LifeHQ

Privacy Policy

Last updated 26 August 2026

LifeHQ holds your calendar, your contacts, your tasks and — if you use that part — what you owe and to whom. This page says plainly what happens to it. It describes the service as actually built, not as a lawyer might wish it were.

The short version

Who is responsible

LifeHQ is operated by [LEGAL ENTITY NAME] of [ADDRESS]. For anything in this policy, write to [PRIVACY CONTACT EMAIL].

What we collect

Only what you type in, plus the minimum needed to run the service. There is no data collected about you from anywhere else.

Your account

What you put in LifeHQ

Everything in the modules you install: calendars and events; todo lists and tasks; memos; contacts; debts and payments; habits; focus sessions; alarms; saved weather locations; and anything captured to your inbox.

Two of those deserve calling out. Contacts means you are storing other people’s personal information — their addresses, phone numbers and birthdays. You are responsible for having a reason to hold it. Debts means balances, interest rates and lender names: financial information about you, held in ordinary database columns like everything else.

Technical data

What we can see

LifeHQ is not end-to-end encrypted. Your data is encrypted in transit (HTTPS) and the disks it sits on are encrypted, but it is stored in a form the service can read — that is what makes search, reminders, recurring events and shared calendars work at all.

In practice this means:

Why we are allowed to hold it

Where UK/EU data protection law applies, our lawful bases are: contract, for everything needed to give you the service you signed up for; legitimate interests, for keeping the service secure and working; and legal obligation, where we must keep or hand over something. We do not rely on consent for anything except optional notification channels, which you can withdraw at any time in Settings.

Who else touches your data

As few companies as we could manage. Each gets only what it needs to do its job.

WhoWhat they getWhy
DigitalOceanEverything — they host the server and databaseHosting and nightly backups (New York region)
CloudflareDNS lookups and connection metadataDomain and network routing
SendGridYour email address and the content of that emailOnly if you enable email reminders
Open-MeteoCoordinates only. Our server asks, not your browser, so they see us rather than you, and there is no account or API key involved.Weather forecasts
Your browser vendorAn encrypted notification payloadOnly if you enable phone or desktop push

Servers and backups are in the United States. If you are in the UK or EU, that is an international transfer; the safeguard we rely on is [TRANSFER MECHANISM — e.g. Standard Contractual Clauses].

Plugins

LifeHQ can be extended with plugins, including ones written by other people. This is the part of the service where your data could most plausibly leave, so it is worth understanding.

Sharing you choose

How long we keep it

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. Most of that you can do yourself, immediately:

Two things survive, and we would rather say so than leave you to discover it. Copies already written to nightly backups age out with those backups rather than disappearing at once. And if you published a plugin other people installed, the plugin keeps working for them — your name, email and application are erased from it, but the software itself is not withdrawn, because doing so would break other people’s dashboards without warning. Ask us and we will withdraw it.

For anything you cannot do yourself, write to [PRIVACY CONTACT EMAIL] and we will respond within 30 days. If you are unhappy with the answer, you can complain to your data protection regulator — in the UK, the Information Commissioner’s Office.

Security

Passwords are scrypt-hashed and salted per account. Traffic is HTTPS-only. Stored third-party credentials are encrypted with AES-256-GCM. Public share links use 32 bytes of cryptographic randomness. Third-party plugin code runs sandboxed and permission-checked on every request.

None of that makes a system invulnerable. If we discover a breach affecting your data, we will tell you and the relevant regulator without undue delay, and within 72 hours where the law requires it.

Children

LifeHQ is not intended for children under [MINIMUM AGE]. We do not knowingly collect their data, and will delete any we learn we have.

Changes

If we change something that materially affects your privacy, we will tell you in the app before it takes effect — not by quietly editing this page. The date at the top always reflects the current version.