Privacy Policy
Last updated: March 2026
1. Who We Are
Data Controller: The Life Academy (sole trader)
Contact: Contact form
ICO Registration: [to be added on launch]
We operate two products under this policy:
- The Alcohol Myth — an online course hub for exploring your relationship with alcohol
- Blueprint — an alcohol assessment tool at blueprint.alcoholmyth.co.uk
This policy covers both products. Where a section applies only to one product, it is clearly labelled.
2. Information We Collect
The Alcohol Myth (course hub)
- Email address and name (account registration)
- Password (stored hashed — never in plain text)
- Course enrolment, progress, and video watch time
- Journal entries you write in reflection prompts (encrypted with your personal key)
- Purchase records: date, amount, course, transaction ID (via Stripe)
- IP address and browser information (security and fraud prevention)
Blueprint (assessment tool)
- Email address (to link results to your account, if you are a course hub user)
- Quiz responses (your answers to assessment questions)
- Assessment results and scoring history
- IP address and browser/device information
- Campaign attribution data (UTM parameters from ad URLs) — internal use only, to measure which campaigns brought users to the service
- If you visit Blueprint via a paid advertisement: Meta click ID (
_fbclid) and hashed email (see Section 9)
3. How We Use Your Information
| Purpose | Product | Legal Basis |
|---|---|---|
| Provide course access and track progress | Course hub | Contract (Art 6.1.b) |
| Process payments | Course hub | Contract (Art 6.1.b) |
| Store journal entries | Course hub | Contract (Art 6.1.b) |
| Send transactional emails | Both | Contract (Art 6.1.b) |
| Deliver assessment and show results | Blueprint | Explicit consent (Art 9.2.a) |
| Send marketing emails | Course hub | Consent (Art 6.1.a) |
| Measure ad effectiveness (Meta CAPI) | Blueprint only | Legitimate interest (Art 6.1.f) |
| Prevent fraud and ensure security | Both | Legitimate interest (Art 6.1.f) |
| Improve service (aggregated analytics) | Both | Legitimate interest (Art 6.1.f) |
We never:
- Sell your personal data
- Share your journal entries with anyone
- Share your Blueprint quiz responses with advertisers
- Allow staff to view individual Blueprint responses through normal interfaces
- Use your data to train AI models
4. Who We Share Data With
We share data only with service providers necessary to operate our products:
| Provider | Data Shared | Purpose | Location | Transfer Basis |
|---|---|---|---|---|
| Supabase | All account and quiz data | Database and authentication | EU | EU (no transfer) |
| Stripe | Email, payment details | Payment processing | US | SCCs |
| Resend | Email address, name | Email delivery | US | SCCs |
| Bunny.net | Video access tokens, IP | Video streaming | EU | EU (no transfer) |
| Anthropic | Quiz responses (no email) | AI-generated summary (Blueprint only) | US | SCCs — zero data retention |
| Meta (Facebook) | Hashed email, IP, user agent, click ID | Ad measurement via Conversions API (Blueprint only) | US | DPF UK Extension |
| Vercel | HTTP traffic, server logs | Application hosting | US | SCCs |
All providers have signed Data Processing Agreements (DPAs). For US-based providers we rely on Standard Contractual Clauses (SCCs) or the UK Extension to the EU–US Data Privacy Framework (DPF).
5. How Long We Keep Your Data
| Data Type | Retention Period | Reason |
|---|---|---|
| Active account (course hub) | While you use the service | Service provision |
| Inactive account | 2 years after last login, then deleted with 30-day notice | Allow return to platform |
| Purchase / financial records | 7 years | UK tax and accounting requirements |
| Journal entries | Until you delete them | Your content, your control |
| Blueprint assessment data | Until you request deletion | Your right to delete (Settings > Delete Blueprint Results) |
| Security logs | 90 days | Security incident response |
We will notify you by email 30 days before deleting an inactive account.
6. Your Rights
Under UK GDPR / UK DPA 2018, you have the right to:
Access and export your data
Download all your personal data (including Blueprint quiz data) at Settings > Export Data
Delete your Blueprint assessment results
Permanently delete your quiz responses and assessment history at Settings > Delete Blueprint Results (Blueprint only)
Delete your full account
Permanently delete your account and all associated data at Settings > Delete Account
Correct your data
Update your profile at Settings > Profile. Note: Blueprint quiz responses cannot be edited after submission, but you can retake the assessment.
Withdraw consent
Withdraw marketing email consent via your email preferences or the unsubscribe link in any email
Object to processing
Contact us to object to processing based on legitimate interest
Lodge a complaint
Contact the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have violated your rights
7. Data Security
We protect your data with:
- Encryption in transit: All connections use HTTPS/TLS
- Encryption at rest: Database encrypted at rest
- Journal encryption: Journal entries are encrypted with AES-256-GCM using your personal per-user key before storage. Database access alone cannot reveal your journal content.
- Row-Level Security (RLS): Database-enforced access controls ensure users can only access their own data
- Blueprint tokens: Anonymous Blueprint access tokens are cryptographically unguessable (64-character random strings), contain no personal data, and are cleared on browser close, login, or via Settings
- Access controls: Role-based access; admin actions are logged
- Regular backups: Encrypted backups with point-in-time recovery
8. Cookies
We use essential cookies only:
| Cookie | Purpose | Duration |
|---|---|---|
| sb-* | Supabase authentication session | Session |
| blueprint_token | Anonymous Blueprint access token — contains no personal data, links an anonymous quiz session to results. Cleared on browser close, login, or via Settings. | Session (browser close) |
We do not use advertising cookies or third-party analytics that track individuals across sites.
9. Blueprint — Assessment Data and Advertising
Special Category Data
Blueprint asks questions about your alcohol use. This may constitute health-related data, which is special category data under Article 9 UK GDPR. We collect and process this data only with your explicit consent (Article 9(2)(a)), given when you choose to start the assessment. You can delete this data at any time via Settings > Delete Blueprint Results.
AI-Generated Summary
Blueprint may use Anthropic's API to generate a personalised summary of your assessment. Your quiz responses (not your email) are sent to Anthropic under zero-data-retention terms — Anthropic does not store or train on your responses. This summary is informational only; no automated decision-making with legal or significant effect takes place (Article 22 does not apply).
Meta Conversions API (CAPI)
If you arrive at Blueprint via a Meta (Facebook/Instagram) advertisement, we may send the following to Meta via the Conversions API to measure whether the ad led to a completed assessment:
- Hashed email address (SHA-256 — not plain text)
- IP address
- User agent
- Meta click ID (
_fbclid)
We do not share quiz responses or assessment results with Meta. Data is transferred to the US under the UK Extension to the EU–US Data Privacy Framework (DPF). This processing is based on legitimate interests (Art 6.1.f). You may object by contacting us.
10. Email Communications
Transactional emails
When you submit the Blueprint quiz or interact with the course hub, we send transactional emails to deliver the service you requested (e.g. your assessment results link, purchase confirmations). These are sent under contract (Art 6.1.b) and cannot be unsubscribed from while you use the service.
Marketing emails
Marketing emails (promotional offers, course information) require explicit opt-in consent and are separate from transactional emails. You can unsubscribe from marketing at any time via the unsubscribe link in any email or via your email preferences, without affecting your access to results or course content.
To stop all emails
To stop all communications and delete your data, see Section 6 (Your Rights).
11. Children's Privacy
The Alcohol Myth course hub is not intended for users under 16. Blueprint is not intended for users under 18, given its subject matter. We do not knowingly collect data from children. If you believe a child has created an account, please contact us immediately.
12. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. For significant changes:
- We will email you at least 14 days before changes take effect
- The updated policy will show the revision date
- Continued use after the effective date constitutes acceptance
13. Contact Us
For privacy questions or to exercise your rights, use our contact form.
Response time: Within 30 days
14. Supervisory Authority
If you are unhappy with how we handle your data, you can complain to:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113