Privacy policy
Effective from 7 August 2026. Version 1.0.
This policy covers the person who holds the account: a parent, a guardian, an adult learner in Self Mode, or a member of staff at an institution. Anything concerning a person under 18 is governed by our children’s data policy, which takes precedence wherever the two differ.
Who we are
LifeCraft is operated by Precision Pulse. For your information we are the data fiduciary under India’s Digital Personal Data Protection Act 2023, and the controller where the General Data Protection Regulation applies. Questions go to privacy@lifecraft.in, and formal complaints to our grievance officer.
What we collect
| Category | What it includes |
|---|---|
| Account details | Your name, email address, a hashed form of your password, your role, language, timezone and country |
| Learner records you create | The profiles, mission activity, observations, reflections, scores and any evidence files you add. For a child this is covered by the children’s data policy |
| Consent records | What you agreed to, when, and against which version of which policy, held as an append-only ledger |
| Subscription and billing | Your plan, billing cycle, subscription status, invoices and the identifier your payment provider gives us. We never receive or store your full card number |
| Security and audit records | Significant actions on your account, with a one-way hash of your IP address and your browser user agent. These contain no mission content and no observations |
| Correspondence | Emails and support messages you send us, and our replies, so we can resolve things and show what was said |
We do not collect precise location, contacts, biometric data or government identifiers from anyone, at any age.
Why we are allowed to hold it
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, delivering the programme | Performance of our contract with you |
| Processing anything about a child | Your verifiable consent as the guardian, recorded per purpose |
| Taking payment, issuing invoices, meeting tax obligations | Contract and legal obligation |
| Keeping accounts secure, preventing abuse, keeping audit records | Our legitimate interest in a service that is not trivially attacked |
| Improving the framework and scoring using aggregated, de-identified data | Our legitimate interest, and consent where a child is involved |
| Sending marketing email | Your consent, withdrawable at any time |
How we use it
- To run the weekly mission cycle and calculate the Life Readiness Score.
- To produce your reports and certificates.
- To send service messages you need: mission reminders, security alerts, receipts, renewal notices and policy changes. These are part of the service and are not marketing.
- To answer your questions and handle complaints.
- To detect and stop fraud, abuse and unauthorised access.
- To improve the framework and the accuracy of our scoring using data that has been aggregated and de-identified, meaning combined with many other records so that no individual can be singled out.
We do not sell, rent or trade personal data. We do not show advertising anywhere in the product, and we never build advertising profiles.
Automated decisions
The Life Readiness Score is calculated by published, deterministic rules from observations that a human recorded. It is not artificial intelligence and it does not make decisions about you. LifeCraft contains no AI features. Nothing in the product produces a legal or similarly significant effect automatically.
Who we share it with
We use a small number of service providers to deliver the product. Each one acts only on our instructions, is bound by contract, and is never permitted to use your data for its own purposes.
| Provider | What they do for us |
|---|---|
| Razorpay | Takes payment from customers in India and holds the card details we never see |
| Stripe | Does the same for customers outside India |
| Resend | Delivers our email: verification codes, receipts, reminders and notices |
| Cloudflare | Sits in front of the site to filter attacks and serve static files. It processes connection data, not your account content |
| Sentry | Receives error reports so we can fix faults. Our logs and error reports are written so they never carry personal data, tokens or anything about a child |
| Hostinger | Hosts the servers and the database in Mumbai, India |
We also share data where the law requires it, such as a valid order from a court or a regulator, and we will tell you unless we are legally prevented from doing so. If the business is ever sold or restructured, your data moves under the same commitments, and you will be told before that happens.
Where your data lives
Accounts, learner records, observations, scores and backups are stored on servers in India. Backups are encrypted and also held in India. Children’s records never leave India.
Some of the providers above operate infrastructure outside India, in particular for payment processing, email delivery, edge filtering and error monitoring. Where a transfer happens we limit it to the minimum needed for that function, we rely on contractual safeguards including the standard contractual clauses where the General Data Protection Regulation applies, and we do not transfer children’s mission content, observations or scores.
How long we keep it
- Account and learner records: for as long as your account is open.
- After you close your account or ask for deletion: permanently deleted within 30 days, apart from the exceptions below.
- Inactive accounts: if there is no sign-in for 24 months we contact you, and if there is no response we delete the account.
- Billing and tax records: kept for the period Indian tax and accounting law requires, even after the account closes.
- Consent records and security audit logs: kept for as long as we are required to be able to show what was agreed and what happened. They contain no mission content and no observations.
- Backups: a deleted record can persist in an encrypted backup until that backup ages out of the 30-day retention window, after which it is gone.
Your rights
Whatever country you are in, you can:
- See everything we hold about you and the learners on your account.
- Download it as a file you can keep or move elsewhere.
- Correct anything that is wrong or incomplete.
- Withdraw any consent you gave, without affecting processing that already happened.
- Have your account and its records permanently deleted.
- Object to processing we do on the basis of legitimate interest.
- Nominate another person to exercise these rights on your behalf if you die or become incapable of acting, as the Digital Personal Data Protection Act provides.
- Complain to us, and then to a regulator if we do not resolve it.
Most of this is self-service in Settings, then Data and privacy. Otherwise write to privacy@lifecraft.in. We respond within 30 days. Because export and deletion are irreversible, we ask you to confirm your password again before either one runs, and we may ask for more information if we genuinely cannot tell that a request is yours.
Marketing
We only send marketing email if you have opted in, and every one of those emails has an unsubscribe link that works immediately. Unsubscribing does not stop service messages such as receipts, security alerts and policy changes, because those are part of holding an account.
Cookies
We use strictly necessary cookies only. There are no advertising cookies and no third-party trackers anywhere in the product. The detail, including every cookie by name, is in our cookie policy.
How we protect it
Passwords are hashed with argon2id, traffic is encrypted in transit, files are private by default, and access to the database goes through a layer that requires your session and enforces who owns what. The full description is on our security page, along with how to report a vulnerability.
Contact and complaints
For anything about this policy, email privacy@lifecraft.in. If you are not satisfied with our answer, our grievance officer will take it up, and you can escalate to the Data Protection Board of India, or to your supervisory authority if you are in the European Economic Area or the United Kingdom. You never need our permission to do that.
Changes
If we change this policy in a way that affects you, we will tell you before the change takes effect and, where the change requires it, ask for your consent again. Every version is retained so you can see what you originally agreed to.