Privacy

What Gaja collects, why it collects it, who it reaches, and the things it will never do.

Last updated 2026-08-18.

This page is not final. Gaja is not yet incorporated, so the governing law is still to be settled and is marked below where it belongs. Everything else describes how Gaja actually works today, and is meant to be relied on. If you are deciding whether to trust Gaja with health or financial data, ask us first — hello@gaja.life.

The short version

  • You connect the sources. Gaja reads them, stores what it reads, and shows it back to you.
  • Nothing is sold, and nothing is shared with advertisers. There are no advertisers.
  • Nothing you connect or write is used to train any model, ours or anybody else's.
  • There is no ambient recording. Nothing listens; nothing reads your screen.
  • In a household, what you mark private stays private — including from the other adult on the account.
  • Ask and we delete it. Today that is a human doing it properly, not a button, and we say so below.

What we collect, and where it comes from

Everything below is data Gajaactually stores. Nothing is collected "just in case".

WhatExamplesWhere it comes from
AccountYour email address; the sign-in links we send youYou, when you sign in
HouseholdDisplay names, whether someone is an adult or a child, which plan the account is onYou, when the household is set up
HealthSleep periods and stages, readiness scores, heart-rate samples, workoutsOura, after you authorise it
MoneyAccounts, balances and transactionsYour bank through Plaid, after you authorise it
DiagnosticsError reports with the message redacted of tokens; aggregate page counts with no identifierAutomatic, when something breaks or a page loads

Health data is sensitive, and it is here only because you connected a device that produces it. That connection is the consent, you can withdraw it at any time by disconnecting, and disconnecting deletes the data it fed.

HIPAA does not apply to Gaja, and it is worth saying so plainly because people reasonably assume otherwise. HIPAA covers health providers, insurers and the companies working for them. Gaja is none of those: it is a consumer product reading a device you own. What protects your health data here is this policy, the consumer health data policy, and consumer privacy law — not HIPAA.

What we do not do

  • No selling, no sharing for advertising. There is no advertising business here to feed.
  • No training. Nothing you connect, capture or store is used to train a model. When Gaja adds an assistant, it will run under zero-retention terms and this page will name the vendor before it processes anything of yours.
  • No ambient capture. No always-on microphone, no screen reading, no background listening.
  • No third-party tracking. The analytics are cookieless and aggregate: no identifier, no session replay, no cross-site profile.
  • No de-identified resale either. "Aggregated and anonymised" is the usual escape hatch in a policy like this one. We do not sell, license or syndicate your data in any form, identified or not. The only aggregate numbers we look at are counts of page loads and errors.

How it is stored and protected

These are properties of the system, not intentions:

  • Every row carries the account and person it belongs to, and the database itself enforces who may read it. Access control is not a filter the application remembers to apply.
  • The keys to your connected accounts are encrypted before they are stored, with the encryption bound to the specific connection they belong to — a copied record does not decrypt somewhere else.
  • Your browser never holds a database credential. Sign-in cookies cannot be read by scripts.
  • Your bank credentials are typed into Plaid and never reach Gaja. We never see them.
  • Tokens and credentials are stripped from logs and error reports before they are written.

Where your data lives

Your data is stored in Canada (ca-central-1). The site itself is served from hosting infrastructure with points of presence in many countries, so a request you make is handled near you, but the stored data stays where it is written.

Where you connect a provider — Oura, or your bank through Plaid — that provider handles your data in its own locations under its own policy, and may be in another country. Data crossing a border can become subject to lawful access requests under the laws of the place it sits.

Households, and what the other adult can see

A family account has two adults, and they do not automatically see each other's data. Every row is either shared with the household or privateto one person, and private means private: it is filtered out before it reaches the other adult's screen, not hidden by the interface.

Children on an account do not sign in, and a child's health data is only stored once a guardian has recorded consent for it.

Who else touches your data

The first four are companies Gaja runs on. The last two are the sources you connect yourself — we do not choose them for you, and their own privacy policies govern their side of the exchange.

WhoWhat forWhat reaches them
SupabaseDatabase and sign-inEverything Gaja stores about you, including your health and financial rows
VercelHosting, and cookieless aggregate analyticsRequests to the site. The analytics carry no identifier and no session replay
SentryError reports when something breaksStack traces and a redacted error message. Tracing is off, and tokens are stripped before anything is written
ResendSign-in links and service emailYour email address and the message body
Ourayou authorise this oneYour sleep, readiness, heart rate and workoutsRead on your authorisation, with the narrowest scopes the product can work with
Plaidyou authorise this oneYour bank and card connectionsYour bank credentials go to Plaid and never to Gaja; we receive account and transaction data

How long we keep it, and how to make it stop

We keep what you connect for as long as the connection exists. Disconnecting a source deletes the data that came from it, along with its stored keys. That is a real delete — the rows are removed, not marked hidden.

One honest caveat about backups. Our database provider keeps encrypted infrastructure backups so the service can be restored after a failure. A deleted row can persist in those backups until they age out on the provider's schedule. Nothing reads from a backup in normal operation, and a restore would be an emergency, not a routine — but "deleted everywhere, this second" would not be true, so we do not say it.

Deleting everything, and taking a copy with you, are both promises we intend to keep as buttons. Neither is built yet. Until they are, email hello@gaja.life and a person will do it properly and confirm when it is done. We would rather say that plainly than show you a button that half works.

Law, and what happens if the company changes hands

We may disclose data where the law compels it — a court order, a subpoena, a lawful demand — or where it is genuinely necessary to stop harm or to protect someone's safety. Where we are permitted to tell you that it happened, we will.

If Gaja is ever sold, merged or reorganised, your data may transfer with it. It would remain governed by this policy, or by one at least as protective, and you would be told before anything changed.

Your rights

Depending on where you live you may have the right to see what we hold, correct it, delete it, take a copy, or object to how it is used. Gaja does not sell personal data or use it for automated decisions with legal effects, so there is nothing to opt out of on those counts.

To exercise any of these, email hello@gaja.life. We will not make you use a form, and we will not charge you.

We will check it is you first. Sending someone their health and financial data because an email claimed to be them would be a breach dressed as good service, and so would deleting a household's history on the same evidence. We verify through the account before acting, which usually means a confirmation to the address that signs in.

Children

Gajais not for children to use on their own, and children do not get logins. A child's health data can appear on a family account only where a guardian has recorded consent for it, and it can be removed at any time by withdrawing that consent.

Changes to this policy

When this changes in a way that affects what we collect or who it reaches, we will say so — by email to account holders, not by silently updating a date. The date at the top is the last substantive revision.

Questions about any of this go to hello@gaja.life. A person reads it.

Privacy · Terms · Gaja