Life_

Privacy Policy

Last updated September 3, 2026

Who we are

Life_ is a personal productivity tool operated by Michael Cerda (Build Something LLC, Alamo, California, mc@bspg.build). It generates a daily editorial brief from your own Gmail and Google Calendar and delivers it via a private link sent by email or optional US SMS.

Life_ is in a free public beta. Each user connects their own Google account; phone verification is required only for optional US SMS. Your data is isolated from every other user by row-level security keyed to your account, and we never train models on the contents of your inbox.

What we collect

  • Google account profile (your email address and a unique account identifier) via OAuth.
  • Gmail message metadata and content for messages received in the last thirty days, including subject, sender, recipients, body text, and timestamps. Used to compose the daily brief and to answer your questions in Ask Anything.
  • Google Calendar events for the current day, including titles, times, and attendees. Used to compose the daily brief.
  • If you choose US SMS delivery, your mobile phone number, which you enter and verify yourself and which is stored encrypted at rest.
  • Your Ask questions, answers, and tool-call diagnostics for up to 30 days, plus content-free product and action metadata for monitoring, debugging, and showing you what Life_ changed.

How we use it

Your Gmail, Calendar, and indexed message corpus are used solely to generate your personal daily brief, prepare private reply proposals inside Life_, and answer your questions in Ask Anything. Brief generation does not create Gmail drafts, send email, or change inbox state. We do not use your data to train any model, and we do not sell or share it for advertising.

How Life_ Handles Google User Data

Life_ accesses certain data from your Google Account (Gmail and Google Calendar) to provide the morning brief service. This section describes how we handle that data, in compliance with the Google API Services User Data Policy, including the Limited Use requirements.

What we access:

  • Gmail messages and metadata (via Google's combined gmail.modify scope): we read inbox content to synthesize the morning brief and identify items that need your attention.
  • Gmail actions (also covered by gmail.modify): Life_ has the technical ability to send email or change inbox state, but does so only after an explicit control names the exact consequence. Generated reply proposals remain inside Life_ until you approve sending.
  • Google Calendar events (via the calendar.readonly scope): we read your calendar to surface upcoming events in the brief and detect conflicts. We do not write to or modify your calendar.

How we use the data:

  • To generate your daily morning brief.
  • To draft replies to emails you would likely want to respond to.
  • To detect time-sensitive items (meeting changes, flight changes, financial anomalies).

How we do NOT use the data:

  • We do not sell or transfer Google user data to third parties for advertising, marketing, or any other purpose unrelated to providing the Life_ service.
  • We do not use Google user data to train, improve, or develop generalized AI or machine learning models. Any AI processing of your data is performed by third-party model providers (such as Anthropic or OpenAI) under contractual restrictions that prohibit them from using your data for model training.
  • We do not allow humans to read your Google user data, except: (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for internal operations where the data has been aggregated and anonymized.

How long we keep the data:

  • Cached email content, Calendar event data, and Ask conversation content are automatically purged 30 days after they were retrieved or created.
  • OAuth tokens are encrypted at rest and rotated according to industry-standard practices.
  • You can revoke Life_'s access to your Google Account at any time via your Google Account permissions page.

Life_'s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Subprocessors

Life_ relies on the following service providers. Your data passes through them only to operate the service. Each has its own privacy policy.

  • Google for OAuth authentication, Gmail access, and Calendar access.
  • Anthropic for synthesizing the daily brief and powering Ask Anything via the Claude API. Anthropic does not train on data sent through the paid API.
  • Supabase for storing indexed messages, brief history, and OAuth tokens (encrypted at rest).
  • Twilio for SMS delivery of the daily brief link.
  • Vercel for application hosting.
  • Slack for forwarding feedback you explicitly submit to the Life_ team.

SMS messaging

You consent to receive SMS messages from Life_ by signing in at life-os.build, entering your US mobile phone number on the Settings page, checking the consent box on that page, and completing the 6-digit verification code we send to your phone. Your consent record (timestamp, IP address, user agent, and the exact wording you agreed to) is stored in our audit log. You will receive at most one SMS per day, sent shortly after the daily brief is generated, containing a private link to that day's brief.

Reply STOP at any time to opt out. Reply HELP for assistance. Message and data rates may apply. To resume messages after opting out, reply START or re-verify your number on the Settings page.

Data sharing

We do not sell, rent, or share your personal information with third parties for marketing or advertising. Data is shared only with the subprocessors listed above, strictly to operate the service. SMS opt-in data and consent records are never shared with third parties for marketing purposes.

Data retention

Indexed source messages, Calendar source data, and Ask content are retained for up to 30 days. Brief history and content-free action metadata are retained while your account is active so you can review prior briefs and changes. Feedback you submit is associated with your account and is deleted with it. You can export your data or permanently delete your account from Account. OAuth tokens are deleted when you disconnect or delete your account.

Security

OAuth tokens are encrypted at rest. Database access is restricted to the application service role. Brief links are gated by random 32-byte tokens with a 24-hour expiry. The service runs over HTTPS.

Your rights

You may request access to, correction of, or deletion of your data at any time by emailing the address below. You may also revoke Google access in your Google account settings, which immediately terminates the service's ability to read your mailbox.

Children

Life_ is not intended for use by anyone under 18. We do not knowingly collect data from minors.

Changes

We may update this policy. The date at the top reflects the most recent revision. Material changes will be communicated to the operator directly.

Contact

Questions, requests, or complaints: mc@bspg.build. Postal contact available on request.