Back to Whole Life

Private alpha

Privacy and data use

Effective August 10, 2026. This notice describes the private founder alpha, what the app stores, what the AI and billing processors may receive, and what must be complete before real health-data testing expands beyond trusted testers.

Current testing boundary

Whole Life is currently a controlled founder alpha. The first test phase should use synthetic accounts and synthetic or low-sensitivity data only. Real medications, diagnoses, lab results, financial records, trauma details, identifiable room photos, and detailed health histories should stay out until the Level B gates are complete and verified.

External access should be limited to the founder and a few trusted testers until account deletion, export, user isolation, AI-context controls, and security tests have passed.

Data inventory

DataPurposeDefault storageAI use
Account email and profile nameSign-in, account display, recoverySupabase Auth and profileThe login display name is not automatically promoted into AI context. An optional preferred-name answer can enter AI context only after onboarding is submitted and Personal AI memory is enabled
Life profile, plans, tasks, timeline, and feedbackOperate Today, Review, backup, and correctionAccount snapshot plus typed, versioned profile facts with explicit missingness; guest data stays in the browserOnly current known facts allowed for the selected scope, with a context receipt
Ideas, notes about ideas, tags, and explicit idea linksCapture, organize, search, and develop the user's own workBrowser first, then owner-scoped Supabase idea and link rows for signed-in accountsOnly ideas individually enabled for Personal AI, and only while the global Personal AI setting is on; idea context is excluded from improvement and training
Home, Mind, and Money module stateRun each separate module and restore the correct signed-in accountExact owner-keyed browser copies and separate owner-scoped Supabase snapshots with Row Level SecurityRaw snapshots are technically marked ineligible and are not queried by Life AI. Only a dated item the user deliberately records in Life can enter a Life context packet
Food, hydration, activity, body check-ins, and Body preferencesHealth logging, source review, and descriptive pattern reviewOwner-keyed browser working copy plus account-scoped Body snapshotUsed only when the feature and personal-memory setting permit it, with uncertainty, source, serving basis, and user confirmation rules
Food, nutrition-label, and room photosUser-requested food candidate, portion-range, label-value, or visible room-condition reviewLocal preview first. The consent receipt stores a SHA-256 payload fingerprint, not image bytes, so the receipt cannot be reused for a different photo. The default is delete after analysis; keeping a food photo with a Body entry requires a separate user choice. Room source photos are not retained by the appSent only to Gemini after an account-scoped consent receipt. Gemini must return candidates or visible findings, confidence, unknowns, and retake questions. A photo result is not a durable fact until the user confirms or corrects it
Files the user explicitly keepsAttach a confirmed supporting photo, document, or audio file to an account recordPrivate Supabase bucket, limited to 15 MB per file and an owner-ID folder protected by RLS and enrolled MFA. Local-only references are not uploadedNot sent to AI unless a separate feature-specific preview and consent flow says exactly which provider will receive it
AI conversations and response feedbackProvide requested support, preserve conversation history, and accept correctionsAccount-scoped Supabase rowsOpenAI requests use store: false; app learning stays in Whole Life storage unless a separate consented fine-tune/evaluation pipeline is created
Product query, shopping priority, optional target price, optional broad shopping area, and grounded price resultUser-requested current price comparisonRecent comparison may remain in the Money browser store; the authenticated request passes through a Supabase Edge Function to Gemini Google Search groundingNo balances, safe-to-spend value, bills, Health, Mind, or full Life profile are sent. The result is a dated unverified market snapshot
Billing account and membership statusOpen secure checkout, apply promotion codes, manage a subscription, and determine paid-package accessStripe stores payment and billing details on its hosted pages. Whole Life stores only the account owner, Stripe customer/subscription/product/price identifiers, subscription state, entitlement, dates, and content-free webhook processing statusBilling data is not sent to OpenAI or Gemini and is not personal AI context or training data
Safety Vault and sealed notesUser-controlled private contextSafety Vault may be account-backed; sealed notes stay on the deviceSafety Vault only in Safety support; sealed notes never
Content-free reliability eventsFind broken authentication, sync, AI, export, deletion, photo, and navigation flowsOwner-scoped Supabase events containing route, action category, duration, release, status, and generic error code only; Cloudflare Web Analytics may provide aggregate page performance after deploymentNever used as personal AI context or training data

Processors and transfers

Whole Life does not sell health information, use it for targeted advertising, or provide raw health content to general analytics.

AI learning model

The app should learn in Whole Life-controlled storage, not by donating user records to model providers. Personal AI memory means the app can retrieve relevant records for the verified user and send the smallest useful context packet for that request. It does not mean OpenAI or Google may train their general models on the account.

App improvement and raw-content research permission are separate, voluntary controls. They are off by default and are not required for access, a trial, a coupon, or a lower price. Synthetic demo accounts are not eligible. Sensitive domains such as health, medication, labs, trauma, money, Safety Vault, sealed notes, and identifiable photos are excluded by default. No raw-content dataset may be used until a separate reviewed pipeline, withdrawal process, provenance record, and dataset-deletion process exist.

Alpha access gate

Before inviting trusted testers, the domain should be protected by Cloudflare Access or an equivalent allowlist so only approved emails can open the alpha. This is separate from Supabase sign-in: Cloudflare controls who can reach the app URL, while Supabase controls the user's account and rows inside the app.

Public routes that must remain reachable, such as provider callbacks or future webhooks, should be bypassed only by narrow path-specific rules.

Monitoring boundary

Monitoring is content-free during the alpha. The app event schema accepts only route, action category, duration, release version, status, and a generic error code. Cloudflare may separately receive ordinary aggregate website performance information after Web Analytics is enabled.

Monitoring should not collect prompts, AI replies, profile answers, meal names, symptoms, medications, photos, room contents, financial values, names of other people, or raw notes. Session replay, heatmaps, and network body capture should stay off unless a later privacy review explicitly approves a masked implementation.

Retention

User controls

In Privacy and data, users can review their profile, control Personal AI memory, keep app-improvement and raw-content research permissions off, record an access, correction, consent-withdrawal, or appeal request, create a full account export, restore their own backup, sign out, clear local guest data, clear all data while keeping the sign-in, and permanently delete a signed-in account.

Clear all account data removes owner-scoped module records, AI history, feedback, consent and privacy-request rows, registered files, and account snapshots while keeping the sign-in and membership, then verifies the deletion and records a reset generation. Each page checks that server reset marker before it can upload a browser copy, preventing an older open tab from restoring cleared data.

Account deletion removes registered cloud objects before the Auth identity, verifies that those objects no longer resolve, removes account-owned database rows through owner cascades, and verifies that account rows are gone. Before those deletion steps, it attempts to cancel active Stripe subscriptions and delete the Stripe customer profile so charging cannot become detached from the sign-in. A failed billing or deletion verification is reported rather than presented as success. Account deletion does not automatically issue a refund; cancellation and refund terms must be published and legally reviewed before live billing.

Account security

New-account passwords are checked in the app for at least 12 characters and three character classes. The hosted Supabase password minimum, leaked-password protection, and rate limits must also be configured and verified because browser checks can be bypassed.

The app includes optional authenticator-app enrollment and challenge flows. Once the MFA migration is deployed, restrictive database policies require an AAL2 session for any user who has a verified factor. Turnstile support is present but remains inactive until a public site key is configured in the frontend and its secret is enabled in Supabase.

Important limits

Whole Life is a wellness organization tool, not a medical service, emergency service, clinician, or continuous monitoring system. It does not diagnose or prove causation. A personal baseline does not establish that a health value is safe.

This notice is an engineering disclosure for the private alpha and still requires legal review before public launch. The in-app export and deletion controls are the current privacy-request path. A monitored external privacy contact must be added before invitations are sent to outside testers.