WWinLife

Privacy Policy

Effective and last reviewed September 15, 2026

WinLife (app.winlife.ai) is a private, invite-only dashboard for personal finances, goals, habits, and memories. It is run by Tobias Diaz Fraga LLC (“we”). This policy explains what WinLife collects, how it is used, and the choices you have. Questions: tobiasdiazfraga@gmail.com.

What we collect

  • Your account: your email address and, if you add them, your name, birthday, and time zone; your member number; and who invited you.
  • Invites you send: each link’s label and status, and the email address someone typed on it. The link itself is stored only as a one-way hash.
  • If you request an invite on winlife.ai: your name and email, kept only to reply to you, until you’re invited or you ask us to delete it. We don’t add you to any mailing list. To limit spam, we also keep a one-way hash of your IP address (not the address itself) for no more than a day.
  • What you add: the finances you log (expenses, income, balances, investments), goals, journal entries, to-dos, workouts, calendar events, and memories, including links and photos you upload.
  • Bank data, only if you connect a bank through Plaid: the institution’s name; each account’s name, type, and last four digits; balances; transactions (date, amount, merchant, and category); and investment account balances.
  • We never receive or store your bank username or password, or your full account and routing numbers.
  • If you use the assistant: a daily count of your requests and what they cost, to enforce a daily limit, and, if you set up Siri, each Siri key’s name and when it was last used (the key itself is stored only as a one-way hash).
  • Google Calendar, only if you connect it: the names and colors of your calendars, which ones you chose to show, and your Google account’s email address. Your events are read from Google when you look at them and are not stored.
  • Phone notifications, only if you turn them on: a push address for each device you turn them on for (issued by Apple, Google, or Mozilla) and the device’s name, plus the nudge settings on your goals and a short history of the nudges sent.
  • Basic technical logs kept by our hosting providers (such as IP address and browser type) to run and secure the service.

How we use it

Only to run WinLife for you: showing your dashboard, filling in your net worth snapshots with your bank balances, listing new bank transactions for you to review and log, showing your Google Calendar, finding free time for the goals you asked to be nudged about, and, when you ask the assistant, doing what you asked.

We do not sell your data or use it for advertising, and other members can't see it, except a memory you choose to share (below). Access to the database is limited to the operator, for maintenance and support.

Friends and family

  • WinLife is invite-only. The person who invites you is recorded (so the network of who invited whom can be shown), and you get a member number. Other members see only your first name, member number, and join date, and only if they invited you or you invited them.
  • The admin (the operator) can see each member's name, email, member number, join date, who invited them, how much of the assistant's daily limit they used, and how many banks they connected, and can turn the assistant or bank connections on or off for a member. The admin page never shows your money, goals, journal, or other entries.
  • Sharing memories: you can link someone in your People to their WinLife account (they accept). Tagging them on a memory then asks them to add it to their Memories; if they accept, they see it read-only: its title, dates, places, story, highlights, videos, links, and cover. Never your feelings, lessons, or rating, and nothing else in your account. Untag them or unlink them and it disappears from their account.

Connecting a bank with Plaid

WinLife uses Plaid Inc. to connect to your bank. On Plaid’s screen you choose which bank and which accounts to share, and Plaid’s End User Privacy Policy applies to how Plaid handles your information. WinLife can only read balances and transactions; it cannot move money.

Connecting a bank requires two-factor sign-in. You can disconnect a bank at any time from Money → Accounts.

Connecting Google Calendar

Connecting Google Calendar is optional and read-only: WinLife asks Google for three narrow, read-only permissions: to see your list of calendars (calendar.calendarlist.readonly), to view their events (calendar.events.readonly), and to see when you’re busy (calendar.events.freebusy). It can never add, change, or delete anything in your calendars. You choose which calendars WinLife shows, and they appear on their own tab, separate from the rest of WinLife.

WinLife keeps only an access key from Google, encrypted with a key that exists only on the server and stored where no signed-in session can read it. Events are fetched from Google when you open the calendar and held in the server’s memory for about two minutes, never written to the database. For goal nudges, WinLife asks Google only when you’re busy (start and end times, not what the events are). If you ask the assistant a question about your calendar (“what’s on tomorrow?”), the matching events’ titles, times, and places are sent to Anthropic to answer it (see below).

WinLife’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to show you your calendar and find free time; it is never sold, used for advertising, or used to train AI models, and no person reads it unless you ask us to for support, it’s needed for security, or the law requires it.

Disconnect any time from Settings → Connections or the Google tab: WinLife revokes its access at Google and deletes the stored key and calendar list immediately. You can also remove access from your Google Account’s security settings.

Phone notifications

If you turn on notifications for a device (for example WinLife on your iPhone’s home screen), WinLife stores that device’s push address and sends at most one goal nudge a day, like “Found 30 min Thursday 6 pm for ‘Call Mom’”. The notification’s text passes through your device maker’s push service (Apple, Google, or Mozilla) to reach you. Remove a device in Settings → Notifications and its push address is deleted.

The AI assistant

“Ask WinLife” (typed, dictated, through Siri, or from a screenshot) is powered by Claude, a model run by Anthropic PBC. When you use it, WinLife sends Anthropic your message and the parts of your WinLife data it needs to act on it: for example your category and people names, this week’s to-dos, your active goals, today’s workout, the spending totals you ask about, or the screenshot you upload. Bank access tokens, passwords, and account numbers are never sent.

Anthropic processes this under its commercial terms, which don’t allow it to train its models on your data, and keeps it only for a limited time (see Anthropic’s privacy center). WinLife doesn’t store your conversations: the panel forgets them when you close it. What the assistant saves appears in your data and your activity log, marked “via assistant” or “via Siri”, and you can edit or delete it like anything else. Screenshots are read once and not kept; only the transactions go to your Expenses inbox for you to review. The same goes for a photo or screenshot of a workout plan: it’s read once and becomes a draft program you review.

Spreadsheets and CSV files you bring (bank exports, gym plans) are read by WinLife itself, not by the assistant, and the file isn’t kept: only the transactions or the plan you choose to save.

Siri keys can only add things, never read or change your data, and you can revoke one at any time in Settings.

Service providers

  • Supabase: database and sign-in, including the emails with your sign-in codes (United States).
  • Vercel: hosting.
  • Plaid: bank connections.
  • Google: when you add a YouTube video or a Google Drive folder to a memory, WinLife fetches its title and thumbnails; and, if you connect it, Google Calendar (read-only, see above).
  • Apple, Google, and Mozilla push services: deliver phone notifications, only if you turn them on.
  • Anthropic: the AI assistant (see above), only when you use it.
  • Tiingo: market prices. No personal data is sent.

They handle data only to provide their services to WinLife.

How we protect it

  • Accounts are invite-only. Two-factor sign-in is optional for members, required for the admin, and required to connect a bank.
  • Each member can reach only their own data, enforced by the database itself.
  • Data is encrypted in transit (HTTPS) and at rest. Bank and Google Calendar access tokens are encrypted a second time with keys that exist only on the server.

How long we keep it, and deleting it

  • We keep your data while your account is open.
  • Disconnecting a bank immediately revokes WinLife’s access at Plaid and deletes the stored access token, the bank’s account records, and any transactions you haven’t logged. Expenses you already logged stay in your ledger until you delete them.
  • Disconnecting Google Calendar immediately revokes WinLife’s access at Google and deletes the stored key and your calendar list. Removing a device from notifications deletes its push address.
  • You can delete individual entries at any time.
  • You can delete your account and everything in it yourself, in Settings → Close your account. It happens immediately: any bank is disconnected at Plaid, your files are deleted from storage, and every row you own is deleted. Nothing is archived. You can also email tobiasdiazfraga@gmail.com and we’ll do it within 30 days and confirm. Copies in routine backups are removed as those backups expire, within 30 days.

Your choices and rights

You can ask for a copy of your data, or ask us to correct or delete it, by emailing us; we respond within 30 days. Depending on where you live (for example, California), you may have additional rights, and we honor these requests for every member. We do not sell or share personal information.

Children

WinLife is invite-only and not intended for children under 13.

Changes to this policy

We review this policy at least once a year. If we make a material change, we’ll update the date above and let members know in the app or by email.

Contact

Tobias Diaz Fraga LLC · tobiasdiazfraga@gmail.com