Privacy

Your information stays yours.

LIFECORE is built around a simple idea: organising your life should not mean giving it away. This page explains what stays on your device, what an online account needs, and what happens when you choose to connect another service.

Your private Vault

Your LIFECORE records are stored in an encrypted Vault on your device. Android Keystore-backed keys protect that Vault. Creating a LIFECORE account does not automatically upload your tasks, notes, documents, family information, money plans or other private Vault content.

Your LIFECORE account

To provide sign-in and recover your account, LIFECORE processes the name and email you provide, securely hashed password credentials, email-verification state, active sessions and security information needed to protect the service. We do not store your password in readable form.

Website visits

LIFECORE does not run visitor analytics or advertising on mylifecore.app. Cloudflare provides the website's hosting and security, so ordinary network requests are processed as needed to deliver and protect the site, but its visitor-analytics beacon is not enabled for LIFECORE.

Subscriptions

Google Play or Apple handles payment details. LIFECORE keeps the minimum information needed to confirm access, such as the store, product, subscription status, renewal window and a protected reference to the purchase. LIFECORE does not receive your full card number from the app store.

Connected services

Connections are optional. Before you connect a service, LIFECORE explains what it needs to read or do. You can disconnect later. The original service remains in control of its own information, and LIFECORE only uses the access you approve.

Family Spaces

Online Family Spaces keep account membership, roles, protected invitation details and encrypted shared updates so invited members can stay in sync. Shared content is encrypted before it leaves the app; the service stores ciphertext rather than readable family details. Leaving or deleting an account removes its membership. If an owner deletes their account, LIFECORE transfers the Space to an existing member where possible, or removes an owner-only Space and its encrypted remote history.

LIFECORE Circle

If you choose to post in LIFECORE Circle, the service stores your display name, thread or reply, time and any report you submit. Other verified members can see active posts. Moderators can review reported content and may issue a private warning or restriction; a moderation notice is visible only to the affected member and authorised RadForge staff. Account deletion de-identifies retained Circle posts as “Former member”. You can remove your own eligible threads and replies before deleting your account.

Ask LIFECORE and on-device AI

Ask LIFECORE answers from your device first. On supported Android phones, LIFECORE may use Google's Gemini Nano through ML Kit to answer a general question inside the app. LIFECORE sends only the question you typed to the on-device model—not your Vault records—and Google states that prompt input and output are processed on the device. Google ML Kit may still collect limited device, app, identifier, performance, usage and error information to operate and improve the SDK. Optional LIFECORE Cloud AI is separate, asks for approval before sending the question and any context you select, and applies account and service limits. AI answers cannot write to your Vault without a separate review-and-confirm step.

Permissions

Device permissions are requested when a feature needs them. If you say no, LIFECORE explains what will be unavailable and keeps the rest of the app working. You can review or change permissions in LIFECORE and Android settings.

Backups and files

Protected backups and exported files are created only when you ask. Once a file leaves LIFECORE, its safety also depends on where you save or share it. Keep backup passphrases private and store backups somewhere you trust.

Security

Account requests use encrypted HTTPS connections. Authentication responses are not cached. Passwords, session tokens, private Vault content and raw store purchase tokens must not be written to production logs.

Deletion

You can request permanent account deletion from the account deletion page. This removes server-held account and entitlement records covered by the LIFECORE account service. Your local Vault remains on your devices until you delete it inside LIFECORE, clear the app's storage or remove the app.

Questions

Contact LIFECORE privacy at privacy@mylifecore.app. Please do not email passwords, backup passphrases or private documents.