Privacy First

Privacy Policy

Effective date: July 22, 2026 · Last updated: July 22, 2026 · Version 4.0

Genesis OS collects only what it needs to serve you, never sells your data, and gives you full control. This policy explains exactly what we collect, why we process it, the legal basis for each use, your rights under GDPR, CCPA/CPRA and other laws, and how to export or permanently delete your data.

🚫We never sell your data
🤖AI disclosure on every feature
Full export & deletion on demand
🔒Encrypted in transit & at rest
🌍GDPR, CCPA & CPRA ready
🧠You control what Boris can read
GDPR · CCPA · CPRA compliant19 sectionsOperated by Genesis AI Applications LLC

1. Who We Are & The Role We Play

This section identifies the data controller, the service this policy governs, and how to reach us.

Genesis OS (also referred to as "Genesis OS", "we", "our", or "us") is an AI operating system for life, work, goals, and creation. Boris is the AI copilot inside Genesis OS that generates your missions, coaching, insights, and creative output. Genesis OS is operated by Genesis AI Applications LLC, a Delaware limited liability company, which acts as the data controller responsible for your personal data under applicable privacy laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. and international privacy statutes.

AttributeDetail
Legal entityGenesis AI Applications LLC
EstablishedDecember 2025 (Genesis OS in development since January 2026)
Role under GDPRData Controller (Art. 4(7))
Role under CCPA/CPRABusiness
Principal place of businessUnited States
Privacy contact (general)support@genesis-applications.com
Data Protection Officer / EU repSee §19 — Contact Us & DPO
Service covered by this policyGenesis OS web app, mobile apps, and all integrated Boris features

What this policy covers

This Privacy Policy applies to all users of Genesis OS — including free, paid (Essential / Pro / Premium / Ultra), Founding Member, and trial accounts — across web, mobile, and any connected devices. It does not apply to third-party services we link to or integrate with; those are governed by their own privacy policies.

2. Our Privacy Principles

These principles shape every product decision we make about your data.

  • Data minimization. We collect only what is necessary to deliver the features you use — nothing more.
  • Purpose limitation. We use your data only for the specific purposes disclosed in this policy, and we ask for fresh consent before using it for a new purpose.
  • No data selling. We never sell, rent, or broker your personal data to advertisers, data brokers, or any third party — as a business model or otherwise.
  • No public model training. Your personal data and conversations are never used to train public AI models.
  • Transparency. AI-generated content is clearly labeled, and you can see and control what Boris is allowed to read.
  • You own your data. You can export, correct, restrict, or permanently delete your data at any time.
  • Security by default. Encryption in transit and at rest, least-privilege access, and continuous monitoring are baseline, not optional.

4. Information We Collect

We collect four broad categories of data. Below is a complete inventory — what each category includes, why we need it, and where it is stored.

4.1 Account & Identity Data

Information you provide to create and authenticate your account.

Data pointWhy we need itRequired?
Email addressAccount identity, login, receipts, security alertsRequired
Full name / display namePersonalization and social featuresRequired
Password (hashed)Authentication — never stored in plaintextRequired
Profile photoAvatar displayOptional
Two-factor authentication secretAccount security (TOTP, encrypted at rest)Optional
OAuth provider ID (Google, Apple)Social sign-in alternative to passwordOptional

4.2 Profile, Preference & Goal Data

Information you provide during onboarding and in Settings — this is what makes Genesis OS personal to you.

Data pointWhy we need it
Life goals and milestonesGenerate missions and track progress
Habits and routinesStreak tracking and daily mission generation
Constraints (time, energy, limits)Personalize recommendations to your reality
Domain focus (fitness, finance, career…)Route Boris to the areas you care about
Notification preferences & quiet hoursRespect your attention; deliver only what you want
Privacy / AI access toggles per domainControl which data Boris may read for insights
Theme, wallpaper, and appearance settingsPersonalize your workspace

4.3 Activity & Usage Data

Generated as you use Genesis OS — the record of what you have done.

  • Tasks completed, habits checked, missions finished, and their timestamps.
  • Journal entries, reflections, and notes you author.
  • Workout logs, sets, reps, weights, and personal records.
  • Nutrition logs, meals, macros, and water intake.
  • Chat conversations with Boris and AI-generated artifacts.
  • Learning sessions, flashcard reviews, and progress entries.
  • XP, achievements, streaks, and gamification history.
  • Feature usage frequency (e.g., which widgets you open) — aggregated and anonymized for product improvement.

4.4 Health, Biometric & Wellness Data (Special Category)

You may voluntarily log sensitive health and fitness data. This is special-category data under GDPR Art. 9 and is processed only with your explicit consent.

  • Body weight, measurements, and progress photos.
  • Heart rate, sleep, and recovery data from connected wearables (if you connect one).
  • Medication logs and health activity records.
  • Mood, energy, and emotional check-ins.

Not medical advice

Boris may use this data to generate coaching suggestions, but it is never a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider for medical decisions.

4.5 Communication & Social Data

If you use social, community, or collaboration features.

  • Direct messages, group conversations, and their content.
  • Social posts, comments, likes, and reactions.
  • Community memberships and roles.
  • Collaboration group activity and shared workspace data.

4.6 Financial & Connected-Account Data

Payments are processed entirely by Stripe (PCI DSS Level 1). We never see or store your card number. If you choose to connect bank or credit accounts via Stripe Financial Connections, additional data flows apply (see §7).

Data pointWho holds itWhat we receive
Card number, CVV, expiryStripe only — we never see itConfirmation of successful payment
Billing name, email, ZIPStripe (shared with us)Shown on receipts and in your account
Subscription plan, price, cycleStored on our sideManage your plan and entitlements
Connected bank balances & transactionsRetrieved via Stripe Financial Connections, stored encrypted on our sideDisplay balances, detect recurring subscriptions

4.7 Technical & Device Data

Collected automatically as part of operating the service and protecting it from abuse.

  • IP address (used for security, rate limiting, and approximate geolocation).
  • Browser type, operating system, and screen resolution.
  • Device identifiers and push-notification tokens (if you enable notifications).
  • Session tokens and authentication cookies (see §13 — Cookies).
  • Crash reports and error logs (anonymized by default; device details only if you opt in).
  • Page-view and feature-usage analytics (aggregated, not linked to your identity).

4.8 AI Processing Data

When you interact with Boris, portions of your relevant data are sent to third-party AI model providers to generate responses. See §6 for the full AI processing disclosure.

5. How We Use Your Information

We use your data only for the specific, disclosed purposes below. We do not use your personal data to train public AI models or for third-party advertising.

PurposeCategories usedLawful basis
Personalized daily missions & strategies4.2, 4.3Contract + consent
Progress tracking, streaks, goal milestones4.2, 4.3Contract
AI coaching, feedback & behavioral analysis4.2, 4.3, 4.4Contract + consent
Creative generation (apps, images, documents)4.3, 4.8Contract + consent
Billing, subscription management, refunds4.6, 4.1Contract + legal obligation
Transactional emails (receipts, security)4.1Legal obligation
Optional product & reminder notifications4.1, 4.2Consent — withdrawable
Fraud, abuse & security threat detection4.7, 4.3Legitimate interests + legal obligation
Product improvement (aggregated, anonymized)4.3, 4.7 (anonymized)Legitimate interests
Connected banking features (balances, recurring detection)4.6Consent

What we will never do

We will never sell your data, rent it to third parties, use it to serve third-party behavioral advertising, or use your personal conversations to train public AI models. These commitments are structural to our business, not optional features.

6. AI Processing & Disclosure

Boris is powered by large language models and other AI systems. This section explains exactly what happens to your data when you use AI features.

6.1 How Boris works

When you ask Boris a question, request a mission, or generate content, Genesis OS assembles a context window from the data you have authorized Boris to read (see §6.6), sends that context to a third-party AI model provider, and returns the generated response to you. The provider processes the request under its own data processing terms.

6.2 What is sent to AI providers

  • Your current message or prompt.
  • Relevant portions of your profile, recent activity, and goals — limited to the domains you have enabled in your AI access settings.
  • Recent conversation history (for continuity within a session).
  • Uploaded files or images you explicitly attach to a prompt.
  • System instructions that shape the response (never your full database).

AI provider list

We use models from providers including OpenAI, Anthropic, Google (Gemini), and others as we add them. Each provider is bound by a data processing agreement that prohibits using Genesis OS customer data to train their public models. The current list of AI sub-processors is maintained in §8 and updated as providers change.

6.3 Boris memory system

Boris maintains a memory of your preferences, facts, and past conversations so it can be more useful over time. Memories are stored on our encrypted infrastructure and associated with your account. You can view, edit, and delete individual memories, or wipe all memories, from the Memory panel. Deleting a memory removes it from future AI context.

6.4 No training on your data

Your personal data and conversations are never used to train public AI models. Our agreements with AI providers explicitly opt Genesis OS traffic out of any training data pipeline. We may, separately and only with fully anonymized, aggregated data, improve our own internal prompt engineering and feature quality.

6.5 AI transparency & not professional advice

All AI-generated content is clearly presented as AI-generated. Boris does not have consciousness or professional credentials. Responses are statistical outputs of language models based on your input. Boris AI output is not professional medical, financial, psychological, legal, or investment advice. Always consult a qualified professional for consequential decisions.

6.6 Privacy controls — what Boris can read

In Settings → Privacy → AI Access, you can toggle Boris's access per domain (fitness, finance, learning, health, career, relationships, discipline, personal). A domain set to "off" is excluded from Boris's context when generating insights for any other domain. Your preference is enforced server-side — not just hidden in the UI.

7. Connected Accounts & Financial Connections

You may optionally connect external accounts. Connecting is always opt-in and reversible.

7.1 Stripe Financial Connections (connected banking)

If you use the connected-banking feature in the Finance widget, you link accounts through Stripe Financial Connections. Stripe acts as the data conduit; we never receive your bank login credentials.

DataSourceStored where
Account balances (available & current)Stripe Financial Connections APIEncrypted on our infrastructure
Transaction history (merchant, amount, date)Stripe Financial Connections APIEncrypted — used to detect recurring subscriptions
Institution name, account last 4, account typeStripeEncrypted on our side
Detected recurring subscriptionsComputed locally from transactionsEncrypted on our side
  • You can disconnect any account at any time; we immediately mark it disconnected and stop syncing.
  • We use connected-banking data only to display balances, track spending, and detect recurring subscriptions inside your Finance widget.
  • We never use it for advertising, never share it with third parties, and never make financial decisions on your behalf.

7.2 Other optional integrations

Genesis OS may offer integrations with calendars, email, cloud storage, and other services via OAuth. When you connect one, you authorize the provider to share specific data with us under that provider's scopes. You can revoke any connection at any time, which immediately stops new data syncing.

8. Data Sharing & Sub-Processors

We share data only with sub-processors who help us operate Genesis OS, and only under data processing agreements that meet GDPR standards. We never sell data.

The table below lists the categories of sub-processors we rely on, what they do, and the data they may process. Specific vendor names may change; we maintain a current list and notify you of material additions.

CategoryPurposeData accessedLocation
Cloud infrastructure providerHost the application & databaseAll stored data (encrypted at rest)United States
AI model providersGenerate Boris responses & creative outputPrompt context sent at request timeUS / EU (per provider)
Payment processor (Stripe)Process payments, subscriptions, financial connectionsCard data (held by Stripe), billing metadataUnited States
Email delivery providerSend transactional & opt-in emailsEmail address, email contentUnited States
Push notification providerDeliver device push notificationsDevice token, notification payloadUnited States
Analytics providerAggregated, anonymized product analyticsAnonymized usage eventsUnited States
Error & crash monitoringStability & bug diagnosticsAnonymized stack traces, device infoUnited States
SMS / 2FA providerTwo-factor authentication codesPhone number (if you enable SMS 2FA)United States

Legal disclosures

We may disclose personal data where required by law, court order, or to protect the safety, rights, and integrity of our users and platform. We resist over-broad requests, challenge those we believe are improper, and disclose only the minimum data necessary to comply.

9. International Data Transfers

Genesis OS is operated from the United States. If you access us from outside the US, your data may be transferred to and processed in the US.

For users in the EU, EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement (IDTA) or Addendum, and other recognized transfer mechanisms to ensure your data receives an adequate level of protection wherever it is processed.

  • We conduct transfer impact assessments (TIAs) as required and document them on request.
  • Where a sub-processor processes data in a third country, our data processing agreement requires them to apply equivalent safeguards.
  • You may request a copy of the applicable SCCs by contacting us at the email in §19.

10. Data Storage & Security

How we protect your data across its lifecycle.

  • Encryption in transit: TLS 1.3 for all data moving between your device and our servers.
  • Encryption at rest: AES-256 encryption for all stored data, including databases, file uploads, and backups.
  • Least-privilege access: Strict role-based access controls. Only authorized engineers can access production systems, and only via short-lived, audited credentials.
  • Authentication security: Passwords are hashed with strong, salted algorithms. Two-factor authentication (TOTP) is available and the secret is encrypted at rest.
  • Secrets management: API keys, signing secrets, and encryption keys are stored in a managed secrets vault with automatic rotation policies.
  • Continuous monitoring: We monitor for security events, anomalous access patterns, and potential intrusions.
  • Regular reviews: We periodically review access logs, dependencies, and infrastructure configuration for vulnerabilities.
  • No card storage: We never store payment card numbers — Stripe (PCI DSS Level 1) handles all card data.

No system is 100% secure

While we apply industry-leading security practices, no system can be guaranteed fully secure. We continuously improve our defenses and act quickly on any vulnerability report. Security researchers can contact us at the email in §19; we acknowledge responsible disclosures.

11. Data Breach Notification

What happens in the unlikely event of a security incident.

We maintain an incident response plan. If we confirm a personal data breach that poses a risk to your rights or freedoms, we will:

  1. 1Notify the relevant supervisory authority within 72 hours of becoming aware of it, where required by GDPR Art. 33.
  2. 2Notify affected users without undue delay where the breach is likely to result in a high risk to your rights and freedoms (GDPR Art. 34).
  3. 3Describe the nature of the breach, the likely consequences, and the measures we are taking, including steps you can take to protect yourself.
  4. 4Document the incident internally for accountability and post-incident review.

12. Data Retention

We keep your data only as long as needed for the purposes described, or as required by law. The table below sets our default retention periods.

Data categoryRetention while activeAfter account deletion
Account & identity dataLifetime of accountDeleted within 30 days
Profile, goals, preferencesLifetime of accountDeleted within 30 days
Activity & usage logsLifetime of accountDeleted within 30 days
Chat conversations & Boris memoryLifetime of accountDeleted within 30 days
Health & biometric logsLifetime of accountDeleted within 30 days
Connected banking dataUntil you disconnectDeleted within 30 days (or sooner on disconnect)
Generated AI artifactsLifetime of accountDeleted within 30 days
Financial transaction recordsLifetime of accountUp to 7 years (legal/tax requirement)
Server & audit logs90 days — 1 year (security)Retained per security policy
Anonymized, aggregated analyticsIndefinitelyIndefinitely (not identifiable)

You can configure a shorter activity-log retention period in Settings → Privacy → Retention (e.g., automatically prune workouts, meals, and journal entries older than a number of days you choose, or retain forever). This puts a hard ceiling on how long your sensitive activity data lives in our system.

Backups

Deleted data is removed from backups within 30 days of deletion as backups cycle out. We do not keep indefinite snapshots of deleted personal data.

13. Cookies & Tracking Technologies

We use the minimum tracking technologies necessary to operate and secure Genesis OS. We do not use third-party advertising cookies or fingerprinting.

Cookie / technologyPurposeTypeLifespan
Session authentication cookieKeeps you logged in securelyEssentialSession / 14 days
CSRF tokenPrevents cross-site request forgeryEssentialSession
Theme & appearance (localStorage)Remembers your UI preferencesEssentialPersistent (local)
Cookie consent preferenceRemembers your consent choiceEssential12 months
Privacy-respecting analyticsAggregated product improvement (opt-out)AnalyticsUp to 12 months
Service worker (PWA)Offline support and update notificationsEssentialUntil cleared

We show a cookie consent banner on first visit where required by law (e.g., the EU and UK). You can change your analytics preference at any time. We do not use advertising pixels, behavioral retargeting, or cross-site tracking.

14. Email Communications

Two types of email — one mandatory, one fully optional.

14.1 Transactional (cannot be opted out)

Billing receipts, security alerts, password resets, and account changes. These are necessary to operate and secure your account; you cannot opt out of them while your account is active.

14.2 Product & reminder (opt-in, withdrawable)

Daily mission reminders, weekly performance summaries, feature announcements, and founder updates — sent only with your consent during onboarding or in Settings. You can opt out anytime from notification settings in the app or by emailing us. Opting out never affects transactional emails.

15. Your Privacy Rights

Your rights depend on where you live. The table below summarizes the rights available under major privacy regimes and how to exercise each one.

RightGDPR (EU/EEA/UK)CCPA/CPRA (California)Other US states
Access / know what we hold✅ Art. 15✅ Right to know✅ Varies by state
Rectification / correction✅ Art. 16✅ Correction✅ Varies
Erasure / deletion✅ Art. 17✅ Delete✅ Varies
Data portability✅ Art. 20✅ Portable format✅ Varies
Restrict processing✅ Art. 18— (use opt-out)✅ Varies
Object to processing✅ Art. 21✅ Opt-out of sale/share*✅ Varies
Withdraw consent✅ Art. 7✅ Where consent given✅ Varies
Not subject to automated profiling✅ Art. 22✅ Varies
Limit use of sensitive data✅ CPRA✅ Varies

*We do not sell your data

Because we never sell or share personal data for monetary or valuable consideration, your CCPA right to opt out of "sale or share" is already fully honored — there is nothing to opt out of. We state this explicitly for clarity and compliance.

15.1 Exercising your rights

  1. 1Use the in-app tools: Settings → Privacy (export your data, adjust AI access, set retention), Settings → Account (delete account), Memory panel (delete memories).
  2. 2Email us at support@genesis-applications.com with the right you wish to exercise. We respond within 30 days (72 hours for urgent erasure).
  3. 3We verify your identity before acting on a request to protect your account from unauthorized access.
  4. 4For GDPR rights you may also lodge a complaint with your local Data Protection Authority; for CCPA, with the California Privacy Protection Agency.

Authorized agents

You may authorize someone to submit a request on your behalf. We will verify the authorization before acting, and may still confirm directly with you for sensitive requests like deletion.

16. Identity Verification for Requests

To protect your account, we verify identity before fulfilling privacy requests.

When you submit a request by email, we match it to the email address on your account. For high-impact requests (full data export, account deletion, or restricting processing), we may require you to complete the request from within your logged-in account, or to confirm additional details. This prevents bad actors from deleting or exporting your data without your permission.

17. Children's Privacy

Genesis OS is not directed to individuals under 16.

We do not knowingly collect personal data from children under 16, and we do not knowingly process the special-category data of minors. If you are a parent or guardian and believe your child has created a Genesis OS account, contact us immediately at support@genesis-applications.com and we will delete the account and all associated data promptly. For users in jurisdictions with a higher minimum age (e.g., 16 in parts of the EU), the higher age applies.

18. Changes to This Policy

We update this policy as our practices or the law evolves.

  • We will notify you of material changes by email and an in-app notice at least 14 days before they take effect.
  • Non-material changes (clarifications, formatting) may be made without separate notice; the "Last updated" date at the top of the page will reflect the change.
  • Your continued use of Genesis OS after a material change takes effect constitutes acceptance of the updated policy.
  • The version number at the top of this page helps you track what changed and when.

19. Contact Us & Data Protection Officer

How to reach us for any privacy matter.

PurposeContact
General privacy questionssupport@genesis-applications.com
Data subject access / deletion requestssupport@genesis-applications.com
Data Protection Officer / EU representative/privacy/dpo (DPO contact form)
Security vulnerability disclosuresupport@genesis-applications.com (subject: SECURITY)
Authorized agent requestssupport@genesis-applications.com

We aim to respond to all privacy inquiries within 5 business days, and to urgent data-subject requests (erasure, restriction, access) within 30 days — faster where required by law.

Your supervisory authority

If you are in the EU/EEA/UK, you may also contact your local Data Protection Authority. We encourage you to come to us first — most concerns can be resolved directly and faster.

Questions about your privacy?

We respond to all privacy inquiries within 5 business days — faster for urgent data-subject requests.

© 2026 Genesis AI Applications LLC · Established December 2025 · Genesis OS in development since January 2026