Version 2026-10-07 · last updated 7 October 2026
In short:
1.1. Data controller. Lifestylo Oy, business ID (Y-tunnus) 3380169-9, Magneettikatu 3 A 30, 02330 Espoo, Finland ("we", "us"). This Privacy Policy applies to the Lifestylo app for iOS and Android, the website lifestylo.eu and helpdesk.lifestylo.eu (together, the "Service").
1.2. Privacy contacts: [email protected], helpdesk.lifestylo.eu, phone +7 911 666-66-05, or by post to the address in clause 1.1.
1.3. Data Protection Officer (DPO): [●].
1.4. This Privacy Policy does not apply to services that you connect yourself (Apple, Google and future integrations with Oura). Those services process data under their own privacy policies.
| Category | What exactly | Source | Required? |
|---|---|---|---|
| Account | Name, email address, password (stored only as a bcrypt hash), Apple or Google sign-in identifiers | You; Apple / Google when you sign in through them | Yes — an account cannot be created without them |
| Health and psychological wellbeing — 1. Psychological tests | Big Five personality test (50 statements, five scales, including emotional stability). Your answers (on a scale of 1 to 5) are used only to calculate five final scores and are deleted after that calculation; only the scores are stored. Taken approximately once every 30 days | You | No |
| 2. Wheel of Life | Ratings of eight areas of life from 0 to 10, including health; analysis of problem areas and trends | You | No |
| 3. Daily morning and evening check-ins | Sleep duration and quality, dreams, mood, physical condition, stress and difficulty of the day, energy, emotions, nutrition, self-care, productivity, weight, and free-text answers | You | No |
| 4. Journal entries | Text, voice notes and their transcripts, photos, videos, goals, habits; people and places mentioned in entries. Entries are not limited by topic and may contain information about illnesses and medications | You | No |
| 5. Device metrics — iOS | From Apple Health, read-only access to five data types: sleep analysis, steps, heart rate, active energy and basal energy (calories) | Apple Health | No — only with your permission |
| 5. Device metrics — Android | From Health Connect, read-only access to: steps, heart rate, resting heart rate, heart rate variability (HRV), calories, distance, floors climbed, blood oxygen saturation, respiratory rate, weight, hydration, exercise sessions, sleep | Health Connect | No — only with your permission |
| Derived metrics | Wellbeing index (mood 40%, sleep 25%, stress 20%, productivity 15%), classification of days as good or bad, trends in sleep, stress, energy, physical condition, weight and heart rate; Oracle's insights | Calculated by the Service from the data above | — |
| Conversations with Oracle | Your messages and the AI's replies, summaries and insights about patterns | You; generated by AI | No — only if you have turned on AI features |
| Location | Coordinates (accuracy of about 100 m, or up to 3 km in battery-saving mode), time, accuracy and speed, city and country; significant places and visits identified from location points; weather | Your device | No — only with your permission |
| Motion | Motion sensor data — to detect that you are moving | Your device | No — only with your permission |
| Technical data | Device model, operating system, language, device and installation identifiers, IP address, push token, crash reports | Automatically from your device | Yes, for operation and security |
| App usage | Screens opened, events, approximate country based on IP address | Automatically (PostHog) | No — with your consent |
| Purchases (once introduced) | Subscription status, transaction identifiers, country; we do not receive your card number | Apple, Google, Stripe, Adapty | Yes, for paid features |
| Support requests | Correspondence and attachments | You | No |
We do not write data to Apple Health or Health Connect, and we do not access clinical health records (Health Records). When you first connect, we read data for the last 14 days; after that, only new data.
2.1. We treat the five data streams in the table — tests, Wheel of Life, daily check-ins, journal entries and device metrics — together with derived metrics as one category: health and psychological wellbeing data. Entries may also reveal beliefs and relationships. We treat all of this as special category data (Article 9 GDPR) and as consumer health data under US state laws.
2.2. Your entries may contain data about other people (names, photos, voices). We process such data only as part of your journal and do not build profiles of those people.
2.3. We do not collect biometric identifiers: voice notes are only converted to text and are not used to recognise the speaker.
| Purpose | Data | Legal basis (EU/EEA) |
|---|---|---|
| Creating an account, storing and syncing your journal, searching entries | Account, entries, technical data | Performance of a contract (Art. 6(1)(b)); for entries containing special category data — explicit consent (Art. 9(2)(a)) |
| AI features: Oracle, summaries, pattern analysis, voice transcription | Entries, mood, health data, conversations | Explicit consent (Art. 9(2)(a)) |
| Adding health and activity metrics to entries | Apple Health and equivalents | Explicit consent (Art. 9(2)(a)) |
| Adding places and weather to entries | Location | Consent (Art. 6(1)(a)) |
| Improving the quality and safety of Oracle using traces | Traces of AI requests | Explicit consent (Art. 9(2)(a)) as part of the consent to AI features |
| Checking requests for violations, investigating fraud | Conversations, technical data | Legitimate interests (Art. 6(1)(f)) — security of the Service; for special category data — Art. 9(2)(f) (establishment, exercise or defence of legal claims) |
| Fixing errors and ensuring stability | Crash reports, technical data | Legitimate interests (Art. 6(1)(f)) — a functioning Service |
| Understanding how the app is used | Usage data | Consent (Art. 6(1)(a); Article 5(3) of Directive 2002/58/EC) |
| Sending push notifications and reminders | Push token | Consent via the iOS / Android system prompt |
| Responding to requests | Correspondence | Performance of a contract |
| Accepting payments, bookkeeping | Purchase data | Performance of a contract; legal obligation (Art. 6(1)(c)) |
| Complying with the law and requests from authorities | Any data, to the extent necessary | Legal obligation (Art. 6(1)(c)) |
| Informing you about changes to the Service and terms | Email address | Performance of a contract |
| Marketing emails (if we send them) | Email address | Consent; you can unsubscribe in every email |
3.1. Legitimate interests (Art. 6(1)(f) GDPR) — the security and proper functioning of the Service and protection against fraud. You can object to such processing (Section 10).
3.2. If you do not provide data. You cannot use the Service without account data. If you do not consent to AI features, health data or location, only the corresponding features will not work; your journal remains available.
3.3. New purposes. If we want to use data for a new purpose (for example, to train our own models, see clause 5.5), we will inform you first and, where required, ask for your consent (Article 13(3) GDPR).
4.1. Separate consents. Before collecting data, we show separate consent screens that are not tied to your acceptance of the Terms of Service:
Each request states what data is collected, why, who receives it and how to withdraw consent.
4.2. How to withdraw consent. You can withdraw any consent in the app under "Documents" → "Withdraw consent", or in your device settings (Health, Location). After you withdraw consent, we stop receiving new data; data already collected can be deleted together with the entries or your account. Withdrawal does not affect the lawfulness of processing before the withdrawal.
4.3. What we do not do with health data:
4.4. Location. We use coordinates to label the place and weather in your entries and to automatically identify your significant places (home, work, frequently visited places) and visits, so that we can suggest places for your entries. Location history is stored on our servers separately from entries; entries only refer to location points. Coordinates are also sent to the map and weather services listed in Section 6. You can turn off location collection in your device settings; you can ask us to delete your location history separately from your account via helpdesk.lifestylo.eu.
5.1. What is sent to AI providers. When you use Oracle, summaries or voice transcription, we send the large language model provider your message, the entries and settings needed for the reply, health metrics, questions and answers from tests and check-ins (without your name or account identifiers), and audio for transcription. This data is not anonymised and may contain names and other information from your entries. The providers we use and their terms:
| Provider | Purpose | Training on your data | Retention by the provider |
|---|---|---|---|
| OpenAI (USA) | Oracle replies, voice transcription, moderation | No — API data is not used for training | Up to 30 days for abuse monitoring |
| Anthropic (USA) | Oracle replies | No — API data is not used for training | Deleted within 30 days; up to 2 years if a violation of its usage policies is suspected |
| OpenRouter (USA) — forwards requests only to OpenAI, Anthropic and Google | Access to models from other providers | No | OpenRouter does not store requests or responses; retention by the end provider: [●] |
5.2. We do not train AI on your entries, and under their terms the AI providers do not do so either.
5.3. Who reads conversations. Your conversations and entries are processed by machines. Lifestylo staff look at them only where required by law, where there is a reasonable suspicion of fraud or abuse, or where you have sent them to support yourself.
5.4. Traces and improving Oracle. We keep technical logs of AI requests (traces) in Langfuse (EU region) for 30 days. Personal data in traces is masked. Traces are analysed automatically — by language models, without human involvement — to find errors and make replies more accurate and safer.
5.5. Training our own models in the future. If we start training our own Lifestylo models, we will do so only on anonymised data and only with your separate consent, which you can withdraw. Before that, we will update this Privacy Policy and notify you (Section 14).
5.6. Moderation. Selected requests are automatically checked by an OpenAI model for violations of the Terms of Service. The results of these checks are not shared with third parties.
5.7. Automated decision-making. AI features provide general wellness observations and do not make decisions that produce legal or similarly significant effects concerning you (Article 22 GDPR). Analysing patterns in your entries is profiling within the meaning of Article 4(4) GDPR; it is carried out only for you and only with your consent.
5.8. Psychological profile. Big Five test results, the Wheel of Life and the wellbeing index are tools for self-reflection, not clinical diagnosis. They are visible only to you, are used only for your recommendations, and are not shared with employers, insurers, advertisers or other third parties. So that Oracle can take your state into account, the questions and your answers from tests and check-ins are sent to AI providers as "question — answer" pairs, without your name, email address or other account identifiers. The answers themselves, especially free-text answers, may still contain information about you.
6.1. We do not sell personal data and do not share it for targeted advertising. Data is received only by processors that act on our instructions and are contractually bound to protect it at least as well as we do (Article 28 GDPR).
| Recipient | Role and data | Country |
|---|---|---|
| Hetzner Online GmbH | Servers, databases, queues and file storage — all data of the Service | Finland, Germany |
| OpenAI, L.L.C. | Language models, voice transcription, moderation — entries, messages, audio | USA |
| Anthropic, PBC | Language models — entries, messages | USA |
| OpenRouter, Inc. (end providers: OpenAI, Anthropic, Google) | Routing to language models — entries, messages | USA and the countries of the end providers [●] |
| ClickHouse, Inc. (Langfuse Cloud) | Traces of AI requests (masked), 30 days | Stored in the EU |
| PostHog | Usage analytics — events, device data, country based on IP address | EU |
| Functional Software, Inc. (Sentry) | Crash reports — technical data, IP address; no entry text | USA |
| Google LLC (Firebase) | Push notifications and crash reports — installation identifiers, push token, crash data | USA and other countries |
| OpenStreetMap Foundation (Nominatim) | Address lookup from coordinates | United Kingdom, Netherlands |
| Esri (ArcGIS) | Maps and address lookup from coordinates | USA |
| OpenWeather Ltd | Weather based on coordinates (according to OpenWeather, request parameters are not stored) | United Kingdom |
| Adapty | Subscription management — user identifier, purchase status | [●] |
| Stripe | Payments outside the app stores — payment details are entered directly with Stripe | Ireland / USA |
6.2. Independent recipients. Apple and Google process data under their own privacy policies when you sign in through them, buy a subscription in their stores, or grant access to Apple Health / Health Connect.
6.3. Authorities. We disclose data to public authorities only in response to a lawful request and only to the minimum extent necessary. Unless prohibited by law, we will notify you of such a request.
6.4. Change of ownership. In the event of a merger, sale or reorganisation, data may be transferred to a successor. The successor will be bound by this Privacy Policy, and we will notify you in advance and give you the opportunity to delete your account.
6.5. With your consent. We share data with other people and services only as a result of your explicit action (for example, if in the future you publish an entry within the app).
7.1. Our primary data storage is located in the EU (Finland, Germany). Data is transferred to the USA for AI features (OpenAI, Anthropic, OpenRouter and, through it, Google), crash reporting (Sentry, Firebase), push notifications (Firebase) and maps (Esri); and to the United Kingdom for weather and address lookup.
7.2. Transfer mechanisms (Chapter V GDPR):
You can request a copy of the applicable safeguards at [email protected].
| Data | Retention period |
|---|---|
| Account, entries, media, conversations with Oracle, health data, location history and significant places | Until you delete them. After an entry or account is deleted — up to 30 days in production systems and up to 90 days in backups |
| Inactive account | Deleted after 24 months without sign-in, following two email warnings sent at least 30 days apart |
| Data in server queues and caches | [●] — only for the duration of processing |
| Requests and responses held by AI providers | Up to 30 days under their terms (Section 5) |
| Traces in Langfuse | 30 days |
| Crash reports | Firebase Crashlytics — 90 days; Sentry — 30 days |
| Push tokens | While the installation is active; deleted after account deletion, and permanently deleted by Google within 180 days |
| Analytics (PostHog) | 30 days |
| Support correspondence | Until your account is deleted or until you request deletion of the correspondence |
| Payment data and invoices | Periods required by the Finnish Accounting Act (Kirjanpitolaki 1336/1997): source documents — 6 years from the end of the financial year |
| Records of consents and withdrawals | For the life of the account + 3 years, to demonstrate compliance with the law |
| Data needed for a dispute or investigation | Until it is concluded |
8.1. We may keep anonymised statistics that cannot be used to identify you without time limit.
8.2. Location history is currently kept for as long as the account exists.
8.3. Final test scores, Wheel of Life ratings and answers to daily check-ins are kept in the same way as entries — until you delete them or for as long as the account exists. Answers to the Big Five test statements are deleted immediately after the scores are calculated.
9.1. Our security measures:
9.2. Data breaches. In the event of a personal data breach, we will notify the Finnish supervisory authority within 72 hours (Article 33 GDPR) and will notify you without undue delay if the breach is likely to result in a high risk to you (Article 34 GDPR). US: We will notify users in the United States within 60 days at the latest, in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318), and within the time limits set by state laws.
9.3. No method of transmitting or storing data is completely secure. Protect your device with a passcode and use a strong password. Please report vulnerabilities to [email protected].
| Right | What it means | How to exercise it |
|---|---|---|
| Access (Art. 15) | Find out what data we process and obtain a copy | Request via helpdesk |
| Rectification (Art. 16) | Correct inaccurate data | In the app or via helpdesk |
| Erasure (Art. 17) | Delete entries or your entire account | Settings → Delete account, or via helpdesk |
| Restriction (Art. 18) | Temporarily suspend processing | Request via helpdesk |
| Data portability (Art. 20) | Receive your data in a machine-readable format | On request via helpdesk |
| Objection (Art. 21) | Object to processing based on legitimate interests and to marketing | Request via helpdesk; unsubscribe link in emails |
| Withdrawal of consent (Art. 7(3)) | At any time, as easily as you gave it | In the app (Documents → Withdraw consent) or in your device settings |
| Complaint (Art. 77) | Lodge a complaint with a supervisory authority | See clause 10.2 |
10.1. We respond within one month; for complex requests, this period may be extended by two further months, in which case we will inform you (Article 12(3) GDPR). Requests are free of charge. We may ask you to verify your identity, usually by signing in to your account or by writing from your account email address.
10.2. Supervisory authority. Our lead supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PL 800, 00531 Helsinki, Finland; [email protected]; +358 29 566 6700; tietosuoja.fi. You may also contact the supervisory authority in the country where you live or work; in the United Kingdom, the Information Commissioner's Office (ico.org.uk).
11.1. Health data. Residents of Washington, Nevada and Connecticut are covered by our separate Consumer Health Data Privacy Policy at lifestylo.eu/consumer-health-data.
11.2. Other states. If you live in a state with its own privacy law (for example, California, Colorado, Connecticut, Virginia, Texas or Oregon), you have the right, to the extent provided by those laws, to:
11.3. Sale and targeted advertising. We do not sell personal data, do not share it for cross-context behavioural advertising ("sell" and "share"), and do not use sensitive data to infer characteristics about you outside the features of the Service. For this reason, "Do Not Sell or Share" and "Limit the Use of My Sensitive Personal Information" options are not needed. We honour Global Privacy Control signals.
11.4. How to submit a request and appeal. Submit requests via helpdesk.lifestylo.eu or [email protected]; you may also use an authorised agent. We respond within 45 days (with a possible extension of a further 45 days). If we refuse your request, write to [email protected] with the subject "Appeal" — we will decide on your appeal within 45 days. If you disagree with our decision, you may contact the Attorney General of your state.
The Service is intended only for persons over 18 years of age. We do not knowingly collect data from minors. If we learn that an account belongs to a person under 18, we will block it and delete the data. Parents and guardians can notify us at [email protected]. In the United States, this also meets the requirements of COPPA with respect to children under 13.
13.1. In-app SDKs. We use Sentry and Firebase Crashlytics for crash reporting, Firebase Cloud Messaging for push notifications, PostHog for analytics and Adapty for subscription management. We do not use advertising SDKs, we do not track you across other apps, and we do not request the advertising identifier (IDFA / AAID).
13.2. Analytics. PostHog collects usage events and device data; the data is stored in the EU. The text of your entries is not sent to analytics, and no screen recording (session replay) takes place. You can turn off analytics in Settings → [●].
13.3. Push notifications are sent only after you allow them in the system prompt and can be turned off in your device settings. The text of notifications does not include the content of your entries.
13.4. Website lifestylo.eu. The website does not use cookies or analytics counters, so no consent banner is shown on it.
14.1. This Privacy Policy takes effect on the date of its publication at lifestylo.eu/privacy; the date is stated at the top of this document.
14.2. We will notify you in advance, in the app and by email, separately from marketing messages, of any material changes — new purposes, new categories of data or recipients, or changes to how you can exercise your rights. If a change requires new consent (for example, for health data), we will ask for it before the processing begins.
14.3. Contacts: Lifestylo Oy, Magneettikatu 3 A 30, 02330 Espoo, Finland; [email protected]; helpdesk.lifestylo.eu; +7 911 666-66-05.
14.4. This Privacy Policy is available in English, Russian, German, Finnish, Italian, Spanish and French. In the event of any discrepancy, the English version prevails, unless mandatory laws of your country require otherwise.