Privacy Policy
Last updated 26 August 2026
LifeHQ holds your calendar, your contacts, your tasks and — if you use that part — what you owe and to whom. This page says plainly what happens to it. It describes the service as actually built, not as a lawyer might wish it were.
The short version
- There is no tracking. No analytics, no advertising, no third-party scripts, no cookies beyond the one that keeps you signed in.
- Nothing is sold or shared for marketing. Not now, and if that ever changed we would ask first rather than update this page quietly.
- Your data is yours. Export all of it at any time, in one file, from Settings.
- Plugins only get what you grant. Third-party plugins run isolated and must ask for each permission by name.
- We can read your data. It is not end-to-end encrypted. See what we can see — this is the most important thing on this page.
Who is responsible
LifeHQ is operated by [LEGAL ENTITY NAME] of [ADDRESS]. For anything in this policy, write to [PRIVACY CONTACT EMAIL].
What we collect
Only what you type in, plus the minimum needed to run the service. There is no data collected about you from anywhere else.
Your account
- Email address — how you sign in and how we reach you.
- Your name, if you give one. Optional.
- Your password, stored only as a scrypt hash with a per-account salt. We cannot read it and cannot tell you what it is.
- Your time zone and light/dark preference.
What you put in LifeHQ
Everything in the modules you install: calendars and events; todo lists and tasks; memos; contacts; debts and payments; habits; focus sessions; alarms; saved weather locations; and anything captured to your inbox.
Two of those deserve calling out. Contacts means you are storing other people’s personal information — their addresses, phone numbers and birthdays. You are responsible for having a reason to hold it. Debts means balances, interest rates and lender names: financial information about you, held in ordinary database columns like everything else.
Technical data
- One sign-in cookie (
lifehq_session), which is httpOnly and lasts 30 days. It is strictly necessary for the service to work, so we do not ask consent for it. There are no other cookies. - Ordinary web server logs, which include IP addresses and are kept for [LOG RETENTION PERIOD].
- If you turn on phone notifications: a push subscription from your browser, and your device’s user-agent string so you can tell your devices apart when revoking one.
What we can see
LifeHQ is not end-to-end encrypted. Your data is encrypted in transit (HTTPS) and the disks it sits on are encrypted, but it is stored in a form the service can read — that is what makes search, reminders, recurring events and shared calendars work at all.
In practice this means:
- Whoever administers the server can technically read any of it. Today that is a very small number of people.
- We access individual accounts only to fix a fault you have reported, to respond to a security incident, or where the law requires it.
- If you would not want a system administrator to be able to read something, do not put it in LifeHQ. That is true of almost every hosted service; it is rarely said out loud.
Why we are allowed to hold it
Where UK/EU data protection law applies, our lawful bases are: contract, for everything needed to give you the service you signed up for; legitimate interests, for keeping the service secure and working; and legal obligation, where we must keep or hand over something. We do not rely on consent for anything except optional notification channels, which you can withdraw at any time in Settings.
Who else touches your data
As few companies as we could manage. Each gets only what it needs to do its job.
| Who | What they get | Why |
|---|---|---|
| DigitalOcean | Everything — they host the server and database | Hosting and nightly backups (New York region) |
| Cloudflare | DNS lookups and connection metadata | Domain and network routing |
| SendGrid | Your email address and the content of that email | Only if you enable email reminders |
| Open-Meteo | Coordinates only. Our server asks, not your browser, so they see us rather than you, and there is no account or API key involved. | Weather forecasts |
| Your browser vendor | An encrypted notification payload | Only if you enable phone or desktop push |
Servers and backups are in the United States. If you are in the UK or EU, that is an international transfer; the safeguard we rely on is [TRANSFER MECHANISM — e.g. Standard Contractual Clauses].
Plugins
LifeHQ can be extended with plugins, including ones written by other people. This is the part of the service where your data could most plausibly leave, so it is worth understanding.
- They must ask. Every plugin declares the permissions it needs, and they are listed on the button you press to install it. A plugin without
contacts:readcannot read your contacts — not by policy, but because the request is refused. - They run isolated. Third-party plugins execute in a sandboxed frame with no access to your sign-in session, no access to any other plugin’s data, and no direct route to our API.
- They are reviewed before publication. Submitted code is held unexecuted, checked automatically, then read by a person before it can be installed by anyone. Review reduces risk; it does not eliminate it.
- You can revoke. Removing a plugin cuts off its access immediately. We can also disable any plugin for everyone at once if we find a problem.
- A plugin that sends data to its own servers is subject to its developer’s privacy policy, not this one. Any external service a plugin contacts must be declared, and we show you what it declared.
Sharing you choose
- Sharing with another person gives them view or edit access to that one calendar or list, and nothing else in your account.
- A public subscribe link is an unguessable, read-only URL. Anyone holding it can read that calendar without signing in — treat it like a password. Revoking kills it immediately, and the link is never cached by anyone in between.
How long we keep it
- Your content stays until you delete it or close your account.
- Removing a plugin does not delete what it stored, so that reinstalling brings your data back. Closing your account does remove it.
- Backups are taken nightly and held for [BACKUP RETENTION — currently unbounded, see notes]. Data you delete stays in backups until those expire.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. Most of that you can do yourself, immediately:
- Export — Settings → Export everything. One JSON file with your calendars, events, todos, contacts, memos, debts, habits and alarms.
- Correct or delete — edit or delete anything directly in the app.
- Close your account — Settings → Close your account. Deletes everything listed above immediately: there is no waiting period and no soft-delete. We show you beforehand what it will take with it, including anything shared with other people.
Two things survive, and we would rather say so than leave you to discover it. Copies already written to nightly backups age out with those backups rather than disappearing at once. And if you published a plugin other people installed, the plugin keeps working for them — your name, email and application are erased from it, but the software itself is not withdrawn, because doing so would break other people’s dashboards without warning. Ask us and we will withdraw it.
For anything you cannot do yourself, write to [PRIVACY CONTACT EMAIL] and we will respond within 30 days. If you are unhappy with the answer, you can complain to your data protection regulator — in the UK, the Information Commissioner’s Office.
Security
Passwords are scrypt-hashed and salted per account. Traffic is HTTPS-only. Stored third-party credentials are encrypted with AES-256-GCM. Public share links use 32 bytes of cryptographic randomness. Third-party plugin code runs sandboxed and permission-checked on every request.
None of that makes a system invulnerable. If we discover a breach affecting your data, we will tell you and the relevant regulator without undue delay, and within 72 hours where the law requires it.
Children
LifeHQ is not intended for children under [MINIMUM AGE]. We do not knowingly collect their data, and will delete any we learn we have.
Changes
If we change something that materially affects your privacy, we will tell you in the app before it takes effect — not by quietly editing this page. The date at the top always reflects the current version.