Privacy Policy
Privacy Policy
Life Altering Corp ("Company," "we," "our," or "us") operates the Taylor mobile application ("App") and website at lifealteringtaylor.com ("Site"). This Privacy Policy explains how we collect, use, and share your information.
1. Information We Collect
1.1 Information You Provide
- Account information: Name, email address, date of birth, gender
- Health profile: Height, weight, fitness goals, dietary preferences, medical conditions you choose to disclose
- User content: Workout logs, nutrition entries, conversation history within the App, feedback
- Beta registration: Email, name, access code (collected at beta signup)
1.2 Information Collected Automatically
- Usage data: Features used, session duration, interaction patterns
- Device information: Device model, iOS version, unique device identifiers
- Log data: App errors, crash reports, performance metrics
- Web analytics: Pages visited, referrer source, approximate country (via Plausible — see §4)
1.3 Health Data from Apple HealthKit
When you grant permission, the App reads the following HealthKit data categories:
- Activity: steps, active energy, exercise minutes, stand hours
- Heart rate and heart rate variability
- Sleep analysis
- Body measurements: weight, height, BMI
- Nutrition: dietary energy, macronutrients (where available)
- Workout records
You control which categories to share from iOS Settings → Privacy & Security → Health → Taylor. Granted permissions are revocable at any time.
2. How We Use Your Information
| Purpose | Legal basis |
|---|---|
| Provide and improve the AI coaching service | Contract performance |
| Personalize workout and nutrition recommendations | Contract performance |
| Send beta program communications | Consent |
| Respond to support requests | Legitimate interest |
| Analytics to improve the App | Legitimate interest |
| Comply with legal obligations | Legal obligation |
We do not sell your personal information. We do not use health data for advertising.
3. On-Device AI Processing
The Taylor AI coach runs inference locally on your device using Apple's MLX framework. Your health conversations and queries are processed on your iPhone without being transmitted to our servers for the primary inference path. Only anonymized feedback signals (where you opt in) may be used to improve model quality.
4. Third-Party Services
| Service | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Supabase | Database hosting (EU region) | Account + health profile data | supabase.com/privacy |
| Resend | Transactional email | Email address only | resend.com/privacy |
| Plausible Analytics | Privacy-first web analytics | No personal data; no cookies | plausible.io/privacy |
| Apple HealthKit | Health data source | No data sent to Apple beyond what iOS handles | apple.com/privacy |
We do not integrate with advertising networks, data brokers, or behavioral profiling services.
5. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of a verified deletion request.
- Health metrics: Retained for up to 2 years to power longitudinal coaching features. Deleted on account deletion.
- Chat history: Stored locally on device by default. Cloud backup is opt-in.
- Analytics events: Retained for 13 months (Plausible rolling window), then deleted.
- Beta registrations: Retained until the App Store launch, then migrated to production accounts or deleted.
6. Security
We protect your data with:
- Encryption at rest: AES-256 for all data stored in our database
- Encryption in transit: TLS 1.3 for all API communications
- Per-user encryption keys: Health data is encrypted with keys unique to your account
- Row-Level Security: Database policies ensure users can only access their own data
- No server-side AI inference: Sensitive health conversations never leave your device
7. Your Rights
Depending on your location, you may have the following rights:
All users
- Access a copy of your personal data
- Correct inaccurate information
- Delete your account and all associated data
- Withdraw consent at any time
EU / EEA residents (GDPR)
- Data portability (receive data in machine-readable format)
- Object to processing based on legitimate interest
- Lodge a complaint with your local supervisory authority
California residents (CCPA)
- Know what personal information is collected and how it is used
- Opt out of sale (we do not sell data)
- Non-discrimination for exercising your rights
To submit a deletion request or data access request, visit /legal/data-deletion or email privacy@lifealteringtaylor.com.
8. Children's Privacy
The App is intended for users 18 and older. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact privacy@lifealteringtaylor.com and we will delete it promptly.
9. Changes to This Policy
We will notify you of material changes via email and in-App notification at least 30 days before the change takes effect. Continued use after the effective date constitutes acceptance.
10. Contact
Life Altering Corp
Privacy inquiries: privacy@lifealteringtaylor.com
General: hello@lifealteringtaylor.com
Questions about this policy? Email privacy@lifealteringtaylor.com. For data deletion requests, visit /legal/data-deletion.