Privacy and control
Voluntary, privacy-protected, and yours to stop
We do not say "anonymous." A long record of daily numbers plus a few facts about a person can, in principle, be linked back. So the promise is narrower and testable: collect the minimum, keep identity separate, release only reviewed aggregates, never sell or advertise, and make every control work.
What is collected
Measurements you choose
Daily summaries only: steps, walking and running distance, and optionally resting heart rate. Never raw samples, never the whole health store, never location.
A minimal, optional profile
Confirmation that you are an adult. Optionally your age in completed years and a broad region you choose. Nothing is inferred from your behavior. "Prefer not to say" is always available and is a valid answer, not an error.
An identity kept apart
Sign in with Apple, or the Android equivalent, lets you recover your record if you change phones. The sign-in is stored separately from the measurements, linked by a random identifier that is not derived from anything about you.
What is never collected
Name, full birth date, address, GPS, contacts, or any diagnosis. Race, sex, income and disability are not asked and never derived.
Four controls, four meanings
| Control | What it does | What it does not do by itself |
|---|---|---|
| Pause | Stops future uploads as soon as the server receives it. | Erase what you already contributed. |
| Change phone permission | Changes what the operating system lets the app read. | Tell our server anything, or delete your history there. |
| Withdraw | Ends your participation and shows your deletion choices. | Remove your contribution from a statistic that was already published. |
| Delete | Starts verified erasure of your account and records, with a receipt and a completion state. | Recall copies of already-published aggregates from the internet. |
Deleting the app is not the same as deleting your account. Deletion starts inside the app, as Apple requires. Removable live records are processed within seven days; ordinary backups expire within thirty. Restored backups replay deletions before they can serve again.
Who can see what
- You see everything you contributed, with dates, and can export it as CSV and JSON.
- The public sees only reviewed aggregate snapshots. The website has no credentials that can read private records.
- The operator can process records to compute aggregates. Encryption protects data in transit and at rest; we do not claim end-to-end encryption that would prevent operator access, because the aggregates require it.
- No one else. No advertisers, no insurers, no employers, no data brokers, no researchers with access to individual records.
What this is, legally
Living Life Data is operated by OhanaCodes LLC, a Colorado company. It is not a nonprofit, not a medical service, and not a research study. Contributions are not tax-deductible. The project is a public-benefit utility; the words above are the commitment, and the full privacy notice will be published before the first contributor is accepted.