BeInLuck
Legal
Privacy Policy
Last updated: August 21, 2026
BeInLuck ("BeInLuck", "we", "us") is a private daily wellness ritual that processes
camera rhythm patterns on your device and lets you add your own reflection. A completed
check-in may display and store a camera pulse estimate only after a strict clear-capture
quality gate. It is labeled Research Beta and is a personal camera observation, not a
medical-device measurement or a diagnosis. An extended 45–60 second capture may also issue
a device-derived Camera HRV (RMSSD) estimate labeled Research Beta. It is not ECG HRV and is
not interpreted as stress, recovery, readiness, fitness, or disease. A capture of at least
30 seconds may also show and store a device-derived camera breathing-rate estimate labeled
Research Beta. It is not clinical respiratory monitoring. This
policy explains, in plain language, what we do and don't do with your information.
Raw camera frames are never stored. We never upload your
camera video, photos, face landmark mesh, or processed analysis trace. A bounded processed pulse
trace, detected peak timing, and beat intervals may remain only in this browser's private
device storage so your own Today trace can be rendered consistently. They are never synced
to our servers. Only a compact 48-point guided visual fingerprint may sync with a bounded
ritual summary. Each completed check-in may retain a bounded, raw-free regional camera
color-response capsule on this device. Optional Face Memory is off by default and adds
a normalized shape reference or eligible cross-device capsule sync only after your explicit choice.
1. Data we process
- Device-only camera data: live frames are used during measurement, remain in
browser memory, and are discarded. A normalized, processed pulse trace plus locally
detected peak timing and beat intervals may be retained for up to 365 days in bounded
browser storage. It contains no video or face image and is not uploaded. Browser storage
may be cleared or evicted by you, your browser, or your operating system.
- Account and check-in data: Google Sign-In name, email, and profile image; check-in
time and timezone; a source-labeled camera pulse, camera breathing-rate, and bounded Camera HRV
Research Beta summary when available;
signal quality; a small visual-only rhythm fingerprint; and any optional journal or profile
details you enter. A compact derived check-in summary is also kept in a device-owned
IndexedDB archive without an app-set date cutoff. Each check-in you explicitly save remains
a separate time point. This archive contains no frames, photos, face landmarks, or
raw waveform and is never uploaded merely because it exists. Optional birth-year and sex profile choices are also kept in an
account-scoped store on this device, so the setting remains useful without cloud access;
they sync only when your account has active cloud memory. When a connection is unreliable
or offline, a bounded check-in summary
may remain in Firestore's browser-local cache with a pending-write marker and is queued to
sync when connectivity returns. Raw frames, photos, and waveforms are never included in
that pending write. To keep home loading efficient, the same derived day summaries may also
be copied into four bounded, fixed-slot home index documents. Calendar journal markers may
likewise use four bounded index documents containing only mood, selected tags, and whether
a note exists—not the note text. These indexes contain no additional camera or raw signal data.
- Device history and limited Cloud Sync pilot: without an account, you can continue to
check in and store compact summaries on this device. The latest seven local-calendar days
remain interactive as a moving window. Earlier day markers remain on this device but their
values and details are locked. Google Sign-In adopts the anonymous device archive and unlocks
its full local history; it does not upload that archive or activate Cloud Sync. Plus and Pro
include Cloud Sync. During the limited beta, the BeInLuck operator may separately invite
selected Free accounts to a bounded 30-day rolling Cloud Sync window and may revoke it. The registry retains a
Firebase user ID, bounded date-only completion markers, and activation/check-in/expiry and
seat metadata for audit and cleanup. It never receives email, camera data, wellness values,
journal context, or device identity. Sign-In and check-in activity alone do not activate Cloud Sync.
- Device camera-color observations: a completed check-in may retain a lighting-sensitive,
raw-free capsule of normalized regional R/G and B/G ratios on this device, including a soft
observation when the encoder has enough frames and regional coverage. It is not a skin-tone,
redness, temperature, sweat, perfusion, or skin assessment. It contains no photo, full 468-point mesh,
landmark coordinates, faceprint, or recognition template, and we do not use
it to identify you. The app may compare it with one to three earlier captures after normalizing
each capture's face-wide color balance. A bounded local device vault may retain up to 365
days/455 raw-free color capsules: up to four per day for the latest 30 days and one
representative capsule per earlier day. Free activates the latest 30 days, Plus 90 days,
and Pro 365 days.
- Optional Face Memory: if you turn it on, BeInLuck may additionally create a normalized
shape capsule (about 78 anchors). Face Memory is account-scoped and is never used to identify
you. Plus and Pro may sync the normalized shape reference and matching eligible color capsules
to your account across signed-in devices; turning Face Memory off disables new cloud sync.
- BeInLuck AI requests: only when you choose the in-app reflection, your question and a
compact wellness context are sent for AI processing. For Plus and Pro, this may include a
long-window summary made from already loaded records: observed-day counts, ritual progress,
and bounded user-authored context patterns. It does not include record dates, document
identifiers, raw arrays, frames, photos, or raw waveforms. Camera pulse and breathing
estimates are included only when they passed their product gate and you explicitly request
a BeInLuck AI response. They are never treated as health, recovery, stress, or appearance conclusions.
- Optional AI Context Capsule and ChatGPT connector: only when you choose to copy
a Capsule or approve an OAuth connection, BeInLuck creates a small wellness context from
records the app already loaded. An anonymous local copy contains only the current day.
After Google Sign-In, a Free Capsule can summarize recent 7-day continuity within up to
30 days of local context; Plus and Pro Capsules may cover up to 90 days. A Capsule can contain recording-day and check-in counts,
date-level camera-quality counts, personal-baseline progress, your selected mood or context
tags, a sourced camera pulse Research Beta, camera breathing-rate Research Beta, a sourced
Camera HRV Research Beta estimate when available, and imported wearable BPM or HRV RMSSD that you selected on this
device. The approval screen separates OAuth tool permissions from six transfer choices:
camera Snapshot, imported wearable summary, ritual context, continuity memory, display
name, and exact dates. No transfer choice is preselected. A focused-context and an
all-available button are shortcuts that still require an affirmative click. The screen
then shows the exact Capsule JSON before a separate final approval. Saved category choices
govern later automatic refreshes, including a ChatGPT-launched check-in. Each number keeps its source.
Your display name is stored and returned only if separately approved. Bounded local dates
remain inside the connector Capsule so it can calculate today/past and selected windows;
exact YYYY-MM-DD dates and timezone are returned to ChatGPT only if exact dates were
separately approved and you explicitly request them. It excludes raw video, face
images, raw waveforms, full wearable time-series, email, account or document identifiers,
and note text. Copying is local and sends nothing to our server.
An approved ChatGPT connector stores one sanitized Capsule in Cloudflare KV so read-only
MCP data tools can return it; MCP reads do not call an AI model or read Firestore. If you
explicitly start a camera check-in from ChatGPT, the connector creates an opaque session
bound to that OAuth user for at most ten minutes. Completing it requires the same BeInLuck
account; the session stores only the sanitized result Capsule and expires automatically.
- Optional local Open Wearables import: a JSON export you select is parsed in your
browser into a small allowlisted BPM and HRV RMSSD snapshot. Type, canonical unit, valid
timestamp, and source provider are validated; unsupported or undated rows are rejected.
The selected file, API key,
provider account identifier, and raw time-series are not uploaded by BeInLuck. The local
snapshot is sent to ChatGPT only if you later approve a connector Capsule containing it.
- Payments: Lemon Squeezy processes checkout and payment details as merchant of
record. We receive identifiers and subscription status needed to grant and manage access,
but do not receive your full card number.
- Privacy-preserving product metrics: an allowlisted event name, a coarse
days-since-first-visit bucket, a broad device family (such as iOS, Samsung Android,
other Android, or desktop), a bounded product area, active-time increments rounded to
short intervals, performance ratings such as good/needs improvement/poor, and
a short allowlisted acquisition category such as direct, share, or Reddit. We never send
a raw referrer, UTM value, campaign string, page URL, or free-form acquisition label. A
recent explicit category may remain locally so signup and first check-in can be counted in
the same anonymous flow; the visible query marker is removed after capture.
A random installation pseudonym lets us count daily, weekly, and monthly active installations
without using a cookie, advertising ID, hardware ID, or fingerprint. After Google Sign-In,
a one-way pseudonym derived from the Firebase UID lets aggregate reports avoid counting the
same signed-in account twice across devices; the raw UID, name, and email are not written to
product analytics. A random page-session pseudonym supports aggregate active-minutes and
exit reports. These pseudonyms are not joined to camera estimates, face data, waveform data,
journal content, or Cloud Sync records. For retention, a local marker limits visit counting
to once per local calendar day; only D1, D7, and D30 are separated while intermediate days stay broad.
The first-visit timestamp never leaves the device. Measurement reliability uses
milestone counts and broad failure categories only. We do
not send the raw user-agent string, device model, exact event timestamp, exact performance timing, Firebase UID,
email, cookie, advertising ID, or device fingerprint.
- Service integrity and AI operations: when configured, Firebase App Check sends a
short-lived attestation token to our custom AI and operator APIs to help distinguish our
app from abusive automated traffic. We may retain only aggregate valid, missing, invalid,
or misconfigured counts by service, bounded endpoint, and rollout mode. We do not retain
the attestation token, app ID, account ID, or user ID in these analytics. We may also count
AI requests, successes, rate limits, quota-service failures, and provider or empty-response
failures by plan and model, without question text, wellness context, or user identifiers.
- Aggregate subscription operations: after Lemon Squeezy signature and store or
product validation, we may count subscription starts, renewals, payment failures,
recoveries, cancellations, resumptions, expirations, and refunds by billing cycle, along
with aggregate USD-cent amounts. The analytics record does not contain an account ID,
email, subscription ID, invoice ID, or payment-card details.
2. Why we use data
- Provide the camera ritual, user-authored reflection, private memory, sync, subscription access, and support.
- Generate a BeInLuck AI reflection when you explicitly request one.
- Protect the service from abuse, enforce bounded quotas, and diagnose reliability.
- Understand aggregate activation, retention, and subscription performance.
Depending on your location, we rely on performance of our service agreement, your consent
for optional Face Memory, and legitimate interests in security and aggregate reliability.
We do not sell personal information, use wellness data for advertising, train our own
general-purpose AI model on it, or use it for facial recognition or automated eligibility
decisions.
3. Service providers
- Google Firebase: authentication and Firestore account storage. Google Sign-In is
limited to basic profile and email and follows the
Google API Services User Data Policy.
- Cloudflare: security, serverless request handling, bounded AI quota state, and
aggregate metrics. The optional ChatGPT connector also uses Cloudflare KV for OAuth grants
and one sanitized Capsule per connected account.
- OpenAI: if you paste a copied Capsule into ChatGPT or connect the optional
ChatGPT app, OpenAI processes the prompt or read-only tool output under your ChatGPT
account and OpenAI's applicable terms and privacy controls. BeInLuck does not send a
Capsule to OpenAI until you take one of those actions.
- Google Gemini and Cloudflare Workers AI: process BeInLuck AI requests only when that
feature is used. BeInLuck does not write conversation text to your Firestore history;
providers may process requests under their own service terms.
- Lemon Squeezy: checkout, tax, receipts, and subscription lifecycle.
These providers may process data in countries different from yours. Where required, they
use contractual and organizational safeguards for international transfers.
4. Retention
Retention depends on the data layer and product tier. The current device's compact, raw-free
check-in summary archive has no app-set date cutoff and keeps each explicitly saved check-in
as a separate time point. Cloud Sync remains bounded to four representative daily snapshots
for Free. Older dates remain available as device history; Free insights and AI
Capsules use at most the latest 30 days, while Plus and Pro context products may use up to 90
days. The separate processed pulse trace and device camera-color vault remain bounded to
their disclosed 365-day limits. No local record is uploaded merely because it remains in the
device archive. Free's exact Firestore detail ledger remains a
seven-day/28-slot ring, and its compact date summaries may cover 30 days. Plus keeps recent
detailed check-ins for 90 days; Pro uses a 365-day detailed window. Paid rhythm-calendar
summaries are smaller and may continue across the subscription so your long-term ritual
remains visible. Bounded rhythm and journal-marker home indexes are derived
caches and are replaced or removed with their source records. Face Memory cloud capsules follow their matching
check-in detail. Local capsules are separated by signed-in account (or an anonymous scope) on shared devices;
changing accounts selects a different local capsule instead of exposing or erasing the prior account's capsule.
Older unscoped local capsules are discarded rather than assigned to an account. Local
archives are deleted through the wellness-data deletion control and may also disappear if the
browser or operating system clears site storage.
We do not store BeInLuck AI conversation text in Firestore. Short-lived quota state and aggregate
App Check, AI operations, and product counts are retained only as needed for abuse prevention and operations. Payment providers
may retain transaction records where tax and financial law requires it.
An approved ChatGPT connector Capsule expires from our connector storage after no more than
35 days unless you refresh or reconnect it. OAuth access tokens last one hour and refresh
authorization lasts up to 30 days. Revoking the connector removes its grants and stored
Capsule; the original BeInLuck records follow the retention rules above.
5. Your controls and deletion
- Face Memory starts off. You can turn it off at any time; turning it off clears the active
account's normalized shape reference and disables new face-capsule cloud sync. Raw-free local
camera-color observations remain part of device check-ins until you delete wellness data.
- Use Settings → “Delete wellness data” to permanently remove your check-ins, rhythm
calendar and its home indexes, ritual progress, journal, personalization, and Face Memory. The app verifies
cloud records online in bounded batches, clears accessible device caches after completion,
and keeps your sign-in and subscription so billing access is not accidentally lost.
- You can export supported wellness context and request access, correction, portability,
or deletion of your account data.
- You can decline a ChatGPT connection without losing any BeInLuck feature. Disconnecting
the connector revokes its OAuth grants and deletes the connector Capsule. Deleting all
wellness data also requires connector revocation if you previously connected it.
- You choose which approved observations to share and whether to use, forward, or act on an
AI response. Camera estimates and AI responses can be wrong and are not for diagnosis,
treatment, or emergencies. This user choice does not remove BeInLuck's responsibility to
protect the connection, minimize data, honor the approved categories, and provide revocation
and deletion controls.
- Canceling a subscription stops future billing according to the checkout terms; account
deletion is a separate request.
To delete your account or exercise a privacy right, email
hello@beinluck.app. We may need to verify that the
account belongs to you. You may also have the right to object, restrict processing, withdraw
consent, appeal a decision, or complain to your local data-protection authority.
6. Security
We minimize payloads, restrict documents to their owner, validate bounded schemas, encrypt
network traffic, and keep raw camera data on device. No method is perfectly secure, but a
breach of cloud storage cannot reveal raw videos or photos because we do not put them there.
7. Children
BeInLuck is not directed to children under 13, or a higher minimum age required in their
country. We do not knowingly collect their personal information.
8. Changes
We may update this policy as the product or law changes. We will update the date above and
provide an appropriate notice for material changes.
9. Contact
Questions or requests? Email us at
hello@beinluck.app.