Privacy Policy
Last updated: July 2, 2026 · Early private beta
- Your documents are private and encrypted — you decide who sees them.
- AI only analyzes a document when you ask it to. Nothing is saved until you confirm.
- We don't sell your data, and your documents are never used to train AI models.
- You can export or delete your documents — or your whole account — at any time.
This Privacy Policy explains what information LifeFolder collects, how we use it, and the choices you have. It applies to the LifeFolder app and website. LifeFolder is an early private beta, so this policy will evolve — we'll keep it honest and plain-spoken.
1. Who we are
LifeFolder ("LifeFolder", "we", "us") is operated by Tuk Tuk Labs, [registered address]. For any privacy question or request, contact us at hello@lifefolder.app. Full provider details are in our Legal Notice.
2. Information we collect
- Account information — your name, email address, and a securely hashed password (or the identifier from a Google sign-in).
- Documents you upload — the files you add and the information inside them (for example a passport, an insurance policy, a contract).
- Details extracted from documents — when you ask LifeFolder to analyze a file, details such as document type, names, and expiry dates so we can organize and remind you.
- People & household data — family members or others you add so you can organize documents by person.
- Usage & device data — basic logs such as IP address, browser type, and actions in the app, used to keep the service secure and working.
3. How we use your information
- To provide the service — store, organize, and let you find your documents.
- To analyze a document and suggest details — only when you ask us to.
- To remind you about expiring documents and missing items.
- To keep accounts secure and prevent abuse.
- To provide support and respond to your requests.
- To meet legal obligations that apply to us.
We do not sell your personal information, and we do not use your documents for advertising.
4. AI processing
Some features use artificial intelligence to read a document and pull out useful details, or to answer questions about your own files. This only happens when you take an action — for example uploading a file for review or asking a question. AI suggestions are shown to you and are not saved until you confirm them.
To do this, the relevant document content is sent securely to our AI provider, Anthropic, which processes it through its API to return a result. Anthropic does not use data submitted through its API to train its models. AI answers about your documents are scoped to your own files.
5. Legal bases (for EEA / UK users)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to give you the service you signed up for), legitimate interests (to secure and improve the service), consent (for anything optional, which you can withdraw), and legal obligation where the law requires it. [Confirm bases with counsel for your jurisdiction.]
6. Where your data is stored
Your documents and account data are hosted in the United Arab Emirates, on infrastructure provided by Heroku. Some of the providers that help us run the service operate in other countries (see below), so limited data may be processed elsewhere.
7. Service providers (sub-processors)
We share data only with providers that help us operate LifeFolder, and only what each needs to do its job:
- Cloudflare — security, content delivery, and protection against attacks.
- Heroku (a Salesforce company) — application hosting and database.
- Anthropic — AI processing of document content, only when you request it. Not used to train models.
- Resend — transactional email (sign-in notifications, password resets).
8. International data transfers
LifeFolder is available to customers worldwide and uses providers located in more than one country. This means your information may be transferred to and processed in countries other than where you live, including the United Arab Emirates and others. Where the law requires it, we put appropriate safeguards in place for these transfers — such as standard contractual clauses. [Confirm transfer mechanism with counsel.]
9. Data retention
We keep your information while your account is active. If you delete a document or your account, we remove it from our active systems and delete or anonymize it within [retention period, e.g. 30 days]. Encrypted backups are purged on a rolling schedule. We may keep limited records longer where the law requires.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing or withdraw consent. You can do much of this yourself in the app, or contact us at hello@lifefolder.app. If you're in the EEA or UK, you also have the right to complain to your local data protection authority.
11. Security
We protect your data with encryption in transit and at rest, access controls, and regular review of our providers. No service can promise perfect security, and LifeFolder is still an early beta — we describe our approach honestly and won't over-promise. If we ever discover a breach that affects you, we'll notify you as required by law.
12. Cookies
During the beta we use only essential cookies needed to sign you in and keep the app working. We don't use third-party advertising cookies.
13. Children
LifeFolder is not intended for children under [16/18]. You may store documents about your children as part of your household, but accounts are for adults.
14. Changes & contact
We'll update this policy as LifeFolder grows and will change the "last updated" date above. For anything privacy-related, reach us at hello@lifefolder.app or by post at Tuk Tuk Labs, [registered address].