LifePilot Privacy Policy

Effective September 27, 2026

LifePilot is a private journal from PilotSuite LLC. You do not create a LifePilot account. Your journal is stored on your device, not in a PilotSuite journal cloud. Some optional features send information to service providers so they can work. This policy explains those cases.

Journal data on your device

New entries and attached images are encrypted in the app's local storage. Entries created by older versions are moved into the encrypted format after you unlock and open them. Entry dates and favorite status remain in the local database so the timeline can work. Your passphrase and encryption key are not sent to PilotSuite. We cannot recover a forgotten passphrase or restore entries that you have not backed up. Backups and items you export or share go to the destination you choose and are then governed by that destination's practices.

Optional AI and voice features

When you choose an AI feature, LifePilot sends the material needed for that request, such as your question, relevant entry excerpts, text for an embedding or spoken response, or audio for transcription. The request passes through a PilotSuite relay hosted by Vercel to OpenAI. We do not keep a journal database on that relay or intentionally log request bodies. Chat requests ask OpenAI not to store the generated response as application state. OpenAI may still retain abuse-monitoring logs under its API data controls, including some request content, for up to 30 days by default. Do not use an AI feature for material you do not want to send for processing.

Free voice capture, including Quick Capture, uses the device platform's speech facilities, which may process audio according to your device settings and Apple or Google's terms. Premium voice transcription uses the AI relay described above.

Network and subscription information

The relay processes your IP address to limit abuse. It stores a per-IP request counter in Upstash Redis for about 24 hours. Vercel may process network metadata and operational logs to deliver and protect the service. LifePilot checks the relevant app store for app updates where supported and Expo for app updates delivered over the air.

Subscriptions are handled by Apple or Google and RevenueCat, depending on where you installed the app. RevenueCat creates an anonymous app user ID and processes purchase receipts and entitlement status so LifePilot can unlock Premium and restore purchases. PilotSuite does not receive your payment card number. The app store and RevenueCat may retain transaction records according to their own policies and legal duties.

What we do not do

LifePilot does not require a name or email address to use the journal. We do not sell journal content, use it for advertising, or run our own behavioral analytics in the app.

Your choices and deletion

You can use the journal without AI features. Settings includes Erase Local Data. Erasing local data removes LifePilot's entries, images, reminders, keys, and app settings from that device; it does not erase backups or shares you saved elsewhere or cancel a subscription. You can manage or cancel a subscription in your Apple or Google account settings. For steps and requests concerning data held by PilotSuite or its providers, see Delete LifePilot data.

Service providers and changes

LifePilot uses Apple or Google, RevenueCat, Vercel, Upstash, OpenAI, and Expo for the functions described above. We may update this policy when the app changes; the effective date on this page will change. PilotSuite LLC is responsible for this policy and can be reached at pilotsuite.admin@pilotsuite.design.