Privacy Policy
Last updated: 23 September 2026
For privacy questions, data requests, or to exercise any of the rights below, email hello@365alive.uk. We aim to respond within 30 days, as required by UK GDPR.
365ALIVE ("we", "us", "our") is a wellness companion app operated under the trading name 365ALIVE LTD. This policy explains what personal information we collect when you use the 365ALIVE app or website (the "Service"), how we use it, who we share it with, and the choices you have. We aim to keep this short and human — if anything is unclear, email us at hello@365alive.uk.
What we collect
We store your account details and profile preferences (such as your display name, location and notification choices) securely in our database so your settings sync across your devices. You can download all your personal data at any time from Profile, and permanently delete your account and data from the Danger Zone.
- Account info — your email address and (optionally) your first name, used to sign you in and personalise the app.
- Wellness content you create — goals, gratitude entries ("Small Wins"), daily reflections, Life List items, saved places, AI trip plans, museum entries, water glasses logged, daily food vibe (one emoji per day, no calorie tracking), optional manual step counts, and the completion timestamps of activities you tick off (Walk, Move, Breathe, daily check-ins). This is stored in your account and only ever shown to you — we have no social feed, friends list, or public profile.
- Reminder notifications you opt into — when you tap "Yes, remind me" on the home screen (or enable push in Profile), the reminder is scheduled locally on your device by your phone's operating system. We never see whether or when it fires. You can revoke at any time from your phone's settings or from Profile.
- Approximate or precise location — only when you actively use "Go Explore" or trip-planning features. We use this to find places near you and never store your raw location alongside your account; we use it only to perform the search you asked for.
- Subscription and billing data — handled by Stripe. We never see or store your card details. We keep your Stripe customer ID, plan status, and credit balance so you keep access to what you've paid for.
- Basic usage analytics — anonymous events such as which screens were viewed, used to improve the product. We do not sell this data.
How we use it
- To run the app and the features you ask for.
- To keep your account secure and prevent abuse.
- To process payments and manage subscriptions through Stripe.
- To send transactional emails (sign-in links, billing receipts).
- To improve the app, fix bugs, and decide what to build next.
Who we share it with
We only share data with the small number of providers we need to run the Service:
- Supabase — authentication and account storage.
- Neon (PostgreSQL) — your goals, journal entries and other content.
- Stripe — payments and subscription management.
- Google Places — used to look up places when you actively search.
- OpenStreetMap (Overpass API), Wikipedia and Wikimedia Commons — used to fetch free walking trails, nature, heritage sites and their photos / short descriptions when you search Go Explore. Their servers see your IP address and the search query (e.g. radius and category), nothing else about you.
- Resend — to send sign-in and notification emails.
- OpenAI — used for AI-generated trip suggestions you ask for, and as a fallback to suggest nearby places for Go Explore on the rare occasions our primary places data source has no result. In both cases it only sees your search terms and general location, never your account details.
- Sentry — crash and error reporting so we can fix things that break. Receives technical diagnostics (stack trace, browser / device info). We configure Sentry not to collect your IP address or account details, and it never receives the wellness content you create.
- PostHog (EU) and Microsoft Clarity — anonymous product analytics, only loaded once you've accepted analytics cookies.
We do not sell or rent your personal data to anyone.
International transfers
Some of our providers (Stripe, OpenAI, Resend, Sentry, Microsoft Clarity, and the Wikimedia Foundation) are based in the United States or process data globally. Where data leaves the UK or EEA, we rely on the providers' UK / EU Standard Contractual Clauses (or equivalent safeguards) to keep your data protected to the same standard as it would be at home.
Your rights
You have the following rights over your personal data under UK and EU GDPR. You can exercise any of them by emailing hello@365alive.uk. We'll respond within 30 days and we won't charge you for the request.
- Access — get a copy of the data we hold on you. You can do this yourself instantly from Profile → Download my data.
- Rectification — correct anything that's wrong. Most fields you can edit yourself in Profile; for anything you can't, email us.
- Erasure ("right to be forgotten") — delete your account and personal data instantly from Profile → Danger Zone. Active database records are removed immediately; backups are overwritten within 30 days.
- Restrict or object — ask us to pause or stop using your data for a particular purpose (for example, analytics or marketing). For analytics you can do this yourself from Profile → Cookie preferences and for marketing emails from your notification settings.
- Portability — get a copy of your data in a machine-readable format. The download in Profile gives you everything as JSON.
- Withdraw consent — change your mind about analytics cookies or marketing emails at any time, from Profile.
- Complain — if you think we've handled your data badly, you can lodge a complaint with the UK Information Commissioner's Office at ico.org.uk/make-a-complaint. If you're in the EU, your local data protection authority handles complaints about us. We'd appreciate the chance to help first, though.
How long we keep things
We keep your account data for as long as your account is active. When you delete your account, your sign-in is removed immediately and your personal content is deleted from our active database. Backup copies are overwritten within 30 days. Some billing records are retained where the law requires it.
Children
365ALIVE is not directed at children under 13. If you believe a child has created an account, contact us and we'll remove it.
Changes to this policy
If we make material changes, we'll let you know in the app or by email. Continued use of the Service after a change means you accept the updated policy.
Contact
Questions, requests, or complaints? Email hello@365alive.uk.
Data controller
365ALIVE LTD
128 City Road
London
EC1V 2NX
United Kingdom
Company number: 16159880