the following limited circumstances:

Share Lists Collaborators When you add someone to a Shared List by email, their email address and your list contents become mutually visible for collaboration purposes only.

Service Providers (Processors) We engage trusted third-party providers who process data on our behalf: • Stripe — Payment processing. Your payment data is subject to Stripe's Privacy Policy. • Google — Calendar sync (only when you connect your Google account). Subject to Google's Privacy Policy and API Services User Data Policy. • Hosting & Infrastructure — Our servers and databases are hosted on secure cloud infrastructure. Providers are bound by data processing agreements. • Email Delivery — Transactional emails (e.g., password reset) are sent via a third-party email provider.

Legal Requirements We may disclose your data if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, safety, or property of ALife, our users, or the public.

Business Transfers In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will notify you before your data is subject to a different privacy policy.

Aggregated Data We may share anonymized, aggregated statistics (e.g., "X% of users complete their weekly plans") that cannot identify any individual.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service.

Account Deletion: When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required by law to retain it longer (e.g., billing records for tax purposes, which are retained for up to 7 years).

Inactive Accounts: Accounts inactive for more than 2 years may be subject to deletion after a prior notification by email.

Shared Content: Content shared with others (e.g., published public templates, shared list history) may persist after your account deletion if it was shared before deletion. We will remove your name and identity from such content upon request.

Log Data: Technical logs and error reports are retained for up to 90 days.

Backup Data: Encrypted backups may retain data for up to 30 days beyond the standard deletion window for disaster recovery purposes.

6. Your Rights

Depending on your location, you have the following rights regarding your personal data:

Right of Access (Art. 15 GDPR) You can request a copy of all personal data we hold about you. Submit a request at privacy@alife.app.

Right to Rectification (Art. 16 GDPR) You can correct inaccurate or incomplete data directly in your account settings, or by contacting us.

Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR) You can request deletion of your account and all associated data from Settings → Account → Delete Account.

Right to Data Portability (Art. 20 GDPR) You can export your goals, tasks, habits, and notes from Settings → Export Data in JSON or CSV format.

Right to Restrict Processing (Art. 18 GDPR) You can request that we limit processing of your data in certain circumstances (e.g., while a dispute is resolved).

Right to Object (Art. 21 GDPR) You can object to processing based on legitimate interests at any time.

Right to Withdraw Consent Where processing is based on your consent (e.g., marketing emails), you can withdraw consent at any time without affecting the lawfulness of prior processing.

Right to Lodge a Complaint EU/EEA users have the right to lodge a complaint with their local Data Protection Authority (DPA) if they believe their rights have been violated.

To exercise any of these rights, contact us at privacy@alife.app. We will respond within 30 days.

7. Data Security

We implement industry-standard security measures to protect your personal data:

  • Encryption in Transit: All data transmitted between your browser/app and our servers is encrypted using TLS 1.2+.
  • Encryption at Rest: Sensitive data, including OAuth tokens and passwords (hashed), is encrypted at rest using AES-256.
  • Access Controls: Access to production databases is restricted to authorized personnel only, with multi-factor authentication required.
  • Regular Security Reviews: We conduct periodic security audits and dependency vulnerability scans.
  • Incident Response: In the event of a data breach affecting your personal data, we will notify you within 72 hours in accordance with GDPR requirements.

Despite our best efforts, no system is 100% secure. You are responsible for maintaining the security of your account password and for logging out of shared devices.

8. Cookies & Tracking

ALife uses a minimal set of cookies and local storage:

Essential Cookies / Local Storage • Authentication session token (required to keep you logged in) • Language preference ('alife-lang') • Theme preference ('alife-theme') • Tour completion status ('alife_tour_dismissed')

These are essential for the Service to function and do not require consent.

Analytics We may collect anonymized usage statistics to understand how features are used. We do not use advertising trackers (e.g., Meta Pixel, Google Ads).

No Third-Party Advertising Cookies We do not place advertising cookies. We do not share browsing behavior with advertising networks.

You can clear cookies at any time via your browser settings. Clearing essential cookies will log you out.

9. Children's Privacy

ALife is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@alife.app and we will delete the information promptly.

In jurisdictions where a higher age threshold applies (e.g., 13 in the United States under COPPA), we comply with those requirements.

10. International Data Transfers

ALife is operated from within the European Union. If you access the Service from outside the EU/EEA, your data may be transferred to and processed in countries with different data protection laws.

When we transfer data outside the EU/EEA, we ensure appropriate safeguards are in place, such as: • Standard Contractual Clauses (SCCs) approved by the European Commission • Adequacy decisions for countries with equivalent data protection standards • Binding Corporate Rules for internal transfers within corporate groups

For US-based providers (e.g., Stripe, Google), transfers are conducted under SCCs or equivalent frameworks.

11. Third-Party Services

Our Service integrates with or links to third-party services. Each has its own privacy policy:

  • Stripe (payments): stripe.com/privacy
  • Google (calendar sync): policies.google.com/privacy
  • IP Geolocation API (language detection): Used to determine your country; no personal data is stored.

We encourage you to review the privacy policies of third-party services before connecting them to your ALife account. We are not responsible for the privacy practices of third parties.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make significant changes, we will: • Update the "Last updated" date at the top of this page • Send a notification email to registered users • Display an in-app banner for 30 days after the update

Your continued use of the Service after changes are posted constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, please delete your account before the effective date.

13. Contact & Data Protection Officer

For all privacy-related inquiries, data access requests, or complaints:

📧 privacy@alife.app

We aim to respond to all privacy requests within 30 days. For complex requests requiring additional time, we will notify you of the expected timeline.

If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your national Data Protection Authority (DPA).