Skip to content

Latest commit

 

History

History
79 lines (44 loc) · 5.8 KB

File metadata and controls

79 lines (44 loc) · 5.8 KB

LifeOS upstream project privacy notice

Version: 1.0
Effective date: 2026-08-04

1. Scope

This notice describes privacy practices for the upstream LifeOS open-source project, including its source repository, issue tracker, pull requests, release materials, and project-operated community surfaces.

It does not describe every independent LifeOS deployment. A person or organization that deploys, hosts, configures, or integrates LifeOS controls the data processed by that deployment and must publish its own notices, establish a lawful basis, configure retention, secure credentials, and satisfy applicable privacy obligations.

The upstream project does not become the controller or operator of an independent deployment merely because that deployment uses LifeOS source code.

2. Information associated with project participation

Project maintainers may receive or have access to:

  • GitHub account identifiers, profile information, contribution metadata, commit authorship, issue and pull-request content, review activity, and release interactions;
  • information voluntarily submitted in discussions, bug reports, feature requests, documentation, or other project communications;
  • technical information made available by GitHub or other project infrastructure, such as timestamps, audit events, security alerts, and abuse-prevention signals; and
  • confidential vulnerability details submitted through an approved private reporting channel.

Repository history and public project discussions are ordinarily public. Do not submit personal goals, health information, relationship data, access tokens, credentials, production exports, private prompts, customer data, or other sensitive information.

3. Self-hosted runtime data

The upstream reference software is designed for user-owned, tenant-scoped data. The upstream project does not intentionally receive data from independent self-hosted deployments unless an operator or user deliberately sends that data to a project surface.

LifeOS does not enable upstream product telemetry merely by being installed from this repository. Operators may add monitoring, analytics, model providers, calendar providers, identity providers, storage, or other integrations. Those services and configurations are controlled by the operator and may have separate privacy terms.

4. Purposes

Project-related information may be used to:

  • maintain, secure, test, document, and improve the project;
  • review and attribute contributions;
  • investigate defects, abuse, security incidents, and license compliance;
  • communicate about issues, releases, governance, and contributor activity; and
  • comply with legal obligations or protect the rights and safety of users, contributors, maintainers, and the public.

The project does not sell personal information submitted through project participation.

5. Public disclosure and service providers

Public contributions, comments, commits, reviews, and issue activity may be visible worldwide, copied into forks, mirrors, archives, package registries, search indexes, or downstream distributions, and may remain available after deletion from the original surface.

Project infrastructure providers process information under their own terms and privacy notices. GitHub is the principal collaboration platform for this repository. Independent deployment operators choose and are responsible for their own infrastructure and subprocessors.

Information may also be disclosed when reasonably necessary to investigate abuse or security incidents, comply with law, enforce project rights, or protect people and systems.

6. Retention

Public repository history is retained as part of the project record and may be replicated outside maintainers' control. Issue and pull-request records may be retained to preserve attribution, security history, engineering decisions, and license provenance.

Private vulnerability reports and related evidence are retained only as long as reasonably necessary for remediation, verification, coordination, and legal or security obligations. The project does not promise a fixed retention period for third-party platforms it does not control.

7. Choices and requests

Use GitHub account and privacy controls for information held by GitHub. For upstream project content, a person may open a non-sensitive repository issue requesting correction or removal. Do not place sensitive details in a public issue.

For a security or privacy matter that includes confidential information, use the private vulnerability-reporting process described in SECURITY.md. Maintainers may be unable to remove information from Git history, forks, mirrors, archives, or third-party indexes, and may preserve records required for attribution, license compliance, security, or legal obligations.

Requests concerning an independent LifeOS deployment must be directed to that deployment's operator.

8. Children

The upstream project is not directed to children. Do not submit a child's personal information to project surfaces. Deployment operators are responsible for age-related requirements applicable to their services.

9. International access

The repository and its service providers may be accessed and operated across multiple countries. Contributors and users should review the notices and transfer mechanisms of the platforms they choose to use.

10. Changes

Material changes will be committed to this file with an updated version or effective date. Repository history provides the change record.

11. Relationship to other documents

Use and distribution of the source code are governed by LICENSE. Contribution obligations are described in CONTRIBUTING.md. Community and reference-project use is further described in docs/legal/terms.md. A separate hosted-service or enterprise agreement, when offered, controls to the extent it expressly conflicts with these upstream project notices.