Privacy Policy

Version 2026-10-07 · last updated 7 October 2026

1. Who we are and key points

In short:

  • Your journal belongs to you. We do not sell your data, we do not show ads, and we do not train AI models on your entries.
  • Your data is stored on your device and on our servers in Finland and Germany.
  • To make the Oracle AI companion work, some of your entries and messages are sent to large language model providers, including providers in the United States. This happens only with your consent.
  • We collect health data and location only after you give a separate permission, which you can withdraw at any time.
  • You can delete your account and all your data in the app settings.

1.1. Data controller. Lifestylo Oy, business ID (Y-tunnus) 3380169-9, Magneettikatu 3 A 30, 02330 Espoo, Finland ("we", "us"). This Privacy Policy applies to the Lifestylo app for iOS and Android, the website lifestylo.eu and helpdesk.lifestylo.eu (together, the "Service").

1.2. Privacy contacts: [email protected], helpdesk.lifestylo.eu, phone +7 911 666-66-05, or by post to the address in clause 1.1.

1.3. Data Protection Officer (DPO): [●].

1.4. This Privacy Policy does not apply to services that you connect yourself (Apple, Google and future integrations with Oura). Those services process data under their own privacy policies.

2. What data we collect

Category What exactly Source Required?
Account Name, email address, password (stored only as a bcrypt hash), Apple or Google sign-in identifiers You; Apple / Google when you sign in through them Yes — an account cannot be created without them
Health and psychological wellbeing — 1. Psychological tests Big Five personality test (50 statements, five scales, including emotional stability). Your answers (on a scale of 1 to 5) are used only to calculate five final scores and are deleted after that calculation; only the scores are stored. Taken approximately once every 30 days You No
2. Wheel of Life Ratings of eight areas of life from 0 to 10, including health; analysis of problem areas and trends You No
3. Daily morning and evening check-ins Sleep duration and quality, dreams, mood, physical condition, stress and difficulty of the day, energy, emotions, nutrition, self-care, productivity, weight, and free-text answers You No
4. Journal entries Text, voice notes and their transcripts, photos, videos, goals, habits; people and places mentioned in entries. Entries are not limited by topic and may contain information about illnesses and medications You No
5. Device metrics — iOS From Apple Health, read-only access to five data types: sleep analysis, steps, heart rate, active energy and basal energy (calories) Apple Health No — only with your permission
5. Device metrics — Android From Health Connect, read-only access to: steps, heart rate, resting heart rate, heart rate variability (HRV), calories, distance, floors climbed, blood oxygen saturation, respiratory rate, weight, hydration, exercise sessions, sleep Health Connect No — only with your permission
Derived metrics Wellbeing index (mood 40%, sleep 25%, stress 20%, productivity 15%), classification of days as good or bad, trends in sleep, stress, energy, physical condition, weight and heart rate; Oracle's insights Calculated by the Service from the data above —
Conversations with Oracle Your messages and the AI's replies, summaries and insights about patterns You; generated by AI No — only if you have turned on AI features
Location Coordinates (accuracy of about 100 m, or up to 3 km in battery-saving mode), time, accuracy and speed, city and country; significant places and visits identified from location points; weather Your device No — only with your permission
Motion Motion sensor data — to detect that you are moving Your device No — only with your permission
Technical data Device model, operating system, language, device and installation identifiers, IP address, push token, crash reports Automatically from your device Yes, for operation and security
App usage Screens opened, events, approximate country based on IP address Automatically (PostHog) No — with your consent
Purchases (once introduced) Subscription status, transaction identifiers, country; we do not receive your card number Apple, Google, Stripe, Adapty Yes, for paid features
Support requests Correspondence and attachments You No

We do not write data to Apple Health or Health Connect, and we do not access clinical health records (Health Records). When you first connect, we read data for the last 14 days; after that, only new data.

2.1. We treat the five data streams in the table — tests, Wheel of Life, daily check-ins, journal entries and device metrics — together with derived metrics as one category: health and psychological wellbeing data. Entries may also reveal beliefs and relationships. We treat all of this as special category data (Article 9 GDPR) and as consumer health data under US state laws.

2.2. Your entries may contain data about other people (names, photos, voices). We process such data only as part of your journal and do not build profiles of those people.

2.3. We do not collect biometric identifiers: voice notes are only converted to text and are not used to recognise the speaker.

3. Why we process data and on what legal basis

Purpose Data Legal basis (EU/EEA)
Creating an account, storing and syncing your journal, searching entries Account, entries, technical data Performance of a contract (Art. 6(1)(b)); for entries containing special category data — explicit consent (Art. 9(2)(a))
AI features: Oracle, summaries, pattern analysis, voice transcription Entries, mood, health data, conversations Explicit consent (Art. 9(2)(a))
Adding health and activity metrics to entries Apple Health and equivalents Explicit consent (Art. 9(2)(a))
Adding places and weather to entries Location Consent (Art. 6(1)(a))
Improving the quality and safety of Oracle using traces Traces of AI requests Explicit consent (Art. 9(2)(a)) as part of the consent to AI features
Checking requests for violations, investigating fraud Conversations, technical data Legitimate interests (Art. 6(1)(f)) — security of the Service; for special category data — Art. 9(2)(f) (establishment, exercise or defence of legal claims)
Fixing errors and ensuring stability Crash reports, technical data Legitimate interests (Art. 6(1)(f)) — a functioning Service
Understanding how the app is used Usage data Consent (Art. 6(1)(a); Article 5(3) of Directive 2002/58/EC)
Sending push notifications and reminders Push token Consent via the iOS / Android system prompt
Responding to requests Correspondence Performance of a contract
Accepting payments, bookkeeping Purchase data Performance of a contract; legal obligation (Art. 6(1)(c))
Complying with the law and requests from authorities Any data, to the extent necessary Legal obligation (Art. 6(1)(c))
Informing you about changes to the Service and terms Email address Performance of a contract
Marketing emails (if we send them) Email address Consent; you can unsubscribe in every email

3.1. Legitimate interests (Art. 6(1)(f) GDPR) — the security and proper functioning of the Service and protection against fraud. You can object to such processing (Section 10).

3.2. If you do not provide data. You cannot use the Service without account data. If you do not consent to AI features, health data or location, only the corresponding features will not work; your journal remains available.

3.3. New purposes. If we want to use data for a new purpose (for example, to train our own models, see clause 5.5), we will inform you first and, where required, ask for your consent (Article 13(3) GDPR).

4. Health data and location

4.1. Separate consents. Before collecting data, we show separate consent screens that are not tied to your acceptance of the Terms of Service:

  1. to the processing of health and psychological wellbeing data — before your first test, Wheel of Life or daily check-in, with an explanation that your answers are stored and analysed;
  2. to the transfer of entries and health data to AI providers for the operation of Oracle;
  3. to access Apple Health (iOS) or Health Connect (Android), and in the future Oura, through the system prompt where you choose the data types;
  4. to access location, with a separate consent for background location.

Each request states what data is collected, why, who receives it and how to withdraw consent.

4.2. How to withdraw consent. You can withdraw any consent in the app under "Documents" → "Withdraw consent", or in your device settings (Health, Location). After you withdraw consent, we stop receiving new data; data already collected can be deleted together with the entries or your account. Withdrawal does not affect the lawfulness of processing before the withdrawal.

4.3. What we do not do with health data:

  • we do not sell it or share it with advertising platforms, data brokers or resellers;
  • we do not use it for advertising, marketing or profiling outside the features of the Service;
  • we do not store Apple Health data in iCloud;
  • we do not set up geofences around healthcare facilities.

4.4. Location. We use coordinates to label the place and weather in your entries and to automatically identify your significant places (home, work, frequently visited places) and visits, so that we can suggest places for your entries. Location history is stored on our servers separately from entries; entries only refer to location points. Coordinates are also sent to the map and weather services listed in Section 6. You can turn off location collection in your device settings; you can ask us to delete your location history separately from your account via helpdesk.lifestylo.eu.

5. Artificial intelligence

5.1. What is sent to AI providers. When you use Oracle, summaries or voice transcription, we send the large language model provider your message, the entries and settings needed for the reply, health metrics, questions and answers from tests and check-ins (without your name or account identifiers), and audio for transcription. This data is not anonymised and may contain names and other information from your entries. The providers we use and their terms:

Provider Purpose Training on your data Retention by the provider
OpenAI (USA) Oracle replies, voice transcription, moderation No — API data is not used for training Up to 30 days for abuse monitoring
Anthropic (USA) Oracle replies No — API data is not used for training Deleted within 30 days; up to 2 years if a violation of its usage policies is suspected
OpenRouter (USA) — forwards requests only to OpenAI, Anthropic and Google Access to models from other providers No OpenRouter does not store requests or responses; retention by the end provider: [●]

5.2. We do not train AI on your entries, and under their terms the AI providers do not do so either.

5.3. Who reads conversations. Your conversations and entries are processed by machines. Lifestylo staff look at them only where required by law, where there is a reasonable suspicion of fraud or abuse, or where you have sent them to support yourself.

5.4. Traces and improving Oracle. We keep technical logs of AI requests (traces) in Langfuse (EU region) for 30 days. Personal data in traces is masked. Traces are analysed automatically — by language models, without human involvement — to find errors and make replies more accurate and safer.

5.5. Training our own models in the future. If we start training our own Lifestylo models, we will do so only on anonymised data and only with your separate consent, which you can withdraw. Before that, we will update this Privacy Policy and notify you (Section 14).

5.6. Moderation. Selected requests are automatically checked by an OpenAI model for violations of the Terms of Service. The results of these checks are not shared with third parties.

5.7. Automated decision-making. AI features provide general wellness observations and do not make decisions that produce legal or similarly significant effects concerning you (Article 22 GDPR). Analysing patterns in your entries is profiling within the meaning of Article 4(4) GDPR; it is carried out only for you and only with your consent.

5.8. Psychological profile. Big Five test results, the Wheel of Life and the wellbeing index are tools for self-reflection, not clinical diagnosis. They are visible only to you, are used only for your recommendations, and are not shared with employers, insurers, advertisers or other third parties. So that Oracle can take your state into account, the questions and your answers from tests and check-ins are sent to AI providers as "question — answer" pairs, without your name, email address or other account identifiers. The answers themselves, especially free-text answers, may still contain information about you.

6. Who we share data with

6.1. We do not sell personal data and do not share it for targeted advertising. Data is received only by processors that act on our instructions and are contractually bound to protect it at least as well as we do (Article 28 GDPR).

Recipient Role and data Country
Hetzner Online GmbH Servers, databases, queues and file storage — all data of the Service Finland, Germany
OpenAI, L.L.C. Language models, voice transcription, moderation — entries, messages, audio USA
Anthropic, PBC Language models — entries, messages USA
OpenRouter, Inc. (end providers: OpenAI, Anthropic, Google) Routing to language models — entries, messages USA and the countries of the end providers [●]
ClickHouse, Inc. (Langfuse Cloud) Traces of AI requests (masked), 30 days Stored in the EU
PostHog Usage analytics — events, device data, country based on IP address EU
Functional Software, Inc. (Sentry) Crash reports — technical data, IP address; no entry text USA
Google LLC (Firebase) Push notifications and crash reports — installation identifiers, push token, crash data USA and other countries
OpenStreetMap Foundation (Nominatim) Address lookup from coordinates United Kingdom, Netherlands
Esri (ArcGIS) Maps and address lookup from coordinates USA
OpenWeather Ltd Weather based on coordinates (according to OpenWeather, request parameters are not stored) United Kingdom
Adapty Subscription management — user identifier, purchase status [●]
Stripe Payments outside the app stores — payment details are entered directly with Stripe Ireland / USA

6.2. Independent recipients. Apple and Google process data under their own privacy policies when you sign in through them, buy a subscription in their stores, or grant access to Apple Health / Health Connect.

6.3. Authorities. We disclose data to public authorities only in response to a lawful request and only to the minimum extent necessary. Unless prohibited by law, we will notify you of such a request.

6.4. Change of ownership. In the event of a merger, sale or reorganisation, data may be transferred to a successor. The successor will be bound by this Privacy Policy, and we will notify you in advance and give you the opportunity to delete your account.

6.5. With your consent. We share data with other people and services only as a result of your explicit action (for example, if in the future you publish an entry within the app).

7. Transfers outside the EU

7.1. Our primary data storage is located in the EU (Finland, Germany). Data is transferred to the USA for AI features (OpenAI, Anthropic, OpenRouter and, through it, Google), crash reporting (Sentry, Firebase), push notifications (Firebase) and maps (Esri); and to the United Kingdom for weather and address lookup.

7.2. Transfer mechanisms (Chapter V GDPR):

  • USA — the adequacy decision for the EU–US Data Privacy Framework, where the recipient is certified; otherwise, the European Commission's Standard Contractual Clauses (SCCs, Decision (EU) 2021/914) incorporated into the data processing agreement.
  • United Kingdom — the European Commission's adequacy decision.

You can request a copy of the applicable safeguards at [email protected].

8. How long we keep data

Data Retention period
Account, entries, media, conversations with Oracle, health data, location history and significant places Until you delete them. After an entry or account is deleted — up to 30 days in production systems and up to 90 days in backups
Inactive account Deleted after 24 months without sign-in, following two email warnings sent at least 30 days apart
Data in server queues and caches [●] — only for the duration of processing
Requests and responses held by AI providers Up to 30 days under their terms (Section 5)
Traces in Langfuse 30 days
Crash reports Firebase Crashlytics — 90 days; Sentry — 30 days
Push tokens While the installation is active; deleted after account deletion, and permanently deleted by Google within 180 days
Analytics (PostHog) 30 days
Support correspondence Until your account is deleted or until you request deletion of the correspondence
Payment data and invoices Periods required by the Finnish Accounting Act (Kirjanpitolaki 1336/1997): source documents — 6 years from the end of the financial year
Records of consents and withdrawals For the life of the account + 3 years, to demonstrate compliance with the law
Data needed for a dispute or investigation Until it is concluded

8.1. We may keep anonymised statistics that cannot be used to identify you without time limit.

8.2. Location history is currently kept for as long as the account exists.

8.3. Final test scores, Wheel of Life ratings and answers to daily check-ins are kept in the same way as entries — until you delete them or for as long as the account exists. Answers to the Big Five test statements are deleted immediately after the scores are calculated.

9. Security

9.1. Our security measures:

  • servers in data centres in the EU with protection at the hosting provider level;
  • encryption in transit (TLS) between the app and our servers;
  • passwords stored only as bcrypt hashes;
  • data on your device is protected by the built-in encryption of iOS and Android; on Android, access keys are stored in the system's secure storage, and entries waiting to be uploaded are encrypted;
  • staff access to data on a least-privilege basis and subject to confidentiality obligations;
  • masking of personal data in AI traces;
  • data processing agreements with all providers listed in Section 6;
  • backups and regular security updates.

9.2. Data breaches. In the event of a personal data breach, we will notify the Finnish supervisory authority within 72 hours (Article 33 GDPR) and will notify you without undue delay if the breach is likely to result in a high risk to you (Article 34 GDPR). US: We will notify users in the United States within 60 days at the latest, in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318), and within the time limits set by state laws.

9.3. No method of transmitting or storing data is completely secure. Protect your device with a passcode and use a strong password. Please report vulnerabilities to [email protected].

10. Your rights (EU, EEA and UK)

Right What it means How to exercise it
Access (Art. 15) Find out what data we process and obtain a copy Request via helpdesk
Rectification (Art. 16) Correct inaccurate data In the app or via helpdesk
Erasure (Art. 17) Delete entries or your entire account Settings → Delete account, or via helpdesk
Restriction (Art. 18) Temporarily suspend processing Request via helpdesk
Data portability (Art. 20) Receive your data in a machine-readable format On request via helpdesk
Objection (Art. 21) Object to processing based on legitimate interests and to marketing Request via helpdesk; unsubscribe link in emails
Withdrawal of consent (Art. 7(3)) At any time, as easily as you gave it In the app (Documents → Withdraw consent) or in your device settings
Complaint (Art. 77) Lodge a complaint with a supervisory authority See clause 10.2

10.1. We respond within one month; for complex requests, this period may be extended by two further months, in which case we will inform you (Article 12(3) GDPR). Requests are free of charge. We may ask you to verify your identity, usually by signing in to your account or by writing from your account email address.

10.2. Supervisory authority. Our lead supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PL 800, 00531 Helsinki, Finland; [email protected]; +358 29 566 6700; tietosuoja.fi. You may also contact the supervisory authority in the country where you live or work; in the United Kingdom, the Information Commissioner's Office (ico.org.uk).

11. US state privacy rights

11.1. Health data. Residents of Washington, Nevada and Connecticut are covered by our separate Consumer Health Data Privacy Policy at lifestylo.eu/consumer-health-data.

11.2. Other states. If you live in a state with its own privacy law (for example, California, Colorado, Connecticut, Virginia, Texas or Oregon), you have the right, to the extent provided by those laws, to:

  • know what data we collect and obtain a copy;
  • correct and delete your data;
  • withdraw your consent to the processing of sensitive data;
  • appeal our refusal of a request (clause 11.4);
  • not be discriminated against for exercising your rights.

11.3. Sale and targeted advertising. We do not sell personal data, do not share it for cross-context behavioural advertising ("sell" and "share"), and do not use sensitive data to infer characteristics about you outside the features of the Service. For this reason, "Do Not Sell or Share" and "Limit the Use of My Sensitive Personal Information" options are not needed. We honour Global Privacy Control signals.

11.4. How to submit a request and appeal. Submit requests via helpdesk.lifestylo.eu or [email protected]; you may also use an authorised agent. We respond within 45 days (with a possible extension of a further 45 days). If we refuse your request, write to [email protected] with the subject "Appeal" — we will decide on your appeal within 45 days. If you disagree with our decision, you may contact the Attorney General of your state.

12. Children

The Service is intended only for persons over 18 years of age. We do not knowingly collect data from minors. If we learn that an account belongs to a person under 18, we will block it and delete the data. Parents and guardians can notify us at [email protected]. In the United States, this also meets the requirements of COPPA with respect to children under 13.

13. In-app SDKs, push notifications and cookies

13.1. In-app SDKs. We use Sentry and Firebase Crashlytics for crash reporting, Firebase Cloud Messaging for push notifications, PostHog for analytics and Adapty for subscription management. We do not use advertising SDKs, we do not track you across other apps, and we do not request the advertising identifier (IDFA / AAID).

13.2. Analytics. PostHog collects usage events and device data; the data is stored in the EU. The text of your entries is not sent to analytics, and no screen recording (session replay) takes place. You can turn off analytics in Settings → [●].

13.3. Push notifications are sent only after you allow them in the system prompt and can be turned off in your device settings. The text of notifications does not include the content of your entries.

13.4. Website lifestylo.eu. The website does not use cookies or analytics counters, so no consent banner is shown on it.

14. Changes and contacts

14.1. This Privacy Policy takes effect on the date of its publication at lifestylo.eu/privacy; the date is stated at the top of this document.

14.2. We will notify you in advance, in the app and by email, separately from marketing messages, of any material changes — new purposes, new categories of data or recipients, or changes to how you can exercise your rights. If a change requires new consent (for example, for health data), we will ask for it before the processing begins.

14.3. Contacts: Lifestylo Oy, Magneettikatu 3 A 30, 02330 Espoo, Finland; [email protected]; helpdesk.lifestylo.eu; +7 911 666-66-05.

14.4. This Privacy Policy is available in English, Russian, German, Finnish, Italian, Spanish and French. In the event of any discrepancy, the English version prevails, unless mandatory laws of your country require otherwise.

← Back