Effective date: 18 September 2026 Last updated: 18 September 2026
In short
Life Hub holds some of the most private information a household has: what medication your children take and when, what you earn and what you owe, when you sleep, what you are struggling to get done. We are telling you plainly what we do with it.
- We do not sell it, rent it, or use it for advertising. Ever.
- We do not use it to train artificial-intelligence models.
- Your household's data is visible only to the people you give a login to.
- It is stored on servers in the United States. Section 7 explains what that means and why you should care.
- You can export it or delete it whenever you like, without asking us.
This summary is here to be read. The rest of the document is the part that is binding.
1. Who we are
Life Hub is operated by Craft Dreams Co. ("we", "us"), based in Ontario, Canada.
We are the organisation accountable for the personal information described here under the federal Personal Information Protection and Electronic Documents Act ("PIPEDA").
Privacy questions, access requests and complaints:
craftdreamsco@gmail.com
Person accountable for privacy: The founder, Craft Dreams Co.
2. Who this applies to
This policy covers app.craftdreamsco.com and the Life Hub kitchen display,
together "the Service".
A Life Hub household is the unit of privacy. One person signs up and creates it; they may then add logins for other people. Everyone with a login to a household can see everything in that household. There are no per-person permission tiers inside a household — this is a deliberate design decision and you should understand it before you add someone.
Where a household enters information about a person who does not have a login — a child, an elderly parent, a partner who does not use the app — the person who entered it is responsible for having the authority to do so. Section 6 says more about children.
3. What we collect
3.1 Information you give us to open an account
- Email address. This is how you sign in and how we reach you.
- A password, which we never store. We store a PBKDF2 hash with a per-account salt, from which the password cannot be recovered.
- Optionally, a household name, and display preferences (currency, timezone, theme, appearance, text size).
3.2 Information your household puts into the Service
This is the substance of the product, and it is unusually sensitive. It includes, depending on what you use:
- Household members. Names, relationships, colours, and photographs you upload. A flag marking a member as supervised (in practice, a child).
- Health information. Medication names, doses and refill dates, attached to a named person and to a time of day. Sleep records — bedtime, wake time, hours slept, and free-text notes. Records of how much you were able to get through in a week.
- Financial information. Income and expense categories and amounts, monthly budgets, savings goals and contributions, and monthly totals derived from bank statements.
- Calendar and scheduling. Events, tasks, routines, chores, reminders.
- Meals and groceries. Recipes, weekly plans, shopping lists, and estimated and actual grocery spend.
- Free text you write. Brain dumps, notes, requests for help.
- Religious or devotional content, if you use the daily-passage feature.
3.3 Information about bank statements — read this one carefully
When you import a bank statement, the statement file never leaves your device. It is read in your browser. What is sent to us is the monthly total per category, plus any description-to-category rules you chose to save.
We do this deliberately. A year of transaction descriptions says where you shop, bank, drink, worship and get treated, and we do not want it. The features that sound as though they need it can be computed on the device that already has the file.
3.4 Information we generate
- Session cookies, so you stay signed in.
- Failed sign-in attempts and the IP address they came from, kept only long enough to rate-limit attacks and then pruned.
- A per-day count of AI requests, to cap cost.
- Technical logs from our hosting provider.
3.5 What we do not collect
We have no analytics, no advertising identifiers, no third-party trackers, and no session-recording tools. We do not track you across other websites.
4. Why we collect it, and our legal basis
We rely on your consent. You give it by signing up and by choosing to enter information; you may withdraw it at any time by deleting your household (section 10), subject to any legal retention we are required to observe.
We use household data only to:
- Run the Service — show you your calendar, compute your totals, send the reminders you asked for.
- Keep it working and secure — diagnose faults, prevent abuse, maintain backups.
- Communicate with you about your account — password resets, email confirmation, billing, service notices, and notification of a privacy breach if one occurs.
- Meet legal obligations — tax records for payments, breach records under PIPEDA.
We do not use your household's data to train, fine-tune or evaluate artificial-intelligence models, and we do not permit our suppliers to.
5. Artificial intelligence
Some features — turning a brain dump into tasks, reading a photographed receipt or recipe — send the text or image you supplied to a model run by Cloudflare (Workers AI) so it can be structured.
- Only the content of that one request is sent. Not your budget, not your calendar, not your household's other data.
- It is sent to produce your result and for no other purpose.
- Under our agreement with Cloudflare it is not used to train models.
- If you would rather not use it, do not use those features. Everything else in the product works without them.
6. Children
Life Hub is built for households, and households contain children. The Service is designed so a parent or guardian can record a child's chores, schedule, medication and photograph.
- An account may only be opened by an adult (18 or over in Ontario).
- Information about a child is entered by the adult running the household, who is responsible for having the authority to enter it.
- We do not knowingly allow a child to open their own household.
- A child's information is visible to everyone holding a login to that household, and on the kitchen display if the household uses one. Please think about where that screen is before you put medication details on it.
- A parent or guardian may see, correct or delete a child's information at any time through Settings, or by writing to us.
7. Where your data is stored — and why we are telling you
Your household's data is stored in the United States, in Amazon Web
Services' Ohio region (us-east-2), by our database provider Neon. Backups
are held with GitHub, also outside Canada.
This matters, and PIPEDA requires us to be straightforward about it:
While your personal information is in the United States, it is subject to the laws of that country, and may be accessible to United States courts, law enforcement and national-security authorities under those laws, including where no Canadian court order would be required. This applies whatever protections we and our suppliers put in place.
We use contractual and technical measures comparable to those we apply in Canada — encryption in transit, encryption at rest, row-level isolation between households, encrypted backups. But we cannot contract out of another country's laws, and we are not going to pretend otherwise.
If you are not comfortable with this, please do not put information into the Service that you would not want subject to it.
[REVIEW NOTE: moving to a Canadian region is a migration, not a rewrite. Worth deciding before launch rather than after.]
8. Who else can see it
We do not sell, rent or trade personal information. We share it only with suppliers who need it to run the Service, each bound to use it only on our instructions:
| Supplier | What they handle | Where |
|---|---|---|
| Cloudflare | Application hosting, content delivery, AI processing, some outbound email | Global edge; United States |
| Neon | The database holding your household's data | United States (Ohio) |
| Stripe | Payment processing. Card numbers go to Stripe, never to us. | United States |
| Resend | Password-reset, verification and notification email | United States |
| GitHub | Encrypted database backups | United States |
If you connect a calendar, Life Hub exchanges calendar events with that provider at your instruction:
| Optional, only if you connect it | What is exchanged |
|---|---|
| Google Calendar | Events, two-way |
| Apple iCloud Calendar | Events, two-way |
We may also disclose personal information where the law requires it — a court order, warrant, subpoena or other lawful demand. Where we are permitted to tell you, we will.
If the business is ever sold or merged, household data may transfer to the buyer, who would be bound by this policy or by one no less protective. We would tell you before it happened.
9. How long we keep it
- While your household exists: as long as you keep it. This includes after a subscription ends. We close access 30 days after a trial or subscription lapses, but we do not delete anything — the household stays intact so that subscribing again restores it, and so that you can still download a copy. If you would rather we did not hold it, delete the household; that is the only thing that erases it.
- After you delete your household: it is immediately inaccessible, and is permanently erased after 30 days. The window exists so a deletion made in a bad week can be undone. During it you may restore from the link we email you.
- Backups: encrypted daily backups are kept for 30 days and then destroyed. A household deleted today disappears from backups within 30 days.
- Failed sign-in records: pruned automatically, within hours.
- Billing records: kept as long as Canadian tax law requires (generally six years), by us and by Stripe.
- Privacy breach records: 24 months, as PIPEDA requires — including breaches we assessed and decided were not reportable.
10. Your rights
Under PIPEDA you may:
- See what we hold. Most of it is on your screen already. Ask us and we will give you the rest, within 30 days and at no charge.
- Correct it. Nearly everything is editable in the app. If something is not, tell us.
- Take it with you. Tasks, chores, budgets and routines export to CSV from inside the app, without asking us.
- Delete it. Settings → delete household. It is real deletion, and it cascades through every table. See section 9 for the 30-day window.
- Withdraw consent, by deleting your household. We cannot run the Service without the data it holds, so withdrawal and deletion are the same act.
- Complain. Write to
craftdreamsco@gmail.com. We will respond within 30 days. If we cannot resolve it, you may complain to the Office of the Privacy Commissioner of Canada —priv.gc.ca, 1-800-282-1376.
We will ask you to confirm your identity before acting on a request, so that someone else cannot make it on your behalf.
11. How we protect it
- Each person has their own login and their own password. Passwords are stored as salted PBKDF2 hashes.
- Every household's rows are separated by database-enforced row-level security, forced on every table. The database account the application uses cannot switch it off, and cannot read a row outside the household it is serving even if asked directly.
- Sessions use cookies that JavaScript cannot read, sent only over HTTPS.
- Sign-in and sign-up are rate-limited.
- The kitchen display is given a token with strictly less access than the person who set it up: it can read a short list of screens and can write almost nothing.
- Backups are encrypted before they are stored.
No system is perfectly secure, and we will not claim otherwise. If a breach occurs that creates a real risk of significant harm to you, we will report it to the Privacy Commissioner and tell you, as PIPEDA requires. Our internal plan for doing so is written down and rehearsed.
12. Cookies
We use cookies only to run the Service:
dt_session— keeps you signed in. Expires after 90 days.dt_display_session— marks a device as the kitchen display. Expires after one year.
Both are strictly necessary. We set no advertising or analytics cookies, so there is nothing here to opt out of. Your browser can refuse them, but you will not be able to sign in.
Your device also stores display preferences locally so the app does not flash the wrong colours while it loads. That never leaves your device.
13. Changes
If we change this policy we will update the date at the top. If the change is significant — a new category of data, a new country, a new supplier with access to household data — we will email you before it takes effect.
14. Contact
Craft Dreams Co.
Ontario, Canada
craftdreamsco@gmail.com
Office of the Privacy Commissioner of Canada — priv.gc.ca — 1-800-282-1376