Security
Protecting your data is foundational to LifeOS.
Encryption
All data is encrypted in transit using TLS. Sensitive credentials, such as OAuth access and refresh tokens, are stored encrypted at rest. Connections to our AI providers are made over encrypted channels.
Access controls
Access to production systems is restricted to authorized personnel and follows the principle of least privilege. We do not access your content except where you explicitly request support, where required for security or legal compliance, or where data has been aggregated and anonymized.
Infrastructure
LifeOS runs on established cloud infrastructure providers with industry-standard physical and network security. The production database is backed up nightly. Backups are encrypted before they are written, with the decryption key held off the server, so a backup is never readable by the machine that produced it, and they are expired on a fixed schedule rather than kept indefinitely.
Your Google data
When you connect Google services, we request access only after your explicit consent and use each permission solely for the feature it enables. We do not sell your data, use it for advertising, or use it to train generalized AI models. Full details are in our Privacy Policy.
Responsible disclosure
If you believe you have found a security vulnerability in LifeOS, we appreciate your help in disclosing it responsibly. Please email us with details and steps to reproduce:
Please give us a reasonable opportunity to investigate and address the issue before any public disclosure. We do not take legal action against researchers who act in good faith and avoid privacy violations, data destruction, or service disruption.