Privacy policy
Last updated 9 September 2026
mylifeplanner holds some of the most personal information there is — where your time goes, what you are trying to change, and what you spend. This policy describes what the software actually does with it, including the parts that are less flattering than a marketing page would put them.
1. Who is responsible for your data
The data controller is the operator trading as mylifeplanner, based in the United Kingdom. mylifeplanner is not a registered company — it is run by an individual. You are entitled to know the operator’s full legal name and address; email hello@mylifeplanner.co.uk and it will be given to you.
Contact for anything in this policy, including requests about your rights: hello@mylifeplanner.co.uk.
2. What we collect
Most of it comes from you, or from a service you chose to connect. During the private beta, an administrator can also provide the limited details needed to invite you before you have an account. We do not buy data, and we do not track you across the web.
- Account — your email address, display name, a hashed password, your plan, currency and week-start preference.
- Before you create an account — if an administrator invites you to the private beta, we hold the email address they entered, an optional suggested display name, the offered plan, seats and trial date, and delivery/expiry status. The invitation expires after seven days; a resend starts a fresh seven-day period.
- What you plan — tasks, goals, milestones, habits and their daily check-ins, time entries, and any notes or free text you write in them.
- Money — figures you enter (savings targets, salary, net-worth snapshots), and bank statements you import. See section 4.
- Health Connect, only if you opt in on Android — read-only daily step totals for the on-device seven-day chart. They remain on that phone and are not sent to our servers, included in Life Score, or shared through Mentor Mode.
- Connected accounts — if you connect Microsoft, Google, Todoist, Notion or HubSpot, we store access tokens (encrypted) plus the account name and email of that account, and we import the tasks or calendar events you have authorised.
- Sharing — Mentor Mode and Household records: who you shared with, what pages you shared, and a log of when a mentor viewed your data.
- Security — session records, password-reset tokens, and a rate-limiting record derived from your IP address and email to slow down brute-force attempts.
- Faults — if the app fails to render or load, it records the error type and which surface you were on. Only three specific error types are accepted; there is no general analytics.
3. Why, and our lawful basis
- To provide the service — performance of our contract with you. This covers your account and everything you put in it.
- To keep accounts secure — legitimate interests: rate limiting, session management, and admin audit records.
- To administer the invite-only beta — legitimate interests: sending an account invitation requested by an administrator, preventing duplicate or reused invitations, and briefly investigating delivery or abuse. The short retention described in section 8 limits the impact on people who do not join.
- To connect other services — consent, given per connector when you authorise it, and withdrawable by disconnecting.
- To send reminders and notifications — consent, withdrawable in Notifications.
- To show Android Health Connect steps on your device — explicit consent, withdrawable in the app or Android settings. The step totals are read locally and are not uploaded to us.
- To send service email — performance of contract for password resets and mentor invitations you trigger; legitimate interests for administrator-created private-beta account invitations sent before an account exists.
We do not sell your data. We do not use it to train machine-learning models. We do not profile you for advertising.
4. The finance vault — stated plainly
Note also that some financial figures live outside the vault in ordinary (unencrypted) database fields: net-worth snapshots you log manually, and any transactions imported through the legacy Google Sheets connector.
5. Health and other sensitive data
The installed Android app can optionally read step totals only from Android Health Connect. Before Android shows its permission screen, the app explains the purpose and asks you to make an explicit choice. If you continue, a seven-day chart is calculated and displayed locally on that device. Those totals are not uploaded to mylifeplanner, written to our database, included in Life Score, or disclosed to a mentor. Disconnecting in mylifeplanner clears its local connection preference; you can also review or revoke the operating-system permission in Android settings.
A separate server-based Google Health connector remains unavailable because its provider registration is not complete. If it is ever enabled, it will require a new, separate consent flow and this policy will be updated before any server processing begins. Health information is special category data under UK GDPR, so we will not silently expand the Android permission or reuse its data for another purpose.
Separately, please be aware that free-text fields — a habit called “therapy”, a goal explaining why it matters, a calendar event, a pharmacy on a bank statement — can reveal health, beliefs or other sensitive matters. We do not analyse those fields for sensitive content, but they are stored like any other content you enter. Write what you are comfortable storing.
6. Who else processes your data
Always, as infrastructure:
- Cloudflare — hosting, database and file storage. All data sent to mylifeplanner’s servers passes through Cloudflare; the local-only Health Connect step totals described above are not sent there.
- Resend — sends password-reset, mentor-invitation and administrator-created private-beta account-invitation emails. It receives the recipient address and the message; the account invitation contains a single-use link.
- Stripe — if and when paid subscriptions begin. Card details go directly to Stripe and never reach our servers.
- Push delivery services (including Google Firebase Cloud Messaging and browser/platform push services) — only if you enable the relevant notifications. They receive the device or browser token, a reduced notification title and message, and limited routing identifiers needed to deliver it. We deliberately keep financial figures and full planner records out of that copy.
- Expo — delivers updates to the legacy mobile beta client. It receives app version and device platform, not your planner content. The new Capacitor Android beta does not currently use over-the-air updates.
Only if you connect them: Microsoft, Google, Todoist, Notion, HubSpot. Data flows both ways — we import what you authorise, and changes you make here can be written back. Those services run under their own privacy policies.
7. Where your data is stored
Your database and uploaded files are stored in Cloudflare’s Western Europe region. To be precise rather than reassuring: that is where Cloudflare currently places the data, not a contractual residency guarantee we have purchased. Cloudflare also processes requests at edge locations worldwide, so data is handled outside the UK and EEA in transit. Those transfers rely on Cloudflare’s data processing addendum, Standard Contractual Clauses and the UK International Data Transfer Addendum. Google, Stripe and Expo are US-based and rely on the same safeguards.
8. How long we keep it
Your planner and account content generally stays for as long as your account exists, until you delete it. A scheduled automated cleanup does remove short-lived records after they can no longer serve their purpose: used or expired password-reset tokens, expired connector authorisation state, stale sign-in rate-limit rows, expired sessions, and notification events after their stated expiry.
Administrator-created account invitations have a shorter lifecycle. A pending invitation keeps the prospective user’s email address and optional suggested name only while its single-use link can work — up to seven days, or until it is accepted or revoked. On the next scheduled cleanup (normally within five minutes), terminal invitations have the email, name and accepted-account link replaced with redacted values. We keep the remaining non-identifying plan, delivery result and timestamps for up to 30 days so we can investigate invitation delivery or abuse during the private beta, then delete that invitation row. Admin audit records retain the action and random invitation ID, but not the invitee’s email address.
Deleting your account (You → Danger zone, type your email to confirm) permanently removes your account and content, including uploaded statement files. Two caveats:
- Admin audit records may retain your user identifier where we need them to show what administrative actions were taken and by whom.
- If you have ever paid, Stripe keeps its own transaction records for financial and tax compliance, typically around seven years. That is Stripe’s obligation, and outside our control.
You can request a comprehensive export at any time from You → Data & exports, without deleting anything. The file says if a very large collection reached the self-service safety cap; contact support for the remainder.
9. Your rights
Under UK GDPR you can ask us to:
- give you a copy of your data (there is a self-service export, and you can also just ask);
- correct anything inaccurate;
- delete your data (self-service, or ask);
- restrict or object to how we use it;
- provide it in a portable format — the export is machine-readable JSON;
- withdraw consent, for anything based on consent, at any time.
Email hello@mylifeplanner.co.uk. We will respond within one month. If you are unhappy with how we handle it, you can complain to the Information Commissioner’s Office at ico.org.uk — but we would rather you told us first so we can put it right.
10. Security
- Passwords are hashed with PBKDF2 and a per-user salt. We never store or see your password.
- Sessions use HttpOnly, Secure cookies on the web and secure device storage on mobile. Only a hash of the session token is stored.
- Access tokens for connected services are encrypted before storage.
- You can see every signed-in session and end any of them individually from You → Security.
No system is perfectly secure, and this one is in beta. If a breach affects your rights, we will tell the ICO within 72 hours and tell you without undue delay. If you find a security problem, please report it to hello@mylifeplanner.co.uk — you will get a straight answer and credit if you want it.
11. Cookies and local storage
One cookie: mlp_session, which keeps you signed in for 30 days. It is strictly necessary, so there is no consent banner — there is nothing to consent to. We use no advertising, analytics or tracking cookies of any kind.
Your browser also stores some things locally: interface preferences, which announcement you have dismissed, and — if you use Money — a copy of your vault key so the browser can decrypt your statements. That key copy stays on the device. Clear your browser storage to remove it.
12. Children
We do not set a minimum age during this beta, and we do not ask for your date of birth — so we hold no age information about anyone. The product is built and written for adults running their own lives and households, and it is not designed for or marketed to children.
Note that Household plans give each member their own separate account, so a parent cannot see inside a family member’s private plans, and a family member cannot see inside the parent’s. If you are a parent or guardian and would like an account belonging to your child removed, email hello@mylifeplanner.co.uk and we will delete it.
13. Changes
If we change this policy in a way that materially affects you, we will tell you in the app or by email before it takes effect. The date at the top always shows the current version.
