Life GPS

Privacy Policy

Last updated: April 25, 2026

Version: 1.0

1. Who we are

This Privacy Policy explains how Life GPS (hereinafter "the App", "we", "us", "our") collects, uses, and protects your personal data.

Controller (data controller under GDPR Article 4):

Data Protection Officer (DPO): The founder acts as the point of contact for data-protection matters at waadsu45@gmail.com. Under GDPR Article 37, appointment of a separate DPO is not required at our current scale (fewer than 250 employees, no large-scale systematic monitoring, no large-scale processing of special-category data). We will appoint an independent DPO before the App exceeds ~50,000 active users in the EU/EEA or begins processing special-category health data at scale.

2. What data we collect

2.1 Data you provide directly

CategoryExamplesLegal basis (GDPR Art. 6)
Account identifiersEmail, hashed password or OAuth ID (Google/Apple)Contract (6(1)(b))
ProfileName, age, (optional) phone, city, avatarContract
Life balance dataSliders for 9 spheres (money, health, love, family, friends, self-realization, education, spirituality, work)Contract — core service
Quiz answersSphere-specific responses (~90 items)Contract — core service
Desires & painsFree-text entries describing goals and obstacles per sphereContract — core service
Tasks & programsTasks, daily check-ins, 21-day program progress, notes, reflectionsContract — core service
Social graph (if used)Contacts you invite, supportive connectionsConsent (6(1)(a)) — explicit opt-in per invite

2.2 Data collected automatically

CategoryWhatLegal basis
Usage analytics (PostHog)Screen views, taps, funnel progression, session duration, device/OS/app versionLegitimate interest (6(1)(f)). Opt-out in Settings.
Error tracking (Sentry)Stack traces, device state, app version, non-identifying breadcrumbsLegitimate interest — fix crashes
Auth metadata (Supabase)Last sign-in timestamp, IP (30-day retention), providerLegitimate interest — security

2.3 Data from third parties

3. How we use your data

  1. Provide the core service — calculate balance, track sphere progress, generate 21-day programs, manage tasks.
  2. Personalize AI guidance — your profile, desires, pains, recent activity inform AI chat responses (Section 5).
  3. Improve the product — aggregated analytics inform roadmap. Pseudonymized in PostHog.
  4. Communicate — transactional emails (login codes, security alerts), opt-in product updates, support.
  5. Security — detect suspicious logins, protect account integrity.
  6. Legal compliance — respond to lawful requests when required.

We do NOT:

4. Third-party services (sub-processors)

ServiceRoleData accessedLocation
SupabaseBackend / DB / authAccount + profileEU (Frankfurt)
Apple (Sign in with Apple)Auth providerEmail / relay emailUSA
Google (Sign In)Auth providerEmail, nameUSA
PostHogProduct analytics (pseudonymized)Usage eventsEU or USA (configurable)
SentryError tracking (no PII)Stack traces, device stateEU (Frankfurt — de.sentry.io)
OpenAI / AnthropicAI inference (chat only)Chat messages + minimal profile contextUSA
Email vendor (selected at launch)OTP / transactional emailEmail + contentUSA / EU

Data transfers outside EU/EEA: Standard Contractual Clauses (SCC) approved by the European Commission, or EU-US Data Privacy Framework where applicable.

5. AI features

Apple App Review Guideline 5.1.2(i) disclosure:

Life GPS includes an AI-powered chat assistant. When you send a message:

  1. Your message + relevant context (name, current sphere scores, active desires/pains, current program, last ~10 messages) is sent to our AI provider (OpenAI and/or Anthropic).
  2. The provider processes data and returns a response.
  3. Per our DPA: messages are not used to train foundation models (zero-retention enabled where supported).
  4. Chat history retained in your Supabase account; you can delete any message any time.

What we do NOT send: your email (provider sees only internal user ID), raw credentials, payment info.

Right to opt out: disable AI chat in Settings. Rest of App keeps working.

6. Data retention

DataRetention
Active accountUntil your account is deleted
Deleted accountHard-deleted within 30 days (backups purged within 90 days)
Auth logs (IP, timestamps)30 days
Error logs (Sentry)90 days
Analytics (PostHog)12 months pseudonymized; aggregated counts indefinitely
AI chat historyUntil you delete or account deletion
Email delivery logs14 days
Legal compliance records3 years post-account-deletion

7. Your rights

Under GDPR / CCPA / similar laws:

Response time: within 30 days (extendable to 60 for complex requests).

8. Security

9. Children

Life GPS is not intended for users under 16 years of age in the EU/EEA, or under 13 in the United States. We do not knowingly collect data from children below these ages. Contact privacy@lifegpsos.com if you believe we have.

10. Cookies and local storage (mobile app)

The mobile app does not use browser cookies. It uses:

11. Changes to this policy

We may update this policy. When we do:

  1. "Last updated" date changes.
  2. Notify in-app at least 14 days before material changes take effect.
  3. Material legal changes may require renewed consent.

12. Contact

ForContact
Privacy / data rightsprivacy@lifegpsos.com
Account / product supportsupport@lifegpsos.com
Abuse / AI content reportsabuse@lifegpsos.com
Business / presshello@lifegpsos.com
Legal / DPOWAADSU s.r.o., waadsu45@gmail.com

Until production domain is live, all addresses route to waadsu45@gmail.com.

13. Supplemental jurisdictional notices

13.1 California residents (CCPA / CPRA)

You have the right to know what categories of personal information we collect and to opt out of "sale" or "sharing". We do not sell or share your information. Contact privacy@lifegpsos.com.

13.2 Brazilian users (LGPD)

LGPD rights are substantially similar to GDPR. Contact our Controller above.

13.3 Russian users (152-FZ)

If located in Russia, you have rights under Federal Law No. 152-FZ. Requests via Section 12 contacts. Response within 30 days.

13.4 Other jurisdictions

Local data protection laws apply. We default to the stricter standard.


End of Privacy Policy v1.0