Skip to content
LEVELYSS ENTER

PRIVACY POLICY

Effective September 1, 2026 · Applies to the Levelyss app (app.levelyss.com) and website at levelyss.com

THE SHORT VERSION

  • Your tasks, quests, and stats live on Levelyss's own servers — nowhere else.
  • The AI that scores tasks and forges quests is self-hosted. Your text is never sent to third-party AI providers.
  • Voice dictation is the one exception: it uses your browser's built-in speech service (Google, Apple, or Microsoft, depending on your browser). We never receive the audio — only the finished text.
  • Usage analytics run on our own server and set no cookies — no third-party trackers, no ad networks, and nothing for you to consent to.
  • No ads, and we never sell your data.

Who we are

Levelyss ("we", "us") is a task-management service operated by Evgeniia Alsagarova PR Alsagarova Software Development, a sole proprietorship registered in the Republic of Serbia and the data controller for everything described here. This policy covers the web app at app.levelyss.com and the website at levelyss.com. For anything privacy-related, write to levelyss_support@proton.me.

What we collect

  • Account. An email address and password (stored only as a secure hash — we never see or keep the plain password), or your Google or Apple identity if you use "Sign in with Google" or "Sign in with Apple". Those providers share your name and email with us (Google also shares your profile picture; Apple lets you hide your real email behind a private relay address). You can also use Levelyss as a guest: a guest account is a random ID with no email attached.
  • Profile. A display name and, if you upload one, an avatar image. Avatars are served from a public URL — anyone who has the link can view the image, so don't upload anything you wouldn't show.
  • Your content and progress. Everything you put into Levelyss: tasks and their text, quests and goals, rewards you name, skills, categories, habits, streaks, XP, levels, completion history, and timestamps. This is the product — it's stored so the service works.
  • AI requests. Each time the System analyzes a task, proposes one, or forges a quest, we log the request and the AI's reply on your account. See "The AI is self-hosted" below.
  • Voice. If you dictate, only the resulting text reaches us — it becomes ordinary task text. The audio itself never touches our servers. See "Voice dictation" below.
  • Payments. If you buy Premium on the web, checkout is handled by Paddle, our merchant of record — we never see or store your card details. What we receive is your subscription status (product, renewal and expiry dates) and the email you used at checkout. In the future mobile apps, purchases will go through Apple or Google instead.
  • Technical. Standard server logs (IP address, browser type, request times) kept for security and operations, and rotated periodically. In your browser, we use local storage for your session and for an offline copy of your own data so the app starts fast.
  • Usage. How the site and the app get used — see "How we measure usage" below.

The AI is self-hosted

Task scoring, the Quest Forge, and task suggestions run on our own hardware, using a language model we operate ourselves. Your tasks and goals are not sent to OpenAI, Google, Anthropic, or any other AI provider — there is no third party in that loop.

What a request contains: the task or goal text you typed, and — for suggestions — a short progress summary (your level, streak, attribute and skill levels, titles of recently completed tasks, and any steer note you add). Nothing else.

Each request and its reply are logged on your account to enforce usage limits, prevent abuse, and tune the System's scoring. Deleting your account removes your logs immediately.

How we measure usage

Usage analytics run on our own server, on software we operate ourselves. No third party receives them. They set no cookies and keep no identifier that follows you — which is why there is no cookie banner here. Your task text, goals, name and email are never included.

Separately, for signed-in users we record which days you were active — the dates only, so we can tell whether Levelyss keeps people coming back. Deleting your account deletes it too.

Voice dictation — the third-party exception

The mic button uses the Web Speech API — your browser's built-in dictation, operated by the browser's maker: Google in Chrome, Apple in Safari, Microsoft in Edge. When you dictate, your browser sends the audio to that provider's speech service, under that provider's own privacy policy, and it may be processed on their servers.

Levelyss never receives, stores, or transmits the audio. What comes back to the app is the transcribed text, which you can edit before saving like anything you typed.

Dictation is strictly opt-in: it only runs after you tap the mic and grant your browser's microphone permission, and it stops on silence or when you stop it. If you'd rather keep speech providers out entirely, simply type — every voice feature has a typed path. (Future native apps will use the platform's speech service; we'll update this policy when they ship.)

Third parties

  • Your browser's speech service (Google / Apple / Microsoft) — only if and when you dictate, as described above.
  • Google or Apple sign-in — only if you choose one. The provider learns that you signed in to Levelyss; we receive your name and email (plus your profile picture from Google; Apple can give us a private relay address instead of your real email).
  • Paddle — our merchant of record for web purchases of Premium. If you buy, Paddle processes your payment details, billing address, and checkout email under Paddle's privacy policy, and handles invoices, taxes, and refunds (see the refund policy). Card numbers never touch our servers.
  • Telegram — only if you use the contact form: your message and the details you enter with it are delivered to us as a Telegram message, so Telegram processes them in transit.
  • Analytics — none. Usage analytics run on our own server: no cookies, no cross-site identifiers, and the data never leaves our machines. See "How we measure usage" above.
  • Our hosting provider — the data center that rents us the server our stack runs on.

We never sell your personal data, and we'll keep this list current as the service evolves.

Retention & deletion

Your data is kept for as long as your account exists. You can delete your account right in the app (Profile → Delete account), or email levelyss_support@proton.me from your account's address. Deletion is permanent; there is no recovery.

Your rights

You can ask us to access, correct, export, or delete your personal data, or object to how we handle it — email levelyss_support@proton.me and we'll respond within 30 days. If you're in the EEA or UK: we process your data to provide the service you signed up for (contract), to keep it secure and prevent abuse (legitimate interest), and for voice dictation only when you invoke it (consent). You also have the right to complain to your local data-protection authority.

Security

All traffic is encrypted in transit (HTTPS). On the server, row-level security scopes every record to its owner — your session can only ever read your own rows. Passwords are hashed, and administrative access is restricted to the developer. No system is perfectly secure, but the attack surface here is deliberately small: one stack, our machines, no third-party sprawl.

Children

Levelyss is not directed at children under 13 (or the higher minimum age your local law sets), and we don't knowingly collect their data. If you believe a child has an account, contact us and we'll delete it.

Changes to this policy

Levelyss is in beta and evolving — native apps are planned, and future features may add to this policy. We'll post updates here with a new effective date, and announce material changes in-app.

This page is the current version. Earlier versions are available on request.

Contact

Questions, requests, or concerns: levelyss_support@proton.me, or use the contact form.

LEVELYSS
FEATURES FAQ BLOG OPEN THE APP TERMS PRIVACY REFUNDS CONTACT

© 2026 LEVELYSS

SYSTEM LOG: [ PRIVACY POLICY LOADED ]