Legal
Privacy Policy
This policy explains how LifeByDesign collects, uses, and protects your personal information. It is written to comply with the Protection of Personal Information Act, 2013 (POPIA) of South Africa, and to extend equivalent protections to international users under the EU/UK GDPR and similar frameworks.
Last updated: 23 June 2026
Who we are
LifeByDesign (the "Service", "we", "us") is operated by DevelopPrecision, the responsible party / data controller for personal information processed through this Service.
Information Officer / Privacy contact:
DevelopPrecision
The Cliffs, Niagara Road, TygerFalls, Bellville, South Africa
Phone: +27 61 455 2149
Scope
This policy applies to personal information collected through the LifeByDesign website, web application, and related services, regardless of where you access them from. If you are located in the European Economic Area, the United Kingdom, California, or another jurisdiction with comparable privacy laws, additional rights described in this policy apply to you.
Information we collect
- Account basics — your name, email address, password hash, and authentication-provider identifiers when you sign up or sign in.
- Life-design content — the goals, vision statements, journal entries, habits, health inputs, and financial figures you choose to enter. This content can be sensitive; we treat it accordingly.
- Payment information — when you subscribe, our payments processor (Stripe) collects card data directly. We receive only a customer identifier, the last four digits of the card, and billing metadata.
- Analytics and device data — pages visited, feature usage, IP address, browser/user-agent, approximate location derived from IP, and cookie identifiers, collected via PostHog and similar tools.
How we use it
- To provide the Service: authenticate you, store your content, generate AI insights, deliver subscription features.
- To process payments and prevent fraud.
- To improve product quality, reliability, and security via aggregated analytics.
- To communicate with you about your account, transactional notices, and (with consent) product updates.
- To comply with legal obligations and enforce our terms.
We do not sell your personal information. We do not use your private life-design content to train third-party general-purpose AI models.
Legal basis for processing
Where GDPR or equivalent laws apply, we rely on:
- Contract — to deliver the Service you signed up for.
- Legitimate interests — to secure, improve, and analyse the Service in ways you would reasonably expect.
- Consent — for non-essential cookies, marketing emails, and any optional sensitive-data features.
- Legal obligation — to meet tax, accounting, and regulatory duties.
Under POPIA, we process personal information on the equivalent grounds set out in section 11 of the Act (consent, contract performance, legal obligation, protection of a legitimate interest, public-law duty, or our or a third party's legitimate interest).
Subprocessors we rely on
We use carefully selected third parties ("operators" under POPIA, "processors" under GDPR) to run the Service. Each is bound by contractual confidentiality and security obligations.
- Lovable Cloud (Supabase) — database hosting, authentication, and file storage.
- Lovable AI Gateway / OpenAI — AI-generated suggestions, summaries, and coaching. Prompts you submit may be sent to these providers for processing.
- Stripe — payment processing and subscription billing.
- PostHog — product analytics and feature-usage telemetry.
A current list is available on request from the contact address above.
International data transfers
LifeByDesign serves users worldwide and the subprocessors above operate in jurisdictions including the European Union, the United Kingdom, and the United States. When we transfer personal information out of South Africa, we do so in line with section 72 of POPIA, relying on (i) the data importer being subject to laws, binding corporate rules, or binding agreements providing an adequate level of protection; (ii) your consent; or (iii) the transfer being necessary for the performance of our contract with you.
For transfers out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) or another lawful transfer mechanism made available by the importer.
How long we keep your data
- Account and life-design content: while your account is active, and for up to 30 days after deletion to allow recovery from accidental deletion.
- Billing records: for the period required by South African tax and accounting law (typically five years).
- Security and audit logs: up to 12 months.
- Backups: rotated out within 35 days of deletion from primary systems.
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption of credentials at rest, row-level access controls in our database, scoped service credentials, and access logging. No system is perfectly secure; we encourage strong, unique passwords and prompt reporting of any suspicious activity.
Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your account and associated personal information.
- Object to or restrict certain processing, and withdraw consent where consent is the legal basis.
- Receive a portable copy of the information you have provided.
- Lodge a complaint with the South African Information Regulator (inforegulator.org.za), or, if you are in the EEA/UK, with your local supervisory authority.
To exercise these rights, contact the Information Officer at the address in section 1. We will respond within the timeframes required by applicable law.
Children
LifeByDesign is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided information to us, please contact us so we can delete it.
Changes to this policy
We may update this policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you in the Service or by email before the changes take effect.
Contact us
Questions, requests, or complaints about this policy or our handling of your personal information:
DevelopPrecision — Information Officer
The Cliffs, Niagara Road, TygerFalls, Bellville, South Africa
Phone: +27 61 455 2149