Life

Privacy Policy

The same policy as the page next door, in the words that survive being quoted. Twelve clauses, and nothing in them that the app doesn't do.

The document

What this is, and who it binds.

Document
Privacy Policy
Applies to
The Life web app at life.rasoi.io, and nothing else.
Operator
rasoi labs, a small team based in India.
Effective
9 August 2026
Contact
contact@rasoi.io

Read it against the plain-words version rather than instead of it: neither is a summary of the other, and where a clause here looks heavier than the promise there, it is the same fact written so that it can be relied on.

Clauses 1–6

What is collected, why, and who else sees it.

  1. 1.Who this is, and how to reach us

    Life is a personal weekly log at life.rasoi.io. It is built and run by rasoi labs, a small team based in India. rasoi labs is the data fiduciary for your personal data under India's Digital Personal Data Protection Act, 2023, and the controller of it for readers to whom the UK or EU GDPR applies. Every question, request and complaint goes to contact@rasoi.io, which reaches us and nobody else.

  2. 2.What the app collects

    Six things, and this is the whole of it:

    • Your account — the name, email address, profile picture address and account identifier Google returns when you sign in. Nothing else is asked for, and no password ever reaches this server. A guest account carries none of this: it has no identity on it at all.
    • What you write — your weeks and everything in them, your goals, chapters, life stages, achievements, letters to your future self, and everything you set up: pillars, habits, prompts, day blocks, your date of birth, the life expectancy you picked, and the words you put under vision, mission, values, aspirations and affirmations.
    • What you publish — anything you post to the requests board: the request itself, your votes on other people's, and your replies, each carrying the first word of the name on your account. It is separated from the line above because it is the only thing in this app that is shown to other users, and because it is the only thing that survives the account being deleted, without a name on it.
    • Connections you choose to make — an access token for a calendar or task list you link, or for the Google Drive the nightly backup writes to, each held encrypted; the address of any calendar feed you paste; a notification subscription if you turn reminders on; and the place name and coordinates you pick for weather.
    • What you ask Life AI, and what it answered — kept so the conversation reads as one, and deleted whenever you press Clear on that screen. Separated from the line above because it is the only writing in this app that leaves it (clause 4), and because it is the only thing here you can erase without erasing the account.
    • Records the service keeps for itself — a signed session cookie, server logs, a record of sign-in attempts, a copy of every email the app sends you, and counts of which features an account uses. Where the screen counting described in clause 4 is running, it separately records which screens were opened, with no account identifier attached to it.

    The app asks for no payment details, no phone number, no contacts, no device location and no advertising identifier, and it has no way to collect any of them. A free-text field will hold whatever you type into it, including things the law treats as sensitive; write in them as you would in a private notebook.

  3. 3.Why it is processed, and on what basis

    Your account and what you write are processed to provide the app you asked for — necessary for performance of the agreement between us, and a legitimate use under section 7 of the DPDP Act. Optional connections, notifications and Life AI are processed on your consent, given by switching each of them on and withdrawn by switching it off. Screen counting carries no account identifier and no IP address, so it identifies nobody: it is aggregate audience measurement on our own server rather than processing about you, which is why there is no switch for it. Server logs and the record of sign-in attempts are kept in the legitimate interest of keeping accounts safe, and to meet a legal obligation where one applies. None of it is processed for advertising, profiling, or any automated decision that produces a legal or similarly significant effect on you. Life AI is a model answering a question you asked and decides nothing: it cannot change a word of your log, and no part of the app reads what it said.

  4. 4.Who it is given to

    It is never sold, never rented, never exchanged, and never used to build an advertising profile. Nothing you write is used to train any model, by us or by anybody else — a narrower promise than “no model ever sees it”, and the difference is the Anthropic line below. It is disclosed only to the services below, only to the extent named, and — for the ones marked optional — only if you have brought them into play:

    • Google, on every page — sign-in, which sees your name, email address and profile picture; its font server, which sees your IP address and nothing else; and its image server, which serves your profile picture and is sent no referrer, so it is not told which screen you were on.
    • Google Calendar (optional) — read-only access to the calendars you pick, if you link one. Revoke it in your Google account or in Settings.
    • Google Tasks (optional) — read-only access to the task lists you pick, if you link it. A separate permission from Google Calendar above, granted and revoked on its own.
    • Todoist (optional) — read-only access to your tasks, if you link it.
    • Google Drive (optional) — permission to create files, if you turn on the nightly backup. It is the narrowest permission Google offers for this: the app can see only the files it created itself, never the rest of your Drive. What it writes is a copy of your own log, into your own account, and it deletes nothing. A separate permission from the two above, granted and revoked on its own.
    • Any calendar feed whose address you paste (optional) — the app fetches it as a browser opening that address would.
    • Open-Meteo (optional) — the coordinates of the place you picked, for the forecast, the air reading and the daylight times. Nothing identifying the account goes with it.
    • Anthropic (optional) — if you switch Life AI on and ask it something, your question and a summary of your own log go to its Claude API so there is something to answer from: your recent weeks, habits, goals, pillars and day blocks, in your own words. Your name, email address and account identifier do not, and nothing from any other account does. It is processed to answer you and is not used to train any model. Switch the feature off and nothing is sent; an account that never opens the screen has never sent anything.
    • Our mail provider — the mailbox this app sends from, used for letters you scheduled to yourself, and for anything you send through the feedback form. It is our own mailbox, not a marketing service, and no address is added to any list.
    • The push service your browser belongs to — Google's, Mozilla's or Apple's — if and only if you turn reminders on. It is handed a notification addressed to your device and encrypted so that it cannot read what is in it.
    • The screen counting, where it is running, is not in this list on purpose: it is software running on the same server as the app, so no third party receives it. It sets no cookies, stores no IP address and attaches no account identifier, and the numbers do not leave that machine.

    Separately from that list: anything you post to the requests board is shown to every other person signed in to this app, under the first word of the name on your account. That is not a disclosure to a service, it is publication, and it happens only for what you type into that one screen — which says so above the box. Your email address is never shown there.

    Beyond these, your data is disclosed only where the law compels it, and you will be told when that happens unless we are forbidden from telling you.

  5. 5.Where it is kept, and how it is protected

    Everything is stored in one database on a single rented server. That database is not reachable from the internet; traffic between your browser and the server is encrypted in transit; every record carries the account it belongs to and every query is filtered by that account, including lookups by identifier; and the tokens for any service you have linked are separately encrypted at rest under a key held apart from the database. The people who can reach the machine are the ones who run it.

  6. 6.Transfers outside India

    The server, and the services named in clause 4, may be located outside India, so providing the app involves transferring your data there. None of the countries concerned has been restricted by the Central Government under section 16 of the DPDP Act. For readers under the UK or EU GDPR, transfers rest on the receiving providers' own standard contractual clauses and on the protections described in clause 5.

Clauses 7–12

How long it lasts, and what you can make us do.

  1. 7.How long it is kept

    • What you write — until you delete it. There is no expiry and no quiet clear-out. Deleting the account from Settings → Your data is immediate and cannot be undone.
    • A guest account — deleted 30 days after it was last used, along with everything written into it.
    • The session cookie — 30 days, then you sign in again.
    • Feature-usage counts — 180 days, after which they delete themselves.
    • Backups — the database is backed up every hour, kept on a rotation of 120 hourly, 7 daily, 4 weekly and 6 monthly copies, and every run is also copied off the machine, encrypted. An account deleted today can therefore still sit inside a backup for up to about six months before the last copy holding it is pruned. Nothing reads a backup except a restore.
    • The record of sign-in attempts — kept, and kept where the app has no credentials to reach it. That is what makes it a security log rather than a convenience. It is named here rather than left out, because a promise with a quiet hole in it is worse than a smaller promise.
    • What you posted to the requests board — kept after the account goes, with the name and the account identifier removed from it, and with your votes deleted. It is the third of the things deleting your account does not remove, and the reason is other people: a request that nine of them voted on and replied to is their work as much as yours.
    • Mail we have sent you — a copy of every email this app posts, including the full text of a letter you wrote to your future self, kept so we can tell what was sent, to whom, and whether it arrived. It is the last of the things deleting your account does not remove, and it is the reason the line under a delivered letter says only that nothing is expected back, rather than that nobody else has read it.
  2. 8.Your rights

    You may, at any time: see everything held about you; correct or complete any of it; take a copy of it; erase all of it; and withdraw consent for any optional connection or notification. Most of these are buttons rather than requests — Settings → Your data counts what the account holds, exports it as a single file, and deletes the account outright — and you never have to ask permission to use them. Where you would rather ask a person, ask, and it will be done within 30 days.

    Under the DPDP Act you may also nominate somebody to exercise these rights on your behalf if you die or become unable to; write to us to do that. If the UK or EU GDPR applies to you, you additionally have the rights of access, rectification, erasure, restriction, portability and objection, and you may complain to your supervisory authority. If you are in California: your personal information is not sold, and is not shared for cross-context behavioural advertising — and never has been.

  3. 9.Children

    The app is not intended for anyone under 18, and an account should not be created by one. It is not marketed to children and collects nothing to identify a reader's age. If you believe a child holds an account here, write to contact@rasoi.io and it will be removed.

  4. 10.Security, and what happens if it fails

    The measures in clause 5 are the ones actually in place rather than a statement of intent. No system is beyond failure. If a breach affects your data you will be told directly, at the address on your account, and the Data Protection Board of India — together with any other regulator with a claim on it — will be notified as required.

  5. 11.Changes to this policy

    This page changes when the app changes; the effective date at the top moves with it. A change that alters what happens to data already held will be said inside the app rather than only here, and the plain-words version of this page is rewritten in the same commit, so the two cannot come to say different things.

  6. 12.Complaints

    Write to contact@rasoi.io. The individual named in clause 1 is also the grievance officer for the purposes of the DPDP Act, and every message gets a reply from a person within 30 days. If that answer does not satisfy you, you may complain to the Data Protection Board of India — or, if you are in the UK or EU, to your own supervisory authority.

Something here unclear, or something you want done? Write to contact@rasoi.io — a person reads it, and it is one of the people who wrote this page.