Private alpha
Privacy and data use
Effective August 10, 2026. This notice describes the private founder alpha, what the app stores, what the AI and billing processors may receive, and what must be complete before real health-data testing expands beyond trusted testers.
Current testing boundary
Whole Life is currently a controlled founder alpha. The first test phase should use synthetic accounts and synthetic or low-sensitivity data only. Real medications, diagnoses, lab results, financial records, trauma details, identifiable room photos, and detailed health histories should stay out until the Level B gates are complete and verified.
External access should be limited to the founder and a few trusted testers until account deletion, export, user isolation, AI-context controls, and security tests have passed.
Data inventory
| Data | Purpose | Default storage | AI use |
|---|---|---|---|
| Account email and profile name | Sign-in, account display, recovery | Supabase Auth and profile | The login display name is not automatically promoted into AI context. An optional preferred-name answer can enter AI context only after onboarding is submitted and Personal AI memory is enabled |
| Life profile, plans, tasks, timeline, and feedback | Operate Today, Review, backup, and correction | Account snapshot plus typed, versioned profile facts with explicit missingness; guest data stays in the browser | Only current known facts allowed for the selected scope, with a context receipt |
| Ideas, notes about ideas, tags, and explicit idea links | Capture, organize, search, and develop the user's own work | Browser first, then owner-scoped Supabase idea and link rows for signed-in accounts | Only ideas individually enabled for Personal AI, and only while the global Personal AI setting is on; idea context is excluded from improvement and training |
| Home, Mind, and Money module state | Run each separate module and restore the correct signed-in account | Exact owner-keyed browser copies and separate owner-scoped Supabase snapshots with Row Level Security | Raw snapshots are technically marked ineligible and are not queried by Life AI. Only a dated item the user deliberately records in Life can enter a Life context packet |
| Food, hydration, activity, body check-ins, and Body preferences | Health logging, source review, and descriptive pattern review | Owner-keyed browser working copy plus account-scoped Body snapshot | Used only when the feature and personal-memory setting permit it, with uncertainty, source, serving basis, and user confirmation rules |
| Food, nutrition-label, and room photos | User-requested food candidate, portion-range, label-value, or visible room-condition review | Local preview first. The consent receipt stores a SHA-256 payload fingerprint, not image bytes, so the receipt cannot be reused for a different photo. The default is delete after analysis; keeping a food photo with a Body entry requires a separate user choice. Room source photos are not retained by the app | Sent only to Gemini after an account-scoped consent receipt. Gemini must return candidates or visible findings, confidence, unknowns, and retake questions. A photo result is not a durable fact until the user confirms or corrects it |
| Files the user explicitly keeps | Attach a confirmed supporting photo, document, or audio file to an account record | Private Supabase bucket, limited to 15 MB per file and an owner-ID folder protected by RLS and enrolled MFA. Local-only references are not uploaded | Not sent to AI unless a separate feature-specific preview and consent flow says exactly which provider will receive it |
| AI conversations and response feedback | Provide requested support, preserve conversation history, and accept corrections | Account-scoped Supabase rows | OpenAI requests use store: false; app learning stays in Whole Life storage unless a separate consented fine-tune/evaluation pipeline is created |
| Product query, shopping priority, optional target price, optional broad shopping area, and grounded price result | User-requested current price comparison | Recent comparison may remain in the Money browser store; the authenticated request passes through a Supabase Edge Function to Gemini Google Search grounding | No balances, safe-to-spend value, bills, Health, Mind, or full Life profile are sent. The result is a dated unverified market snapshot |
| Billing account and membership status | Open secure checkout, apply promotion codes, manage a subscription, and determine paid-package access | Stripe stores payment and billing details on its hosted pages. Whole Life stores only the account owner, Stripe customer/subscription/product/price identifiers, subscription state, entitlement, dates, and content-free webhook processing status | Billing data is not sent to OpenAI or Gemini and is not personal AI context or training data |
| Safety Vault and sealed notes | User-controlled private context | Safety Vault may be account-backed; sealed notes stay on the device | Safety Vault only in Safety support; sealed notes never |
| Content-free reliability events | Find broken authentication, sync, AI, export, deletion, photo, and navigation flows | Owner-scoped Supabase events containing route, action category, duration, release, status, and generic error code only; Cloudflare Web Analytics may provide aggregate page performance after deployment | Never used as personal AI context or training data |
Processors and transfers
- Supabase: authentication, Postgres account records, Edge Functions, and registered storage files.
- Cloudflare: website hosting, HTTPS, caching, security controls, and performance telemetry.
- OpenAI: AI responses only after the server feature is enabled and the user submits a request. API requests are configured with
store: false. OpenAI business/API data sharing must remain disabled unless the founder explicitly changes it. - Google Gemini: optional paid API vision analysis for food labels, plate photos, or room photos, plus minimal product-only Google Search grounding for price comparison. Grounded shopping requests use
store: false, but Google states that Search grounding still stores the prompt, context, and output for 30 days and that this storage cannot be disabled. Whole Life therefore excludes raw financial and cross-module context from that route. - Stripe: hosted Checkout, promotion codes, subscription billing, and the hosted customer portal. Stripe receives the account email, a Whole Life account identifier, and billing or payment details the user enters directly on Stripe. Whole Life stores customer/subscription/product/price identifiers, signed subscription state, and entitlements. Whole Life never receives card, bank-account, or wallet credentials. Health, Mind, Productivity, Money, notes, photos, and AI conversations are not sent to Stripe. Billing remains in test mode until live launch is explicitly approved.
- Local application bundle: the pinned Supabase browser library is served from Whole Life's own release rather than a third-party client-library CDN.
Whole Life does not sell health information, use it for targeted advertising, or provide raw health content to general analytics.
AI learning model
The app should learn in Whole Life-controlled storage, not by donating user records to model providers. Personal AI memory means the app can retrieve relevant records for the verified user and send the smallest useful context packet for that request. It does not mean OpenAI or Google may train their general models on the account.
App improvement and raw-content research permission are separate, voluntary controls. They are off by default and are not required for access, a trial, a coupon, or a lower price. Synthetic demo accounts are not eligible. Sensitive domains such as health, medication, labs, trauma, money, Safety Vault, sealed notes, and identifiable photos are excluded by default. No raw-content dataset may be used until a separate reviewed pipeline, withdrawal process, provenance record, and dataset-deletion process exist.
Alpha access gate
Before inviting trusted testers, the domain should be protected by Cloudflare Access or an equivalent allowlist so only approved emails can open the alpha. This is separate from Supabase sign-in: Cloudflare controls who can reach the app URL, while Supabase controls the user's account and rows inside the app.
Public routes that must remain reachable, such as provider callbacks or future webhooks, should be bypassed only by narrow path-specific rules.
Monitoring boundary
Monitoring is content-free during the alpha. The app event schema accepts only route, action category, duration, release version, status, and a generic error code. Cloudflare may separately receive ordinary aggregate website performance information after Web Analytics is enabled.
Monitoring should not collect prompts, AI replies, profile answers, meal names, symptoms, medications, photos, room contents, financial values, names of other people, or raw notes. Session replay, heatmaps, and network body capture should stay off unless a later privacy review explicitly approves a masked implementation.
Retention
- Account records remain until the user deletes them, corrects them, or a feature-specific shorter period is implemented.
- AI context packets are marked with a two-hour expiry. Automated expiry cleanup must be verified before external beta.
- Content-free operational events are limited to 90 days. The hosted daily purge records only execution time, migration version, examined/removed counts, status, and a content-free error code.
- AI conversations and feedback remain until the user clears or deletes the account.
- Deleted ideas immediately lose their title, body, tags, and AI permission in cloud storage. A content-free tombstone remains to prevent an older device from restoring the deleted idea.
- Sealed notes remain only in the active browser until the user clears them or browser storage is removed.
- Source food and room photos are not persisted by the analysis function. The browser discards room previews after analysis; a food photo is kept with a Body entry only after a separate explicit choice. Registered cloud files remain private until the user removes them, their feature retention rule expires, or the account is deleted; deletion verifies each registered cloud object before deleting the Auth identity.
- Google Search grounding retains the product-search prompt, context, and output for 30 days under Google's current Gemini API terms even when optional interaction storage is disabled.
- Content-free Stripe webhook event identifiers, event types, modes, processing states, timestamps, and generic error codes are limited to 90 days. Webhook payloads are not stored by Whole Life.
- Membership records remain while the account or subscription exists and as needed to reconcile billing. Stripe may retain transaction records where legally or operationally required under its terms.
- Backups downloaded by the user are controlled by the user and are not removed when the online account is deleted.
User controls
In Privacy and data, users can review their profile, control Personal AI memory, keep app-improvement and raw-content research permissions off, record an access, correction, consent-withdrawal, or appeal request, create a full account export, restore their own backup, sign out, clear local guest data, clear all data while keeping the sign-in, and permanently delete a signed-in account.
Clear all account data removes owner-scoped module records, AI history, feedback, consent and privacy-request rows, registered files, and account snapshots while keeping the sign-in and membership, then verifies the deletion and records a reset generation. Each page checks that server reset marker before it can upload a browser copy, preventing an older open tab from restoring cleared data.
Account deletion removes registered cloud objects before the Auth identity, verifies that those objects no longer resolve, removes account-owned database rows through owner cascades, and verifies that account rows are gone. Before those deletion steps, it attempts to cancel active Stripe subscriptions and delete the Stripe customer profile so charging cannot become detached from the sign-in. A failed billing or deletion verification is reported rather than presented as success. Account deletion does not automatically issue a refund; cancellation and refund terms must be published and legally reviewed before live billing.
Account security
New-account passwords are checked in the app for at least 12 characters and three character classes. The hosted Supabase password minimum, leaked-password protection, and rate limits must also be configured and verified because browser checks can be bypassed.
The app includes optional authenticator-app enrollment and challenge flows. Once the MFA migration is deployed, restrictive database policies require an AAL2 session for any user who has a verified factor. Turnstile support is present but remains inactive until a public site key is configured in the frontend and its secret is enabled in Supabase.
Important limits
Whole Life is a wellness organization tool, not a medical service, emergency service, clinician, or continuous monitoring system. It does not diagnose or prove causation. A personal baseline does not establish that a health value is safe.
This notice is an engineering disclosure for the private alpha and still requires legal review before public launch. The in-app export and deletion controls are the current privacy-request path. A monitored external privacy contact must be added before invitations are sent to outside testers.