Privacy Policy
Last updated: July 2026
1. Introduction
This Privacy Policy explains how LAZO (“we,” “us,” or “our”), the operator of Life Tier List (the “Service”), collects, uses, shares, and protects your personal data when you use our Service at lifetiers.lazo.build.
Life Tier List is a competitive self-improvement platform where you log real-life habits, earn a tier and rank, and compete on leaderboards and in friend leagues. We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data-protection laws.
2. Data Controller
The data controller for the purposes of this Privacy Policy is:
LAZO
Sole proprietorship / Individual
Podgorica, Montenegro
Email: support@lazo.build
3. Data We Collect
3.1 Account Data
- Email address
- Nickname (displayed publicly)
- Country (two-letter code, if provided)
- Authentication data managed by our auth provider (we never store your password in plaintext; if you sign in with Google, we receive basic account identifiers from Google)
3.2 Activity & Progress Data
- The habits you log each day and the values you enter (for example minutes trained, hours slept, pages read)
- Derived gameplay data: scores, streaks, per-category and overall tiers, ranks, percentiles, season history
3.3 Photo Proofs
For certain categories you may submit a photo taken in response to a random challenge, so the activity can be verified. Each photo is sent to our AI verification provider (see Section 6) for assessment. Photos are not retained by default: an image is written to private storage only if your proof is randomly sampled for peer review, in which case it may be shown to members of your league and is automatically deleted on a rolling basis (currently within 7 days). Photos that are not sampled are discarded as soon as they have been assessed.
3.4 Verification Answers
Short written answers you submit for text-based verification, which are analyzed by our AI provider and stored with your log.
3.5 Social Data
League and community membership, and content generated by participating (such as head-to-head comparisons and peer-review votes).
3.6 Technical & Anti-abuse Data
- IP address and basic request metadata, used for rate-limiting and abuse prevention
- Anti-fraud signals such as suspicion and trust scores derived from your activity
4. How We Use Data
- Service provision: to operate the Service — logging, scoring, ranking, verification, leagues, communities, cosmetics, and seasons
- Verification & fair play: to verify activity and to detect and prevent cheating, manipulation, and abuse
- Payments: to process purchases and subscriptions through Paddle
- Communications: to send account, security, and service-related messages
- Improvement & security: to analyze usage in aggregate and to keep the Service secure
- Legal compliance: to comply with applicable laws
We do NOT sell your personal data, use it for third-party advertising, or share your individual data with advertisers or data brokers.
5. Legal Basis for Processing (GDPR)
- Contract (Art. 6(1)(b)): processing necessary to provide the Service you signed up for, including logging, scoring, ranking, and verification
- Legitimate interests (Art. 6(1)(f)): keeping rankings fair, preventing fraud and abuse, securing the Service, and improving it — balanced against your rights
- Consent (Art. 6(1)(a)): submitting photo proofs is optional and based on your consent, which you can withdraw at any time
- Legal obligation (Art. 6(1)(c)): where processing is necessary to comply with the law
6. AI & Photo Verification
To verify certain activities, photo proofs and written answers are processed by a third-party AI model. Specifically:
- AI provider: we use Google's Gemini API (Google Ireland Limited / Google LLC)
- What is sent: only the specific image or text answer needed for the verification task, together with the challenge instructions. We do not send your account data or unrelated records
- How it works: the model returns a machine assessment (for example, whether the photo plausibly shows the activity and meets the challenge), which the Service uses to mark the log as verified or not
- Provider data handling: per Google's API terms, data submitted through the paid Gemini API is not used to train Google's models; Google may retain inputs and outputs for a limited period for abuse-monitoring purposes before deletion
- Automated verification does not produce legal or similarly significant effects about you; it affects only in-game scoring, and you can retake a proof or log without verification (with reduced points)
7. Data Sharing & Sub-processors
We share data with the following providers solely to operate the Service:
- Supabase (Supabase, Inc.) — database, authentication, and private file storage for photo proofs
- Vercel (Vercel, Inc.) — application hosting and edge network
- Upstash (Upstash, Inc.) — rate-limiting infrastructure
- Google (Google Ireland Limited / Google LLC) — Gemini AI verification, and Google Sign-In if you use it
- Paddle (Paddle.com Market Limited) — payment processing as Merchant of Record
We may share anonymized, aggregated statistics that cannot identify any individual. We do not otherwise sell or share your personal data.
8. Public & Social Data
The Service is social and competitive. Your nickname, tier, rank, streak, and public profile are visible to other users on global and category leaderboards and to members of any league or community you join, and your public profile page is accessible by nickname. Please do not use a nickname or profile content you are not comfortable making public. If a photo proof of yours is sampled for peer review, it may be shown temporarily to members of your league for verification.
9. Data Retention
- Active accounts: account and activity data are retained while your account is active
- Photo proofs: discarded immediately after assessment unless sampled for peer review, and in that case automatically deleted on a rolling basis (currently within 7 days); only the verification result (verified / not) is kept with your log
- After deletion: when you delete your account, associated personal data is deleted within 30 days
- Backups: residual copies may persist in backups for up to 90 days after deletion
- Anonymized data: aggregated data that cannot identify you may be retained indefinitely; certain data may be retained longer where required by law
10. Your Rights (GDPR)
Under the GDPR you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7(3)), as well as the right to lodge a complaint with a supervisory authority.
You can delete your account and associated data at any time from your account settings. To exercise any other right, contact us at support@lazo.build. We will respond within 30 days and may verify your identity first.
11. Data Security
- Encryption in transit: all traffic uses TLS/HTTPS
- Encryption at rest for stored data
- Row-level security: database policies ensure users can only access their own data
- Private storage: photo proofs are kept in a private bucket and served only via short-lived signed links when needed for peer review
- Access controls limiting access to production data to authorized personnel
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. International Transfers
Your data may be processed outside the European Economic Area, including in the United States, where providers such as Supabase, Vercel, Upstash, and Google operate infrastructure. Where data is transferred outside the EEA, we rely on appropriate safeguards such as European Commission Standard Contractual Clauses or an adequacy decision.
14. Children's Privacy
The Service is not intended for anyone under the age of 16 (the age of digital consent under Article 8 GDPR; a higher age applies where your local law requires). We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it as soon as practicable. If you believe a minor has provided us data, contact us at support@lazo.build.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the date at the top of this page, and for material changes we will make reasonable efforts to notify you. Your continued use of the Service after changes constitutes acceptance of the updated policy.
16. Contact
For any questions about this Privacy Policy or to exercise your rights, contact us at:
Email: support@lazo.build
LAZO
Podgorica, Montenegro