LifeOrg
ENRUSR
← Back to LifeOrg
  • Privacy Notice
  • Terms of Service
  • Health & AI Notice
  • Cookies & Device Storage
  • Service Providers & Data Transfers
  • Subscriptions, Cancellation & Consumer Rights
  • Account & Data Deletion
  • Security & Vulnerability Reporting
Edition: 2026-09-16
Evgenii Konstantinov PR Novi Sad Mite Ružića 2, sprat 2, stan 3, 21101 Novi Sad, Republika Srbija Matični broj: 67388461 · PIB: 114190836 privacy@lifeorg.app

Privacy Notice

This notice explains how the LifeOrg operator identified on this page processes personal data through the LifeOrg website, applications and support channels. Serbian data-protection law applies to our operations. The EU General Data Protection Regulation (GDPR) also applies where its territorial conditions are met, including relevant services offered to people in the EU. A reference to a jurisdiction does not announce service availability there.

  1. Responsibility and contact
  2. Data and sources
  3. Purposes and legal grounds
  4. AI, recognition and human review
  5. Sharing, publication and external recipients
  6. International processing
  7. How long information is kept
  8. Your rights and response times
  9. Adults, security and notice changes

1. Responsibility and contact

The identified operator is responsible for deciding why and how your personal data is processed. Contact privacy@lifeorg.app for privacy questions and rights requests, support@lifeorg.app for account support, security@lifeorg.app for security reports and legal@lifeorg.app for legal or consumer complaints. You can also write to the operator’s postal address shown on this page.

Our provider page identifies external services used for particular features. A provider may act on our instructions or have its own responsibilities for processing. The operator is your primary privacy contact; any appointed data protection officer or representative and their contact details will be identified here when applicable.

2. Data and sources

Sources include you, your device and interactions with LifeOrg, imports you initiate, other users’ shared contributions, map/geocoding services and AI-generated results. A Google-branded AI or map provider does not mean LifeOrg reads your Google account, Gmail or Calendar. Any future account integration requires its own disclosed access and permissions.

  • Account and profile: account identifier, email, username, registration and authentication information, name, avatar, description, language, time zone, city and preferences that you provide or generate through account use.
  • Organizer content: tasks, calendars, notes, contacts, imported contact files, goals, reminders, schedules and associated attachments you enter or upload. Imported records can contain information about other people.
  • Nutrition, activity and wellbeing: food and meal records, workouts, body measurements, sleep, check-ins, goals and notes. Some entries and conclusions drawn from them reveal health information or other specially protected information.
  • Personal finances: income and expense records, budgets, amounts, categories, receipt images and extracted receipt information that you submit. Receipts and free-text content may incidentally reveal health, beliefs or information about others. Recording finances does not connect LifeOrg to your bank by itself.
  • AI features: your request, relevant feature context, submitted text or images, AI responses and derived classifications, job status, provider/model details and usage information. The Health & AI Notice distinguishes personal assistance from moderation of photos intended for publication.
  • Places, maps and community contributions: searches, place names and addresses, coordinates you provide or allow a feature to use, contributed place information, photographs and publication/moderation status. Coordinates can be precise; browser or device permission is relevant when you request location-based features.
  • Technical and security information: IP address, browser or device information, access and authentication events, operational logs, errors, traces, audit events and signals needed to investigate failures or misuse.
  • Communications: contact information, message text and attachments you send to support. Submitting the website contact form sends its contents through Telegram to the operator. Email has a separate delivery route.

3. Purposes and legal grounds

We use information for the disclosed purpose and limit it to what that purpose requires. Where we rely on legitimate interests, you can object on grounds relating to your situation; an objection to direct marketing is unconditional. We do not sell personal data or use health information for advertising.

Required account information is needed to open and secure an account. Other information depends on the feature you choose: declining location access, for example, can limit nearby results while allowing a manually entered search. We explain additional required information when requesting it. You do not need to populate every organizer module.

  • Providing the requested service: account management, saving and synchronizing organizer content, running requested searches and recognition, and resolving support requests. For ordinary personal data necessary for these functions, the basis is performance of our contract or steps requested before entering it.
  • Sensitive information: health-related data requires an applicable special-category condition as well as a general legal basis. LifeOrg uses a separate explicit consent for its health diary, calculations and personalisation, requested before collecting data through those features, and an additional choice for optional AI processing. Accepting the Terms, reading this notice or an existing AI choice does not itself provide health-data consent. The Health & AI Notice explains these choices and withdrawal.
  • Security and reliable operation: preventing unauthorized access and abuse, investigating incidents, diagnosing service failures and maintaining integrity. The basis is our legitimate interest in a safe and functioning service, where this is not overridden by your interests or fundamental rights.
  • Moderating contributions intended for public display: checking submitted place photos for suitability and misuse, including automated image analysis. We rely on the legitimate interest in maintaining safe and relevant shared content, subject to the required balancing of rights. This processing is separate from your health AI choice. Avoid sensitive personal information in public submissions and request review if you disagree with a moderation result.
  • Legal duties and claims: responding to binding lawful requests, keeping records required by applicable law and establishing, exercising or defending legal claims. The relevant basis is a legal obligation, or legitimate interests for claims where appropriate; any specially protected data requires its own applicable exception.
  • Optional marketing or non-essential tracking: a separate consent where required, with a way to decline and withdraw. Providing an account or support email is not consent to unrelated promotional messages.

4. AI, recognition and human review

AI assistance is identified as AI in the product. Selected personal-assistance requests and public-photo moderation may send inputs to the paid Google Gemini API. Google does not use these paid-service prompts and responses to improve its products; separate abuse monitoring and review still apply. AI outputs can include inferred categories or observations about you and are themselves personal data when linked to you. See the Health & AI Notice for inputs, controls, provider handling and limitations.

LifeOrg is an organizer, not a service for making binding medical, credit, employment or other legal decisions about you. Suggestions and recognition results should be checked before use. If you believe an automated result has significantly affected you, contact privacy@lifeorg.app to explain the result, request an explanation or challenge it and seek human review where applicable law provides that right.

Authorized people may access information when necessary to resolve your request, investigate security or unlawful content, maintain the service or meet a legal duty. Do not include confidential information that is unnecessary for those tasks in a support ticket or public contribution.

5. Sharing, publication and external recipients

We use providers for storage, infrastructure, AI, maps and communication. They receive information relevant to their function, as described in the Service Providers & Data Transfers page. Other possible recipients are professional advisers subject to confidentiality, competent authorities where disclosure has a lawful basis, and parties to a business transfer subject to applicable data-protection requirements.

Private account content and shared contributions have different audiences. Some place-library content is shared, and an approved place photograph can become publicly accessible. Your personal product records belong to your account and are not public place contributions. Choosing to submit material for publication is not a request to keep it in a private account space. Other people may copy material once it is public; deletion from LifeOrg cannot recall copies independently made by others.

We do not make account passwords or private finance and health records public as part of library publication. Before contributing, remove faces, documents, contact details, geolocation metadata and other personal information that the public does not need. You must have the rights and a lawful basis to submit information about another person.

6. International processing

Processing may involve Serbia and the countries in which the providers relevant to your feature operate or permit access. An infrastructure region alone does not establish where all processing, support or onward transfers occur. Contact privacy@lifeorg.app for information about recipients, relevant countries and safeguards for your data, including how to obtain a copy of applicable contractual safeguards, with unrelated confidential information removed.

Transfers must satisfy the rules of the applicable jurisdiction. Depending on the recipient and circumstances, these rules may require an adequacy decision, approved contractual safeguards and supplementary measures, or a narrowly applicable statutory exception. Serbia is not currently covered by an EU adequacy decision. For US recipients, reliance on the EU–US Data Privacy Framework requires the relevant organization and processing to be covered by that framework.

7. How long information is kept

Retention is determined by the record’s purpose, applicable duty and storage lifecycle. You can ask for the criteria and deletion status relevant to your data. The Account & Data Deletion page describes the request process and the effect on shared contributions.

  • Account and organizer records are kept while needed to provide the account and the content you maintain, then deleted or appropriately de-identified when the purpose ends, subject to the exceptions below. Feature-level deletion and account deletion have different scopes.
  • AI requests and results may remain in saved application records and job history until deleted through the relevant feature or account-deletion process. A temporary processing cache expiring does not mean all saved prompts, images or outputs have been erased. Google’s separate retention is explained in the Service Providers & Data Transfers notice.
  • Operational logs and diagnostics are retained according to their security and troubleshooting purpose, the sensitivity of their contents, the need to investigate an incident and applicable duties. Records relevant to an unresolved incident may need to be retained longer than routine logs.
  • Support correspondence is kept as needed to handle the matter, follow up, document the outcome and address applicable claims. Consent and contract-version evidence is retained to demonstrate relevant choices and obligations, limited to what is needed for that purpose.
  • Deletion can involve separate live storage, provider copies and backup cycles. Backup expiry is not instantaneous. Data retained solely in backups or for a legal obligation or claim is restricted to that purpose and should not be used to restart a deleted account or for marketing.

8. Your rights and response times

Use available account controls or contact privacy@lifeorg.app. You can also use the operator’s postal address. We may request proportionate information to verify identity; do not send a password, one-time code or identity document unless a specific, justified verification request explains why it is necessary.

Under the GDPR, we respond without undue delay and within one month of receipt. Where necessary because of the complexity or number of requests, this may extend by two further months; we explain the extension within the first month. Under Serbian law the initial period is 30 days, with a possible extension by a further 60 days under the statutory conditions and notice within the initial period. If both regimes apply, we respect each applicable requirement.

Requests are normally free. A lawful fee or refusal is possible only in limited cases such as manifestly unfounded or excessive requests, with reasons and information about available remedies. You do not have to contact us before approaching a data-protection authority.

  • Request confirmation and information about processing, access and a copy of your personal data, and correction of inaccurate or incomplete information.
  • Request erasure or restriction where the legal conditions apply. Erasure may be limited by a legal obligation, the rights of others or the need to establish, exercise or defend legal claims.
  • Receive data you provided in a structured, commonly used, machine-readable format, and request transmission to another controller where technically feasible, when portability applies to automated processing based on consent or contract.
  • Object to processing based on legitimate interests on grounds relating to your situation, and object at any time to direct marketing. Withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Exercise applicable protections concerning solely automated decisions with legal or similarly significant effects, and complain to a competent supervisory authority or seek judicial remedies.
  • Serbian Commissioner: contact and complaints
  • EEA data-protection authorities

9. Adults, security and notice changes

LifeOrg accounts are intended for adults aged 18 or over. Do not create an account for a child or use the service to maintain a child’s sensitive records. If you believe a child has provided personal information, contact us so that we can assess the situation and take appropriate action.

Our Security page explains the reporting channel and limits of public security statements. Appropriate measures depend on the data and risk; no internet service can guarantee that an incident will never occur.

The update date identifies this notice’s version. We provide prominent information about material changes and notify affected users where required. A new processing purpose or a change requiring consent will not obtain that consent merely because this notice was updated or you continued using LifeOrg.

About this version

This edition clarifies data flows, retention criteria and consumer rights. It does not record your acceptance of changed terms or a new consent.

Previous edition: 21 August 2026

Last updated: 2026-09-16