In plain words
Your data lives on your device and, when you sign in, syncs to your account so it can follow you across devices. On our servers we keep your account and that synced data, plus your billing status, any message you send us, and an anonymous crash report when a page breaks in your browser; section 3 lists it all and why. If you connect Google Calendar, section 4 is the complete account of that data — what we read, what we keep, and every party it reaches. There are no ads, no trackers and no analytics scripts on this site. We do not sell your data or train AI models on your private content. You can export a backup of your core practice data anytime, and you can leave; for a copy of everything else we store, email us.
1. Who is responsible
Life Mastery, operated from the Netherlands, is the data controller for the processing described here. For anything privacy-related, write to support@lifemasteryplatform.com.
2. What lives on your device
Life Mastery is local-first: your journal entries, habits, routines, goals, reviews, notes, preferences and other member data are stored in your browser's local storage on your own device, and the app reads that copy first. Reaching the member app requires an account, so you sign in first; from then on the app keeps working from the local copy on your device and syncs it to your account in the background. Two practical consequences:
- Clearing your browser's site data deletes the local copy. If you were signed in, your synced data returns when you sign in again; Settings also offers a JSON backup export (and import) of your core practice data so you can protect and move it yourself.
- Anyone with access to your device profile can open the app as you left it, so protect the device like you would a notebook.
3. What we store on servers
- Your account. Authentication runs on Clerk. When you sign up, Clerk holds your email address, your name and avatar if you provide them, sign-in metadata, and the connection to Google if you sign in that way. We never see or store a password. We keep a copy of your email address, name and avatar in our own database so the app can show them and so we can support you.
- Synced app data.When you are signed in, your member data syncs to our database, hosted on Convex, so it can follow you across devices. Today that includes your goals, habits and check-offs, routines and scheduled calendar blocks, journal, notes, reviews, captures and links, your identity statements, your wealth workspace, your vision boards (including images you add to them), the images and video clips you generate with AI — the file itself, along with the description you wrote and any style you applied — and any image styles you save, your Academy progress, your Coach conversations, your community profile and posts, feedback you file, the shared wisdom libraries with your personal changes, and your account-level preferences. We also keep your AI credit balance and the history behind it: each month’s grant, any top-up you buy, and any adjustment we make. If you arrived through an affiliate link, we keep a record of which link brought you, so the referrer can be credited. When you use an AI feature we also keep per-day usage counts and request outcomes (never the content of a conversation) so the daily allowances and the credit meter work. If you connect Google Calendar, we also store a copy of your events — section 4 is the full account of that data and everyone it reaches. The in-app build status at /status lists what syncs at any moment.
- Payments.Subscriptions are processed by Stripe. Stripe holds your card details and billing information; they never touch our servers. We store your plan and subscription status, the Stripe customer and subscription identifiers, the price and billing interval you are on, when the current period ends, and whether it is set to cancel. We also keep your AI credit balance and the history of credits granted, added or adjusted on your account; a top-up entry holds Stripe’s reference for that payment, never card details.
- AI features. When you use an AI feature — the Coach, capture and writing assists, "Make into…", the daily briefing, voice dictation, read-aloud, or AI image and video generation — what that feature needs is sent to a model provider to generate the result: Anthropic, OpenAI or Google, depending on the feature and our current configuration. For the Coach, the assists, "Make into…" and the briefing, that is the context you allow it to see. For dictation it is the audio clip you record, and for read-aloud the text being spoken (both run on OpenAI). For image and video generation it is the description you write — and, if you ask us to transform a picture you already have, that picture itself; images run on OpenAI, video on Google. Your Coach conversations sync like the rest of your member data. You control which sources the AI may read, sensitive ones stay off until you allow them, and no provider uses this data to train their models.
- Messages you send us. If you email support, we have that email. Feedback filed inside the app by a signed-in member syncs to us so we can act on it. Messages sent through the public contact form reach us directly: we store the name, email address and message you submit so we can reply. (On a build without a backend the form saves your message locally in this browser instead, and says so on the page.)
- Crash reports.When a page breaks in your browser, it sends us the error message, a short technical trace, which page you were on, the build you were running and your browser’s user-agent string, so we can find and fix the fault. These carry no name, no account and no page content, and the address is stripped of anything after the path. They are sent from every page of this site and the app, whether or not you are signed in.
4. Google user data
Connecting Google Calendar, or signing in with Google, means we handle data that belongs to your Google account. This section is the whole account of it: what we access, what we keep, who else sees it, and how to make it go away. Nothing here applies unless you connect Google yourself.
- What we access. The app asks for two calendar permissions, and only these two.Read-only access to your Google calendars — that permission, as Google defines it, covers the calendars you can see, and we use it to read only your primary calendar, so the in-app calendar can show your real schedule. It is a read-only scope, so it cannot change anything in your Google account. And, only if you turn on the optional calendar push, permission to write to a calendar we create. Google limits that second permission to the "Life Mastery" calendar we create, so we never write to your own Google calendars. If you sign in with Google, we also receive your email address, and your name and avatar if your Google account has them.
- What we keep. A copy of the events on your primary calendar: each event's title, start and end times, location, free/busy status, a link back to it in Google, and Google's own identifier for it. Each sync covers a window of roughly the past week to the next two months and replaces the previous copy; we hold that copy for as long as the connection exists, not just for the length of the window. If push is on, we also keep the identifier of the Life Mastery calendar we created, a synchronisation token Google issues us for it, and a record of which of your Life Mastery blocks we wrote there (including the identifiers of recently removed ones), so edits you make to those blocks in Google sync back. A copy is also cached on your own device so the calendar works offline.
- Why. To show your real commitments on your calendar, so plans are made around them, and — if you turned push on — to put your Life Mastery blocks where the rest of your life already is. That is the only reason we hold it.
- If you turn a Google event into a Life Mastery block. The calendar offers a deliberate "make this a Life Mastery event" action on a Google event. Taking it copies that event's title into your own plan, where it becomes an ordinary Life Mastery block and is treated like everything else you write — it syncs to your account and, like your other blocks, can travel to an AI model provider when you use an AI feature. Deleting that block, not disconnecting Google, is what removes it.
Who we share, transfer or disclose Google user data to. We share it with the service providers that operate Life Mastery, and only so the features you turned on can work. This is the complete list:
- Clerk — our authentication provider. It holds the connection to your Google account and the access tokens, and hands our server a short-lived token when a sync runs. If you sign in with Google, Clerk also holds the account details above.
- Convex — our database. The copy of your events and the push record are stored there.
- Vercel — our hosting provider. The data passes through it in transit whenever you use the app.
- Our AI model provider — Anthropic, OpenAI, or Google. Sending your Google events is off by default and happens only if you switch it on yourself. When it is on, the titles and times of that day's events are included in the context sent to the model, so the Coach can plan around your real day. (The one exception is a Google event you chose to turn into a Life Mastery block, described above: that is your own entry from then on, and travels with your other blocks whether or not this switch is on.) Which provider serves a given feature is our configuration and can change; today it is one of those three, and Google's own Gemini models are among them, so your calendar data may go back to Google in that role. You can turn this on or off at any time on the calendar's Sync tab, or in the Coach's "What the Coach reads" panel, where it is listed as a private source — the setting is stored with your account, so turning it on or off applies everywhere you are signed in. No provider uses this data to train their models.
- Google itself — if, and only if, you turn on calendar push. We write your Life Mastery blocks into the Life Mastery calendar we created in your account: the block's title (or just "Busy — Life Mastery" if you turn titles off), its times, and whether you completed it.
- Stripe, our payment processor — if you subscribe or buy credits, and only your email address, which is the one your Google account gave us if you signed in with Google. Stripe never receives anything from your calendar.
- Other Life Mastery members — if you signed in with Google and you use Community, the display name and initials on your community profile are the ones your Google account provided, unless you change them. Nothing from your calendar is ever shown to another member.
That is the entire list. We do not transfer or disclose Google user data to any other party, and never for any purpose other than providing the features described here — except where the law requires us to, or where it is necessary to investigate a security incident or a violation of our terms. We do not sell or rent it, we do not use it for advertising, we do not use it to build profiles, and we do not use it to train, develop or improve any general-purpose AI model — ours or anyone else's. Your calendar data is stored against your own account and there is no staff or admin screen anywhere in Life Mastery that can open it. Direct access to the underlying database is limited to the person who operates the service, for maintenance and support, and is not used to browse member calendars.
How long we keep it, and how to remove it. We keep it for as long as the connection exists. Disconnecting Google inside Life Mastery deletes our copy of your events, removes the stored connection, and clears the copy cached on your device. Turning push off removes the Life Mastery calendar from your Google account; if Google refuses or cannot be reached at that moment, we keep the small record we need to finish removing it and retry — email us and we will clear it, and you can delete that calendar in Google yourself. Two things deliberately survive a disconnect, because they are your own writing rather than a copy of Google's: any Google event you turned into a Life Mastery block, and anything a coaching reply or daily briefing quoted at the time. Delete those like any other entry. Deleting your account removes all of it, within 30 days — except a record of the deletion itself (your account identifier, your email address, and the outcome), which we keep so a deletion can be evidenced. You can also revoke our access at any time from your Google account permissions page. Revoking there stops all access immediately; email us and we will clear our copy.
Life Mastery's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar is a Google Workspace API, so this applies too: the use of raw or derived user data received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. In particular, we do not use, transfer or sell Google user data — raw, aggregated or derived — to create, train or improve any foundational or generalised machine-learning or artificial-intelligence model. Where an AI feature you switched on sends your calendar data to a model provider, it is used only to generate that result for you, and no provider trains on it.
5. What we deliberately do not do
- No advertising, and no selling or renting of personal data, ever.
- No third-party analytics or tracking scripts on the site or in the app today.
- No training of AI models on your private content.
- Only functional cookies and local storage: what Clerk needs to keep you signed in, what the app needs to remember your preferences (like your theme), and — if you arrive through an affiliate link — a first-party cookie recording which link sent you, so the referrer can be credited. It lasts 90 days and is never shared or used to track you elsewhere.
6. Why we process data
We process your data to provide the service you asked for (account, sync, support, and later billing), to keep the service secure, and to meet legal obligations. That is the whole list. Where the law requires a legal basis, ours is the performance of our contract with you, our legitimate interest in running a secure service, and consent where we ask for it explicitly.
7. Service providers
We use a small set of processors to run Life Mastery: Clerk (authentication), Convex (database and sync), Vercel (hosting), Stripe (payments), Google (in two distinct roles — the Calendar connection, only if you choose to link it, reading your primary calendar and, only if you enable push, writing to the app-created Life Mastery calendar; and, like the two below, as an AI model provider through its Gemini models), and Anthropic and OpenAI (AI model providers; each receives only the context you allow, at the moment you use an AI feature). Each processes data under a data-processing agreement. Some providers process data in the United States; where they do, transfers are covered by recognised safeguards such as the EU standard contractual clauses. For which of these see Google user data specifically, and on what terms, see section 4.
8. Retention and deletion
Server-side data is kept while your account exists. You can request account deletion from the Account page; we action deletion requests and remove the account record and your synced data within 30 days, except where the law requires us to keep something longer (invoices, for example). The data on your own device is under your control alone; requesting deletion does not touch it.
9. Your rights
Under the GDPR you can ask for access, correction, deletion, restriction, portability, and you can object to processing. The JSON export in Settings covers portability of your core practice data on the spot; for anything else, email support@lifemasteryplatform.com and we will respond within a month. You can also complain to your data-protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.
10. Security
All traffic is encrypted in transit. Server-side data lives with the providers named above, each with their own strong security programmes. No card data ever reaches our servers. No system is perfectly secure, but a deliberately small set of providers, no third-party trackers and no advertising keep the honest attack surface small by design.
11. Children
Life Mastery is not directed at children and requires users to be at least 16.
12. Changes to this policy
If this policy changes in a way that matters, we will announce it in the app or by email before the change takes effect. The date at the top tells you when it last changed.
13. Contact
For anything about your privacy: support@lifemasteryplatform.com.