Life AI Kit

Privacy Policy

Version 2026-09-23 · last updated 23 September 2026

1. Who is responsible

The controller of your personal data for Life AI Kit is Titan Software z. s., IČO 29738725, Ametystová 702/46, Radotín, 153 00 Praha 5, Czech Republic, registered in the register of associations (spolkový rejstřík), file L 82236, kept by the Municipal Court in Prague ("we"). Contact: [email protected]. This is the service-specific privacy notice for Life AI Kit. It supplements Titan's general Privacy Policy; where the two differ for this service, this notice applies. We have not appointed a data protection officer.

2. What we process, why, and on what legal basis

  • Account — email address, optional name, a bcrypt hash of your password, the date you confirmed your email, and the Terms version you accepted. Purpose: giving you access to what you bought. Basis: performance of a contract (GDPR Art. 6(1)(b)).
  • Purchases — order status, amount, tax, currency, Stripe identifiers, and the time you consented to immediate access. Purpose: fulfilling and documenting the sale, refunds and chargebacks. Basis: contract (Art. 6(1)(b)) and our legal obligations under accounting and tax law (Art. 6(1)(c)).
  • Your use of the product — a record of which pages or recipes were opened, prompts copied and downloads made, linked to your account id, plus your 30-Day Challenge progress. Purpose: showing your progress and understanding which content is useful. Basis: contract for challenge progress; our legitimate interest in improving the product (Art. 6(1)(f)) for usage events. You may object at any time (section 7).
  • Security records — sign-ins, failed sign-ins, password resets, administrative changes and account deletions, with the IP address they came from; temporary rate-limit counters (stored as one-way hashes). Purpose: protecting accounts and investigating abuse or incidents. Basis: legitimate interest (Art. 6(1)(f)) and our security obligations (Art. 32).
  • Messages you send us — name, email and message from the contact form or email. Purpose: answering you. Basis: contract or legitimate interest (Art. 6(1)(b)/(f)).
  • Emails we send — only transactional messages (email confirmation, purchase confirmation, password reset and change notices, refund and payment notices). We do not send marketing email.

We never receive your card number or security code — payments are handled entirely by Stripe. Providing your email address is necessary to buy and to hold an account; everything else is optional.

3. Automated decisions

When Stripe tells us a payment was fully refunded or disputed (chargeback), access bought with that payment is removed automatically, and restored automatically if a dispute is decided in your favour. No profiling takes place. If you think access was removed wrongly, contact us and a person will review it.

4. Who receives your data

  • Stripe (Stripe Payments Europe, Ltd., Ireland, and its group companies) — payment processing and fraud prevention. Stripe acts as an independent controller for the payment data it collects.
  • Resend (Plus Five Five, Inc., USA) — delivery of our transactional emails and of contact-form messages to our support inbox. Processor under a data processing agreement.
  • Data centre — Coolhousing s.r.o. (data centre in Prague, Czech Republic): houses the server that runs the service and its database (colocation — space, power and connectivity). The server and the data on it are operated by us.
  • Cloudflare (Cloudflare, Inc., USA) — content delivery and protection against attacks: every request to the website passes through Cloudflare's network, which processes your IP address and the technical details of the request. Processor under Cloudflare's data processing agreement.

We do not sell your data and do not use advertising or third-party analytics trackers.

5. Transfers outside the EEA

Cloudflare, Resend and parts of the Stripe group are located in the USA. Transfers rely on the EU–US Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's Standard Contractual Clauses. Ask us for a copy of the relevant safeguards.

6. How long we keep it

  • Account data: until you delete your account (you can do this yourself on the Account page).
  • Unconfirmed accounts with no purchase: deleted automatically after 30 days.
  • Order records: for the period required by Czech accounting and tax law; if you delete your account, the order is kept with your email replaced by a non-reversible placeholder.
  • Usage events: 395 days.
  • Security records: 365 days. Rate-limit counters: until their time window ends.
  • Password-reset and email-confirmation links: 1 day.
  • Stripe event ids (used to avoid processing a payment twice): 90 days.
  • Contact messages: as long as needed to handle your request, and at most 2 years.
  • Backups: overwritten on a rolling basis; deleted data disappears from backups within that cycle.

7. Your rights

You have the right to access your data, to have it corrected or erased, to restrict its processing, to data portability, and to object to processing based on legitimate interest. You can download a copy of your data and delete your account yourself on the Account page, or write to [email protected] — we reply within one month. You also have the right to lodge a complaint with the Czech data protection authority, Úřad pro ochranu osobních údajů (uoou.gov.cz), or the authority where you live.

8. Cookies

We only use cookies that are strictly necessary for signing in: authjs.session-token (keeps you signed in, up to 7 days), authjs.csrf-token (protects sign-in forms) and authjs.callback-url (returns you to the right page after sign-in). No analytics or advertising cookies are used, so no consent banner is needed.

9. Security

Passwords are stored only as bcrypt hashes, sessions are signed and encrypted and end immediately when you change your password, administrator accounts require two-step verification, and payment notifications from Stripe are verified cryptographically. If a personal-data breach affects you in a way that poses a high risk, we will tell you.

10. Changes

We will publish any change here with a new version and date, and notify account holders by email before material changes take effect.