Back
Legal

Privacy Policy

Last updated: July 10, 2026

1. Who we are

Transformational Hub ("we", "us", "our") operates Transformational Hub. This notice explains what personal data we collect, how we use it, and the choices you have. We act as the data controller for personal data described here.

2. Information we collect

  • Account data: email, display name, and authentication info (including Google ID if you sign in with Google).
  • Your reflections: answers to onboarding questions, coaching prompts, tiny actions, and any journal text you write.
  • Practice data: which tools you've started, completed, and committed actions for; your pillar ratings and Alignment Score over time.
  • Subscription data (where applicable): which plan you have, subscription status, and billing period. Payment card details are collected by Paddle, not by us.
  • Usage data: standard logs (IP, browser, timestamps) used to operate and secure the Service.
  • Support: messages you send us and information you provide in connection with support requests.

3. How we use it

  • To run the Service — show you your data, calculate your score, sequence your Path (contract performance).
  • To send essential account emails (sign-in confirmation, security notices).
  • To manage subscriptions and entitlements where applicable (contract performance).
  • To prevent fraud, abuse, and violations of our Terms (legitimate interests).
  • To improve the Service in aggregate (e.g. which tools are most used).
  • To comply with legal obligations (legal obligation).

We do not sell your data. We do not use your reflections to train AI models. We do not share your individual entries with anyone.

4. AI processing

Some parts of the Service send the relevant portion of your reflections to third-party AI providers (for example, models routed via the Lovable AI Gateway) to generate the output you request. These providers process the data on our behalf under their enterprise terms and do not retain it to train their models.

5. Who can see your data

Only you. Row-level security in our database ensures your reflections, journal entries, and tool sessions are scoped to your account and cannot be read by other users. Authorized engineers may access systems for support or maintenance under confidentiality obligations.

6. Sharing your data

  • Service providers and subprocessors that host our infrastructure, database, authentication, email, and AI inference, acting on our behalf.
  • Merchant of Record — Paddle: where you purchase a subscription, we share the data needed to process your order, manage your subscription, handle payments, calculate tax, and issue invoices. Paddle acts as the seller of record.
  • Professional advisers (legal, accounting, insurance) under confidentiality obligations.
  • Authorities where required by law, subpoena, or to protect rights, property, or safety.
  • Business transfers: as part of a merger, acquisition, or asset sale, with notice.

7. Where it lives & retention

Data is stored on managed infrastructure (Supabase, hosted on AWS). Backups are encrypted. We retain account data while your account is active and your reflections until you delete them or your account. Some data may be retained longer where required for legal, tax, accounting, security, or fraud-prevention purposes. Backups may persist for a limited period before being overwritten.

8. Your rights

You can:

  • Edit your reflections via the app.
  • Request an export of all your data (or download it directly from your Profile).
  • Delete your account and all associated data from your Profile.

Email privacy@transformationhub.app for export or deletion requests. Depending on where you live, you may also have rights to access, correct, restrict, or object to certain processing, or withdraw consent where processing is based on consent. If you're in the EU/UK, GDPR rights apply. If you're in California, CCPA rights apply. You also have the right to lodge a complaint with your local data-protection authority.

9. Security

We use appropriate technical and organisational measures — including encryption in transit, access controls, row-level security, and least-privilege principles — to protect personal data. No system is perfectly secure and we cannot guarantee absolute security.

10. International transfers

We may process data in countries other than your own, including in the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for cross-border transfers.

11. Cookies & tracking

We use a single first-party cookie/local-storage entry to keep you signed in. We do not use third-party advertising trackers. If we add analytics or marketing cookies in the future, we will update this notice and, where required, ask for your consent.

12. Children

The Service is not intended for users under 18, and we do not knowingly collect their personal data.

13. Changes

If we make material changes to this policy, we'll notify you by email or in the app before they take effect, and update the "Last updated" date above.

14. Contact

Privacy questions: privacy@transformationhub.app.

This policy is a starting template. Before public launch, have it reviewed by a lawyer familiar with your jurisdiction and the regulations that apply to your users (GDPR, CCPA, and others).