Privacy Policy
Effective date: May 28, 2026
Gamified Lives ("we", "us", or "our") operates the Gamified Lives mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the App.
1. Information We Collect
Information you provide directly:
- Account information: When you sign in with Apple or Google, we receive your name and email address (or a relay email if you use Apple's Hide My Email).
- Profile information: Your chosen display name, gender selection, date of birth (for age verification), and avatar preferences.
- Photos: If you choose to upload a selfie for avatar creation or use photo verification for tasks, those images are processed by our AI services for avatar creation and verification, and are not stored on our servers after processing.
- Body progress photos (optional): If you choose to take monthly progress photos, they are stored privately in our Supabase Storage. Only you can access them via short-lived signed URLs. Photos never leave the device unless you explicitly enable cloud sync.
- Goals, habits, and tasks: The content you create within the App to track your personal development.
- Life domain entries (optional): If you choose to log entries for Finance, Sleep, Mind, Learning, or Recovery domains, the data stays on your device by default. You may opt in to cloud sync, in which case the entries are stored in our Supabase backend.
- Food and macro data (optional): Meal logs, calorie / macro entries, and meal photos are stored locally by default. You may opt in to cloud sync. Meal photos sent for AI macro estimation are processed and discarded — not retained on our servers.
- Body tracking data (optional): Weight entries are stored locally by default. You may opt in to cloud sync, in which case weight history is stored in our Supabase backend.
- Chat messages: Messages sent to the AI Advisor are processed by our AI services and are not stored beyond the active session.
- Voice conversation audio: When you initiate an Avatar Call (premium voice feature), short audio clips of your speech are transmitted to our transcription provider for real-time speech-to-text. See Section 7 for details.
HealthKit data (Apple Health):
If you grant permission, Gamified Lives reads the following metrics from Apple Health solely to auto-verify your daily habit completion:
- Step count
- Exercise / workout minutes
- Mindful minutes
- Sleep hours
- Active energy (calories burned)
HealthKit data is read on-device only and is never transmitted to our servers, used for advertising, or shared with third parties. You can revoke HealthKit access at any time via iOS Settings → Health → Data Access & Devices.
Information collected automatically:
- Usage analytics: We use Amplitude to collect anonymized usage data such as feature interactions, session duration, and app events. This data is not linked to your identity.
- Crash reports: We use Sentry to collect crash reports and error logs to improve app stability. These may include device model, OS version, and stack traces.
- Device information: Device type, operating system version, and app version for compatibility and debugging.
- Push notification tokens: When you opt in to notifications, we store an Apple push token on our backend so we can deliver in-app event notifications (such as incoming Avatar Calls).
Information we do NOT collect:
- Location data (GPS, IP-based, or otherwise)
- Contacts or address book
- Browsing history outside the App
- Advertising identifiers (IDFA)
- HealthKit data beyond the five activity metrics listed above
2. How We Use Your Information
- To provide and maintain the App's features, including AI-powered avatar generation, task verification, coaching, and weekly reports.
- To personalize your experience (adaptive difficulty, AI coaching context).
- To process in-app purchases and manage your subscription status via RevenueCat.
- To send push notifications you have opted into (task reminders, streak alerts, squad nudges).
- To analyze usage patterns and improve the App (via anonymized Amplitude analytics).
- To diagnose and fix bugs (via Sentry crash reporting).
3. Data Storage
Your game state (XP, level, streak, goals, habits, tasks, cosmetics, and avatar) is stored locally on your device using AsyncStorage. If you sign in, core profile data is synced to our Supabase backend for cross-device access, squad features, and account recovery.
Photos uploaded for avatar creation or task verification are sent to third-party AI services for processing and are not retained on our servers after the response is generated.
Body progress photos (when used) are stored in our private Supabase Storage bucket scoped to your user account. Access is enforced by per-user row-level security and short-lived signed URLs (60-second TTL). Photos are never indexed, shared, or used for any purpose other than displaying them back to you in the App.
Life-domain data (Finance, Sleep, Mind, Learning, Recovery), food / macro logs, and body weight entries default to local-only. They are uploaded to our Supabase backend only if you explicitly enable the corresponding cloud-sync toggle in the App.
4. Third-Party Services
We use the following third-party services that may process your data according to their own privacy policies:
- Supabase: Backend database, authentication, file storage, and edge functions. Privacy Policy
- Anthropic (Claude): Powers the AI Coach, weekly reports, daily quests, habit clarification, and structured photo analysis (food macros, workout stats, etc.). Receives your chat messages, mood and journal entries, and your goal/habit summaries when you use AI Coach features. Audio and text content sent for processing is governed by Anthropic's privacy policy. Anthropic does not train models on data sent via its API.
- OpenAI: Powers avatar image generation and voice synthesis for Avatar Calls. Receives your selfie when generating your avatar and short text when generating your coach's voice for AI calls. Governed by OpenAI's privacy policy. OpenAI does not train models on data sent via its API.
- Deepgram: Real-time speech-to-text transcription during Avatar Calls. Receives your voice recordings to transcribe what you said. Audio is processed in transit and discarded; no recordings are retained. Privacy Policy
- RevenueCat: Subscription and in-app purchase management. Privacy Policy
- Amplitude: Anonymized usage analytics. Privacy Policy
- Sentry: Crash reporting and error tracking. Privacy Policy
- Apple / Google: Authentication via Sign in with Apple / Google Sign-In, and Apple HealthKit for on-device activity reads.
Your consent & controls for AI services
The first time you use a feature that sends data to one of our AI providers (Anthropic, OpenAI, or Deepgram) — whether that is AI Coach chat, photo verification, smart-import, avatar generation, voice calls, or any of our domain AI tools — the App displays a consent screen that:
- Lists each third-party AI service by name and what data each receives.
- Lists every feature that will be disabled if you decline.
- Requires you to explicitly tap "I agree — enable AI features" before any data leaves your device.
If you decline, all AI-powered features remain disabled and no data is sent to any of these providers. You can review or change this decision at any time in Settings → AI & Data Sharing. Disabling AI sharing immediately blocks all further calls to Anthropic, OpenAI, and Deepgram — the rest of the App (habits, goals, tasks, XP, streaks, cosmetics, friends, squads, leaderboards, and analytics) continues to work normally.
We confirm that each AI provider listed above contractually commits to data protections substantially equivalent to those described in this policy. None of these providers train their underlying models on data sent via their commercial APIs, and none retain raw inputs beyond what is required for the specific request.
5. Data Sharing
We do not sell, rent, or trade your personal information to third parties. We share data only as described in this policy (with the third-party services listed above) and as required by law.
If you join a squad, your display name, level, streak, and daily task count are visible to other squad members.
6. Push Notifications
You may opt in to push notifications for task reminders, streak alerts, and squad activity. You can disable notifications at any time through your device settings. All notification content is generated locally using templates — no personal data is transmitted for notification purposes.
7. Voice Conversations (Avatar Calls)
Gamified Lives offers AI-powered voice conversations ("Avatar Calls") as a premium feature. During these calls:
- Your microphone is used only while you hold the on-screen "Hold to Speak" button. Audio is not recorded otherwise.
- Each captured audio clip is sent to Deepgram for speech-to-text transcription. Deepgram processes the audio in-flight and does not retain recordings.
- The transcribed text is sent to Anthropic to generate the avatar's reply. The reply text is sent to OpenAI to synthesize the spoken audio you hear back.
- No raw audio recordings are ever stored on our servers or by any third-party.
- A short text summary of each call (one to two sentences) is retained in your account history so you can review past conversations.
- You can delete all call summaries at any time through the App's Settings, or delete your account entirely to remove all call data.
You must explicitly opt in to Avatar Calls in the App's Settings before any voice data is collected. You can revoke microphone permission at any time via iOS Settings → Gamified Lives → Microphone.
8. Children's Privacy
The App is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will delete it.
9. Data Retention and Deletion
Local data is stored on your device and can be deleted by uninstalling the App. If you have synced data to our backend, you can request deletion of your account and all associated data by using the "Delete Account" option in the App's settings, or by contacting us at the email below. We will process deletion requests within 30 days.
10. Security
We implement reasonable security measures to protect your data. API keys for AI services are stored server-side and are never included in the app bundle. All network communication uses HTTPS encryption.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Opt out of analytics tracking
- Export your data in a portable format
To exercise any of these rights, contact us at [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy in the App or on our website. Your continued use of the App after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy, contact us at: