Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains how João Nuno Figanier Alves Pereira, operating the website lifeoutput.com ("Life Output," "we," "us"), collects, uses, and protects personal data belonging to visitors and customers ("you"). It's written to comply with the EU General Data Protection Regulation (GDPR), Portugal's Lei 58/2019, which implements the GDPR nationally, and Lei 41/2004, which governs electronic communications and cookies in Portugal.
If anything here is unclear, contact us at hello@lifeoutput.com and we'll explain it in plain terms.
1. Who We Are
Life Output is operated by João Nuno Figanier Alves Pereira, based in Lisbon, Portugal. For the purposes of GDPR, we are the data controller for the personal data described in this policy.
Contact: hello@lifeoutput.com
If you have a concern we haven't resolved, you have the right to lodge a complaint with Portugal's data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt, or, where applicable, another competent EEA supervisory authority, including the one in the country where you live or work.
2. What Personal Data We Collect
We collect only what we need to run the site, deliver what you've asked for, and understand whether the site is working. Specifically:
a) Email address, when you sign up for a template, a download, or updates via one of our forms. Some forms include a separate, unticked checkbox letting you choose whether to also receive ongoing emails about the Household Wiki. Checking it is entirely optional and never required to receive the item you signed up for. We don't ask for your name or any other detail at signup.
b) Website usage data, if you consent to analytics, collected automatically when you browse the site: pages viewed, approximate location (derived from IP address), device and browser type, and how you arrived at the site. We use this to understand what content is useful and to confirm our forms work correctly.
c) Purchase information, if you buy the Household Wiki. Payment is processed by Gumroad. We do not receive or store your card details. Gumroad's role depends on what it's doing with the data: it's our processor when it stores buyer information on our behalf (your email address and purchase history), and it's an independent controller in its own right when it processes payments and payouts as merchant of record, and for fraud prevention, tax reporting, and its own legal compliance. See Gumroad's own privacy policy for how it handles data in that second role.
d) Anything you send us directly, such as a reply to one of our emails or a message through a contact form, which we keep to respond to you.
e) Your cookie preference, recorded when you make a choice through our cookie banner, whether that's granting consent, rejecting it, or adjusting individual categories, including a timestamp. Where you've given consent, we keep this as evidence that it was validly obtained. Where you've rejected cookies, or haven't yet made a choice, we still store a small marker so the banner doesn't repeatedly interrupt you; this reflects a preference, not consent to anything.
f) Basic technical and security information, such as IP addresses in server access logs, generated automatically by our hosting provider independently of analytics consent, to keep the site secure and operating reliably.
Do you have to provide this? The email address for a requested download is necessary if you want it delivered; without it, we can't send you the file. Purchase information is necessary to process a sale; without it, Gumroad can't complete your purchase. The marketing checkbox is entirely optional, and declining it has no effect on anything else you've asked for. Responding to a message you've sent us naturally depends on the information in that message; leaving out details we need to help may limit how fully we can respond. Analytics consent is also optional, and rejecting it does not prevent you from using the site normally. Technical and security log data isn't something you actively provide; it's generated automatically as part of how the site operates.
We do not collect or have access to the information you enter into your own copy of the Household Wiki or the free template once downloaded. Those files live on your own device or in your own Google account. Even though the product itself is built to hold sensitive household information (medical details, children's data, schedules), none of that ever reaches us. This policy governs data collected by the website, not the contents of a file you fill in privately after downloading it.
3. Why We Process Your Data, and Our Legal Basis
| What we do | Legal basis (GDPR Article 6) |
|---|---|
| Send you the free template you requested and resolve related delivery issues | Legitimate interest, in fulfilling the specific request you made |
| Send you occasional emails about the Household Wiki | Consent, which you can withdraw at any time |
| Understand how visitors use the site (analytics) | Consent, for non-essential cookies |
| Process a purchase and deliver the product | Performance of a contract |
| Keep basic records for tax and accounting | Legal obligation |
| Respond to a message you've sent us | Legitimate interest, in communicating with people who contact us |
| Use a contribution or quotation from your correspondence in our content | Consent, given separately from simply responding to your message |
| Record evidence that valid consent was given, where you've granted it | Legal obligation, under GDPR Article 7, to be able to demonstrate consent |
| Remember your preference where you've rejected cookies or haven't made a choice, so the banner doesn't repeatedly interrupt you | Legitimate interest, in respecting your choice and avoiding repeated prompts |
| Maintain basic technical and security logs | Legitimate interest, in keeping the site secure and operating reliably |
| Comply with a legal obligation, or establish, exercise, or defend a legal claim | Legal obligation, or legitimate interest where a legal claim is involved |
Where we rely on consent, you can withdraw it at any time. Withdrawing consent doesn't affect the lawfulness of anything we did before you withdrew it. If you've told us it's fine to quote something you sent us, and we later anonymize it so it no longer identifies you, the resulting anonymous content falls outside GDPR entirely; it's the original correspondence, and the process of selecting and anonymizing it, that this table covers.
4. Cookies and Similar Technologies
We use cookies and comparable technologies for two purposes:
Strictly necessary cookies. These are limited to what's genuinely required for the site to work, for example, remembering your cookie-consent choice itself, so the banner doesn't reappear every time you load a page. They don't require consent under the ePrivacy Directive.
Analytics cookies, which help us understand aggregate visitor behavior. We currently use:
| Tool | Purpose | Data shared |
|---|---|---|
| Google Analytics 4 (via Google Tag Manager) | Understand traffic and confirm form submissions | Usage data, approximate location, device data |
These are non-essential and only run after you've given consent through our cookie banner, powered by CookieYes, a Google-certified CMP Partner integrated with Google Consent Mode. Before you make a choice, and if you choose to reject, none of these cookies are set. You can change your preference at any time using the floating consent icon in the bottom corner of the site.
Google Search Console is different, and isn't gated by the cookie banner above. It doesn't run on lifeoutput.com and sets no cookie on your device. It shows us aggregated data about how the site appears in Google's own Search, News, and Discover results, impressions, clicks, and position, generated entirely on Google's side from how people interact with our listing inside Google's services. No client-side tracking of your visit to our site is involved.
For a full, itemized list of every cookie we use, including exact names, providers, and expiry, see our detailed Cookie Policy, which updates automatically as our cookie usage changes.
You can also control cookies through your browser settings, though blocking all cookies may affect how parts of the site work.
5. Who We Share Data With
We share personal data with a small number of companies that help us run the site and deliver what we sell. Most act as our processor for at least part of what they do; Gumroad has a distinct independent-controller role for certain functions, explained in the table below.
| Company | What they handle | Located | Transfer mechanism |
|---|---|---|---|
| Kit (email platform) | Email addresses, email delivery | United States | EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as Kit's fallback mechanism where the DPF doesn't apply, per Kit's own Data Processing Addendum |
| Google (Analytics, Tag Manager) | Website usage data | Google Ireland Limited — Ireland (EEA), our direct contracting entity | Personal data may be transferred onward to Google LLC and other Google entities outside the EEA. Where that happens, it's protected by the EU-U.S. Data Privacy Framework (for certified participants) or Standard Contractual Clauses as a fallback |
| CookieYes (cookie consent management) | Consent choices and logs, so we can demonstrate compliance | United Kingdom (CookieYes Limited, company no. 13074037) | European Commission adequacy decision for the UK under GDPR Article 45, renewed 19 December 2025 and valid through 27 December 2031. CookieYes also uses its own subprocessors for parts of its service, some outside the UK/EEA; see Section 6 |
| Hostinger | Website hosting | Hostinger International Limited — Cyprus (EEA), our contracting entity. Physical hosting: Boston, Massachusetts, United States | For this transfer of data outside the EEA, Hostinger's Data Processing Agreement incorporates the European Commission's Standard Contractual Clauses (controller-to-processor and processor-to-processor modules) |
| Gumroad | Payment processing, purchase records. Gumroad is our processor for buyer information it stores on our behalf, and an independent controller in its own right for payment processing as merchant of record, fraud prevention, and tax reporting | United States | Processor role: Standard Contractual Clauses (Module Two) under Gumroad's Data Processing Agreement, which does not cover Gumroad's independent-controller processing. Independent-controller role: Gumroad's own Privacy Policy states that, for personal information transferred from the EEA to the United States, it relies on Standard Contractual Clauses adopted by the European Commission. That commitment appears in the general cross-border transfer section of Gumroad's Privacy Policy, worded without restricting it to one processing role |
We may also disclose data where required by law, or to protect our legal rights.
6. International Data Transfers
Some of the companies listed in Section 5 are based outside the European Economic Area, or transfer data onward to entities that are. Where that's the case, the transfer is protected by one of the safeguards recognised under GDPR: an adequacy decision by the European Commission, the EU-U.S. Data Privacy Framework, or the European Commission's Standard Contractual Clauses. The specific mechanism for each company is listed in the table in Section 5.
CookieYes's onward transfers specifically: our direct relationship with CookieYes is a Portugal-to-UK transfer, covered by the UK adequacy decision. CookieYes also relies on its own subprocessors to run its service, and some of these sit outside the UK/EEA. Based on CookieYes's own published subprocessor list, this includes US-based providers such as Cloudflare (DNS, CDN, and security services) and Microsoft Clarity (behavioral analytics), both protected under the EU-U.S. Data Privacy Framework together with Standard Contractual Clauses. Other CookieYes subprocessors, such as AWS in Ireland and Cloudways in Malta, sit inside the EEA and need no additional safeguard. CookieYes keeps a current list of its subprocessors publicly available; see CookieYes's current subprocessor list.
As of the date of this policy, the EU-U.S. Data Privacy Framework remains a valid European Commission adequacy mechanism. We monitor relevant legal developments and will update our transfer arrangements where required.
You can contact us at hello@lifeoutput.com for further information about the safeguards used for any of these transfers, including how to obtain a copy of the relevant safeguard where applicable.
7. How Long We Keep Your Data
- Email addresses used for ongoing marketing (you checked the box): kept for as long as you remain subscribed. If you unsubscribe, we keep the minimum information necessary on a suppression list, your email address and the fact that you opted out, so we don't accidentally email you again. This doesn't require a separate request from you.
- Email addresses used only to deliver a requested download (you left the box unticked): kept for 30 days from the date of your request, then deleted, unless you separately subscribe to ongoing emails within that window. During that period, we use the address only to deliver the requested file and, where necessary, to resolve delivery problems or related enquiries.
- Either case: you can ask us to erase your email address entirely at any time under Section 8; we'll honour that to the extent required by GDPR, which allows some limited exceptions, for example where we need to keep minimal information to comply with a legal obligation or to defend a legal claim.
- Website analytics data: retained in Google Analytics for 14 months, both event-level and user-level data, after which it's automatically deleted. This is a setting we control in GA4 and may adjust over time; this policy will be updated if it changes.
- Cookie consent and preference records: kept for as long as necessary to demonstrate valid consent where consent was given, to remember and respect your cookie preferences, and to respond to any related compliance query.
- Contact correspondence: kept for as long as reasonably necessary to handle your enquiry and any related follow-up, then deleted unless we need to keep it for legal or accounting reasons.
- Technical and security logs: kept only as long as needed for security and to keep the site running reliably.
- Purchase records: kept for as long as required by Portuguese tax and accounting law. Under Article 52 of the Portuguese VAT Code (Código do IVA), this is currently ten years for the records that law covers.
8. Your Rights
Depending on the circumstances, GDPR gives you the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data, sometimes called "the right to be forgotten," where applicable
- Restrict how we use your data, where applicable
- Port your data to another provider, in a structured, machine-readable format, where this applies to the processing in question
- Object to processing based on legitimate interest
- Object to direct marketing at any time. This right is absolute: if you object, we'll stop using your data for that purpose
- Withdraw consent at any time, for anything based on consent
- Complain to the CNPD, Portugal's supervisory authority, or, where applicable, another competent EEA supervisory authority, including the one in the country where you live or work, if you believe we've mishandled your data
To exercise any of these, email hello@lifeoutput.com. We'll respond without undue delay and normally within one month. Where GDPR permits us to take longer, because of the complexity or number of requests, we'll tell you within that first month and explain why.
The simplest way to stop receiving emails from us, and to exercise your right to object to direct marketing, is the unsubscribe link at the bottom of every email, which takes effect immediately.
9. Children's Privacy
Life Output is intended for adults managing a household, not for children. We don't knowingly collect personal data from anyone under the age of 13, the digital age of consent set under Portuguese law (Lei 58/2019) for a child's own consent to information-society services. Below that age, a parent or legal representative's consent is required. If you believe a child has provided us with personal data, contact us at hello@lifeoutput.com and we'll delete it.
10. Changes to This Policy
We may update this policy as the site or the tools behind it change. The date at the top shows when it was last revised. If a change is significant, such as a new category of data we collect or a new company we share data with, we'll make that clear, either through a notice on the site or by email where appropriate.
11. Contact Us
Questions about this policy or your data: hello@lifeoutput.com
Supervisory authority: Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt, or another competent EEA supervisory authority where applicable.