Last updated: July 26, 2026
Effective Date: July 26, 2026
Life Tracker stores account and authentication data, profile information, API-key metadata, optional billing state, and the personal content you choose to record.
Personal content can include Items, Areas, links, narrative updates, return context, progress, reminder intent, meaningful reminder outcomes, and Activity summaries.
If you connect Anchor, Life Tracker stores one encrypted scoped Anchor backend credential, a sanitized connection status, Anchor notification identifiers, and the latest meaningful mapped state needed to represent your reminder loop.
Life Tracker does not copy Anchor provider receipts, delivery attempts, or operational event history.
Data is used to authenticate you, provide the Life Tracker features you request, protect owner isolation, generate durable reminders, submit due occurrences to your connected Anchor account, reconcile meaningful reminder outcomes, provide exports and deletion, and maintain service security and reliability.
Core Life Tracker use does not perform model inference.
Transactional email, optional OAuth providers, optional Stripe billing, hosting and database providers, error monitoring when configured, and Anchor may process limited data required for their role.
Anchor owns its notification delivery and operational history.
Stripe owns its billing records.
Deleting Life Tracker data does not claim to erase records lawfully retained by those separate systems.
Life Tracker uses owner-scoped database access, opaque identifiers, server-side sessions, HttpOnly cookies, CSRF protection, recent authentication for consequential actions, scoped API-key permissions, encryption for Anchor credentials, bounded provider calls, and secret redaction.
No system can promise absolute security.
You can inspect Activity, correct product data, export Life Tracker-owned content in JSON and CSV, delete an Item immediately, revoke API and Anchor keys, and request account deletion through the authenticated product flow.
Account deletion removes Life Tracker personal content even if an external provider is unavailable.
Content-free encrypted Anchor cancellation work may remain for up to 30 days solely to stop active external prompting.
Active product data remains until you change or delete it.
Expired authentication and idempotency records are removed through bounded cleanup.
Backups follow the operator’s protected backup retention schedule.
Detached cancellation credentials are bounded as described above.
See the Cookie Policy for essential browser-session behavior.
Life Tracker is not designed for children who cannot lawfully consent to an online account in their jurisdiction.
Material policy changes are reflected by the date above.
Use the support contact published by the Life Tracker operator for privacy questions or rights requests.