Privacy Policy
Last updated 27 August 2026
Life in Views is a private space for your own notes and numbers. This page explains exactly what it stores, who else touches it, and how to take it back.
Who this is about
Life in Views (“the service”) is operated by Hamdi Hassan. Questions about this policy, or about your data, go to hello@lifeinviews.com.
What is collected
Only what the service needs to work. There is no profile enrichment, no data bought from anyone else, and nothing collected about you from other sites.
- Account
- Your email address, and a password stored only as a cryptographic hash — the plain password is never written down and cannot be read back, including by us.
- Profile
- The display name you choose during setup, and your time zone, which is what makes “today” mean your today rather than the server’s.
- What you write
- The life areas, priorities, recurring routines, measurements and their readings, memories, seasons and notes you enter. This is the substance of the service and it is yours.
- Billing
- If you subscribe, an identifier for your customer record at Stripe and the status of your subscription. Card numbers are entered on Stripe’s own checkout page and never reach this service.
- Technical
- A session cookie so you stay signed in. Standard server logs are produced by the hosting provider in the course of serving requests.
Cookies, and what is not here
The service sets cookies for one purpose: keeping you signed in. There are no analytics cookies, no advertising cookies and no third-party trackers, so there is no consent banner to dismiss and nothing to opt out of.
Your entries are never used to train models, never sold, and never shared for marketing. No advertising is carried anywhere in the service.
Who else processes it
Four providers, each doing one job, each bound by its own agreement. No one else receives your data.
- Supabase
- Database and authentication. This is where your account and your entries live, and it sends the confirmation, invitation and password-reset emails.
- Vercel
- Hosting and delivery of the application itself.
- Stripe
- Payments and subscription management, including the billing portal where you change a card, read invoices or cancel.
- Resend
- One message only: the email confirming that an account has been deleted.
How it is kept separate
Every table is protected by row-level security in the database, so an account can only ever read and write its own rows. That boundary is enforced by the database itself rather than by application code, and it is checked by an automated test that signs in as two real accounts and tries, from one, to read, modify, reference and delete the other’s data. Passwords are hashed, and all traffic is served over HTTPS.
No system is perfect, and this one is small. What is promised here is the design and the testing, not an absolute guarantee.
How long it is kept
Your data stays until you delete it. Deleting your account removes your profile and every entry attached to it, immediately and permanently — this is a real deletion, not a flag that hides the rows.
Two things outlive it, deliberately. Encrypted database backups are retained for seven days before ageing out, so a deletion is fully reflected in backups within a week. And where a payment was taken, the customer and invoice records at Stripe are kept as a financial record, because tax and accounting rules require it. Everything else is gone.
What you can do
- See it. Everything stored about you is already on screen in the app — there is no hidden profile behind it.
- Correct it. Every entry can be edited or removed where it appears, and your name and time zone in Settings.
- Delete it. Settings has a delete-account control. It cancels any active subscription first, then removes the account.
- Ask. For a copy of your data in a portable file, or anything this page does not answer, write to the address above.
Depending on where you live you may have further rights over your personal data, including to object to or restrict its processing, and to complain to your local data protection authority.
Age
Accounts are for adults: you must be at least 18 to create one, and the service is not intended for and not knowingly provided to anyone younger. If you believe someone under 18 has an account, write to the address above and it will be removed.
Changes
If this policy changes in a way that materially affects you, the date at the top will change and account holders will be told by email before it takes effect.