Privacy
What we collect, where it lives, and what we will never do with it.
Last updated
The short version
- This site has no analytics, no tracking cookies and no third-party scripts. Nothing here watches you read it.
- Your data is never sold, never shared, and never used to train any model. Subscriptions are the only money that comes in.
- Keys and tokens for the services you connect are encrypted before they are stored, and decrypted only while a collection is running.
- You can download a copy of everything, or delete your account and all of it, yourself — both are in the app under Settings. If you cannot reach the app, email privacy@quantifiedlife.io and a person does it within 30 days.
Who this covers
QuantifiedLife is a personal analytics service: it collects the data you already generate — health, workouts, games, money — into one store that only you can read. This policy covers quantifiedlife.io (this site), the app at my.quantifiedlife.io, and the QuantifiedLife apps for iPhone and Android. They are one service and share one datastore.
“We” below means QuantifiedLife. Anything on this page that you want to ask about, argue with, or act on goes to privacy@quantifiedlife.io.
What we collect
Seven things, and this is the whole list. Nothing is collected to profile you, because nothing about this business would be improved by profiling you.
Your account
Sign-in runs on Firebase Authentication: an email address and a password, or a Google account. We never see your password — Firebase holds it, and Google sign-in means it is never typed here at all.
The application database has no users table. Every row is keyed on the anonymous user id Firebase issues; your email address stays in Firebase Authentication, and the one place it travels beyond that is Stripe checkout, so receipts land on the address you sign in with.
Data from the services you connect
Only from sources you connect yourself, using your own key or your own sign-in with that service. Once connected, collection runs three times a day. What arrives depends on the source: sleep and recovery from a strap, workouts and heart rate from a watch, matches from a game, transactions from a budgeting tool.
It is stored as individual measurements — a value, its real timestamp, its unit, and any tags the source recorded. We ask each service for the narrowest access that lets its metrics be collected, use it for nothing but showing you your own data and computing your own analysis, and hand it to nobody. You can switch off any single metric, or the whole source, whenever you like.
What you type in
Journal entries, goals, and the dashboards you build. Journal entries can be health information — moods, symptoms, habits — and are treated exactly like the rest: yours, and nobody else’s business.
Keys and tokens for connected services
API keys and OAuth tokens are encrypted with a Google Cloud KMS key before they are written to the database, so the database never holds a usable credential. Plaintext exists only in memory, only on the machine running a collection, and only for as long as that run takes. The run history records what ran and whether it worked; it never records the values.
Files you upload
Some sources take an export file rather than an API — an Apple Health export, for instance. The file is held on the server only while it is being read, then deleted. What remains is the measurements taken out of it, plus a fingerprint of the file so that re-uploading the same export does not double-count it.
Payment details
Payments run on Stripe, and card numbers never reach our servers — checkout happens on Stripe’s own page. What we store is the Stripe customer and subscription identifiers, your plan, your subscription status and the renewal date, which is what tells the app whether the subscription is live.
Server logs
Google Cloud keeps ordinary request logs for the service — time, path, response code, IP address — for 30 days, then deletes them automatically. No analytics product reads them; they exist so a broken deploy can be diagnosed.
What we never do
- We do not sell your data. Not to anyone, at any price, in any form.
- We do not share it. The companies in the list below process it on our behalf to run the service, under contract; nobody receives it for their own purposes.
- We do not use it to train models — ours or anyone else's — and no part of it is fed to an AI service.
- We do not run advertising, ad networks, affiliate tracking or data brokers, and we do not enrich your account with data bought from anywhere else.
- We do not read your journal or your health data except when you ask us to look at something, or to fix something you have reported.
These are structural rather than aspirational: subscriptions are the only income this product has, so there is no second business here that your data could be the raw material for.
Cookies and browser storage
This site sets no cookies, loads no third-party scripts, and sends no analytics anywhere. It writes exactly one thing to your browser: ql-theme, remembering whether you chose light or dark. Nothing on it identifies you, and nothing reports back.
The app keeps a little more, all of it functional: your sign-in session, so that every page does not ask you to log in again, plus ql-theme and ql-weight-unit — kilograms or pounds. That is the complete list, and none of it is a tracker.
Where it is kept, and how it is protected
The service runs on Google Cloud Run in the us-central1 region, in the United States. Your measurements, journal, goals and dashboards live in a Postgres database hosted by Neon. Traffic is encrypted in transit, and every request has to carry a verified sign-in token before it can read a single row — one account’s data is never reachable from another’s session.
Keys and tokens for connected services get the extra step described above: encrypted with a managed key, so a copy of the database on its own does not let anybody collect from your accounts.
If you are outside the United States, using QuantifiedLife means your data is transferred there and stored there.
No system is perfectly secure and it would be dishonest to say otherwise. If you find a weakness, please tell us at privacy@quantifiedlife.io before you tell anyone else, and you will get a real answer.
Who else processes it
Running the service means a few companies necessarily handle data on our behalf. This is the complete list; when it changes, this page changes with it.
| Who | What they do for us |
|---|---|
| Google Cloud | Firebase Authentication holds your sign-in and your email address; Cloud Run runs the app and the collectors; Cloud KMS guards the keys that encrypt your source credentials; Firebase Hosting serves this site; Cloud Logging holds the 30-day request logs. |
| Neon | Hosts the Postgres database your measurements, journal, goals, dashboards and encrypted credentials live in. |
| Stripe | Takes the payment and runs the subscription. Card details go to Stripe and never to us. |
Getting a copy, and getting it deleted
Both are buttons in the app, under Settings, and neither asks you to wait for us.
- An export is a complete copy of what we hold, downloaded on the spot: every measurement with its timestamp, unit and tags, plus your journal, goals, dashboard and source settings — as one NDJSON file or a zip of CSVs. Stored credentials are never included; the file notes which sources have one, never the values.
- Deleting your account removes everything under it — measurements, journal entries, goals, dashboards, and the stored credentials for your connected sources — plus the sign-in itself, and cancels any subscription. It is permanent: the app spells out exactly what is about to go and makes you type a confirmation before it will do it.
- Both work even if your subscription has lapsed. Holding your data until you pay to leave would be exactly the kind of thing this page is supposed to rule out.
- Stripe keeps its own record of payments you have made, because tax and accounting law requires it to. That part is outside our control and outside our database.
If you cannot reach the app — a lost sign-in, a closed account you want confirmed gone — email privacy@quantifiedlife.io from the address on your account and a person handles it within 30 days, usually much sooner.
You do not have to wait for us to stop collection: disconnecting a source in the app halts it immediately, and clearing its saved key removes the credential. Revoking QuantifiedLife’s access at the service itself — in your WHOOP, Strava or Google account settings — works too, and we would rather you had both routes.
Depending on where you live you may have legal rights to access, correct, export, or delete your data, or to object to how it is handled. We honour those requests from everybody, wherever they live, at the same address and on the same 30 days.
How long it is kept
Your measurements and entries are kept for as long as your account exists. That is the point of the product rather than a policy choice: correlations need months of overlapping history, and a store that quietly expired last year’s data could not do the job.
Nothing is deleted automatically when a subscription lapses — your history is waiting if you come back. If you would rather it were gone, delete the account in Settings and it is gone. Server logs expire on their own after 30 days.
Children
QuantifiedLife is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has an account here, email us and it will be deleted.
Changes to this policy
When this policy changes, the date at the top changes with it. Anything material — a new company on the processor list, a new category of data, a different answer to any question above — is written here before it takes effect, not after.
Contact
One address, and a person reads it: privacy@quantifiedlife.io. Exports, deletions, questions about anything above, or a security report — all of it goes there.
Curious what the service actually does with all this? Features and Pricing spell out the product and how it is paid for.