YULA Lab
Privacy
LifeOS

LifeOS privacy policy

Last updated: 2026-09-06

One-line summary

LifeOS is an offline-first app built around on-device data storage. Data processed for accounts, purchase state, crash reporting and optional cloud backup is described separately below. Content kept on your device is distinct from the account and service data sent to those services.

Data that stays on your device

  • Health data (read from Apple Health / Health Connect: steps, heart rate, sleep, exercise)
  • Financial records (income, expenses, goals)
  • Learning and goal tracking
  • Voice journal and Z-Report entries (audio is transcribed on-device)
  • Photos and other attachments

The app's main database is encrypted on-device with SQLCipher + AES-256. Its key is stored in the device's Keychain (iOS) or Keystore (Android). Audio, photos, exports and other attachments may be separate files; database encryption does not mean that it covers every one of those files.

Data sent to our servers

  • Account information: Email and device ID (only if you create an account). You can use the app with most features without creating an account.
  • Crash reports: Sentry is used for crash reporting. You can check and change your reporting preference in Settings > Privacy. When reporting is enabled, diagnostic data about application errors is sent to Sentry.
  • Purchase state: Apple App Store / Google Play receipt validation. We only store active/inactive and tier (Plus / Pro).
  • Cloud sync (optional): If you enable cloud sync, records included in sync may be transferred to Supabase. Encryption of the database on your device does not mean that the cloud copy is end-to-end encrypted. Check the in-app information for your version for the data included and the available encryption features; you can ask support for clarification before sending personal content.

HealthKit / Health Connect

We request Apple HealthKit (iOS) and Android Health Connect permissions to read health data. You grant these optionally. Health data is processed on-device, is NOT sent to any server, and is NOT used for model training. Fully compliant with Apple's Health Data Use Policy.

Third parties

  • Supabase: Account registration and optional cloud backup. Hosted on EU (Frankfurt) servers.
  • Apple HealthKit / Health Connect: Health data read permission (optional).
  • Apple App Store / Google Play: Subscription payments and receipt validation.
  • Sentry: Crash reports, subject to your reporting preference in the app.

Data retention

Device data is kept until you delete it. Deleting an account and removing files from your device are separate actions. Receipts documenting completion of an account deletion may retain the user identifier after the account has been deleted. We therefore do not give a blanket guarantee that all server-side records are removed within 30 days. For the scope and retention period of records associated with your account, or a deletion request, contact support@yulalab.com.

Children

LifeOS is for users 13 and older. If we learn that we have collected data from a child under 13, we will delete the account and clear the records.

Medical disclaimer

LifeOS is a health tracking tool and does NOT provide medical advice. Please consult a licensed health professional for medical decisions. The app is not intended to diagnose, treat, or prevent any disease.

Your rights

You have rights of access, correction, deletion, portability, and objection under KVKK Article 11 and GDPR Articles 15-22. For device records, check which data the export and deletion tools in your version cover; separate attachments may require an additional action. Send requests about account and server-side records to support@yulalab.com.

Data security

The main device database is encrypted with SQLCipher + AES-256, with its key held in Keychain/Keystore. This protection has a different scope from separate attachments and optional cloud sync. This page does not guarantee end-to-end encryption or server unreadability of cloud sync data across all versions.

Changes

We may update this policy from time to time. Significant changes will be announced via in-app notice and reflected in the 'Last updated' date.

Contact

Data Controller: YULA Lab — Mustafa Kaan Koçak
Email: support@yulalab.com
Location: Türkiye