Privacy Policy
Lifora asks for a small amount of information about your routine so it can suggest useful things to do. This page says what it keeps, why, and what it will not do with it.
The short version
- Your health and routine information is used to build your daily plan, and for nothing else.
- It is never used to select advertising.
- It is never sold, and never shared with advertisers.
- You can export everything Lifora holds, or delete your account entirely, from inside the app.
Who we are
Lifora is operated by BMKS, contactable at [email protected]. For UK and EU data protection law we are the data controller for the information described here.
What Lifora collects
| What | Why |
|---|---|
| The goals you choose | To decide which kinds of actions to suggest. |
| Your routine answers — when you wake and sleep, your working pattern, meal times, roughly how much you sit, exercise and drink | To place actions at times that suit your day. Every one of these questions is optional. |
| Age range, height and weight | Optional, and currently unused by the recommendation engine. You can leave them blank with no effect. |
| The actions Lifora suggested and whether you completed, snoozed or skipped them | This is what makes tomorrow's plan better than today's. |
| Your email address, if you choose to add one | So your account survives a lost or replaced phone. Lifora works without one. |
| Your device's time zone and language | To schedule reminders at the right local time. |
| A device token, if you enable notifications | To tell your phone when your plan has changed. |
| Subscription status from Apple or Google | To know whether you have Lifora Plus. We never receive your card details. |
| Anonymous usage events — which screens are used, how many actions are completed, and in which category | To understand whether the product works. These carry no health measurements and no text you have written. |
You can use Lifora without an account
When you first set Lifora up it creates an account with no email address and no password, identified only by a random identifier. That account is fully functional. Adding an email later is about being able to recover your history, not about unlocking anything.
Health data and advertising
Lifora shows some sponsored content to people on the free plan. Here is exactly how it is chosen:
- the country your device reports;
- the language your device is set to;
- which screen you are looking at;
- a product category, only if you have deliberately browsed one in Lifora Picks.
That is the complete list. Your goals, your routine answers, your daily plan, what you complete, what you skip and anything Lifora has inferred about you are not available to the code that selects advertising — not because we promise not to look, but because the two parts of the system are separate and there is no path between them.
We do not use an advertising identifier, we do not build an advertising profile, and we do not share anything with advertising networks. Lifora Plus removes sponsored content entirely.
Lifora Picks
Lifora Picks shows products from partners, and is reached deliberately from your profile rather than appearing alongside a suggestion. Those products are advertising. They are not recommendations, they are not chosen based on anything about your health, and no partner has any influence over what Lifora suggests you do.
How Lifora uses AI
Lifora uses a language model to choose between actions from a fixed, human-reviewed library, to word them naturally, and to answer questions in Coach. It is never asked to invent health advice, and anything it produces is checked before you see it.
When Lifora calls the model it sends only what is needed for that decision: your goals, your waking hours, roughly how often you exercise, and a summary of which categories you tend to complete. It does not send your name, your email address, your height or weight, or any identifier that points back to you.
The model runs on Cloudflare's infrastructure, in the same account as the rest of Lifora.
Where your data is held
On Cloudflare's network, in a database located in Western Europe. Nothing is transferred to a third party for storage or processing beyond the services listed here.
Who else sees it
| Who | What they get |
|---|---|
| Cloudflare | Hosts the app's backend and database. |
| Apple and Google | Handle payment for Lifora Plus and tell us whether a subscription is active. We never see your payment details. |
| Advertising partners | Nothing about you. They supply the content; we choose when to show it, using only the signals listed above. |
We do not sell your data. There is no arrangement under which we would.
How long it is kept
- Your profile, goals and action history: until you delete your account.
- Usage events and AI request records: 90 days, then deleted automatically.
- Sign-in tokens: 60 days, or until you sign out.
Your rights
Under UK and EU data protection law you can ask for a copy of your data, correct it, delete it, restrict how it is used, or object to its use. Two of these are available immediately inside the app:
- Export — Profile → Privacy → Export my data. This includes your action history, not only your profile.
- Delete — Profile → Delete account. This removes everything, permanently and immediately. It cannot be undone.
For anything else, email [email protected]. If you are unhappy with how we have handled a request, you can complain to the UK Information Commissioner's Office at ico.org.uk.
Children
Lifora is not intended for anyone under 16 and we do not knowingly collect information from children. If you believe a child has created an account, email us and we will delete it.
Notifications
Lifora only ever sends you reminders about your own plan. It does not send advertising in a notification, and it will not. You can change how many you receive, set quiet hours, or turn them off entirely in Profile → Notifications.
Security
Connections are encrypted in transit. Passwords are stored hashed and are never recoverable, including by us. Sign-in tokens are stored hashed, and a token that is reused invalidates the whole session — so a stolen token cannot be used indefinitely.
Changes to this policy
If we change it meaningfully we will tell you in the app before the change takes effect. The date at the top always reflects the current version.