Privacy Policy
Effective date: July 22, 2026 · Last updated: July 22, 2026 · Version 4.0
Genesis OS collects only what it needs to serve you, never sells your data, and gives you full control. This policy explains exactly what we collect, why we process it, the legal basis for each use, your rights under GDPR, CCPA/CPRA and other laws, and how to export or permanently delete your data.
1. Who We Are & The Role We Play
This section identifies the data controller, the service this policy governs, and how to reach us.
Genesis OS (also referred to as "Genesis OS", "we", "our", or "us") is an AI operating system for life, work, goals, and creation. Boris is the AI copilot inside Genesis OS that generates your missions, coaching, insights, and creative output. Genesis OS is operated by Genesis AI Applications LLC, a Delaware limited liability company, which acts as the data controller responsible for your personal data under applicable privacy laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. and international privacy statutes.
| Attribute | Detail |
|---|---|
| Legal entity | Genesis AI Applications LLC |
| Established | December 2025 (Genesis OS in development since January 2026) |
| Role under GDPR | Data Controller (Art. 4(7)) |
| Role under CCPA/CPRA | Business |
| Principal place of business | United States |
| Privacy contact (general) | support@genesis-applications.com |
| Data Protection Officer / EU rep | See §19 — Contact Us & DPO |
| Service covered by this policy | Genesis OS web app, mobile apps, and all integrated Boris features |
What this policy covers
This Privacy Policy applies to all users of Genesis OS — including free, paid (Essential / Pro / Premium / Ultra), Founding Member, and trial accounts — across web, mobile, and any connected devices. It does not apply to third-party services we link to or integrate with; those are governed by their own privacy policies.
2. Our Privacy Principles
These principles shape every product decision we make about your data.
- Data minimization. We collect only what is necessary to deliver the features you use — nothing more.
- Purpose limitation. We use your data only for the specific purposes disclosed in this policy, and we ask for fresh consent before using it for a new purpose.
- No data selling. We never sell, rent, or broker your personal data to advertisers, data brokers, or any third party — as a business model or otherwise.
- No public model training. Your personal data and conversations are never used to train public AI models.
- Transparency. AI-generated content is clearly labeled, and you can see and control what Boris is allowed to read.
- You own your data. You can export, correct, restrict, or permanently delete your data at any time.
- Security by default. Encryption in transit and at rest, least-privilege access, and continuous monitoring are baseline, not optional.
3. Legal Bases for Processing (GDPR)
Under the GDPR, we may only process your personal data where we have a valid legal basis. The table below maps each processing purpose to its legal basis.
| Processing purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing your Genesis OS account and core features | Performance of a contract (Art. 6(1)(b)) |
| Generating AI missions, coaching, and insights | Performance of a contract + your consent (Art. 6(1)(b)/(a)) |
| Processing payments and billing | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails (receipts, security) | Legal obligation + contract (Art. 6(1)(c)/(b)) |
| Sending optional product & reminder emails | Your consent (Art. 6(1)(a)) — withdrawable anytime |
| Aggregated, anonymized product improvement analytics | Legitimate interests (Art. 6(1)(f)) |
| Detecting fraud, abuse, and security threats | Legitimate interests + legal obligation (Art. 6(1)(f)/(c)) |
| Connected bank/financial accounts (Financial Connections) | Your consent (Art. 6(1)(a)) |
| Health, fitness & biometric logging | Your explicit consent (Art. 6(1)(a) + Art. 9 conditions) |
Special category data
Health, fitness, and wellness data you log in Genesis OS is "special category" data under GDPR Art. 9. We process it only with your explicit, opt-in consent, which you can withdraw at any time in Settings → Privacy. Withdrawing consent stops future processing but does not affect processing already lawfully completed.
For users in California (CCPA/CPRA), the legal bases above correspond to the "business purposes" and "commercial purposes" for which we collect and use personal information, as described in §15.
4. Information We Collect
We collect four broad categories of data. Below is a complete inventory — what each category includes, why we need it, and where it is stored.
4.1 Account & Identity Data
Information you provide to create and authenticate your account.
| Data point | Why we need it | Required? |
|---|---|---|
| Email address | Account identity, login, receipts, security alerts | Required |
| Full name / display name | Personalization and social features | Required |
| Password (hashed) | Authentication — never stored in plaintext | Required |
| Profile photo | Avatar display | Optional |
| Two-factor authentication secret | Account security (TOTP, encrypted at rest) | Optional |
| OAuth provider ID (Google, Apple) | Social sign-in alternative to password | Optional |
4.2 Profile, Preference & Goal Data
Information you provide during onboarding and in Settings — this is what makes Genesis OS personal to you.
| Data point | Why we need it |
|---|---|
| Life goals and milestones | Generate missions and track progress |
| Habits and routines | Streak tracking and daily mission generation |
| Constraints (time, energy, limits) | Personalize recommendations to your reality |
| Domain focus (fitness, finance, career…) | Route Boris to the areas you care about |
| Notification preferences & quiet hours | Respect your attention; deliver only what you want |
| Privacy / AI access toggles per domain | Control which data Boris may read for insights |
| Theme, wallpaper, and appearance settings | Personalize your workspace |
4.3 Activity & Usage Data
Generated as you use Genesis OS — the record of what you have done.
- Tasks completed, habits checked, missions finished, and their timestamps.
- Journal entries, reflections, and notes you author.
- Workout logs, sets, reps, weights, and personal records.
- Nutrition logs, meals, macros, and water intake.
- Chat conversations with Boris and AI-generated artifacts.
- Learning sessions, flashcard reviews, and progress entries.
- XP, achievements, streaks, and gamification history.
- Feature usage frequency (e.g., which widgets you open) — aggregated and anonymized for product improvement.
4.4 Health, Biometric & Wellness Data (Special Category)
You may voluntarily log sensitive health and fitness data. This is special-category data under GDPR Art. 9 and is processed only with your explicit consent.
- Body weight, measurements, and progress photos.
- Heart rate, sleep, and recovery data from connected wearables (if you connect one).
- Medication logs and health activity records.
- Mood, energy, and emotional check-ins.
Not medical advice
Boris may use this data to generate coaching suggestions, but it is never a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider for medical decisions.
4.5 Communication & Social Data
If you use social, community, or collaboration features.
- Direct messages, group conversations, and their content.
- Social posts, comments, likes, and reactions.
- Community memberships and roles.
- Collaboration group activity and shared workspace data.
4.6 Financial & Connected-Account Data
Payments are processed entirely by Stripe (PCI DSS Level 1). We never see or store your card number. If you choose to connect bank or credit accounts via Stripe Financial Connections, additional data flows apply (see §7).
| Data point | Who holds it | What we receive |
|---|---|---|
| Card number, CVV, expiry | Stripe only — we never see it | Confirmation of successful payment |
| Billing name, email, ZIP | Stripe (shared with us) | Shown on receipts and in your account |
| Subscription plan, price, cycle | Stored on our side | Manage your plan and entitlements |
| Connected bank balances & transactions | Retrieved via Stripe Financial Connections, stored encrypted on our side | Display balances, detect recurring subscriptions |
4.7 Technical & Device Data
Collected automatically as part of operating the service and protecting it from abuse.
- IP address (used for security, rate limiting, and approximate geolocation).
- Browser type, operating system, and screen resolution.
- Device identifiers and push-notification tokens (if you enable notifications).
- Session tokens and authentication cookies (see §13 — Cookies).
- Crash reports and error logs (anonymized by default; device details only if you opt in).
- Page-view and feature-usage analytics (aggregated, not linked to your identity).
4.8 AI Processing Data
When you interact with Boris, portions of your relevant data are sent to third-party AI model providers to generate responses. See §6 for the full AI processing disclosure.
5. How We Use Your Information
We use your data only for the specific, disclosed purposes below. We do not use your personal data to train public AI models or for third-party advertising.
| Purpose | Categories used | Lawful basis |
|---|---|---|
| Personalized daily missions & strategies | 4.2, 4.3 | Contract + consent |
| Progress tracking, streaks, goal milestones | 4.2, 4.3 | Contract |
| AI coaching, feedback & behavioral analysis | 4.2, 4.3, 4.4 | Contract + consent |
| Creative generation (apps, images, documents) | 4.3, 4.8 | Contract + consent |
| Billing, subscription management, refunds | 4.6, 4.1 | Contract + legal obligation |
| Transactional emails (receipts, security) | 4.1 | Legal obligation |
| Optional product & reminder notifications | 4.1, 4.2 | Consent — withdrawable |
| Fraud, abuse & security threat detection | 4.7, 4.3 | Legitimate interests + legal obligation |
| Product improvement (aggregated, anonymized) | 4.3, 4.7 (anonymized) | Legitimate interests |
| Connected banking features (balances, recurring detection) | 4.6 | Consent |
What we will never do
We will never sell your data, rent it to third parties, use it to serve third-party behavioral advertising, or use your personal conversations to train public AI models. These commitments are structural to our business, not optional features.
6. AI Processing & Disclosure
Boris is powered by large language models and other AI systems. This section explains exactly what happens to your data when you use AI features.
6.1 How Boris works
When you ask Boris a question, request a mission, or generate content, Genesis OS assembles a context window from the data you have authorized Boris to read (see §6.6), sends that context to a third-party AI model provider, and returns the generated response to you. The provider processes the request under its own data processing terms.
6.2 What is sent to AI providers
- Your current message or prompt.
- Relevant portions of your profile, recent activity, and goals — limited to the domains you have enabled in your AI access settings.
- Recent conversation history (for continuity within a session).
- Uploaded files or images you explicitly attach to a prompt.
- System instructions that shape the response (never your full database).
AI provider list
We use models from providers including OpenAI, Anthropic, Google (Gemini), and others as we add them. Each provider is bound by a data processing agreement that prohibits using Genesis OS customer data to train their public models. The current list of AI sub-processors is maintained in §8 and updated as providers change.
6.3 Boris memory system
Boris maintains a memory of your preferences, facts, and past conversations so it can be more useful over time. Memories are stored on our encrypted infrastructure and associated with your account. You can view, edit, and delete individual memories, or wipe all memories, from the Memory panel. Deleting a memory removes it from future AI context.
6.4 No training on your data
Your personal data and conversations are never used to train public AI models. Our agreements with AI providers explicitly opt Genesis OS traffic out of any training data pipeline. We may, separately and only with fully anonymized, aggregated data, improve our own internal prompt engineering and feature quality.
6.5 AI transparency & not professional advice
All AI-generated content is clearly presented as AI-generated. Boris does not have consciousness or professional credentials. Responses are statistical outputs of language models based on your input. Boris AI output is not professional medical, financial, psychological, legal, or investment advice. Always consult a qualified professional for consequential decisions.
6.6 Privacy controls — what Boris can read
In Settings → Privacy → AI Access, you can toggle Boris's access per domain (fitness, finance, learning, health, career, relationships, discipline, personal). A domain set to "off" is excluded from Boris's context when generating insights for any other domain. Your preference is enforced server-side — not just hidden in the UI.
7. Connected Accounts & Financial Connections
You may optionally connect external accounts. Connecting is always opt-in and reversible.
7.1 Stripe Financial Connections (connected banking)
If you use the connected-banking feature in the Finance widget, you link accounts through Stripe Financial Connections. Stripe acts as the data conduit; we never receive your bank login credentials.
| Data | Source | Stored where |
|---|---|---|
| Account balances (available & current) | Stripe Financial Connections API | Encrypted on our infrastructure |
| Transaction history (merchant, amount, date) | Stripe Financial Connections API | Encrypted — used to detect recurring subscriptions |
| Institution name, account last 4, account type | Stripe | Encrypted on our side |
| Detected recurring subscriptions | Computed locally from transactions | Encrypted on our side |
- You can disconnect any account at any time; we immediately mark it disconnected and stop syncing.
- We use connected-banking data only to display balances, track spending, and detect recurring subscriptions inside your Finance widget.
- We never use it for advertising, never share it with third parties, and never make financial decisions on your behalf.
7.2 Other optional integrations
Genesis OS may offer integrations with calendars, email, cloud storage, and other services via OAuth. When you connect one, you authorize the provider to share specific data with us under that provider's scopes. You can revoke any connection at any time, which immediately stops new data syncing.
8. Data Sharing & Sub-Processors
We share data only with sub-processors who help us operate Genesis OS, and only under data processing agreements that meet GDPR standards. We never sell data.
The table below lists the categories of sub-processors we rely on, what they do, and the data they may process. Specific vendor names may change; we maintain a current list and notify you of material additions.
| Category | Purpose | Data accessed | Location |
|---|---|---|---|
| Cloud infrastructure provider | Host the application & database | All stored data (encrypted at rest) | United States |
| AI model providers | Generate Boris responses & creative output | Prompt context sent at request time | US / EU (per provider) |
| Payment processor (Stripe) | Process payments, subscriptions, financial connections | Card data (held by Stripe), billing metadata | United States |
| Email delivery provider | Send transactional & opt-in emails | Email address, email content | United States |
| Push notification provider | Deliver device push notifications | Device token, notification payload | United States |
| Analytics provider | Aggregated, anonymized product analytics | Anonymized usage events | United States |
| Error & crash monitoring | Stability & bug diagnostics | Anonymized stack traces, device info | United States |
| SMS / 2FA provider | Two-factor authentication codes | Phone number (if you enable SMS 2FA) | United States |
Legal disclosures
We may disclose personal data where required by law, court order, or to protect the safety, rights, and integrity of our users and platform. We resist over-broad requests, challenge those we believe are improper, and disclose only the minimum data necessary to comply.
9. International Data Transfers
Genesis OS is operated from the United States. If you access us from outside the US, your data may be transferred to and processed in the US.
For users in the EU, EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement (IDTA) or Addendum, and other recognized transfer mechanisms to ensure your data receives an adequate level of protection wherever it is processed.
- We conduct transfer impact assessments (TIAs) as required and document them on request.
- Where a sub-processor processes data in a third country, our data processing agreement requires them to apply equivalent safeguards.
- You may request a copy of the applicable SCCs by contacting us at the email in §19.
10. Data Storage & Security
How we protect your data across its lifecycle.
- Encryption in transit: TLS 1.3 for all data moving between your device and our servers.
- Encryption at rest: AES-256 encryption for all stored data, including databases, file uploads, and backups.
- Least-privilege access: Strict role-based access controls. Only authorized engineers can access production systems, and only via short-lived, audited credentials.
- Authentication security: Passwords are hashed with strong, salted algorithms. Two-factor authentication (TOTP) is available and the secret is encrypted at rest.
- Secrets management: API keys, signing secrets, and encryption keys are stored in a managed secrets vault with automatic rotation policies.
- Continuous monitoring: We monitor for security events, anomalous access patterns, and potential intrusions.
- Regular reviews: We periodically review access logs, dependencies, and infrastructure configuration for vulnerabilities.
- No card storage: We never store payment card numbers — Stripe (PCI DSS Level 1) handles all card data.
No system is 100% secure
While we apply industry-leading security practices, no system can be guaranteed fully secure. We continuously improve our defenses and act quickly on any vulnerability report. Security researchers can contact us at the email in §19; we acknowledge responsible disclosures.
11. Data Breach Notification
What happens in the unlikely event of a security incident.
We maintain an incident response plan. If we confirm a personal data breach that poses a risk to your rights or freedoms, we will:
- 1Notify the relevant supervisory authority within 72 hours of becoming aware of it, where required by GDPR Art. 33.
- 2Notify affected users without undue delay where the breach is likely to result in a high risk to your rights and freedoms (GDPR Art. 34).
- 3Describe the nature of the breach, the likely consequences, and the measures we are taking, including steps you can take to protect yourself.
- 4Document the incident internally for accountability and post-incident review.
12. Data Retention
We keep your data only as long as needed for the purposes described, or as required by law. The table below sets our default retention periods.
| Data category | Retention while active | After account deletion |
|---|---|---|
| Account & identity data | Lifetime of account | Deleted within 30 days |
| Profile, goals, preferences | Lifetime of account | Deleted within 30 days |
| Activity & usage logs | Lifetime of account | Deleted within 30 days |
| Chat conversations & Boris memory | Lifetime of account | Deleted within 30 days |
| Health & biometric logs | Lifetime of account | Deleted within 30 days |
| Connected banking data | Until you disconnect | Deleted within 30 days (or sooner on disconnect) |
| Generated AI artifacts | Lifetime of account | Deleted within 30 days |
| Financial transaction records | Lifetime of account | Up to 7 years (legal/tax requirement) |
| Server & audit logs | 90 days — 1 year (security) | Retained per security policy |
| Anonymized, aggregated analytics | Indefinitely | Indefinitely (not identifiable) |
You can configure a shorter activity-log retention period in Settings → Privacy → Retention (e.g., automatically prune workouts, meals, and journal entries older than a number of days you choose, or retain forever). This puts a hard ceiling on how long your sensitive activity data lives in our system.
Backups
Deleted data is removed from backups within 30 days of deletion as backups cycle out. We do not keep indefinite snapshots of deleted personal data.
14. Email Communications
Two types of email — one mandatory, one fully optional.
14.1 Transactional (cannot be opted out)
Billing receipts, security alerts, password resets, and account changes. These are necessary to operate and secure your account; you cannot opt out of them while your account is active.
14.2 Product & reminder (opt-in, withdrawable)
Daily mission reminders, weekly performance summaries, feature announcements, and founder updates — sent only with your consent during onboarding or in Settings. You can opt out anytime from notification settings in the app or by emailing us. Opting out never affects transactional emails.
15. Your Privacy Rights
Your rights depend on where you live. The table below summarizes the rights available under major privacy regimes and how to exercise each one.
| Right | GDPR (EU/EEA/UK) | CCPA/CPRA (California) | Other US states |
|---|---|---|---|
| Access / know what we hold | ✅ Art. 15 | ✅ Right to know | ✅ Varies by state |
| Rectification / correction | ✅ Art. 16 | ✅ Correction | ✅ Varies |
| Erasure / deletion | ✅ Art. 17 | ✅ Delete | ✅ Varies |
| Data portability | ✅ Art. 20 | ✅ Portable format | ✅ Varies |
| Restrict processing | ✅ Art. 18 | — (use opt-out) | ✅ Varies |
| Object to processing | ✅ Art. 21 | ✅ Opt-out of sale/share* | ✅ Varies |
| Withdraw consent | ✅ Art. 7 | ✅ Where consent given | ✅ Varies |
| Not subject to automated profiling | ✅ Art. 22 | ✅ | ✅ Varies |
| Limit use of sensitive data | — | ✅ CPRA | ✅ Varies |
*We do not sell your data
Because we never sell or share personal data for monetary or valuable consideration, your CCPA right to opt out of "sale or share" is already fully honored — there is nothing to opt out of. We state this explicitly for clarity and compliance.
15.1 Exercising your rights
- 1Use the in-app tools: Settings → Privacy (export your data, adjust AI access, set retention), Settings → Account (delete account), Memory panel (delete memories).
- 2Email us at support@genesis-applications.com with the right you wish to exercise. We respond within 30 days (72 hours for urgent erasure).
- 3We verify your identity before acting on a request to protect your account from unauthorized access.
- 4For GDPR rights you may also lodge a complaint with your local Data Protection Authority; for CCPA, with the California Privacy Protection Agency.
Authorized agents
You may authorize someone to submit a request on your behalf. We will verify the authorization before acting, and may still confirm directly with you for sensitive requests like deletion.
16. Identity Verification for Requests
To protect your account, we verify identity before fulfilling privacy requests.
When you submit a request by email, we match it to the email address on your account. For high-impact requests (full data export, account deletion, or restricting processing), we may require you to complete the request from within your logged-in account, or to confirm additional details. This prevents bad actors from deleting or exporting your data without your permission.
17. Children's Privacy
Genesis OS is not directed to individuals under 16.
We do not knowingly collect personal data from children under 16, and we do not knowingly process the special-category data of minors. If you are a parent or guardian and believe your child has created a Genesis OS account, contact us immediately at support@genesis-applications.com and we will delete the account and all associated data promptly. For users in jurisdictions with a higher minimum age (e.g., 16 in parts of the EU), the higher age applies.
18. Changes to This Policy
We update this policy as our practices or the law evolves.
- We will notify you of material changes by email and an in-app notice at least 14 days before they take effect.
- Non-material changes (clarifications, formatting) may be made without separate notice; the "Last updated" date at the top of the page will reflect the change.
- Your continued use of Genesis OS after a material change takes effect constitutes acceptance of the updated policy.
- The version number at the top of this page helps you track what changed and when.
19. Contact Us & Data Protection Officer
How to reach us for any privacy matter.
| Purpose | Contact |
|---|---|
| General privacy questions | support@genesis-applications.com |
| Data subject access / deletion requests | support@genesis-applications.com |
| Data Protection Officer / EU representative | /privacy/dpo (DPO contact form) |
| Security vulnerability disclosure | support@genesis-applications.com (subject: SECURITY) |
| Authorized agent requests | support@genesis-applications.com |
We aim to respond to all privacy inquiries within 5 business days, and to urgent data-subject requests (erasure, restriction, access) within 30 days — faster where required by law.
Your supervisory authority
If you are in the EU/EEA/UK, you may also contact your local Data Protection Authority. We encourage you to come to us first — most concerns can be resolved directly and faster.
Questions about your privacy?
We respond to all privacy inquiries within 5 business days — faster for urgent data-subject requests.
© 2026 Genesis AI Applications LLC · Established December 2025 · Genesis OS in development since January 2026