← Living Ascent

Privacy Policy

Your ascent belongs to you.

Last updated September 3, 2026. This policy explains how The Living Ascent Protocol (“LAP”) handles information when you create an account, save your ascent, use the Vitality Workspace, use Ask LAP, or connect an optional third-party service.

Information we collect

Account information may include your email address, authentication identifiers, optional authenticator-factor identifiers, and an optional display name.

Ascent information may include the levels, weather, actions, progress, notes, and other information you choose to save across the nine LAP mountains.

Vitality information may include health measurements and health-related information you choose to enter, such as age, height, weight, waist circumference, blood pressure, resting heart rate, health goals, medications or supplements, laboratory and hormone results, DEXA/body-composition information, sleep-study or wearable information, diet and exercise logs, and periodic check-ins. This information may be sensitive health information.

Ask LAP information includes the messages you send and the responses generated for you. Because LAP is a personal-development system, you may choose to enter information that is personal or sensitive. Only enter information you are comfortable storing and processing through the service.

If you connect Google Calendar, LAP stores encrypted authorization credentials and limited connection metadata, such as the provider, scopes, connection date, and optional account identifier. Calendar availability and event details are processed only when needed to provide calendar features you request.

Basic technical and analytics information may also be processed by our hosting and analytics providers to operate, secure, and improve the service.

How we use information

We use account, ascent, and Vitality information to authenticate you, sync your LAP experience across devices, remember your saved progress, generate requested Vitality analyses, provide Ask LAP context, protect the service from abuse, troubleshoot problems, and improve the product.

We do not sell your personal information to advertisers.

Authentication and security

LAP uses Supabase Auth for account authentication. Passwords are not stored in LAP application tables; Supabase stores password hashes rather than plaintext passwords.

When a new password is created or a valid password is used to sign in, LAP may check whether that password appears in a known breach corpus. LAP uses the Have I Been Pwned Pwned Passwords k-anonymity range service: the raw password and complete password hash are not sent to that service.

Users may optionally enroll a time-based authenticator app as a second factor. When two-factor authentication is enabled, LAP requires the additional authenticator challenge before protected cloud account data is made available to that session.

Signed-in LAP sessions use HttpOnly, Secure cookies in production so client-side JavaScript cannot read the access or refresh tokens. Network requests use HTTPS. LAP database tables use Row Level Security so an authenticated user can access only records associated with that account.

LAP is not end-to-end encrypted. Information stored in or processed by the service can be technically accessible to the systems and service providers required to operate the product. Do not enter information you are not comfortable storing and processing through LAP.

No security system can guarantee absolute protection. We continuously review the application and its service providers for reasonable security improvements.

Service providers and AI processing

We use service providers to operate LAP. Current providers include Supabase for authentication and database services and Vercel for website hosting, application infrastructure, and AI gateway services. Password breach screening uses the Have I Been Pwned Pwned Passwords service as described above.

When you request a Vitality Brief, the health information currently present in your Vitality Workspace may be sent through Vercel AI Gateway to an OpenAI model so the requested analysis can be generated. The analysis is designed for organization, education, trend awareness, questions, and next-step planning; it is not medical diagnosis or a prescription.

When you use Ask LAP, relevant portions of your current ascent state, recent conversation context, and new message may be sent through Vercel AI Gateway to an OpenAI model so a response can be generated. These providers process information under their own service terms, security controls, and retention practices.

LAP stores the Ask LAP conversation history associated with your account so the feature can maintain continuity. You can clear that conversation from Ask LAP, export it, or delete it by deleting your account.

Optional calendar connections

You can choose to connect Google Calendar so LAP can check availability and create or manage LAP time blocks at your direction. LAP requests only the calendar permissions needed for those features and does not use calendar information for advertising.

Google authorization credentials are encrypted before they are stored and are associated with your LAP account. You can disconnect Google Calendar from the Integrations page at any time; LAP will request revocation of the Google grant and delete its stored connection credentials.

Retention

Your LAP profile, saved ascent state, saved Vitality information, and optional integration credentials are retained while your account remains active unless you remove them or delete the account. Stored Ask LAP messages remain until you clear the conversation or delete the account.

Infrastructure providers may retain limited operational, security, backup, or abuse-prevention logs for their own configured retention periods. Deleting your LAP account removes the active account-linked application records, but provider backups or security logs may take additional time to age out under provider policies and legal requirements.

Your privacy choices and rights

From Account & Privacy, you can download a machine-readable copy of your LAP profile, ascent state, Vitality information, and Ask LAP history. You can also manage optional two-factor authentication and permanently delete your LAP account and linked application data.

Depending on where you live, including California and parts of Europe, you may have additional rights to access, correct, delete, restrict, object to certain processing, or receive a portable copy of your personal information. The in-product export and deletion tools are intended to make common requests self-service; other privacy requests can be submitted through the website contact channel.

Children

LAP is not intended for children under 13. Users who have not reached the age of majority where they live should use the service only with appropriate parent or guardian involvement and consent.

Changes to this policy

We may update this policy as LAP evolves. Material changes will be reflected by updating the date on this page and, when appropriate, providing additional notice.

Contact

For privacy questions or requests that cannot be completed through the account controls, use the contact channel on the website and identify the request as a Living Ascent privacy request.