Legal
Privacy Policy
Last updated 8 August 2026
This policy explains what The Sev-1 Database collects, why, and who else touches it. The short version: we keep the minimum needed to run accounts and subscriptions, we never see or store your card number, and we don't sell your data.
What we collect
When you complete card-backed checkout (or sign in to an existing account) we store:
- Your email address, and your name if you provide one.
- A one-way hash of your password (PBKDF2) when you set one. Checkout-created accounts may exist with no password until you choose one via the email link. We never store the password itself and cannot recover it.
- Your subscription tier and when it expires.
- Identifiers our payment processor gives us for your customer and subscription, so we can match a payment to your account.
- Newsletter preference if you opt in (or leave the default checked) for The Sev-1 Database Substack list, we add those addresses manually and record whether you are pending, added, or opted out.
- Coarse acquisition context when you sign up or start checkout (for example UTM tags, referring site class such as search / LinkedIn / Substack, and the landing path). Used to understand where Pro checkouts and existing free/canceled accounts come from, not for ads. New accounts are not created as cardless free signups.
- Account timestamps (created, updated).
- Optional learning resume data when you are signed in: last pathway and lesson you opened, and which pathway steps you have visited on this site. Used only so you can continue where you left off. It is tied to your account, not shared with other users, and is not used for advertising.
If you send us a message through the contact form, we store the name, email, and message you submit so we can reply.
What we do not collect
We never receive or store your card number, CVC, or bank details. All payment card data is handled directly by Stripe. We do not sell personal data. We do not use advertising pixels or ad personalization on this site.
Analytics
When analytics is enabled in production, we use Google Analytics 4 to understand aggregate traffic (which pages are used, approximate region, device/browser type, and referral source). We configure GA4 with advertising storage denied and IP anonymization so it is used for first-party product analytics, not ads. Google acts as a processor under its Privacy Policy. Analytics loads only when a measurement ID is configured for a deployment; local development typically has it unset.
Stored on your device
After you sign in, your browser may keep a sign-in token in local storage (local development) or an HttpOnly session cookie (production) so you stay logged in, plus a small preference for your light/dark theme choice. We also store a local learning-progress snapshot (last pathway / lesson and visited steps) so resume works even when you are offline; when you are signed in we may sync that same self-only blob to your account. Clearing site storage removes the local copy. Before checkout or signup we may also keep a short-lived attribution snapshot in session storage (UTM / referrer class) so we can attach source when the account is created. If Google Analytics is enabled, Google may also set analytics cookies or use local storage as described in Google's policies.
Who processes your data
- Stripe, processes payments and holds your card details under its own privacy terms. We receive only non-sensitive identifiers and subscription status.
- Cloudflare, hosts the site and the account database, and serves it globally.
- Google, when GA4 is enabled, processes analytics events for site usage measurement (see Analytics above).
- Our email provider, if email is enabled, sends account emails such as a welcome message or set-password link to the address you used at signup or checkout.
- Substack, if you opt in to the newsletter, we may add your email to our publication list there under Substack's terms. Opt-out is available via Substack or by contacting us.
These providers act on our behalf and are not permitted to use your data for their own marketing.
Why we can hold it
We process account and payment data to provide the Service you asked for and to meet our legal and accounting obligations. We keep it while your account is active and for as long afterwards as we are required to for records and tax.
Your choices
You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete your account and its data, subject to any records we must keep by law. Send the request from the contact page using your account email so we can verify it. You can cancel billing yourself at any time from the billing portal.
Changes
If this policy changes, the "last updated" date above changes with it. Continued use after an update means you accept the revised policy.
Related: Terms · Privacy · Refunds & cancellation · Contact