Life OS

Privacy Policy

Last updated: August 28, 2026

The short version

Life OS holds a lot about your family: your calendar, your money, your sleep, your children. We keep it because the product does not work without it, we isolate each household from every other one, and we do not sell it, rent it, or use it to advertise to you. You can export it or delete all of it.

Who we are

Life OS is an invite-only family organiser operated by Caldwell Group. For data protection purposes we are the controller of the information described here. Contact: derek@caldwellrg.com.

What we collect

Only what a household adds or explicitly connects.

  • Account and identity — email address, password (hashed by our auth provider, never visible to us), and the name, role, colour, photo and date of birth each household records for its members.
  • Household life — calendar events, tasks, chores, meal plans, groceries, recipes, school items, trips, packing lists, notes and reminders.
  • Calendar — if you connect Google Calendar: the list of your calendars, and the events on the ones you choose. We can also create and change events, but only when you ask us to.
  • Financial — if you connect a bank through Plaid: account names, types, balances and transactions. We never receive or store your bank username or password. Plaid handles that and gives us a token.
  • Health and activity — if you connect WHOOP, Oura, Strava or Apple Health: sleep, recovery, readiness, steps and workouts.
  • Home — if you connect Home Assistant, the state of devices you expose to it. Home Assistant runs on your own hardware; we hold a token to reach it.
  • Location — a home address you enter, used to calculate travel time to events. We do not track device location in the background.
  • Technical — sign-in sessions, push notification tokens, error reports, and a record of scheduled jobs.

Children

Life OS is designed for families and holds information about children — names, dates of birth, photos, school details, chores and rewards. That information is entered by a parent or guardian on the account, and children are given access only when a parent creates a login for them. A child's view is limited to their own board: their schedule, their chores, their stars. Children are never shown household finances, other people's health data, or adult check-ins.

We do not knowingly let a child create an account without a parent, we do not advertise to children, and we do not use children's information to train models. A parent can delete a child's profile and all associated data at any time from Settings, which removes it from our database.

How we use it

  • To show your household its own information — the whole point of the product.
  • To generate your morning brief, reminders, and the check-ins that ask whether something slipped.
  • To answer questions you ask the assistant, and to carry out actions you ask it to take.
  • To keep the service running: error monitoring, and alerting us when a sync stops.

We do not sell personal information. We do not share it with advertisers. We do not use your household's data to train any AI model, and the AI providers we use are engaged under terms that prohibit training on it.

Who else processes it

Running the product means sending some data to other companies. Each one receives only what its job requires.

  • Vercel — hosting and delivery.
  • Supabase — database, authentication and file storage (photos, trip documents).
  • Trigger.dev — scheduled background jobs (calendar sync, the morning brief).
  • Sentry — error monitoring.
  • OpenRouter and the model providers it routes to — the text of an assistant request and the household snapshot needed to answer it.
  • Google — Calendar (what you connect), and Maps/Places for travel times and address lookup.
  • Plaid — the bank connection.
  • WHOOP, Oura, Strava — the wearable connections you choose.
  • Kroger — only if you connect it, to build a cart from your grocery list.
  • MealViewer — public school lunch menus. No personal data is sent.
  • Open-Meteo — weather for your area. No personal data is sent.
  • ElevenLabs — speech for spoken announcements, if you enable them.
  • ScrapingBee and Jina — fetching a recipe page you asked to import. Only the URL is sent.
  • Apple (APNs) and web push services — delivering notifications to your devices.
  • Cloudflare — receiving email you forward to your household's capture address.

How it is protected

  • Household isolation is enforced in the database itself through row-level security, not only in application code. One household cannot read another's rows.
  • Third-party access tokens — the keys to your bank, calendar and wearables — are encrypted with AES-256-GCM before they are written, using a key held only in the application environment. A database leak alone does not expose them.
  • Secret columns are unreadable to normal application queries; only the server components that need them can decrypt them.
  • Incoming webhooks are verified cryptographically, so nobody can impersonate Plaid or WHOOP to us.
  • Children's accounts are excluded from household data access at the database level.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your data we will tell you promptly and describe what happened.

How long we keep it

Household content stays until you delete it or close the household. Disconnecting an integration deletes the stored token and stops future syncing. Deleting your household removes its data from our database; backups age out on our provider's retention schedule. Error reports are kept for a limited period by Sentry.

Your choices

  • Access and correction — everything we hold about your household is visible and editable in the app.
  • Export — you can request a copy of your household's data.
  • Deletion — you can delete individual records, a person, an integration, or the entire household.
  • Disconnect — every integration can be revoked from Settings, and from the provider's own account page.
  • Notifications — push can be turned off per person, with quiet hours.

Depending on where you live you may have additional rights — to object, to restrict processing, or to complain to a regulator. Write to derek@caldwellrg.com and we will honour them.

Google user data

Life OS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the ability to read your calendar list, and to read and write events. We do not request the ability to delete calendars or change their sharing. Google Calendar data is used solely to show and manage your household's schedule inside Life OS, is never sold, never used for advertising, and never used to train AI models. It is shared with no one other than the sub-processors listed above that are required to operate the feature. You can revoke access at any time in Settings or at your Google account permissions.

Where data is processed

Our providers operate in the United States. If you use Life OS from elsewhere, your information will be processed in the United States.

Changes

We will update this page when the product changes what it collects or who it shares with, and move the date at the top. For a change that materially affects your data, we will tell you in the app before it takes effect.

Privacy PolicyTerms of Service