Laiffi

Privacy Policy

Version 1.1.0Last updated 14 September 2026

About this policy

This policy explains what personal data Laiffi processes, why, who receives it, how long it is kept, and what choices and rights you have.

It covers the Laiffi mobile app, the Laiffi backend service that stores your data, and the public Laiffi website. It applies to everyone who uses Laiffi during the free beta.

It describes how the app works today. Where something is not yet settled, this policy says so plainly instead of promising something we have not decided.

Who controls your data

Laiffi is operated from Finland by a private trader (a sole trader, not a company), so Finnish and EU/EEA data-protection law applies. The controller responsible for your personal data is:

Jesse Kristian Haimitrading as Haimi Studios (sole trader)Business ID (Y-tunnus): 3644492-2Suonionkatu 6 D 10600530 HelsinkiFinlandsupport@laiffiapp.fi

What Laiffi is

Laiffi is a personal planning and wellbeing-support app. It helps you plan your day, organize tasks and routines, estimate travel between places, set reminders, and — if you choose — keep short daily reflections about how your day went.

Laiffi is not a medical, healthcare, or emergency service.

Using Laiffi requires an account: your plans, tasks and settings are stored on our server so they follow you across devices.

Account and sign-in data

To give you an account we store:

  • your name and email address
  • a securely hashed password, if you sign up with email and password
  • a record that you confirmed you are at least 16 years old
  • the technical account records needed to keep you signed in

We also use short-lived, single-use codes — stored only as a hash, never in readable form — to verify your email address, change your email address, or reset your password. They expire after a short time.

Signing in with Apple or Google

You can create an account or sign in using Apple or Google instead of a password. If you do, we receive a stable identifier for your Apple or Google account and the basic profile details they release to us, such as your email address and name.

The sign-in itself is verified by our server against Apple's and Google's public verification data. We never receive your Apple or Google password, and we do not keep long-lived access tokens for those accounts or use them to reach any other service on your behalf.

Legal acceptance and age confirmation

When you register, we record evidence of what you agreed to:

  • that you confirmed you are at least 16 years old
  • which version of the Terms of Service you accepted, and when
  • which version of this Privacy Policy you acknowledged, and when

The version is decided by our server, not by the app, so the record reflects exactly which document you were shown. We keep these records as evidence that the agreement was made — they are kept for as long as your account exists.

Settings, saved places and coordinates

We store the preferences you set, such as your default transport mode, wake and bedtime targets, meal and reminder preferences, appearance and language.

We also store the places you save — for example your home, work or default lunch location — together with the precise latitude and longitude of each place, plus any day-specific location you set for a particular date. Precise coordinates are needed to estimate travel times and routes; without them the planner cannot tell how long a trip takes.

Saved places are created by you, and you can edit or delete them at any time in the app.

Tasks, routines, to-dos and checklists

To plan your days, Laiffi stores the planning content you create:

  • tasks and their details — titles, notes, tags, times, durations and locations
  • routines and repeating templates, and the days they apply to
  • to-dos, including any optional deadline you set
  • checklist items attached to a task, and which of them you have ticked off
  • whether an item is done, skipped or still open

This content is yours. You can edit or delete any of it in the app, and deleting your account deletes all of it.

Device-calendar imports

If you grant calendar permission, you can import events from your device calendar so the planner can work around them. Importing is always something you start: Laiffi does not read your calendar in the background and does not upload your whole calendar.

For an event you import, we store its details — title, time, and location if it has one — together with a reference to the source event and the name of the calendar it came from, so a later re-import updates the same item instead of duplicating it and so you can set a default place per calendar. If you set your own location on an imported item, a re-import will not overwrite it.

You can delete an imported item in the app, and you can revoke calendar permission at any time in your device settings.

Generated schedules, travel and history

When you generate a day, Laiffi stores the resulting schedule so you can come back to it:

  • the ordered blocks of your day and their times
  • travel blocks between places, including the transport mode, the estimated duration and distance, and — for routes returned by a routing provider — the route line so it can be drawn on a map
  • whether a travel estimate is an approximation rather than a provider route
  • your execution history: which blocks you started, completed, skipped or rescheduled, and when

This history is what lets the app show your day as it actually happened rather than only as planned.

Calendar subscription links

Laiffi can publish your accepted schedule as a calendar feed that a calendar app subscribes to and refreshes on its own. The feed is reached through a single long, randomly generated link that is unique to your account.

Nothing exists until you ask for it. No subscription link is created for your account unless you turn the feature on, and if you never do, there is no link and no feed.

This is not the same as exporting a day as an ICS file. An export is a one-off download of one day, made while you are signed in. A subscription feed is a live address that keeps returning your accepted schedule — currently the past 30 days and the year ahead — every time a calendar app asks for it.

If you do turn it on, the link is the credential. Anyone who has it can retrieve that feed without signing in to your account and without your password, so treat it like a password: do not post it, forward it, or put it anywhere public. The feed is read-only and cannot change anything in your account, and it carries your accepted schedule — not your reflections, your to-dos or your account details.

You stay in control of it. Asking for a new link replaces the old one, and the previous link stops working immediately. Turning the feature off does the same and leaves you with no link at all. Deleting your account also ends the feed, along with the rest of your data.

A calendar app you subscribed with may keep its own copy of what it has already downloaded. That copy sits with that provider under its own terms, and replacing your link, turning the feed off or deleting your account does not reach it.

During the beta this feature is not yet offered in Laiffi's apps, so there is currently no way to turn it on from the app and no link has been created for you.

Schedule feedback, voice transcripts and revisions

You can adjust a generated day by describing the change you want, either by typing it or by recording it.

When you do, we store the text of your request — for a recording, the transcribed text — together with a structured, machine-readable version of the change and the proposed new schedule, so the app can show you a preview before you accept it.

Once a request has reached its final state — accepted, discarded, replaced by a newer one, or failed — the raw request text and any stored transcript are deleted after 30 days. The structured revision records are kept on their own shorter schedule (see "How long we keep data"), and the schedule you accepted stays until you change or delete it.

Feature requests and problem reports

From Settings you can send us a feature request or a problem report. Both are optional, and both are something you start.

When you send one, we receive:

  • the free-text message you wrote
  • your account name and email address, which our server attaches from your account — the app does not send them
  • which of the two kinds it is (feature request or problem report)
  • a short technical description of your app: the app version, the build number if your build has one, whether you are on iOS or Android, your operating-system version, and the language the app is set to

Nothing else is attached automatically. A support message never includes your schedules, tasks, routines, to-dos, calendar items, reflection answers, saved places, coordinates, routes, notifications, error logs or screenshots. If you want us to see something like that, you have to describe it yourself in the message.

We use these messages to reply to you, to diagnose the problem you reported, and to decide what to improve in Laiffi. The message is delivered to our support inbox by email through Resend, and it is not stored in Laiffi's database — there is no in-app history of what you sent.

Our legal basis is our legitimate interest in supporting and improving Laiffi and in answering the people who write to us, balanced against your rights and limited to the message and the small technical description above.

Support and feedback messages are retained for up to 24 months after receipt or deleted earlier when they are no longer needed to handle the request. A message may be retained longer where necessary to establish, exercise, or defend legal claims.

Reflections and wellbeing information

Reflections are optional and off until you turn them on. If you enable them, Laiffi stores your reflection entries — ratings and answers, including how you slept and how motivated you feel, any notes you write, any custom questions you create, and the plans you write in your morning check-in — so you can see your history and insights over time. We also store generated summaries of your evening reflection history.

From your entries Laiffi works out a morning starting score and an evening day score, along with trends and insights. These are calculated when you ask to see them and are not stored as separate records.

Reflection information can reveal details about your wellbeing or health, so it is treated as sensitive. We process it only with your explicit consent, and only for showing you your own history, scores and insights.

Your morning plans stay part of your reflections unless you choose to add one to your to-dos. If you do, that to-do becomes an ordinary task like any other you create yourself.

If you have added the same morning plan to your to-dos on at least two different mornings in the last 30 days, Laiffi may offer it again as a suggestion in your next morning check-in. Suggestions are worked out fresh each time you open the check-in, are not stored as a profile of you, and involve no AI. Choosing one only adds it to that morning's plans — it does not create a to-do by itself. You can turn suggestions off in Settings, under Reflections; turning them off stops Laiffi looking through your past morning plans, and deletes nothing.

The rest of Laiffi works normally whether or not you use reflections. Declining reflections, or withdrawing consent later, does not disable planning, schedules, tasks, travel, reminders or any other part of the app.

Reflection consent and withdrawal

Reflection processing happens only after you give explicit, versioned consent in the app, and you can withdraw it at any time in Settings.

Withdrawing your reflection consent permanently deletes your reflection data — your entries, answers, notes, custom questions, morning plans, prompts, insights and generated summaries. There is no "keep the data" option on withdrawal. It also turns your reflection reminders off and cancels any morning reminder already scheduled on your device. You can also delete your reflection data without deleting your account, with the same effect on the data.

One thing is deliberately not deleted. A to-do you created from a morning plan is an ordinary task from the moment you add it, so it stays in your to-do list — with the title you gave it — even after you withdraw. You can delete it yourself from the Tasks screen at any time. Nothing is left on that to-do to record that it came from a reflection.

Withdrawing does not disable any other part of Laiffi.

For accountability we keep a minimal record that consent was given and later withdrawn, but not your reflection content.

Reminders and notifications

If you turn on task or reflection reminders, Laiffi stores that preference. Reminder times are calculated on your device from your plan. The morning reminder is timed from your planned wake-up block, and Laiffi does not store a separate clock time for it.

The plan those times are calculated from — your schedule, including the wake-up block — comes from our server, as it does everywhere else in the app. Working out the reminder instant from it, and scheduling the reminder, happen on your device.

The generic reminder can appear on your lock screen. It does not include your answers, scores or plan titles.

Reminders are scheduled locally on your device by the operating system. Laiffi does not operate a server-side push service and does not collect a push token, so no reminder content is sent from our server to your device.

Device permissions

Some features ask your operating system for permission. Each is optional and controlled by your device settings:

  • Calendar — to import events you select from your device calendar
  • Microphone — only while you are recording spoken feedback for a schedule change
  • Notifications — to show your reminders on your device

Laiffi does NOT ask for location permission and does not read your device's location. Travel times and routes are worked out from the places you save yourself — see "Settings, saved places and coordinates". When you pick a point on the map, your phone turns that point into a readable street name locally; that lookup does not tell us where you are.

You can change or revoke these permissions at any time in your device settings. Revoking one disables the feature that needs it, not the rest of the app.

Product analytics (optional)

This section is about analytics in the Laiffi app. The public website has separate optional analytics of its own, with its own consent — see "The Laiffi website".

Laiffi can send a small amount of usage information to help us understand whether the app works: whether sign-in completes, how far people get through setup, whether a schedule is generated and accepted, and which features are used at all.

This is off unless you turn it on. You will not be asked during setup, nothing is collected before you switch it on in Settings under "Product analytics", and refusing costs you nothing else — the rest of Laiffi works exactly the same. Our legal basis is your consent, and you can withdraw it at any time in the same place.

WHAT IS SENT. A fixed, closed list of events — about fourteen — each carrying only values chosen from a fixed list in our own code, plus rough size ranges such as "6-20" instead of exact counts. Your tasks, calendar events, notes, reflections, locations, addresses, search text and error messages are never sent, and there is no field in which they could be placed.

WHAT IDENTIFIES THE DATA. A random identifier created on your device when you turn analytics on. It is not your account: your email address, your name, your Apple or Google identifier and your Laiffi account number are never sent to our analytics provider, and the identifier is never linked to them. You can see it in Settings under "Product analytics". It is deleted when you turn analytics off, when you delete your account and when you delete the app, and a new one is created if you turn analytics back on. It changes if a different account signs in on the same device.

WHAT WE DELIBERATELY DO NOT COLLECT. We do not record your screen and do not use session replay. We do not automatically capture taps, screen names or the text shown on screen. We do not collect your device model, operating-system version, app version or language through analytics, and the software components that would collect them are not installed. There is no advertising identifier, no advertising, and no tracking of you across other apps, websites or services.

WHO PROCESSES IT. PostHog, Inc., acting as our processor, on its European cloud with servers in Frankfurt, Germany. See "Who we share data with" and "International transfers".

HOW LONG IT IS KEPT. Analytics events are kept for one year by our analytics provider and then removed. We do not currently have a way to set a shorter period there.

DELETING IT. Turning analytics off in Settings stops all collection immediately and deletes the identifier from your device, but it does not delete events already collected. Because those events are deliberately not linked to your account, we cannot find them from your account — the identifier is the only way. To have them deleted, copy the identifier from Settings and send it to our support and privacy contact from the Data rights & support screen. Deletion is processed by our provider in batches and can take up to about a week.

IMPORTANT: DELETING YOUR ACCOUNT DOES NOT DELETE THESE EVENTS. Nothing connects them to the account, so there is nothing for the deletion to find. If you want them removed as well, save the identifier before you delete your account — the account-deletion screen shows it to you — and send it to our support and privacy contact from the Data rights & support screen.

AI-assisted features

Three features send data to a third-party AI provider (currently OpenAI). What is sent differs by feature:

  • Schedule generation and feedback — task and event details such as titles, tags, durations, times and place labels, plus the text of the change you asked for, so the assistant can order your day or understand your request. If the provider is unavailable, Laiffi falls back to a non-AI ordering.
  • Voice transcription — when you record spoken feedback, the audio is sent to the provider to be transcribed into text. The audio is held in memory for the request only; it is never written to our storage. The returned transcript is treated as your feedback text and may be stored as described above.
  • Reflection summaries — only aggregated, numeric evening reflection data (such as averages, counts and completion rates) is sent, together with fixed labels written by Laiffi. Your written answers, notes, your own question wording, your morning check-ins and your morning plans are not sent to the AI provider.

We do not send your name, email address or account identifier to the AI provider, and AI output is never used to make a decision about you beyond arranging the day you asked it to arrange.

Automated schedule generation

Laiffi arranges your day automatically: it orders your tasks, places meals and travel, and proposes changes when you ask for them. This is automated processing of your planning data.

It produces a suggestion, not an outcome. Nothing is applied without you seeing it, you can edit or reject any part of it, and the result affects only your own plan — it does not determine access to anything, and it produces no legal or similarly significant effect on you.

Who we share data with

We share data only with the service providers that make Laiffi work, and only what each one needs:

  • Hosting and database — stores your account and all app data on our behalf
  • Functional Software, Inc. (Sentry) — error monitoring, diagnostics and service reliability. When our backend hits an unexpected fault it sends a limited, sanitized technical error report: the type of the error, the place in our own program code where it happened, which build of Laiffi was running, and a short set of fixed operational labels. We configure the integration so that it does not deliberately include your account identity, the contents of your request, or anything you have written into your plans, tasks or reflections. We cannot promise that no fragment of technical detail is ever personal data, so we treat these reports as personal data and keep them to what diagnosing the fault needs.
  • OpenAI — AI processing, as described in "AI-assisted features"
  • Resend — sends transactional email: address verification, password reset and email-change messages, and delivers the feature requests and problem reports you send from Settings to our support inbox. It receives your email address and the message itself. We do not send marketing email.
  • Apple and Google — verify your sign-in, if you choose to use it
  • Digitransit (HSL) — route planning and address search. Laiffi asks it for public-transport routes, and also for walking and cycling routes. It receives the start and end coordinates of the trip, the time you are planning to travel, and the text you type into address search. It does not receive your name, email address or Laiffi account identifier.
  • A public OSRM routing service — driving-route estimation. See the next section.
  • PostHog, Inc. — analytics, ONLY if you have turned it on. In the app it receives the fixed events described in "Product analytics (optional)" together with a random identifier created on your device. On the website, if you accepted website analytics, it receives the fixed events described in "The Laiffi website" with no visitor identifier at all. In neither case does it receive your name, email address, Apple or Google identifier, or Laiffi account identifier.

We update this list if our providers change.

Driving routes and the public routing service

When you plan a trip by car, our backend asks a public, freely available OSRM routing service for the route.

What it receives is only the start and end coordinates of that one trip, plus fixed technical routing parameters. It does not receive your name, email address, Laiffi account identifier, task or event title, saved-place label, or the date of your plan — it sees two unlabelled points and nothing that identifies you.

The request is made by our server, not by your phone, so your device's IP address is not exposed to that service.

You should know the limits of this arrangement, because we cannot promise what we do not have. This is a public service used free of charge during the beta. We have no service-level agreement with its operator, no data-processing agreement, no guarantee about which country processes the request, and no commitment about whether or how long it keeps request logs. If it is unavailable or returns something we cannot verify, Laiffi does not fail — it falls back to an estimated travel time that is marked as an estimate for you to review. We will reassess this arrangement before Laiffi becomes a paid service or reaches meaningful scale.

Hosting, backups and server logs

Your account and app data are stored in a managed database run by our hosting provider, and our backend runs on the same platform. The provider processes this data on our instructions and does not use it for its own purposes.

Our own application logs are written to avoid recording your content: they carry event names, stable status codes and internal identifiers, and deliberately not reflection text, feedback text, task titles, place labels or coordinates.

Separately from those logs, an unexpected backend fault also produces a sanitized technical error report that is sent to our error-monitoring provider. What that report may and may not contain is described under "Who we share data with".

Our hosting and database run in Frankfurt, Germany (EU). The database keeps a three-day point-in-time-recovery window, and platform logs are retained for seven days. Because of that recovery window, data you delete can remain restorable from a backup for up to three days after deletion; if we ever restored a backup, we would re-apply the deletions made since it was taken.

International transfers

OpenAI, Resend and PostHog are United States companies and may process data outside the European Economic Area.

Our analytics provider PostHog stores analytics data — from the app, and from the website if you accepted website analytics — on its European cloud, on servers in Frankfurt, Germany. We do not claim that no analytics data is ever processed outside the EEA: PostHog is a United States company and uses a globally distributed network to deliver its service. Its data-processing agreement offers the European Commission's Standard Contractual Clauses, which is the safeguard we rely on for it.

The providers named in this policy that may process data outside the EEA — our hosting provider, our error-monitoring provider, OpenAI, Resend and PostHog — are each covered by a data-processing agreement we have entered into, and transfers out of the EEA rely on the European Commission's Standard Contractual Clauses those agreements incorporate. The one exception is the public routing service described under "Driving routes and the public routing service": we have no agreement with its operator, and we say so there rather than implying otherwise. We do not claim a safeguard here that we have not entered into.

Why we process your data

We process your data to:

  • create and secure your account and sign you in
  • provide planning, scheduling, reminders, travel estimates and route information
  • provide reflections, insights and summaries, if you enable them
  • keep the service reliable and safe, prevent abuse, and diagnose and fix problems
  • communicate with you about your account
  • answer the feature requests and problem reports you send us, diagnose the problems they describe, and decide what to improve
  • keep evidence of the age confirmation and legal acceptance the law requires us to be able to show

Our legal bases

Under EU/EEA data-protection law we rely on:

  • Contract — for everything the core service needs: your account, sign-in, tasks and routines, schedules, travel estimates, calendar imports, saved places, reminders and schedule feedback
  • Explicit consent — for reflection and wellbeing data, which can reveal information about your health. You can withdraw it at any time, and withdrawal deletes the data.
  • Consent — for optional analytics, both in the Laiffi app and on the public website. Each is off unless you turn it on, and the two are separate: accepting one is not accepting the other. You can withdraw either at any time, and withdrawal stops that collection immediately. "Product analytics (optional)" explains how to have app data already collected deleted; "The Laiffi website" explains why the same is not possible for website events.
  • Legitimate interests — for keeping Laiffi secure and reliable, preventing abuse, diagnosing and fixing faults — including the sanitized error reports described in "Who we share data with" — and answering and acting on the feature requests and problem reports you send us, balanced against your rights and limited to what that actually requires
  • Legal obligation — for keeping the age-confirmation and acceptance records we may need to demonstrate

Where we rely on consent, refusing or withdrawing it costs you nothing else: the rest of Laiffi keeps working.

Data minimization

We try to process only what a feature actually needs.

Reflection summaries use aggregated numbers instead of your written notes. Voice recordings are transcribed without being stored. The driving-route service receives coordinates without any label, name or date. Our logs record event names and codes rather than your content. Debug logging that would print task titles, place labels or coordinates is disabled in production by the code itself, not merely by configuration.

No selling, advertising or tracking

We do not sell your personal data or share it for anyone else's commercial purposes. We do not show advertising in Laiffi, do not build advertising or marketing profiles, and do not track you across other apps, sites or services. Laiffi contains no advertising SDK, no advertising identifier and no cross-app or cross-site tracking.

The Laiffi app and the Laiffi website each include one optional analytics component, each off unless you turn it on, described in "Product analytics (optional)" and "The Laiffi website". They exist to tell us whether Laiffi works, are not used for advertising or marketing, are not linked to your account, and do not follow you anywhere else.

The Laiffi website

The public Laiffi website is a static site. It shows no advertising, contains no tracking pixels or third-party embeds, has no forms, and makes no runtime requests to third-party font or media services. Nothing you do on the website is linked to your Laiffi account, and we do not build a profile of you from it.

NECESSARY STORAGE. When you answer the website's cookie question, your answer is stored in your browser's local storage so you are not asked again. That single entry records nothing but the choice itself — accepted or rejected — and it is never used for advertising or profiling. It stays in your browser until you clear your browsing data.

OPTIONAL WEBSITE ANALYTICS. The website can send a small amount of usage information so we can understand how the site is used and whether its download links work. It runs only if you accept it: nothing is loaded, requested or sent before you do. Refusing costs you nothing — the whole site works exactly the same. Our legal basis is your consent, and you can withdraw it at any time from the cookie settings on the website, which stops collection immediately.

WHAT IS SENT. A small, fixed set of events written by hand in our own code: that a page was viewed, and that a download link, a social link or the language switch was used. We do not record your screen and do not use session replay. We do not automatically capture clicks, page elements or the text shown on the page, and we use no heatmaps, no surveys and no form capture — the website has no forms to capture. There is no advertising cookie, no advertising identifier, and no tracking of you across other sites or services.

NOTHING IDENTIFIES YOU. Website analytics does not identify visitors. We do not ask our analytics provider to identify you, no visitor profile is created for you, and the provider is configured to remember nothing between page loads — what it needs is held in memory for the page you are on, so no analytics cookie and no lasting visitor identifier is ever set. Website events carry a fixed label recording only that they came from the website, which is what keeps them separate from the app's product analytics. They are not linked to your Laiffi account, your email address or any account identifier.

WHO PROCESSES IT, AND FOR HOW LONG. The same processor as the app's product analytics: PostHog, Inc., acting as our processor, on its European cloud with servers in Frankfurt, Germany. See "Who we share data with" and "International transfers". Events are kept for one year by that provider and then removed.

WHAT THAT MEANS FOR DELETION, STATED PLAINLY. Because website analytics deliberately carries no visitor identifier, nothing ties an event to you. That is the point of it, and it is also a real limit we will not talk around: we cannot find your website events in order to delete them individually, and neither can you, because there is no identifier to look them up by. Withdrawing consent stops all further collection immediately; it does not remove events already collected, and those are deleted when the one-year period ends. The app's product analytics is different — a device identifier exists there and individual deletion is possible; see "Product analytics (optional)".

Separately from all of the above, our hosting provider may process standard technical request information such as IP addresses in order to serve the site, as any web host does. The website also publishes a short Cookie Policy that sets out the same facts in one place.

How long we keep data

Most of your data is kept until you delete it or delete your account. On top of that, these specific rules are implemented:

  • Accounts that are never verified — deleted 30 days after registration
  • Used or expired verification, password-reset and email-change records — deleted after 24 hours
  • Raw schedule-feedback text and stored voice transcripts, once the request has reached its final state — deleted after 30 days
  • Reflection summaries — deleted after 30 days, and invalidated immediately whenever the reflection data they were built from changes
  • Schedule revisions awaiting processing — deleted after 24 hours
  • Schedule revisions ready for your review but never acted on — deleted after 7 days
  • Failed schedule revisions — deleted after 30 days
  • Discarded or superseded schedule revisions — deleted after 60 days
  • Accepted schedule revisions — deleted 90 days after acceptance. The schedule itself is unaffected; only the processing record of how it was produced is removed.
  • Product-analytics events from the app, if you turned analytics on — kept for one year by our analytics provider, then removed. They are not linked to your account and are NOT deleted when you delete your account; see "Product analytics (optional)"
  • Website-analytics events, if you accepted website analytics — kept for one year by the same analytics provider, then removed. They carry no visitor identifier at all, so they cannot be deleted individually and are unaffected by deleting your account; see "The Laiffi website"
  • Age-confirmation and legal-acceptance records — kept while your account exists, as evidence of the agreement
  • Feature requests and problem reports — not stored in Laiffi's database at all; they live only in our support mailbox, on the schedule described in "Feature requests and problem reports"

Reflection entries have no fixed expiry. Completed and unfinished entries alike are kept until you delete your reflection data, withdraw your reflection consent, or delete your account — whichever comes first.

Alongside that: records that consent was given and later withdrawn are kept while your account exists, as evidence of that history; a to-do you created from a morning plan follows the ordinary to-do lifecycle and stays until you delete it or delete your account; and a reminder scheduled on your device stays there until it fires, until it is cancelled or rescheduled as your plan changes, or until you withdraw reflection consent, sign out or delete your account.

Reflection data is deleted when you withdraw consent or delete it, and everything is deleted when you delete your account.

Status of automated deletion

We want to be precise about the difference between a rule and a running job. The retention rules above are implemented in Laiffi's code and covered by automated tests.

A scheduled daily job reports what has become eligible for deletion under the rules above. Automatic deletion is not yet switched on; until it is, the deletions above are applied by us on review.

Deletion you trigger yourself — deleting an item, deleting your reflection data, withdrawing reflection consent, or deleting your account — is immediate and does not depend on any scheduled job.

Deleting your data and your account

You have two separate controls:

  • Delete your reflection data — in Settings, under Reflections. This permanently deletes your reflections, answers, notes, custom questions, insights and summaries, and keeps the rest of your account. Withdrawing reflection consent does the same deletion.
  • Delete your account — in Settings, under "Danger zone". This is immediate and permanent: it removes your account and profile, your tasks, routines, to-dos and checklists, your saved places and settings, your schedules, travel and execution history, your feedback and revisions, and your reflection data, and signs you out on every device.

Account deletion cannot be undone. How deletion propagates into hosting backups is covered under "Hosting, backups and server logs".

ONE THING ACCOUNT DELETION DOES NOT REACH: if you turned product analytics on, the events already collected are not deleted with your account. They are deliberately not linked to it, so there is nothing for the deletion to find. The account-deletion screen shows you the analytics identifier before you confirm — save it and send it to our support and privacy contact if you want those events deleted too. See "Product analytics (optional)".

Security

We take measures appropriate to a service of this size: encrypted connections (HTTPS) for all traffic, passwords stored only as salted hashes, verification and reset codes stored only as hashes and expiring quickly, session tokens that can be invalidated, access controls on the database, and logging written to avoid capturing your content.

To protect the service from abuse, our backend reads the IP address of each request and counts how many requests that address has recently made, so it can slow down or refuse floods of sign-in attempts, password resets, account look-ups and routing queries. That count is held in the server process's own memory, and it expires with each limit's time window or whenever the service restarts. We do not deliberately store it in Laiffi's database. Our basis for this is our legitimate interest in keeping Laiffi secure, reliable and available to everyone using it. Separately from this, our hosting provider may process request information such as IP addresses in order to run the platform, as any host does.

No online service can be perfectly secure, and we do not claim otherwise. If you believe you have found a security problem, please contact us at the address on the Data rights & support screen.

Your rights

Under EU/EEA law you have the right to:

  • access the personal data we hold about you
  • have inaccurate data corrected
  • have your data erased
  • restrict how we process your data
  • object to processing based on our legitimate interests
  • receive data you provided in a structured, commonly used, machine-readable form, and have it transmitted to another controller where technically feasible
  • withdraw consent at any time where processing is based on consent, without affecting processing already carried out

Exercising a right is free, and doing so does not degrade the service.

How to make a request

You can exercise many rights yourself in the app: view and edit your profile and content, delete your reflection data, withdraw reflection consent, and delete your account.

For anything else — including access and portability requests — email our support and privacy contact from the Data rights & support screen. During the beta these requests are handled manually rather than by a self-service export tool, and we may need to verify your identity before acting on one so that nobody else can obtain your data.

The app can export a schedule as a calendar (ICS) file. That is a convenience feature for your calendar, not a complete export of your account data — for a full copy, use the email route above.

We aim to respond without undue delay and in any case within the time limits set by data-protection law.

Complaints

If you believe we have not handled your data properly, please contact us first — we would rather fix it.

You also have the right to lodge a complaint with a supervisory authority, in the EU/EEA country where you live or work or where the issue occurred. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), whose website you can open from the Data rights & support screen.

Age requirement

Laiffi is intended for people aged 16 or older, and creating an account requires confirming that you are at least 16.

Laiffi is not directed at children under 16 and we do not knowingly collect their data. If you believe someone under 16 has created an account, contact us and we will delete it.

Changes to this policy

We may update this policy as Laiffi develops. The current version and date are shown at the top of this screen.

For material changes we will tell you in the app before they take effect, and where the change requires it we will ask you to review and accept the updated documents. Minor corrections that do not change how we handle your data may be made without a separate notice.

Contact

For privacy questions or to exercise your rights, use the Data rights & support screen, which includes a button to email our support and privacy contact. It is a single address covering support, privacy and data-rights requests, security reports and account-deletion help.

For privacy questions or to exercise your rights, contact support@laiffiapp.fi.