Privacy Policy
Life in Lofi is designed to work locally. An account and cloud sync are optional, and product analytics are off until you choose to enable them.
Who this policy covers
This policy covers the Life in Lofi website, web app, Android app, iOS app, account service, and optional cloud sync. “We,” “us,” and “Life in Lofi” refer to the operator of these services. Questions or privacy requests can be sent to login@lifeinlofi.io.
Data you choose to keep in the app
The app can store routines, focus sessions, tasks, reading progress, water, movement, sleep, weight, mood, notes, settings, imported books, and similar activity records. By default, app data is kept on your device using browser or app storage.
If you enable optional account sync, your email address, account and device-session identifiers, and a synchronized copy of supported app records are sent to our service so your devices can share one space. Passwordless sign-in codes and account-deletion codes are stored only in protected hashed form and expire.
Photo Journals
A Photo Journal is a page of six moments from one day. If you make one, our service stores the text that page is built from: the account it belongs to, the day it describes, the story you told about that day, the title, subtitle and the six titles and captions, an optional place name, and the finished image. Finished images are held in private storage that only your account can read.
So that the same people look like themselves from panel to panel, a journal also stores a short written description of each recurring person in it — a name or nickname you use for them and a few words about their appearance. These descriptions are written text, not photographs: we do not store reference photos of anyone, and any photo used while making a journal stays with the assistant you were using and is never sent to us.
Some of these people are not Life in Lofi users. Treat what you write about them as you would treat writing about them in any diary, and only include what they would be comfortable with.
You can see everyone your journals have remembered, and read the description kept for each, from the Photo Journal itself. Removing someone there deletes that description; journals you have already made keep the pictures they already have, and nothing new is drawn from it again. Deleting your account removes all of these descriptions along with everything else.
Device permissions and sensitive data
- Health and fitness: if you connect Health Connect on Android or HealthKit on iOS, the app reads only the categories you approve, such as steps and sleep, to fill your chosen trackers. You can revoke access in your device settings.
- Location and activity: location, motion, and background location may be requested only for an activity you start, such as recording a walk. The app uses these signals to calculate and display that activity.
- Camera, photos, files, and NFC: these permissions are requested only when you choose a feature that needs them, such as importing or capturing content, sharing, or writing a quick-log NFC tag.
Permission-derived information first becomes part of your local app records. If you have enabled account sync, supported records may also be included in your synchronized data. We do not sell health, fitness, location, or other personal data, and we do not use it for advertising.
Optional product analytics
Analytics are off until you turn them on, and that is enforced rather than promised: with no consent recorded, the analytics software is never started, no identifier is created, and nothing is written to your device or sent anywhere. You are asked once during setup, with the switch already off, and declining costs you nothing — no feature is withheld for it. You can change your mind at any time in Settings › Privacy, and turning it off again erases what was stored on your device.
If you do turn them on, the app records which features are used — that a tracker was logged, that a focus session started, that a permission was granted or refused — along with the platform and app version. It never records the values you log. That you drank water is an event; how much, what you weigh, how you slept, what you wrote and what you read are not, and they never leave your device.
Turning analytics on also records a replay of how you moved through the app — which things you tapped, where you scrolled, where you got stuck. Every character of text is blurred before it leaves your device, not after it arrives: the numbers on your stat cards, your name, anything you type, and any value you have logged are all masked, and Photo Journal is cut out of the recording entirely so no photograph of you or anyone you know is ever captured. What is kept is the artwork and your taps, which is what shows us that a control is in the wrong place. You can switch this off with everything else in Settings › Privacy.
Until you sign in, these events are tied only to a random identifier for that installation. If you sign in, they are linked to your account id so the same person on a phone and a laptop is not counted twice. Signing out breaks that link. Your email address is never sent to our analytics provider.
The website at lifeinlofi.io asks separately, in a banner, and records only which pages are read. Refusing is one tap and the site works identically either way. Our privacy, terms and support pages run no scripts at all and are never measured.
Website and service data
When you use the website or account service, infrastructure providers may process ordinary network and security information such as IP address, request time, user agent, and error or abuse signals. We use this to deliver the service, protect it, diagnose failures, and rate-limit sign-in or deletion requests.
Why we process data
We process data to provide the features you request, authenticate and synchronize an optional account, maintain security and reliability, comply with law, and—only after your choice—understand broad product usage. Where consent is required, you may withdraw it at any time. Other processing is limited to providing the service or our legitimate interest in keeping it secure and functional.
Service providers and disclosures
We share data with the following third parties, and only for the purposes listed. We do not sell or rent personal data, and we do not share it for anyone else’s advertising.
- Cloudflare — hosts the website, the app, the API, the database and stored Photo Journal artwork. All data you sync passes through and rests on their infrastructure.
- Resend — delivers transactional email. They receive your email address and the contents of sign-in, email-change and deletion-code messages.
- Google Books — receives the text you type when you search for a book, and serves the cover images shown in the app. It is used only while you are searching.
- Radio stations — when you play a station, your device connects directly to that broadcaster (currently SomaFM, Radio France, Deutschlandfunk, the BBC, listen.moe and Zeno.fm), which receives your IP address like any website you visit.
- PostHog — measures how the app and website are used, and only if you have turned analytics on. Hosted in the European Union, and reached through our own servers rather than directly, so their systems never see your device's address book of requests or any cookie belonging to your account. They receive the events described above and nothing you have logged. If you never enable analytics, no request is ever made to them.
- Spotify — opened as a link when you choose a station or a listening room’s playlist. Playback happens in your own Spotify account under their policy; we never receive it.
- Apple and Google — process information under their own policies when you obtain the app from their stores or use their device services.
We may also disclose data if required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.
Connected AI assistants
You can choose to connect an outside AI assistant, such as ChatGPT or Claude, to your Life in Lofi account. Nothing is connected unless you set it up, and the app works fully without it.
When you connect one, you sign in and grant it a specific set of permissions. Depending on what you grant, it can read the trackers you have turned on, add entries to them, read and add to your book list and pantry, and create Photo Journals. It can only reach what those permissions allow, and only for your own account.
Anything the assistant reads leaves our service and is handled by whoever operates it — OpenAI, Anthropic, or another provider — under their own privacy policy and terms, not this one. We do not control what they retain or how they use it, so it is worth reading their policy before connecting. We do not sell this data or send it anywhere you have not connected yourself.
You can disconnect an assistant at any time from Settings, which revokes its access immediately. Doing so does not remove anything it has already received; that is a matter for that provider.
Retention and deletion
Local records remain on your device until you remove them, clear app storage, or uninstall the app. Synced account data remains while your account is active. Short-lived authentication and deletion codes expire automatically; security and rate-limit records are retained only as reasonably needed to prevent abuse. Aggregated or de-identified operational records may be retained where they can no longer reasonably identify you.
You can permanently delete your account and synced data from Settings in the app or through our web deletion page. Deletion removes the account, synchronized records, device sessions, and API tokens linked to it. Copies in disaster-recovery systems, if any, expire through normal backup rotation. Removing a cloud account does not automatically erase records stored only on another offline device; clear that device’s app data or uninstall it as well.
Your choices and rights
You may use Life in Lofi without an account, decline optional permissions, disable analytics, revoke health or location access in system settings, export or clear local data using available app controls, and delete a synced account. Depending on where you live, you may also request access, correction, portability, restriction, objection, or deletion by contacting us. We may need to verify your identity before acting on a request.
International processing, security, and children
Our providers may process data in countries other than yours under their applicable contractual and legal safeguards. We use HTTPS, access controls, expiring verification codes, hashed secrets, and limited data collection, but no system can guarantee absolute security. Life in Lofi is not directed to children under 13, or the higher minimum age required in their country, and we do not knowingly collect their personal data.
Changes
We may update this policy as the product or law changes. We will post the revised policy here with a new effective date and provide additional notice when a material change requires it.