Legal
Privacy Policy
Last updated: August 18, 2026
BeInLuck ("BeInLuck", "we", "us") is a private daily wellness ritual that processes
camera rhythm patterns on your device and lets you add your own reflection. A completed
check-in may display and store a camera pulse estimate only after a strict clear-capture
quality gate. It is labeled Research Beta and is a personal camera observation, not a
medical-device measurement or a diagnosis. An extended 45–60 second capture may also issue
a device-derived Camera HRV (RMSSD) estimate labeled Research Beta. It is not ECG HRV and is
not interpreted as stress, recovery, readiness, fitness, or disease. A capture of at least
30 seconds may also show and store a device-derived camera breathing-rate estimate labeled
Research Beta. It is not clinical respiratory monitoring. This
policy explains, in plain language, what we do and don't do with your information.
Raw camera frames are never stored. We never upload your
camera video, photos, face landmark mesh, or processed analysis trace. A bounded processed pulse
trace, detected peak timing, and beat intervals may remain only in this browser's private
device storage so your own Today trace can be rendered consistently. They are never synced
to our servers. Only a compact 48-point guided visual fingerprint may sync with a bounded
ritual summary. Optional Face Memory is off by default
and stores only normalized, derived feature capsules after your
explicit choice.
1. Data we process
- Device-only camera data: live frames are used during measurement, remain in
browser memory, and are discarded. A normalized, processed pulse trace plus locally
detected peak timing and beat intervals may be retained for up to 365 days in bounded
browser storage. It contains no video or face image and is not uploaded. Browser storage
may be cleared or evicted by you, your browser, or your operating system.
- Account and check-in data: Google Sign-In name, email, and profile image; check-in
time and timezone; a source-labeled camera pulse, camera breathing-rate, and bounded Camera HRV
Research Beta summary when available;
signal quality; a small visual-only rhythm fingerprint; and any optional journal or profile
details you enter. A compact derived check-in summary is also kept in a device-owned
IndexedDB archive without an app-set date cutoff. Each check-in you explicitly save remains
a separate time point. This archive contains no frames, photos, face landmarks, or
raw waveform and is never uploaded merely because it exists. Optional birth-year and sex profile choices are also kept in an
account-scoped store on this device, so the setting remains useful without cloud access;
they sync only when your account has active cloud memory. When a connection is unreliable
or offline, a bounded check-in summary
may remain in Firestore's browser-local cache with a pending-write marker and is queued to
sync when connectivity returns. Raw frames, photos, and waveforms are never included in
that pending write. To keep home loading efficient, the same derived day summaries may also
be copied into four bounded, fixed-slot home index documents. Calendar journal markers may
likewise use four bounded index documents containing only mood, selected tags, and whether
a note exists—not the note text. These indexes contain no additional camera or raw signal data.
- Device history and retired Founding pilot: without an account, you can continue to
check in and store compact summaries on this device. The latest seven local-calendar days
remain interactive as a moving window. Earlier day markers remain on this device but their
values and details are locked. Google Sign-In adopts the anonymous device archive and unlocks
its full local history; it does not upload that archive or activate Cloud Sync. Cloud Sync is
a separate paid entitlement. The former Founding pilot no longer accepts activations, extends
access, or authorizes product reads and writes. Its isolated legacy registry may retain a
Firebase user ID, bounded date-only completion markers, and activation/check-in/expiry and
seat metadata for audit and cleanup. It never receives email, camera data, wellness values,
journal context, or device identity. Sign-In alone does not activate Cloud Sync.
- Optional Face Memory: if you turn it on, BeInLuck may create a normalized shape
capsule (about 78 anchors) and a lighting-sensitive camera color-response capsule. The color
capsule is not a skin-tone, redness, temperature, sweat, perfusion, or skin assessment. These are not a
photo, full 468-point mesh, faceprint, or recognition template, and we do not use them to
identify you. With your consent, the app may compare regional R/G and B/G color ratios with
one to three earlier clear captures after normalizing each capture's face-wide color
balance. It describes only camera-observed red-toned color change—not clinical redness,
flushing, inflammation, or a health result. Consent is account-scoped. A bounded local
device vault may retain up to 365 days/455 raw-free color capsules: up to four per day for
the latest 30 days and one representative capsule per earlier day. Free activates the
latest 30 days, Plus 90 days, and Pro 365 days. Plus and Pro may sync matching capsules to
your account across devices.
- Aluna requests: only when you choose the in-app companion, your question and a
compact wellness context are sent for AI processing. For Plus and Pro, this may include a
long-window summary made from already loaded records: observed-day counts, ritual progress,
and bounded user-authored context patterns. It does not include record dates, document
identifiers, raw arrays, frames, photos, or raw waveforms. Camera pulse and breathing
estimates are included only when they passed their product gate and you explicitly request
an Aluna response. They are never treated as health, recovery, stress, or appearance conclusions.
- Optional AI Context Capsule and ChatGPT connector: only when you choose to copy
a Capsule or approve an OAuth connection, BeInLuck creates a small wellness context from
records the app already loaded. An anonymous local copy contains only the current day.
After Google Sign-In, a Free Capsule can summarize recent 7-day continuity within up to
30 days of local context; Plus and Pro Capsules may cover up to 90 days. A Capsule can contain recording-day and check-in counts,
date-level camera-quality counts, personal-baseline progress, your selected mood or context
tags, a sourced camera pulse Research Beta, camera breathing-rate Research Beta, a sourced
Camera HRV Research Beta estimate when available, and imported wearable BPM or HRV RMSSD that you selected on this
device. The approval screen shows the exact Capsule JSON
and every requested OAuth scope before a separate final approval. Each number keeps its source.
Exact local dates and your approved display
name are returned by connector tools only when you explicitly request them; the timezone is
used internally to distinguish today from an earlier record and is not returned. It excludes raw video, face
images, raw waveforms, full wearable time-series, email, account or document identifiers,
and note text. Copying is local and sends nothing to our server.
An approved ChatGPT connector stores one sanitized Capsule in Cloudflare KV so read-only
MCP data tools can return it; MCP reads do not call an AI model or read Firestore. If you
explicitly start a camera check-in from ChatGPT, the connector creates an opaque session
bound to that OAuth user for at most ten minutes. Completing it requires the same BeInLuck
account; the session stores only the sanitized result Capsule and expires automatically.
- Optional local Open Wearables import: a JSON export you select is parsed in your
browser into a small allowlisted BPM and HRV RMSSD snapshot. Type, canonical unit, valid
timestamp, and source provider are validated; unsupported or undated rows are rejected.
The selected file, API key,
provider account identifier, and raw time-series are not uploaded by BeInLuck. The local
snapshot is sent to ChatGPT only if you later approve a connector Capsule containing it.
- Payments: Lemon Squeezy processes checkout and payment details as merchant of
record. We receive identifiers and subscription status needed to grant and manage access,
but do not receive your full card number.
- Privacy-preserving product metrics: an allowlisted event name, a coarse
days-since-first-visit bucket, a broad device family (such as iOS, Samsung Android,
other Android, or desktop), a bounded product area, active-time increments rounded to
short intervals, performance ratings such as good/needs improvement/poor, and
a short allowlisted acquisition category such as direct, share, or Reddit. We never send
a raw referrer, UTM value, campaign string, page URL, or free-form acquisition label. A
recent explicit category may remain locally so signup and first check-in can be counted in
the same anonymous flow; the visible query marker is removed after capture.
A random installation pseudonym lets us count daily, weekly, and monthly active installations
without using a cookie, advertising ID, hardware ID, or fingerprint. After Google Sign-In,
a one-way pseudonym derived from the Firebase UID lets aggregate reports avoid counting the
same signed-in account twice across devices; the raw UID, name, and email are not written to
product analytics. A random page-session pseudonym supports aggregate active-minutes and
exit reports. These pseudonyms are not joined to camera estimates, face data, waveform data,
journal content, or Cloud Sync records. For retention, a local marker limits visit counting
to once per local calendar day; only D1, D7, and D30 are separated while intermediate days stay broad.
The first-visit timestamp never leaves the device. Measurement reliability uses
milestone counts and broad failure categories only. We do
not send the raw user-agent string, device model, exact event timestamp, exact performance timing, Firebase UID,
email, cookie, advertising ID, or device fingerprint.
- Service integrity and AI operations: when configured, Firebase App Check sends a
short-lived attestation token to our custom AI and operator APIs to help distinguish our
app from abusive automated traffic. We may retain only aggregate valid, missing, invalid,
or misconfigured counts by service, bounded endpoint, and rollout mode. We do not retain
the attestation token, app ID, account ID, or user ID in these analytics. We may also count
AI requests, successes, rate limits, quota-service failures, and provider or empty-response
failures by plan and model, without question text, wellness context, or user identifiers.
- Aggregate subscription operations: after Lemon Squeezy signature and store or
product validation, we may count subscription starts, renewals, payment failures,
recoveries, cancellations, resumptions, expirations, and refunds by billing cycle, along
with aggregate USD-cent amounts. The analytics record does not contain an account ID,
email, subscription ID, invoice ID, or payment-card details.
2. Why we use data
- Provide the camera ritual, user-authored reflection, private memory, sync, subscription access, and support.
- Generate an Aluna response when you explicitly request one.
- Protect the service from abuse, enforce bounded quotas, and diagnose reliability.
- Understand aggregate activation, retention, and subscription performance.
Depending on your location, we rely on performance of our service agreement, your consent
for optional Face Memory, and legitimate interests in security and aggregate reliability.
We do not sell personal information, use wellness data for advertising, train our own
general-purpose AI model on it, or use it for facial recognition or automated eligibility
decisions.
3. Service providers
- Google Firebase: authentication and Firestore account storage. Google Sign-In is
limited to basic profile and email and follows the
Google API Services User Data Policy.
- Cloudflare: security, serverless request handling, bounded AI quota state, and
aggregate metrics. The optional ChatGPT connector also uses Cloudflare KV for OAuth grants
and one sanitized Capsule per connected account.
- OpenAI: if you paste a copied Capsule into ChatGPT or connect the optional
ChatGPT app, OpenAI processes the prompt or read-only tool output under your ChatGPT
account and OpenAI's applicable terms and privacy controls. BeInLuck does not send a
Capsule to OpenAI until you take one of those actions.
- Google Gemini and Cloudflare Workers AI: process Aluna requests only when that
feature is used. BeInLuck does not write conversation text to your Firestore history;
providers may process requests under their own service terms.
- Lemon Squeezy: checkout, tax, receipts, and subscription lifecycle.
These providers may process data in countries different from yours. Where required, they
use contractual and organizational safeguards for international transfers.
4. Retention
Retention depends on the data layer and product tier. The current device's compact, raw-free
check-in summary archive has no app-set date cutoff and keeps each explicitly saved check-in
as a separate time point. Cloud Sync remains bounded to four representative daily snapshots
for Free. Older dates remain available as device history; Free insights and AI
Capsules use at most the latest 30 days, while Plus and Pro context products may use up to 90
days. The separate processed pulse trace and optional Face Memory vault remain bounded to
their disclosed 365-day limits. No local record is uploaded merely because it remains in the
device archive. Free's exact Firestore detail ledger remains a
seven-day/28-slot ring, and its compact date summaries may cover 30 days. Plus keeps recent
detailed check-ins for 90 days; Pro uses a 365-day detailed window. Paid rhythm-calendar
summaries are smaller and may continue across the subscription so your long-term ritual
remains visible. Bounded rhythm and journal-marker home indexes are derived
caches and are replaced or removed with their source records. Face Memory cloud capsules follow their matching
check-in detail. Local capsules are separated by signed-in account (or an anonymous scope) on shared devices;
changing accounts selects a different local capsule instead of exposing or erasing the prior account's capsule.
Older unscoped local capsules are discarded rather than assigned to an account. Local
archives are deleted through the wellness-data deletion control and may also disappear if the
browser or operating system clears site storage.
We do not store Aluna conversation text in Firestore. Short-lived quota state and aggregate
App Check, AI operations, and product counts are retained only as needed for abuse prevention and operations. Payment providers
may retain transaction records where tax and financial law requires it.
An approved ChatGPT connector Capsule expires from our connector storage after no more than
35 days unless you refresh or reconnect it. OAuth access tokens last one hour and refresh
authorization lasts up to 30 days. Revoking the connector removes its grants and stored
Capsule; the original BeInLuck records follow the retention rules above.
5. Your controls and deletion
- Face Memory starts off. You can turn it off at any time; turning it off clears the active
account's local capsules. Use “Delete all face memory” to remove both active local and synced capsules.
- Use Settings → “Delete wellness data” to permanently remove your check-ins, rhythm
calendar and its home indexes, ritual progress, journal, personalization, and Face Memory. The app verifies
cloud records online in bounded batches, clears accessible device caches after completion,
and keeps your sign-in and subscription so billing access is not accidentally lost.
- You can export supported wellness context and request access, correction, portability,
or deletion of your account data.
- You can decline a ChatGPT connection without losing any BeInLuck feature. Disconnecting
the connector revokes its OAuth grants and deletes the connector Capsule. Deleting all
wellness data also requires connector revocation if you previously connected it.
- Canceling a subscription stops future billing according to the checkout terms; account
deletion is a separate request.
To delete your account or exercise a privacy right, email
hello@beinluck.app. We may need to verify that the
account belongs to you. You may also have the right to object, restrict processing, withdraw
consent, appeal a decision, or complain to your local data-protection authority.
6. Security
We minimize payloads, restrict documents to their owner, validate bounded schemas, encrypt
network traffic, and keep raw camera data on device. No method is perfectly secure, but a
breach of cloud storage cannot reveal raw videos or photos because we do not put them there.
7. Children
BeInLuck is not directed to children under 13, or a higher minimum age required in their
country. We do not knowingly collect their personal information.
8. Changes
We may update this policy as the product or law changes. We will update the date above and
provide an appropriate notice for material changes.
9. Contact
Questions or requests? Email us at
hello@beinluck.app.