Skip to main content
Compliance Hub
Institutional Documentation

Data Privacy Practices

Last updated: September 2026Documentation status: Current documentation

This page documents LifeLeveled's current data privacy practices. It describes what data is collected, how it is used, who can access it, and the rights available to users and institutions.

Important: This documentation describes current practices based on the application's code and infrastructure. LifeLeveled has not independently verified the data practices of its third-party service providers, including AI vendors. Institutional data privacy obligations are defined in the contractual agreement.

1. Categories of Information Collected

LifeLeveled collects the following categories of user information:

  • Account information: email address, full name, and role (admin or user).
  • User-generated content: budgets, bills, savings goals, emergency fund configurations, weekly check-ins, simulator profiles and progress, resume profiles, roleplay practice sessions, and AI coach conversations.
  • Usage analytics: event tracking for feature usage (e.g., lesson started, pricing page viewed) via the platform's analytics system.

LifeLeveled does not collect biometric data, location data, or contact list information. Camera Coach uploads (if used) are processed through the platform's integration layer and are not stored permanently in the application database.

2. Purpose and Legal Basis for Collection

User data is collected and processed for the following purposes:

  • Providing educational features. Budgets, bills, savings goals, simulator profiles, and other user-generated content are used to deliver the platform's life-skills educational features.
  • Progress tracking. User progress data enables the platform to track learning milestones, skill development, and achievement unlocking.
  • AI feature delivery. User inputs to AI features (Coach, Roleplay, Camera Coach) are processed through the platform's integration layer to generate responses.
  • Communication. Email address is used for account notifications, password resets, and platform communications.
  • Product improvement. Aggregate, anonymized usage analytics help improve the platform's features and user experience.

The legal basis for data processing depends on the user's jurisdiction and the institutional agreement. For institutional deployments, the legal basis is defined in the contractual agreement with the institution.

3. User and Institutional Access

User access: Users can view and manage their own data through the application. Row-level security (RLS) rules enforce that users can only read, update, or delete their own records. Users cannot access other users' data.

Institutional access: Organization administrators can view aggregate organizational data through the org dashboard and corporate admin pages. Admin users (as defined by the platform's role system) can access user records for support purposes, as permitted by the RLS configuration on each entity.

4. Service Providers and Third-Party Disclosures

LifeLeveled uses the following service providers to operate the platform:

  • Base44. Provides hosting, database, authentication, and AI integration infrastructure. User data is stored in the Base44 platform's database.
  • Stripe. Processes payments. Card data is handled by Stripe's PCI-compliant infrastructure and is never stored in the LifeLeveled application.
  • Google, Microsoft, Apple, Facebook. Provide OAuth authentication. These providers receive authentication requests but do not receive user-generated content.

LifeLeveled's application code does not include advertising integrations or third-party advertising SDKs. However, LifeLeveled has not independently verified whether its service providers use data for their own purposes beyond providing the contracted services. Service provider data practices are governed by their respective terms and privacy policies.

5. AI-Related Data Use

LifeLeveled's AI features (AI Coach, Roleplay, Camera Coach, Driver AI) process user inputs through the Base44 platform's integration layer (InvokeLLM). User inputs are sent to the AI model to generate responses.

What is known: AI inputs and responses are processed through the platform's integration layer. AI feature access can be controlled by administrators through the feature flag system.

What is not known: LifeLeveled has not independently verified whether its AI vendors use user inputs for model training, model evaluation, or other purposes beyond generating the requested response. LifeLeveled does not make claims about AI vendor data practices that it cannot verify.

6. Data Retention and Deletion

Account deletion: Users can request account deletion through the in-app delete-account function. This function processes the deletion request and removes the user's account and associated data.

Data retention: For institutional deployments, data retention periods and deletion procedures are defined in the contractual agreement with the institution. For individual users, data is retained for the duration of the user's account unless the user requests deletion.

Camera Coach uploads: Files uploaded to the Camera Coach feature are processed through the platform's integration layer. LifeLeveled tracks these uploads but does not provide a permanent storage endpoint for them in the application database.

7. Data Export and Correction Requests

Profile editing: Users can view and update their profile information (full name) through the profile settings page.

Data export: Users can view their own data through the application's various feature pages. A comprehensive bulk data export feature is partially available — users can access their data through individual feature interfaces, but a single-click full data export is not yet fully implemented.

Correction requests: Users can correct their own data by editing it directly in the application. For data that cannot be self-corrected, users can contact info@lifeleveled.org for assistance.

8. Cookies and Analytics

LifeLeveled uses the platform's built-in analytics system to track usage events (e.g., lesson started, pricing page viewed). These events help improve the platform's features and user experience.

The application does not include third-party advertising cookies, advertising tracking SDKs, or social media tracking pixels. Analytics events are processed through the platform's analytics infrastructure.

For institutional deployments, analytics configuration can be discussed as part of the institutional agreement.

9. Student, Parent, and Institutional Rights

Student and parent rights: For users under 18, LifeLeveled is designed to be deployed under institutional agreements that define the rights of students and parents regarding data access, correction, and deletion. These rights are exercised through the institution.

Institutional rights: Institutions have the right to:

  • Configure data retention and deletion schedules per institutional policy
  • Manage user access and roles within their organization
  • Request data export for institutional review
  • Define breach notification terms in the contractual agreement

These rights are defined and exercised through the institutional agreement, not unilaterally by LifeLeveled.

10. Contact Information

For questions about data privacy practices, to request data access, correction, or deletion, or to discuss institutional privacy requirements, please contact:

info@lifeleveled.org

LifeLeveled will respond to privacy inquiries within a reasonable timeframe. For institutional deployments, response timelines and escalation procedures are defined in the contractual agreement.

What this page does not claim: LifeLeveled does not claim that user data is "never sold," "never used for advertising," "never shared with third parties," or "never used to train AI models." These absolute claims cannot be independently verified without vendor agreements. What can be verified is that the application code does not include advertising integrations, and that user-generated content is protected by row-level security.