Privacy Policy
Last updated: May 2026 · v2026.06.30
1. Data Controller
The Data Controller is Jasmin Eden, a natural person residing in Italy.
Privacy contact: jasmineden23@gmail.com
To exercise your GDPR rights (Art. 15–22) write to this email in Italian or English. We reply within 30 days.
Privacy contact: jasmineden23@gmail.com
To exercise your GDPR rights (Art. 15–22) write to this email in Italian or English. We reply within 30 days.
2. What we collect and why
- Account: email, password (encrypted, never plaintext) or Google/Apple identity. Legal basis: contract performance.
- Public profile: nickname, city in Veneto, country of origin, languages, optional photo, "light" color, open-question answers. Legal basis: consent.
- Year of birth: used only to confirm you are 18+. Never shown publicly.
- User content: global and private chat messages, voice notes, reactions, help posts, advice threads, quick actions, events.
- Technical: IP address (hashed only, anti-abuse), minimal security logs, device type. Legal basis: legitimate interest.
- Lesson payments: handled entirely by Stripe; we never store card data. Legal basis: contract performance.
3. Public vs private
- Public: nickname, city, country, languages, photo, color, story, public chat messages, events, advice.
- Private: email, year of birth, direct messages, payment data, technical logs.
4. Retention
- Active account: as long as you use the service.
- Deleted account: personal data removed within 30 days of the request (see Sec. 7). Public content may remain in anonymised form.
- Security logs: max 12 months.
- Billing data (lessons): 10 years (Italian tax law).
5. Sub-processors
We rely on these GDPR-compliant providers:
- Lovable Cloud / Supabase (database, auth, storage) — EU/USA under SCCs.
- Cloudflare (CDN, edge hosting) — EU/USA under SCCs.
- Stripe (payments) — Ireland + USA under SCCs.
- Google / Apple (optional login).
- Resend / SendGrid (transactional email, if enabled) — EU/USA.
6. Cookies
See our Cookie Policy for the breakdown. In short: essential cookies only by default; analytics and marketing only with your explicit consent.
7. Your GDPR rights
You can at any time:
- Access your data (Art. 15).
- Correct it (Art. 16) from your Profile page.
- Export it as JSON (Art. 20) from Settings → "Download my data".
- Delete your account (Art. 17) from Settings → "Delete account". 30-day grace period: you can cancel.
- Restrict or object to processing (Art. 18–21) by writing to us.
- Withdraw consent at any time.
- Lodge a complaint with the Italian Data Protection Authority if you believe the processing infringes the GDPR.
8. Minors
NewChapter is restricted to people aged 18 or older. We verify age at signup. If you discover a minor has an account, please report it and we will remove it within 72 hours.
9. Security
Bcrypt-hashed passwords, mandatory HTTPS/TLS, leaked-password protection (HIBP), Row-Level Security on the database, audit log for admin actions.
10. Changes
We may update this policy. For material changes we will ask again for your consent at the next login. The current version is shown at the top.
11. Contact
Any privacy question: jasmineden23@gmail.com