B BeInLuck

Legal

Privacy Policy

Last updated: August 18, 2026

BeInLuck ("BeInLuck", "we", "us") is a private daily wellness ritual that processes camera rhythm patterns on your device and lets you add your own reflection. A completed check-in may display and store a camera pulse estimate only after a strict clear-capture quality gate. It is labeled Research Beta and is a personal camera observation, not a medical-device measurement or a diagnosis. An extended 45–60 second capture may also issue a device-derived Camera HRV (RMSSD) estimate labeled Research Beta. It is not ECG HRV and is not interpreted as stress, recovery, readiness, fitness, or disease. A capture of at least 30 seconds may also show and store a device-derived camera breathing-rate estimate labeled Research Beta. It is not clinical respiratory monitoring. This policy explains, in plain language, what we do and don't do with your information.

Raw camera frames are never stored. We never upload your camera video, photos, face landmark mesh, or processed analysis trace. A bounded processed pulse trace, detected peak timing, and beat intervals may remain only in this browser's private device storage so your own Today trace can be rendered consistently. They are never synced to our servers. Only a compact 48-point guided visual fingerprint may sync with a bounded ritual summary. Optional Face Memory is off by default and stores only normalized, derived feature capsules after your explicit choice.

1. Data we process

2. Why we use data

Depending on your location, we rely on performance of our service agreement, your consent for optional Face Memory, and legitimate interests in security and aggregate reliability. We do not sell personal information, use wellness data for advertising, train our own general-purpose AI model on it, or use it for facial recognition or automated eligibility decisions.

3. Service providers

These providers may process data in countries different from yours. Where required, they use contractual and organizational safeguards for international transfers.

4. Retention

Retention depends on the data layer and product tier. The current device's compact, raw-free check-in summary archive has no app-set date cutoff and keeps each explicitly saved check-in as a separate time point. Cloud Sync remains bounded to four representative daily snapshots for Free. Older dates remain available as device history; Free insights and AI Capsules use at most the latest 30 days, while Plus and Pro context products may use up to 90 days. The separate processed pulse trace and optional Face Memory vault remain bounded to their disclosed 365-day limits. No local record is uploaded merely because it remains in the device archive. Free's exact Firestore detail ledger remains a seven-day/28-slot ring, and its compact date summaries may cover 30 days. Plus keeps recent detailed check-ins for 90 days; Pro uses a 365-day detailed window. Paid rhythm-calendar summaries are smaller and may continue across the subscription so your long-term ritual remains visible. Bounded rhythm and journal-marker home indexes are derived caches and are replaced or removed with their source records. Face Memory cloud capsules follow their matching check-in detail. Local capsules are separated by signed-in account (or an anonymous scope) on shared devices; changing accounts selects a different local capsule instead of exposing or erasing the prior account's capsule. Older unscoped local capsules are discarded rather than assigned to an account. Local archives are deleted through the wellness-data deletion control and may also disappear if the browser or operating system clears site storage.

We do not store Aluna conversation text in Firestore. Short-lived quota state and aggregate App Check, AI operations, and product counts are retained only as needed for abuse prevention and operations. Payment providers may retain transaction records where tax and financial law requires it.

An approved ChatGPT connector Capsule expires from our connector storage after no more than 35 days unless you refresh or reconnect it. OAuth access tokens last one hour and refresh authorization lasts up to 30 days. Revoking the connector removes its grants and stored Capsule; the original BeInLuck records follow the retention rules above.

5. Your controls and deletion

To delete your account or exercise a privacy right, email hello@beinluck.app. We may need to verify that the account belongs to you. You may also have the right to object, restrict processing, withdraw consent, appeal a decision, or complain to your local data-protection authority.

6. Security

We minimize payloads, restrict documents to their owner, validate bounded schemas, encrypt network traffic, and keep raw camera data on device. No method is perfectly secure, but a breach of cloud storage cannot reveal raw videos or photos because we do not put them there.

7. Children

BeInLuck is not directed to children under 13, or a higher minimum age required in their country. We do not knowingly collect their personal information.

8. Changes

We may update this policy as the product or law changes. We will update the date above and provide an appropriate notice for material changes.

9. Contact

Questions or requests? Email us at hello@beinluck.app.