Lifiary
ENCS

Privacy Policy

This information reflects how Lifiary is currently built and operated. It is provided for transparency and is not legal advice.

Last updated: July 28, 2026

This policy explains how Lifiary processes personal data when you use the app or website, which choices you have, and how to exercise your rights.

Controller and contact

The controller is Jiří Šindelář, Company ID (IČO) 06791417, registered office at Pod Parukářkou 2760/14, 130 00 Prague 3 – Žižkov, Czech Republic; a sole trader registered in the Czech Trade Licensing Register. Privacy and data-subject requests can be sent to privacy@lifiary.com.

What we store

We process account and sign-in data; profile preferences; your birth date and user-chosen life horizon; day and week reflection scores, notes and categories; support messages and limited device diagnostics; notification tokens when enabled; consent records; and short-lived per-account abuse-counter keys plus one-way-hashed network-address buckets used only for rate limiting. We do not store the raw network address in those buckets or sell personal data.

Purposes and legal bases

We process account, profile, life settings and reflections to provide the service and perform our contract with you (GDPR Article 6(1)(b)). Security, abuse prevention, reliability and support rely on our legitimate interests (Article 6(1)(f)); legal obligations use Article 6(1)(c). Optional PostHog interaction analytics is processed only with separate consent (Article 6(1)(a)) and can be refused or withdrawn without losing core features.

Consent-free aggregate product metrics

A server-only function calculates aggregate account totals, onboarding and life-setup completion, activation (life setup plus at least one scored reflection), trailing-30-day activity, exact D1/D7/D30 reflection return windows, scored daily and weekly reflection totals, note totals, and completed versus eligible periods in each selected rhythm (28 completed days or 12 completed ISO weeks). Account, activation and monthly-active counts are also split between anonymous and linked accounts. It reads records already needed to provide Lifiary, creates no tracking rows or device identifiers, includes no note text or other content, returns no user-level rows, and is accessible only to the server-side service role.

Feature-update emails

On the “What we're working on” page, you can subscribe to email updates about the app's launch and the whole product roadmap (consent under GDPR Article 6(1)(a)). We store the normalized email address, the subscription, the consent time and source, plus any withdrawal time. A single confirmation email contains one unsubscribe link that ends the whole subscription, and you may also write to privacy@lifiary.com. Active consent lasts until you withdraw it. We keep the record of your consent and its withdrawal for three years after the withdrawal, as evidence that the mail was lawful. A suppression record prevents further mail and is kept for as long as we send feature updates at all, because deleting it would remove the guarantee that no further message reaches you.

Processors and international transfers

We use Supabase for database, authentication and storage in the EU Central (Frankfurt, eu-central-1) region; Cloudflare for website hosting and web delivery; Resend for application-generated outgoing email, including forwarded in-app feedback, feature-update messages and authentication email; Zoho Mail for incoming support, general and privacy correspondence and human replies, hosted in the EU; Expo for enabled push notifications; PostHog for consented analytics; Sentry for sanitized error reports; and Apple or Google where you choose their sign-in or app-store services. Providers may process data outside the EEA under an adequacy decision, Standard Contractual Clauses, or another lawful safeguard.

Retention

Anonymous accounts that are at least 35 days old and have no reflection logs are eligible for automated deletion. Live account, profile, life-setting, reflection and notification-token data, together with in-app feedback rows in public.feedback, is deleted when in-app account deletion completes; foreign-key cascades remove database rows and the deletion function separately removes avatar files. A copy of in-app feedback forwarded to the mailbox is separate from its public.feedback row and is not deleted automatically with the account. We retain support and general correspondence, including forwarded in-app feedback, for 12 months after the last message in the thread; privacy correspondence is retained for 24 months after the last message in the thread. Verified email erasure requests are handled without undue delay and normally within one month. Rate-limit buckets are eligible for deletion 24 hours after their last use. The intended maximum is 12 months for analytics events and 90 days for sanitized error reports. Encrypted database backups held by our hosting provider roll off on that provider’s schedule; we keep no separate copies.

Your rights

Subject to the GDPR, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw analytics consent in Settings and feature-email consent through its unsubscribe link; withdrawal does not affect earlier lawful processing. The app provides profile editing, JSON data export and account deletion. We normally answer verified requests within one month.

Right to complain

You may lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, uoou.gov.cz, or with the competent authority where you live or work.

Data protection officer

No data protection officer has been appointed because the conditions in GDPR Article 37 are not met.

Security and data minimization

User-owned records are protected by authentication and row-level access rules, and data is encrypted in transit. Optional analytics never includes reflection notes or other free-form content. Error reporting disables default personal data and sanitizes reports. No system can be guaranteed completely secure; contact us if you suspect misuse of your account.

Minimum age

Lifiary is intended for people aged 15 or older. Czech law permits a child to consent to information-society data processing from age 15; where another local rule or a separate legal basis requires parental authorization, use Lifiary only with that authorization.

Automated decisions and changes

Lifiary does not make decisions with legal or similarly significant effects about you. The life horizon is chosen by you and is not a medical assessment. We may update this policy when the service or law changes, show a new date, and provide appropriate notice for material changes.

Contact

For privacy questions or rights requests, contact privacy@lifiary.com. We may need to verify that the request relates to your account before disclosing or changing data.

Back to the home page

Lifiary
Life in weeksWhat we're working onPrivacy PolicyTerms of ServiceSupportDelete account
© 2026 Lifiary

We use optional analytics cookies only if you accept. The site works without them.