Privacy
Privacy notice
An app about cleaning up your data had better be careful with its own. Here's exactly what we collect, why, who sees it, and how to get rid of it.
Who we are
Lifesweeper is operated by Taylor Jay Beal (“Lifesweeper”, “we”, “us”), a sole trader based in Australia trading as Lifesweeper.
For the personal data described here, Taylor Jay Beal is the data controller — we decide what data is collected and why. You can reach us any time at support@lifesweeper.app.
What we collect and why
Account data — your email address, your name if you give it, and your password hash (handled by our authentication provider). Used to create and secure your account. Legal basis: performance of our contract with you.
Your preferences — what you told us you want to clean up and your notification choices. Used to tailor the app. Legal basis: contract.
Mailbox metadata — message headers only from the mailbox you connect (sender, subject line, date, unsubscribe links), plus the OAuth tokens needed to read them, which we store encrypted. We never read message bodies or attachments and never store the contents of your email. Used to build your list of companies, newsletters and subscriptions. Legal basis: contract, with your explicit consent given at the point you connect a mailbox.
Cleanup records — which unsubscribe, cancellation or deletion requests you made and what happened. Legal basis: contract, and our legitimate interest in keeping accurate service records.
Technical data — IP address, device and browser information, and basic usage and error logs. Used for security, fraud prevention, and fixing faults. Legal basis: legitimate interests.
Support messages — anything you send us. Used to answer you. Legal basis: legitimate interests.
What we never collect
No email bodies, no message text, no attachments, and no passwords for any of the third-party companies you use. We never hold logins for anyone else's service, and we never sell your personal data or share it for advertising.
Who we share it with
Merchant of record — Paddle.com Market Ltd acts as the reseller and merchant of record for all purchases. Paddle receives the personal data needed to sell you the product, manage your subscription, take payment, handle refunds, comply with tax law and issue invoices. Paddle is the controller of the payment data it collects, and handles that data under its own privacy notice at paddle.com/legal/privacy. We never see or store your full card details.
Service providers acting as our processors — hosting and database infrastructure, authentication, email delivery, error monitoring, and the AI provider that classifies sender names into categories (it receives sender and subject metadata only). They may only process your data on our instructions.
Mailbox providers — Google and Microsoft, only to authenticate you and read the header metadata you authorised.
Professional advisers — our accountants or lawyers where reasonably needed.
Authorities — where we are legally required to disclose, or to protect our rights and the safety of users.
Where your data is held
Our infrastructure and some providers are located outside Australia, including in the United States and the European Union. Where data leaves the UK or EEA, transfers rely on standard contractual clauses or an adequacy decision, and we require equivalent protections from every provider.
How long we keep it
Retention is per data type — the table below is the full picture. Anything past its period is deleted or irreversibly anonymised on a rolling basis.
| Data type | Kept for | Notes |
|---|---|---|
| Mailbox metadata and scan results | While your account is active | Deleted immediately when you clear your results, disconnect the mailbox, or delete your account. |
| Mailbox OAuth access and refresh tokens | Until you disconnect | Deleted from the database the moment a mailbox is disconnected or the account is deleted. |
| Account and profile data (email, name, password hash) | Account lifetime, then 30 days | Encrypted backups holding the same rows cycle out within a further 90 days. |
| Your cleanup preferences and notification settings | Account lifetime, then 30 days | Deleted with the account. |
| Cleanup records (unsubscribes, cancellations, deletion requests) | Account lifetime, then 30 days | Kept while active so we can show you what has already been sorted. |
| Security and error logs, IP addresses | 90 days | Kept for fraud prevention and fault-finding, then automatically purged. |
| Optional analytics events | 13 months | Only collected if you consent on the cookie notice; aggregate and non-identifying. |
| Support emails and refund requests | 24 months from resolution | Kept so we can follow up and evidence what was agreed. |
| Order, invoice and tax records | 7 years | Required by tax law and held largely by Paddle as merchant of record. |
Getting a copy of your data, or deleting it
Export — in Settings you can download everything we hold about you as a machine-readable JSON file: your profile, preferences, connected mailboxes, scan results and cleanup history. If you'd rather we prepared it for you, or you can no longer sign in, email support@lifesweeper.app from your account address and we'll send it within 30 days.
Deletion — Settings has two options. “Clear my results” wipes all scan data and mailbox metadata immediately while keeping your login. “Delete my account” removes your account, preferences, tokens, scan data and cleanup history immediately, cancels any active subscription, and clears backups within 90 days.
Can't reach Settings? Email support@lifesweeper.app with the subject “delete my data”. We'll verify you own the address, action it, and confirm in writing within 30 days at no cost. Invoice and tax records are the one exception — we're legally required to keep those for seven years, and requests for those go to Paddle as merchant of record.
How we protect it
All traffic is encrypted in transit with TLS, and data is encrypted at rest. Mailbox access tokens are additionally encrypted with AES-256-GCM using a key held only on the server.
Every row of your data is locked to your account at the database level with row-level security, so no other signed-in user can read it. Administrative access is restricted to named accounts, protected by multi-factor authentication and used only for support and abuse handling.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or receive it in a portable format. Where we rely on consent — such as connecting a mailbox — you can withdraw it at any time by disconnecting.
Most of this you can do yourself in Settings: clear your scan results, or delete your account and everything with it, both effective immediately. For anything else, email support@lifesweeper.app and we will respond within 30 days.
If you are in the UK or EEA you may also complain to your local data protection authority; in Australia you may complain to the Office of the Australian Information Commissioner.
Cookies
We use essential cookies and browser storage to keep you signed in and to remember your cookie choice, plus one optional analytics category that is off unless you consent. We never use advertising or cross-site tracking cookies. Paddle sets its own cookies on the checkout it operates.
Every cookie and storage item is listed, with its purpose and lifetime, on our cookie notice — where you can also change or withdraw your analytics consent at any time.
Changes
If we make a material change to this notice we will tell you by email before it takes effect. Last updated August 2026.