1. Introduction
WHITE LIFE LLC ("Company," "we," "us," or "our") operates the WHITE LIFE AI platform at https://whitelifeai.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service. We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant regulations.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, company name, job title, and password when you register
- Billing Information: Payment details processed securely through Stripe; we do not store full credit card numbers
- Communications: Messages you send to us via email, contact forms, or support tickets
- User Content: Data, prompts, and files you submit to the Service for AI processing
2.2 Information Collected Automatically
- Usage Data: API call logs, feature usage patterns, task execution metrics, and error rates
- Device Information: Browser type, operating system, IP address, and device identifiers
- Cookies & Analytics: Session cookies for authentication and anonymized analytics data to improve the Service
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, operate, and maintain the WHITE LIFE AI platform
- AI Processing: To route your tasks to appropriate AI models and return results
- Billing: To process payments, send invoices, and manage subscriptions
- Communication: To respond to inquiries, send service updates, and provide technical support
- Security: To detect and prevent fraud, abuse, and unauthorized access
- Improvement: To analyze usage patterns and improve Service performance, reliability, and features
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process personal data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our contractual obligations to you
- Legitimate Interests: Processing necessary for our legitimate business interests, such as fraud prevention and service improvement
- Consent: Where you have provided explicit consent for specific processing activities
- Legal Obligation: Processing necessary to comply with applicable legal requirements
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your data with:
- AI Providers: We transmit task data to AI model providers (Anthropic, OpenAI, Google, DeepSeek) to process your requests. Each provider's data handling is governed by their respective privacy policies
- Payment Processors: Stripe processes your payment information under their privacy policy
- Infrastructure Providers: Cloudflare (hosting, CDN, edge computing) and Supabase (database) process data on our behalf
- Legal Requirements: We may disclose information when required by law, court order, or governmental regulation
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Usage logs and audit trails are retained for up to 24 months for security and compliance purposes. You may request deletion of your account and associated data at any time by contacting [email protected]. We will process deletion requests within 30 days, subject to any legal retention obligations.
7. Data Security
We implement comprehensive security measures to protect your data:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- HMAC-authenticated gateway for all API requests
- Tenant isolation with row-level security (RLS) policies
- Hash-chain audit trail for all system operations
- Regular security audits and penetration testing
- SOC 2 Type II compliance (in progress)
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Request restriction of processing of your personal data
- Portability: Request transfer of your data in a structured, machine-readable format
- Objection: Object to processing of your personal data for certain purposes
- Withdraw Consent: Withdraw previously given consent at any time
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Cookies
We use essential cookies for authentication and session management. We use anonymized analytics cookies to understand how users interact with the Service. You can control cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the Service.
10. International Data Transfers
Your data may be processed in the United States and other countries where our infrastructure providers operate. For transfers from the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and other appropriate safeguards. Cloudflare's global edge network may process requests at the nearest point of presence to optimize latency.
11. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email at least 30 days before changes take effect. The "Last updated" date at the top of this page indicates the most recent revision.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
WHITE LIFE LLC
16192 Coastal Highway, Lewes, Delaware 19958, United States
Email: [email protected]
For EEA residents, you may also lodge a complaint with your local supervisory authority.