Life OS
← Life OS

Legal documents

Personal Data Processing Policy

What Life OS processes, why it is needed, and which providers are involved.

Version 2026-08-02

1. General

This Policy applies to lifeosclub.ru and the Life OS web and mobile applications. Processing follows applicable law, including Russian Federal Law No. 152-FZ.

  • Controller: Гретченко Дмитрий Ростиславович.
  • Status: плательщик налога на профессиональный доход (самозанятый).
  • Address: г. Мариуполь, проспект Ильича, дом 52.
  • Email: dimagret1997@yandex.com.

2. Data categories

  • email, account identifier, session information and consent records;
  • password and other authentication credentials: registration, standard sign-in, deletion reauthentication and password changes pass the password to Supabase Auth; fallback owner sign-in sends it to the Life OS API solely to verify it against server configuration. Life OS does not write the submitted password to its own tables, localStorage, WebView storage, or SQLite;
  • profile, assessment, goals, tasks, plans, completion evidence, focus sessions, reflections and events;
  • AI request text and selected context only after explicit opt-in;
  • IP address, technical identifiers, request timestamps, and limited security and error logs.

Life OS is not intended for passport details, payment credentials, medical diagnoses, or biometric data.

3. Purposes and grounds

Data supports registration, sign-in and recovery, local storage and cloud synchronisation, planning features, user requests, security and support. Grounds include consent, performance of the user agreement, pre-contract user requests and legal obligations.

4. Storage locations

Data may be stored in browser localStorage, mobile WebView storage, or on-device SQLite. Signed-in state is synchronised with Supabase. Transfers use HTTPS; this Policy does not make an unsupported promise about provider-side encryption at rest.

5. Providers and transfers

  • Supabase — authentication, email/OTP and RLS-protected cloud tables;
  • OpenRouter — permitted AI requests; selected Google Gemini models process the submitted text;
  • Upstash — distributed rate limiting by account identifier and IP when configured;
  • the VPS provider and nginx — application delivery and technical logs.

Provider data-centre countries, cross-border routes and provider retention are not asserted without verified configuration and contractual evidence.

6. AI and local cache

AI is off by default. Grant and revocation of explicit opt-in are synchronised to an account-scoped Supabase record; the server checks active consent before rate limiting or transferring data. After consent, Life OS sends OpenRouter the prompt and limited relevant context: mode, tone, strictness, abyss index, inner core and verdict. Only the listed Google Gemini models are allowed. Failure produces a deterministic local fallback. Revocation clears local AI preferences and cache. Local cache TTL ranges from 1 to 24 hours.

7. Retention, deletion and withdrawal

Account data is kept until account deletion, consent withdrawal, or the end of a lawful processing purpose. A user may request deletion and cancel a pending request before final processing on the account deletion page. This Policy does not promise a final-deletion deadline or server/provider log-retention period until production enforcement is verified.

8. Rights and security

A user may request access, correction, restriction, deletion, or consent withdrawal at dimagret1997@yandex.com. Session checks, RLS, rate limiting and log-field minimisation are used for protection. Material Policy changes are published on this page.