Privacy

Privacy Policy

How we handle your information — and specifically, why nobody but you can read what you write.

Last updated 1 August 2026

Your rights come first

If anything on this page conflicts with your statutory rights in the country where you live, your statutory rights win.

The short version

We collect as little as we can. We do not sell or share your data. Your private reflections are not readable by administrators, are not used to train anything, and are not sent to any analytics or marketing tool. You can export or permanently delete everything at any time from your account.

This matters more than usual here, because some readers are using this workbook while living with someone who monitors them. We have designed around that possibility rather than assuming it away.

What we collect, and why

Four groups, and nothing beyond them:

  • To sell you the workbook: your email address, optionally a first name, and the order record PayPal returns to us. We never receive or store your card details — PayPal handles all of that.
  • To give you access: an account record, sign-in tokens, and a log of when download links were issued and used.
  • To run the programme you chose: your start date, timezone, reminder time, delivery preference, which days you have marked complete, your distress readings, and the reflections you write.
  • To answer you: support messages, any files you attach, and the emails we send you.

Your reflections

What you write on a daily page is stored so you can come back to it, and for no other purpose. There is no screen in our administration portal that displays reflection content. There is no export path for staff. There is no analytics event containing it.

If a support request ever genuinely required someone to look at a specific entry, we would ask you first, record your permission along with the exact wording you agreed to, time-limit that access, and log every read. You can refuse, and refusing does not affect your access to anything.

Reflections are stored encrypted at rest by our database provider and transmitted over TLS.

What we deliberately do not do

Some of these are worth stating plainly:

  • We do not store IP addresses. Where we need to limit abuse, we store a one-way hash instead.
  • We do not use tracking cookies, advertising pixels, or third-party analytics that profile you.
  • We do not put personal data in URLs, analytics events, or error logs.
  • We do not include tracking pixels in our emails, so we do not know whether you opened one.
  • We do not upload or read your contacts. The referral tool sends one email to one address you type in.

Cookies

We set two, both strictly necessary and both first-party. A session cookie keeps you signed in, and a referral cookie remembers a referral code for thirty days if you arrived through someone’s link. Neither is used for advertising or profiling, which is why there is no consent banner interrupting you.

How long we keep things

Retention is bounded and specific:

  • Account, programme and reflections: until you delete them, or two years after your last sign-in, whichever comes first.
  • Support cases and attachments: two years.
  • Order records: seven years, because tax and accounting law requires it. After an account deletion these survive only in a de-identified form.
  • Sign-in tokens and download links: deleted within seven days of expiry.
  • Audit logs of administrative actions: two years.

Your rights

You can get a copy of everything we hold, correct it, delete it, restrict how we use it, or object. Export and deletion are self-service buttons in your account rather than a request you have to write. Deletion is deferred by seven days so an accidental request can be undone, and you can cancel it in that window.

If you are in the UK or EU, our lawful bases are: contract (delivering what you paid for), consent (marketing email, testimonials), and legitimate interests (security, fraud prevention, keeping the service running). You can withdraw consent at any time without affecting anything you have already received.

If you believe we have handled your data badly, please tell us first — but you also have the right to complain to your national data-protection authority.

Who else is involved

We keep this list short on purpose. PayPal processes payments. Our database and file storage are hosted by Supabase. The site runs on Vercel. Transactional email is sent by our configured email provider. Each of these processes data only to provide their service to us.

NEEDS CONFIRMING BEFORE LAUNCH: the exact hosting regions, the email provider actually used in production, and any data-processing agreements required in your markets.

Children

This workbook is written for adults and is not intended for anyone under 16. We do not knowingly create accounts for children. If you believe a child has an account here, please contact us and we will remove it.

Questions about any of this? Write to info@calmandconnectbook.com or use the contact form.