Security Policy
Last updated: 21 August 2026
LifeOS AI ("we") takes the security of your personal information seriously. This Security Policy provides a high-level overview of the practices we follow to protect the Service and your data. It is separate from the account-level security settings available within the app. We are a company registered in the Republic of South Africa and process personal information in accordance with POPIA.
1. Data protection by design
We apply the principles of data protection by design and by default. Access to your data is restricted on a least-privilege basis and enforced through row-level security rules so that only you and those you explicitly authorise can view or act on your records.
2. Authentication and account security
- Secure authentication with session management and token-based access.
- Optional two-factor authentication (2FA) to add a second verification step to your account.
- OTP-verified email changes to prevent unauthorised account takeover.
- Audit logging of security-relevant actions on your account.
3. Data sharing and consent
Cross-user data sharing (for example, a coach viewing a client's data) is enforced server-side against an explicit permission and consent record. Access can be revoked at any time, and all grants are logged for auditability.
4. Encryption and transport
Data in transit is protected using TLS. Sensitive credentials and secrets are stored server-side and never exposed in frontend code. Payment processing is handled by our certified payment partner, iKhokha, and we do not store full card details.
5. AI and safety guardrails
AI Coach interactions include safety guardrails, including crisis-resource surfacing when potential self-harm is detected and a non-overridable safety policy that all coaching agents follow. AI outputs are suggestions only; all implementation remains at your sole discretion.
6. Monitoring and incident response
We monitor the Service for security events and maintain an incident response process. If we become aware of a security incident affecting your personal information, we will take reasonable steps to investigate, contain, and notify affected users and regulators where required by law.
7. Reporting vulnerabilities
If you believe you have discovered a security vulnerability, please follow the guidance in our Responsible Disclosure page rather than testing it on the live Service. We appreciate responsible reporting and will acknowledge good-faith submissions.
8. Changes to this policy
We may update this Security Policy from time to time. Material changes will be reflected in the "Last updated" date above.
