Privacy policy
Last updated 26 August 2026
What we collect
Your account: name, email address and a password hash, or the identity your OAuth provider shares when you sign in with Google or Microsoft.
Your content: the tasks, projects, customer records, workspace details and settings you create.
Calendar data: when you connect a calendar, event details from the calendars you choose, used to show and sync your schedule.
Billing: subscriptions are processed by Stripe. We store your plan and billing period, not your card details.
What we use it for
To run the service: storing your workspaces, syncing calendars you connected, sending emails you asked for (invitations, password resets), and charging subscriptions.
To keep it working: error reports go to Sentry so failures get found and fixed, and Vercel Web Analytics counts page views and measures loading speed. It sets no cookies and does not follow you between sites.
To measure advertising: if you arrived from an ad, a signup or purchase may be reported to Meta and Google with a hashed email so campaigns can be measured. We do not sell personal data.
Where it lives
Data is stored in a Supabase Postgres database and served through Vercel. Payments run on Stripe, transactional email on Resend. Each processor receives only what its job needs.
Calendar access
Calendar authorization uses OAuth; we never see your Google or Microsoft password. Access is limited to the scopes shown on the consent screen, and disconnecting a calendar in settings revokes our access to it.
Retention and deletion
Your data stays as long as your account does. Deleting a workspace deletes its content; deleting your account deletes the account and every workspace you solely own.
Your choices
You can export or delete your content, disconnect calendars, and cancel subscriptions from within the app. For anything else, write to uday@lifeat.io.