Privacy Policy

Last updated 2 August 2026v2026-08-02

LifeGrid is a personal productivity app run by an individual (the "Operator"), not a company. This policy explains what the app collects, why it collects it, who else can see it, and what you can do about it. It applies to lifegrid.ca and everything served from it.

The short version: your content is yours, it is stored so that it can sync between your devices, it is never sold, and it is never used to train anyone's models. The rest of this page is the detail behind that sentence.

1Who is responsible for your data

LifeGrid is operated by an individual based in Canada. For the purposes of Canadian privacy law (PIPEDA) the Operator is the organization accountable for the personal information described here. If you are in the UK or the European Economic Area, the Operator acts as the data controller for that information.

You can reach the Operator about anything on this page at privacy@lifegrid.ca.

2What LifeGrid collects

Almost everything the app holds is content you typed in yourself. The rest is the minimum needed to run an account, keep the service working, and keep it within its free hosting limits.

Account information
Your email address, a password (stored only as a hash by the authentication provider, never in readable form), your display name, and your account settings: interface language, timezone, clock format, navigation preferences, and your dashboard layout.
Content you create
Tasks and boards, mind maps, habits, transactions and budgets, calendar events, trips and itineraries, journal entries, wardrobe items and outfits, meal plans and shopping lists, focus sessions, tracked products, friends, and chat messages. Photos you upload are included here.
Health and other sensitive information
If you use the period tracker, the dates and symptoms you log are health information. If you keep a journal, its contents are likely to be personal. Both are treated as sensitive: see the section on sensitive information below.
Usage information
So the Operator can see whether the app is being used and stay inside free hosting tiers, the app records a periodic heartbeat while a tab is open and engaged: seconds of active use per day, the time you were last seen, the page you were last on, and whether you were on a phone or a desktop. This is per-account and visible only to the Operator.
Approximate location
Once per session, your approximate location (country, region, and city) is resolved from your IP address. The IP address itself is not stored: only a keyed hash of it is kept, so that a repeat visit from the same network does not have to be looked up again. Your device's GPS is never used, and the browser never asks for location permission.
Anonymous visitor statistics
Logged-out visits increment a per-city counter with no account, no IP address, and no per-visit record attached. This is an aggregate count only.
Feedback and support messages
If you send feedback, the message, the type you chose, any mood you picked, and the page you sent it from are stored and shown to the Operator alongside your account.
Payment information
If you subscribe to LifeGrid+, payment is handled entirely by Stripe. LifeGrid never sees or stores your card number. What LifeGrid stores is your Stripe customer and subscription identifier, your subscription status, and when the current period ends.

LifeGrid has no advertising, no analytics or tracking pixels from third parties, and no cross-site trackers. There is nothing here that follows you to other websites.

3Why LifeGrid collects it, and on what legal basis

Under Canadian law the basis is your consent, given when you create an account and accept this policy, and withdrawable as described below. If UK or EU law applies to you, the corresponding bases are:

  • Performance of a contract: storing and syncing your content, running your account, and providing a paid subscription you asked for.
  • Legitimate interests: keeping the service secure, preventing abuse, understanding whether the app is being used, and staying within free hosting limits. These are balanced against your interests and are limited to what is described above.
  • Consent: sensitive information such as period tracking and journal entries, browser notifications, and sharing any of your content with another person. Consent can be withdrawn at any time.
  • Legal obligation: retaining records where the law requires it, for example basic records of payments.

4Sensitive information

Some of what LifeGrid can hold is more sensitive than a task list, and it is handled differently.

Period tracking is off unless you use it, is visible only to you, and is shown to a partner only if you explicitly invite one and choose what they can see. It is never included in any aggregate the Operator can view.

The journal is the only app in LifeGrid that cannot be shared with anyone. There is no collaborator mechanism for it, by design, and no way for another user to be granted access to your entries.

Neither is used for any purpose other than showing it back to you. Neither is profiled, analysed, or used to derive anything about you.

The Operator has database-level administrative access to the hosting infrastructure, which is technically capable of reading stored content. That access is used for operating and repairing the service, not for reading your entries. If that is not a level of trust you are comfortable with, please do not store anything in LifeGrid you would not want an administrator to be able to reach.

5When your content is visible to other people

Nothing you create is visible to another user unless you make it so. The ways that can happen are all explicit actions you take:

  • Inviting someone to a task board, mind map, trip, calendar, wardrobe, or grocery list as a viewer or an editor. They see that resource and, where the feature allows it, your display name against your contributions.
  • Sending a chat message or starting a call: the other participants see it. Calls connect your device directly to theirs, which means each of you can see the other's IP address, as with any peer-to-peer call.
  • Sending a file or a text snippet with Send: it goes directly between the two devices. If a direct connection cannot be established, the file is encrypted in your browser and relayed through temporary storage, where it is deleted after download and in any case within one day. The encryption key never reaches the server.
  • Sharing your screen: the other person sees a live mirror of your LifeGrid tab, excluding your chat panel and the assistant. Nothing is recorded or stored.
  • Adding a friend: they can see your display name, your online status, and when you were last seen.
  • Inviting a partner to the period tracker, where you control what is shared.

6Who else processes your data

LifeGrid runs on third-party infrastructure. These providers process data on the Operator's instructions in order to make the app work. They are not permitted to use it for their own purposes.

Supabase
Database, authentication, file storage, and realtime sync. This is where your account and your content live.
Cloudflare
Hosting, content delivery, and DNS. Cloudflare terminates the connection and therefore sees request metadata such as your IP address, and supplies the country-level traffic counts and the approximate location described above. Temporary Send relay files are stored here.
Stripe
Payment processing for LifeGrid+. Stripe collects and holds your payment details directly, under its own privacy policy.
Resend
Sends transactional email: invitations, sign-up confirmation, and password resets. It processes your email address and the content of those messages.
IPStack
Turns an IP address into an approximate city. Used only when Cloudflare's own edge location data is unavailable.

7Requests your browser makes to other services

Several features fetch public data directly from your browser, which means those services see your IP address and the query, but receive nothing that identifies your LifeGrid account. None of them require a key or an account:

  • OpenStreetMap, Photon, and Nominatim for map tiles, place search, and address lookup in Trips.
  • Wikipedia and Wikimedia Commons for place descriptions and photos.
  • Open-Meteo for trip weather forecasts.
  • An open exchange-rate feed for the currency converter.
  • Your browser's built-in speech synthesis for pronouncing vocabulary words. This runs on your device and sends nothing anywhere.

8The AI assistant

Tala, the in-app assistant, is rule-based by default: it matches what you type against a fixed set of commands, entirely inside the app, and nothing leaves the server.

The optional AI fallback only works if you supply your own API key from Anthropic or OpenAI. When you do, and only for the requests that fall through to it, the relevant part of your message and the data needed to answer it are sent to that provider under your own account and their terms. The Operator pays nothing and receives nothing back.

Your key is encrypted before it is stored, using a key derived separately for your account, and the browser is not able to read it back: it can only see a masked hint and whether one is saved. Removing the key in Settings ends this entirely.

Your content is never used to train any AI model, by the Operator or by anyone else. The commercial API terms of both supported providers exclude training on submitted data.

9How long things are kept

  • Your content is kept until you delete it or close your account.
  • Deleted task boards, mind maps, trips, and journal notebooks go to a recycle bin and are recoverable for 30 days, after which they are removed permanently.
  • Chat messages may expire automatically. The retention period is shown in the app and depends on your plan; where no period is set, messages are kept until deleted.
  • Relayed Send files are deleted as soon as the recipient downloads them, and no later than one day after upload.
  • Usage heartbeats and approximate location are kept as a single current record per account per day, and are removed with the account.
  • Anonymous visitor counts are aggregates with no link to any account and are kept indefinitely.
  • Basic payment records are kept as long as tax and accounting rules require, independently of account deletion.

10Your rights

You can do most of this yourself, from inside the app:

  • Access and correction: your content is visible and editable in the app at any time, and your account details are in Settings.
  • Deletion: Settings has a delete-account option that removes your account and the content attached to it. Deletion is permanent and cannot be undone.
  • Withdrawing consent: stop using a feature, remove a share, revoke a collaborator, turn off notifications, or delete your AI key. Withdrawing consent for the processing that runs the account means closing the account.
  • Portability: you can export your finance data as CSV from within the app. For a copy of anything else the app holds about you, ask and it will be provided.
  • Objection and restriction: if UK or EU law applies to you, you can object to processing based on legitimate interests and ask that processing be restricted while an objection is considered.

11Where your data is processed

The providers listed above operate internationally, and your information is likely to be stored or processed outside Canada, including in the United States and the European Union. While it is in another country it is subject to that country's laws, which can include lawful access by its courts and authorities.

Where UK or EU law applies, transfers rely on the providers' standard contractual clauses and equivalent safeguards.

12Security

  • Every table in the database enforces row-level security, so a request can only ever reach rows the signed-in account is entitled to. Sharing is enforced at the database, not in the interface.
  • Traffic is encrypted in transit. Passwords are only ever stored hashed.
  • Photos are normally re-encoded in your browser before upload, which removes embedded metadata including any GPS coordinates the camera recorded. This is not guaranteed for every image: where re-encoding fails or would not reduce the file size, the original is uploaded as it is and may still carry that metadata. Remove location data from a photo yourself if it matters to you.
  • Relayed Send transfers are encrypted in your browser before they leave your device.
  • Your AI provider key is encrypted at rest with a key derived per account, and is not readable by the browser.

No system is perfectly secure, and this one is run by one person on free infrastructure tiers. Please keep that in mind when deciding what to store here.

13Children

LifeGrid is not intended for children. You must be at least 16 years old to create an account. If you believe someone under that age has created one, contact privacy@lifegrid.ca and it will be removed.

14Cookies and local storage

LifeGrid sets no advertising or analytics cookies, and there is no consent banner because there is nothing to consent to beyond what the app needs to function.

The cookies that are set hold your login session. The app also uses your browser's local storage for device-specific preferences that deliberately do not sync: whether the sidebar is collapsed, where you dragged the assistant bubble, your call data-saver choice, and which introductory panels you dismissed.

15Changes to this policy

This policy may change as the app does. The date at the top of the page is updated whenever it does. If a change materially affects how your information is handled, you will be asked to review and accept it in the app rather than being expected to notice a new date.

16Contact and complaints

For any question, request, or complaint about this policy, write to privacy@lifegrid.ca. You will get a reply within 30 days.

If you are not satisfied with the response, you can complain to the Office of the Privacy Commissioner of Canada. If you are in the UK or the EEA, you can complain to your national data protection authority instead.

Privacy Policy | LifeGrid