Security Architecture
Life Engine is built so you can see how access works — not behind marketing fog. Here is what actually protects your data today: Postgres Row Level Security, TLS in transit, hosting-provider encryption at rest, and a visibility model that controls sharing between people.
Four Pillars of Protection
These are the controls the product ships with. They are not certifications, pen-test calendars, or claims that operators cannot read your data.
Data Encryption
Data moves over TLS. At rest, encryption is provided by the hosting platform (Supabase and its cloud provider) — not by encrypting on your device before upload. Storage is not operator-blind; privileged platform access can still read stored data.
Access Control
Every app-table query is constrained by Postgres Row Level Security. Clients use the authenticated role; there is no privileged app server sitting above the database for normal product paths.
Privacy by Design
The Visibility Model controls what other people in your household can see — Private, Shared, and Restricted tiers enforced in the data layer. That is user-to-user privacy, not a promise that Life Engine operators cannot access stored data.
Infrastructure Security
Life Engine runs on managed cloud infrastructure (Supabase). We rely on the provider for hosting hardening, transport security, and platform backups — and we document product controls rather than inventing audit badges.
The Visibility Model
Life Engine gives you control over what other household members can see. The three-tier Visibility Model operates at record and field level — for example, share a vehicle record while keeping purchase price Private. Enforcement is via Row Level Security between users, not operator-blind storage.
Hidden from other household members by default — not your family members and not your partner unless you explicitly share it. Enforced at the database level by Row Level Security.
Visible to members of your household or family node. Use this for shared logistics like vehicle maintenance schedules, family calendars, and collaborative task lists.
Visible only to specific people you explicitly grant access. Useful for sensitive records that need to be shared with one person, like financial data shared with a partner.
Security Practices
Security here means the controls that are actually in the stack today — authentication, RLS, and client access patterns — not a continuous-integration scanner or external assessment calendar we do not run.
Authentication Security
Database Security
Application Security
Operational Security
Use in-product export tools for domains that support them. A universal full-account export is not guaranteed yet — contact us if you need help getting your data out.
Account deletion is available from security settings. We process deletion of your account data; backup retention follows the hosting provider’s normal lifecycle rather than a marketed 30-day guarantee.
Where exports exist, they use ordinary formats you can take elsewhere. We aim to widen portability over time without locking you in with proprietary formats.
You Own Your Data. Period.
Records you create belong to you. Life Engine is the product surface and hosting arrangement — not a claim that we sell or re-license your personal content. You can delete individual records in-app, and you can delete your account from security settings.
Domain exports exist where the product ships them (for example contacts or finances reporting). We do not promise a single full-account CSV/JSON dump of every domain today. Full portability improvements are tracked as product work, not as a guaranteed one-click export.
Honest About Standards
Life Engine is built in Australia. We aim to handle personal information carefully and align with Australian privacy expectations. We do not claim formal certifications we have not earned.
Australian Privacy Act
We aim to align with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) — transparent handling, access and correction paths, and clear contact for privacy requests. This is intent and product design, not a lawyer-signed compliance certificate.
Secure Development Habits
We prefer least privilege, RLS-first data access, and small surfaces over checklist theatre. This project has no continuous-integration security gate and we do not market one.
Transport & Storage Encryption
In transit: TLS via the platform. At rest: encryption provided by the hosting provider. We do not market Life Engine–owned key management or device-pinning schemes as product features.
Hosting & Data Location
Data is stored on Supabase-managed infrastructure. We will be transparent about region and provider choices as the deployment hardens; we do not invent certified-data-centre marketing claims beyond the provider’s own posture.
Privacy Principles
We aim to follow common privacy principles — collect what the product needs, purpose limitation, and a path to erase your account. International privacy frameworks inform our thinking; we do not claim formal certification under them.
No Fake Certifications
We do not claim formal third-party audit certifications, assessment calendars, or other badges we have not earned. If that changes, this page will say so with evidence — not aspiration dressed as fact.
What We Will Never Do
Trust needs clear boundaries. These are product and policy commitments we hold ourselves to — not a substitute for reading the Privacy Policy and Terms.
Your personal data will never be sold to third parties, advertisers, data brokers, or anyone else. This is a foundational principle, not a negotiable business decision.
We will never share your data with any third party without your explicit, informed consent. Legal requirements are the only exception, and we will notify you whenever legally permitted.
We do not and will never analyse your personal data to build advertising profiles, serve targeted ads, or generate marketing insights for third parties.
We will never use deceptive design to trick you into sharing more data than you intend, downgrading your privacy settings, or making it difficult to delete your account.
Your personal information will never be used to train machine learning models, artificial intelligence systems, or large language models. Your data serves you and only you.
We will never bypass Row Level Security, ship a privileged client path for normal app data, or gut visibility enforcement to make development faster.
Report a Vulnerability
If you discover a potential vulnerability in Life Engine, please tell us. We take reports seriously and aim to respond when we can. Dedicated security mailboxes are not live yet — use the Contact page for now. Responsible disclosure is appreciated.
Go to ContactYour Data. Your Control. Your Life Engine.
A LifeOS built around visibility you control and access enforced in the database — not slogans. Start when you are ready, and read the Privacy Policy for the full legal picture.