Privacy notice
Last updated 29 September 2026 · This is a translation. In case of differences, the Dutch text prevails.
LifestyleOS knows a lot about you. Your sleep and your mood, what you eat, where your money goes, what you write down when nobody is watching. That is the point of the app, but it also means you should be able to read exactly what happens with it.
Below is that, as concretely as possible: which data, what for, who else sees it, and what you can do about it. No legal fog where a plain sentence will do.
1Who processes your data
LifestyleOS is built and run by Mike Griffioen. For everything below I am the data controller: I decide which data the app processes and for what purpose.
Questions, requests or complaints can go to app@lifestyleos.app. You can use that address to request your data or have your account deleted, although you can do both yourself in the app.
2What data the app processes
Almost everything below comes from you: you enter it, or you connect a service that supplies it. Nothing is collected about you outside the app.
- Account: your email address and when you sign in.
- Profile: your name, sex, date of birth, height and weight.
- Health: sleep and sleep stages, heart rate variability, resting heart rate, oxygen saturation, respiratory rate, VO2 max, skin temperature, recovery, mood, steps, energy burned, distance, floors climbed, workouts and body measurements. These are special category data, which carry stricter rules: see below.
- Nutrition: what you log, how much, water, supplements and your nutrition plan.
- Finances: accounts, transactions, investments, budgets and goals, entered by hand, imported, or through a bank connection.
- Mail, calendar and contacts: only if you connect such an account. Messages and events are stored so the app can show and search them offline.
- What you write: notes, reflections, goals, tasks, motivation sessions and your conversations with Echo, including voice recordings that are converted to text.
- Technical: error reports, and the data needed to send notifications to your device.
- Agreements: which permissions you gave and when, and if you sign the confidentiality agreement also the name you typed, the moment, your IP address and your browser. That is exactly what gives such a signature its evidential value; without it, it is a checkbox.
3Your health data in short
Health data is a special category of personal data, so it deserves precision rather than a reassuring sentence. Here is what happens once you connect a wearable.
- What is read: Read-only, never written: your sleep, heart rate variability, resting heart rate, oxygen saturation, respiratory rate, VO2 max, steps, energy burned, distance and workouts.
- What for: To calculate your vitality, recovery and sleep quality, to base your calorie target on what you actually burn, and to feed your insights and experiments. Nothing else.
- Who else sees it: Nobody. No advertising, no resale, no profiles for third parties. If you use an AI feature, only the part needed to answer is sent, and only after your separate consent.
- What you can do about it: Disconnect whenever you want, withdraw your consent, export your data, or delete your account with everything in it.
4What for, and on what basis
The ordinary working of the app (storing, showing, searching and summarising your data) happens to perform our agreement with you. Without that processing there is no app.
Health data is different. It is special category data and may only be processed with your explicit consent. You are asked for that separately when setting up your account, and you can withdraw it at any time.
Using AI also requires separate consent, because it sends data to an external model provider. What exactly goes there is described further down.
For security (preventing abuse, finding faults, throttling misuse) the basis is legitimate interest.
What does not happen: no advertising, no profiles for third parties, no reselling, and no using your data to sell you things.
In the words of the law: the ordinary working of the app rests on article 6(1)(b) of the GDPR (performance of the contract), health data and AI on article 6(1)(a) together with article 9(2)(a) (explicit consent), and security on article 6(1)(f) (legitimate interest). No decisions with legal effect are taken by a computer alone; what Echo suggests, you decide (article 22 GDPR).
5Who else processes your data
The app does not run in a vacuum. These parties process data on my behalf, only for the task listed with them:
- Supabase: database, sign-in and file storage. The vast majority of your data lives here.
- Vercel: hosting; processes traffic and technical logs, and counts page visits and loading times.
- Cloudflare (Turnstile): the check at sign-in. It uses your IP address and technical properties of your browser to tell whether a person is signing in and not a program.
- OpenRouter and the model providers behind it: Echo's answers, summaries and analyses.
- Deepgram, for speech recognition: this is where the audio you record becomes text.
- OpenAI: voice mode, generating recipe images, and speech recognition as a fallback when Deepgram is unavailable.
- Google, Microsoft or Apple: only if you connect a mail or calendar account there.
- Enable Banking: only if you connect a bank account; they are the licensed party that retrieves the bank data.
- Your wearable's provider: only if you connect one, and only that one: Whoop, Garmin, Oura, Polar or Google Health (the last one for Fitbit and Pixel devices).
- The push service of your browser or operating system, for notifications.
6Transfers outside the European Union
The app itself runs on European servers, and so do the database, the file storage, the sign-in and the AI models. For ordinary use of LifestyleOS your data therefore does not leave the European Union, apart from the check at sign-in.
That check is Cloudflare's (Turnstile): at sign-in your IP address and technical properties of your browser go to Cloudflare, and they may be processed outside the EU. Nothing else goes there: no address, no password and nothing from the app.
Beyond that there is one route where it does, and you walk it yourself: if you connect a mail, calendar or wearable account, the data of that connection goes to that provider, wherever it sits. The same applies to the push service of your browser or operating system if you switch notifications on. You choose whether to do that, and you can undo it.
Where such a transfer ends up outside the EU, it rests on what article 44 and onwards of the GDPR prescribes for it: the European Commission's adequacy decision for that country, or the Commission's 2021 standard contractual clauses.
7AI and your data
When you use Echo or switch on an AI feature, text is sent to an external language model. Not your whole account: each feature sends what it needs in order to answer: your question, and the data you are asking about.
The AI providers are configured so that they do not retain your data and do not use it to train their models. That is a setting on our side, not a guarantee I can give on their behalf; who does what is set out in their own terms.
What Echo says is generated text. It can be wrong, even when it sounds certain.
8The bank connection
If you connect a bank account, that runs through Enable Banking, a party holding a PSD2 licence. They retrieve the data from your bank after you have given consent there yourself; that consent is valid for ninety days and then expires on its own.
The connection is read-only. No money can be moved with it. LifestyleOS never sees your bank login details: you enter those at your own bank.
9How long data is kept
For as long as your account exists. LifestyleOS is built to show patterns across years, so nothing is quietly cleaned up.
If you delete your account, your data is erased immediately and irreversibly, including your files and connected accounts. Database backups may briefly still contain your data; those expire by themselves.
Want to keep everything before you go? Export first. One button gives you a JSON file with everything that is yours.
10How your data is secured
Traffic is encrypted. Access to data is restricted per user at the database level, so a bug in the app cannot show someone else's data. Access keys for connected accounts are stored encrypted.
Absolute security does not exist. If something goes wrong involving your data, you will hear it from me, and where required I will report it to the Dutch Data Protection Authority.
11Cookies and what stays on your device
There are no advertising or tracking cookies in the app, and there is no analytics service following your behaviour across websites.
What is counted is how often a page is visited and how quickly it loads, using Vercel Web Analytics and Speed Insights. That happens without cookies and without anything being stored on your device, and the page address is trimmed down to the module on the way out: the title of a note or a goal does not travel with it.
What is there is functional: a cookie that keeps you signed in, a cookie that remembers your language, and local storage for your preferences (which panels you had open, which explanations you dismissed) and to let the app work offline. Strictly necessary storage falls under the exemption in article 11.7a of the Dutch Telecommunications Act, so no consent is asked for it.
Your browser may clear all of it. You will then be signed out and your preferences are gone; your data is not.
12What you can do
You have the right to access, correct, delete and take away your data. Two of those are built in: under Settings you can export everything and delete your account.
Consent you have given can be withdrawn, including per part. That takes effect from the moment you do it; what happened before remains lawful.
If you disagree with something, tell me first, that is quicker. If we cannot resolve it, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Those rights are in articles 15 to 21 of the GDPR: access, rectification, erasure, restriction, portability and objection. I answer a request within one month. You can complain to the Dutch Data Protection Authority (article 77 GDPR), or to the supervisory authority of your own EU country if you live elsewhere.
13Age
LifestyleOS is meant for adults. If you are under sixteen, you may only take part with the consent of your parent or guardian. That is the age limit from article 8 of the GDPR as set by the Dutch GDPR Implementation Act.
If I notice a child's account has been created without that consent, I delete it.
14About the test phase
LifestyleOS is not public yet. Taking part is by invitation only, and the app sits behind an extra password.
As the operator I can see in an admin screen who is taking part: name, email address, when someone was last active and how many actions were taken in which module. Counts and timestamps, in other words, not content: I do not read your notes, messages or transactions.
If you send feedback from within the app, I do of course read it, together with the page you were on and what kind of device you used.
It is a test phase, with what that entails: there may be outages and data may be lost. Export anything you really cannot afford to lose.
15Changes
If something material changes about what the app does with your data, I will update this notice and ask for your consent again. The date at the bottom shows when the text was last updated.