Information Security & Data Protection Policy

LIFE Direct (the "Company") · Version 1.0 · Effective July 3, 2026 · Owner: Enzo Weinberg, Founder & Security Lead · Reviewed quarterly and after any material change to the Service

1. Purpose & scope

This policy defines how LIFE Direct identifies, mitigates, and monitors information-security risk across the application at lifedirectapp.com, its backend systems, and the vendor services it relies on. It applies to everyone with administrative access to production systems (currently the Founder) and to all consumer data the Service processes.

2. Governance

3. Access control

4. Data protection

5. Secure development & vulnerability management

6. Data retention & deletion

DataRetainedDeleted
Account profile, receipts, items, calendars, notifications, AI memoryWhile the account is activeImmediately and permanently on account deletion (Settings → Delete account), which cascades across all user tables and ends all sessions
Vault documents (encrypted)While kept by the userOn user deletion of a document, or account deletion
Linked-bank access tokens / account IDsWhile the bank connection is activeOn disconnect (access is also revoked at the vendor) or account deletion
Transaction data from bank vendorsNot persisted — fetched on demandn/a
Infrastructure volume snapshotsProvider-managed, short-livedExpire automatically on the provider's schedule (days, not months)

7. Consumer consent

Users create accounts deliberately and are shown Terms & Privacy at signup; connecting a bank is an explicit, separate user action performed through the vendor's own consent flow; family location sharing is off by default and requires the family member's approval. Children's accounts are restricted and parent-linked.

8. Incident response

On indication of a security incident: contain (revoke affected credentials/sessions, take affected systems offline if needed) → assess scope and affected users → notify affected users and vendors without undue delay, and within any timeline required by applicable law → remediate and review (root-cause fix, then a written post-incident review feeding back into this policy).

9. Subprocessors

VendorPurpose
Fly.ioApplication hosting, encrypted storage
StripeSubscription payments; bank account connections (Financial Connections)
PlaidBank account connections
GoogleSign-in with Google (identity)
AnthropicAI assistant processing
ElevenLabsVoice synthesis
Questions about this policy or a security concern to report? Email inquire@wineinc.net — reports are acknowledged promptly and handled under Section 8. See also our Terms of Service and Privacy Policy.