REWIRED — LEGAL
Privacy Policy
1. Who we are, and what this policy covers
This policy is provided by the individual seller operating under the pen name "James Brown" (referred to as "we", "us", or "our"). We are the data controller for the personal data described in this policy.
- Legal name of the controller: Benjamin Tayar Matijasevich, an individual (sole proprietor) based in Argentina. “James Brown” is a pen name used for the book; it is not the controller.
- Contact: support@rewire.ink
- Postal address: Charcas 5121, CABA, Argentina
This policy covers:
- our landing page (at rewire.ink),
- our checkout and delivery platform (Hotmart, pay.hotmart.com),
- the Program web app (at app.rewire.ink), and
- the emails we send you.
Defined terms. The "Ebook" is Rewired: The Science of Breaking the Porn Cycle (152-page PDF + EPUB). The "Program" is the 84-day web program. The "Bundle" is the Ebook plus 3 months (90 days) of Program access, with an optional month-by-month extension afterward.
2. The short, honest version
Privacy is architecture here, not a promise bolted on afterward.
- Your journal and daily check-ins never leave your device. They are stored only in your browser's local storage. We have no copy, no backup, no analytics on them. We cannot read them even if asked.
- We store the minimum on our side: your email address, what you bought, and until when you have Program access. That is essentially the whole database.
- We know that buying this product is itself sensitive information. We treat our customer list accordingly: we never use it for advertising, never upload it to any ad platform, and never sell or share it. Section 4 spells this out.
- No analytics cookies today. The landing page, store pages we control, and the Program app do not set advertising or analytics cookies. If this ever changes (for example, adding a cookieless, privacy-preserving analytics tool such as Plausible), we will update this policy first.
The rest of this document is the detailed version of those four sentences.
3. What we collect, and where it comes from
We collect data from you directly — we never buy data about you or receive it from data brokers.
| Source | Data | Why |
|---|---|---|
| Your purchase (Hotmart checkout) | Name, email address, billing country, order details (product, amount, date). Payment is handled entirely by Hotmart and its payment processors — we never see or store your card number. | To process your order and deliver what you bought. |
| Ebook delivery (Hotmart's content delivery) | Your email, linked to your download links. | To deliver the Ebook files. |
| Program account (Supabase) | Your email address and your entitlement dates (purchase date, access-until date). Login is by passwordless magic link sent to your email — there is no password to store. | To know who has Program access and until when, and to let you log in. |
| Transactional email (Resend) | Your email address and delivery logs for the emails we send (welcome email, magic links). | To deliver the emails that make the product work. |
| Hosting (Netlify) | Standard, short-lived server access logs, which include IP addresses. Netlify deletes these automatically within 30 days. We do not export or analyze them per user. | Security and keeping the sites running. |
| Support (email) | Whatever you choose to include when you write to us. | To answer you. |
What we deliberately do not collect: journal entries, check-ins, or any Program progress data (device-only); analytics or advertising cookies; precise location; social login identities (we do not offer "Sign in with Google/Apple" — deliberately, so that no third party learns you use this product through login).
4. Sensitive data: what buying this product reveals, and how we protect it
This is the most important section of this policy.
The plain truth: purchasing a product called Rewired: The Science of Breaking the Porn Cycle can reveal information about your sex life and your health. Under EU law (GDPR Article 9) that makes the fact of your purchase "special category data". Under several US state laws (including Washington's My Health My Data Act) it is "consumer health data". We treat it that way, without trying to argue otherwise.
What we commit to:
- We never use the customer list for ad targeting. We do not upload it, hashed or otherwise, to Meta, Google, TikTok, or any other advertising platform ("custom audiences", "lookalikes", or anything similar).
- There are no advertising pixels or conversion trackers on the store, the checkout, the landing page, or the Program app — no Meta Pixel, no Google tag with purchase events, nothing that tells a third party that you specifically bought this product.
- We never sell your data. We never have and we never will.
- We never share it, except with the four service providers listed in Section 6, who process it strictly on our instructions under data processing agreements, only to deliver the product to you.
- Marketing email, if we ever send any, is separate opt-in only. Buying the product does not put you on a marketing list.
Your explicit consent. Because the purchase itself reveals sensitive information, we ask for your explicit consent at checkout: an unticked checkbox with wording substantially like — "I understand that purchasing this product reveals information about my health and sex life, and I explicitly consent to its processing for the sole purpose of delivering my purchase and providing Program access. I can withdraw consent and request deletion at any time (support@rewire.ink)." We record the consent text version and timestamp, and nothing else.
You can withdraw this consent at any time (Section 8). Withdrawing it means we delete your data; it does not affect the lawfulness of processing before withdrawal, and it may mean we can no longer provide Program access (we cannot grant access to an email we no longer store).
4a. Consumer Health Data disclosures (Washington My Health My Data Act, Nevada SB 370, and similar laws)
This subsection provides the disclosures required for "consumer health data" under Washington's My Health My Data Act (MHMDA) and Nevada's consumer health data law. The same disclosures are also published as a separate, stand-alone Consumer Health Data Privacy Policy, linked from our homepage, as Washington guidance recommends.
- Categories of consumer health data we collect: the fact that you purchased the Ebook, Bundle, or a Program extension, linked to your email address, name (from the order), billing country, and Program access dates. This can reveal information about sexual or mental health. We collect nothing else that qualifies: no health surveys, no biometric data, no precise location, no journal content (device-only).
- Sources: you, directly, when you make a purchase or log in.
- Purposes: delivering the product you asked for — processing the order, delivering the Ebook, provisioning and maintaining Program access, sending the transactional emails that make those work, and support. We collect nothing beyond what is necessary to provide what you requested.
- Categories of consumer health data we share, and with whom: we do not sell or share consumer health data with any third party for their own purposes. It is processed on our behalf only by our processors: Hotmart (order processing, payments, and ebook delivery), Supabase (login and access database), Resend (transactional email), and Netlify (hosting). No affiliates (we have none). No advertising platforms, ever.
- Your rights (Washington residents, and we extend the same to everyone): the right to confirm whether we collect or share consumer health data about you; to access it, including a list of the third parties (processors) it has been disclosed to; to withdraw consent; and to have it deleted. To exercise them, email support@rewire.ink. We will respond without undue delay and in all cases within 45 days (extendable once by 45 days where reasonably necessary; we will tell you if so). Deletion requests are propagated to our processors. If we deny a request, you may appeal by replying to our response; if the appeal is denied, Washington residents may contact the Washington Attorney General at www.atg.wa.gov/file-complaint.
- Non-discrimination: we will not discriminate against you for exercising any right — same product, same price, same service.
- No geofencing: we do not collect or use location data, and we do not operate any geofence.
Connecticut residents: Connecticut law requires consent to process sensitive data such as this. The explicit-consent checkbox described above, plus strict minimization (we process only what is reasonably necessary to deliver what you bought), is how we comply. You have the rights described in Section 8.
5. Why we are allowed to process your data (legal bases — GDPR)
For visitors and customers in the EU/UK, our legal bases are:
| Processing | Legal basis (Art. 6) | Special-category condition (Art. 9) |
|---|---|---|
| Processing your payment, delivering the Ebook, provisioning Program access, magic-link login emails | Contract — Art. 6(1)(b): we need this to deliver what you bought | Explicit consent — Art. 9(2)(a), collected at checkout (Section 4) |
| Fraud prevention, site security, defending against chargebacks | Legitimate interest — Art. 6(1)(f) | Explicit consent covers the sensitive inference; the security processing itself uses only order/log data |
| Keeping order records for tax and accounting | Legal obligation — Art. 6(1)(c) | Where you request erasure, order records are redacted so they no longer identify you (Section 8) |
| Marketing emails (none today; only if you separately opt in) | Consent — Art. 6(1)(a), separate from everything else | Separate explicit consent — Art. 9(2)(a) |
Providing your email is a contractual requirement in the narrow sense that we cannot deliver a digital product or Program access without an email address to deliver it to.
6. Who processes data for us, and where it goes
We use exactly four service providers ("processors"). Each is bound by a data processing agreement (DPA) and acts only on our instructions.
| Processor | Role | Location / data flow | DPA | International-transfer mechanism |
|---|---|---|---|---|
| Hotmart | Checkout, orders, payments, ebook delivery | EEA/UK customer data is processed by Hotmart B.V. (Netherlands, EEA); onward transfers within the Hotmart group (incl. Brazil) rely on Standard Contractual Clauses. | hotmart.com/en/legal | EEA establishment + SCCs |
| Supabase | Login (magic links) + entitlements database | Region-selectable; an EU region (Frankfurt) is recommended and under evaluation. | supabase.com/legal/dpa | SCCs + UK Addendum (not DPF-certified); publishes its own Transfer Impact Assessment |
| Resend (Plus Five Five, Inc.) | Transactional email | United States | resend.com/legal/dpa | EU-US Data Privacy Framework + UK Extension; SCCs as fallback |
| Netlify | Hosting (landing + Program app) | United States (global CDN) | netlify.com/v3/static/pdf/netlify-dpa.pdf | EU-US Data Privacy Framework + UK Extension + Swiss DPF |
International transfers. Some of these providers process data in the United States. Where they do, transfers from the EU/UK rely on the EU-US Data Privacy Framework (currently valid; an appeal against it is pending before the EU Court of Justice) and/or Standard Contractual Clauses, as noted above. You can obtain copies of the safeguards through the DPA links in the table.
We share data with no one else — no ad platforms, no data brokers, no "partners". If a court or authority ever lawfully compels disclosure, we will disclose only what is legally required and, where allowed, tell you.
7. How long we keep data
| Data | Retention | Why |
|---|---|---|
| Order records (Hotmart) | For as long as tax and accounting law requires — under Argentine commercial law, generally about 10 years. If you request erasure, the record is redacted so it no longer identifies you, and only the anonymous sale record remains. | Legal obligation |
| Active entitlement (email + access dates, Supabase) | While your access is active, plus 12 months | Support and optional extension purchases |
| Expired entitlement / login account | Deleted within 12 months after access ends | Data minimization |
| Email delivery logs (Resend) | The provider's standard log retention period; we keep no separate copies | Deliverability and debugging |
| Server access logs (Netlify) | Deleted automatically by Netlify within 30 days | Provider policy |
| Email suppression list (opt-outs) | Kept for as long as needed to keep honoring your opt-out | We can't remember not to email you if we forget you asked |
| Consent records (version + timestamp) | As long as the related data is kept | Proof of consent |
| Backups | Deleted data leaves database backups automatically as backups rotate and expire | Standard backup rotation |
8. Your rights, and how to use them
Wherever you live, you can ask us to:
- Access the data we hold about you (it is short: email, purchase, dates);
- Correct it;
- Delete it ("right to erasure" / "right to be forgotten");
- Export it in a portable format;
- Restrict or object to processing;
- Withdraw consent at any time, as easily as you gave it.
How: email support@rewire.ink from the email address you purchased with. That is also how we verify identity — we deliberately do not ask for ID documents, because collecting more data to delete data would defeat the point. If you write from a different address, we will confirm through the purchase email.
When: we answer within 30 days. (Washington consumer-health-data requests: within 45 days as stated in Section 4a; we aim for 30 across the board.)
How deletion actually works — honestly: deletion is currently a manual, verified process. When we confirm your request, we delete your row(s) in our access database and your login account (Supabase), remove your contact and check the suppression list at our email provider (Resend), and request erasure of your personal data from the order records at our checkout platform (Hotmart), which may keep an anonymized sale record for accounting and legal purposes. Netlify logs expire on their own within 30 days. Backup copies disappear as backups rotate. Your journal and check-ins are on your device, not ours — you can delete them in the Program's settings or by clearing the site's data in your browser. We confirm by email when deletion is complete.
No automated decision-making. We do not make any automated decisions about you and we do not profile you.
Complaints. If you are unhappy with how we handled your data or your request: in the EU, you can complain to your national data protection authority (list at edpb.europa.eu); in the UK, to the ICO (ico.org.uk); in the US, to your state Attorney General; and you can always write to us first — we would rather fix it.
9. EU/UK representative
We are finalizing our approach to EU and UK availability and, where the law requires it, the appointment of an Article 27 GDPR / UK GDPR representative. Until that is confirmed, EU and UK customers can reach us for any data-protection matter at support@rewire.ink, and we will honor the rights described in Section 8. Pending legal review
10. Children
This product is for adults. You must be 18 or older to purchase or use it. We do not knowingly collect personal data from anyone under 18, and never from children under 13. If we learn that a minor has provided us data, we will delete it and terminate the account. If you believe a minor has used the product, contact support@rewire.ink.
11. California disclosures (CalOPPA)
- Categories of personal information collected: identifiers (name, email, billing country) and commercial information (purchase records), as described in Section 3.
- Third parties: only the processors in Section 6, only to operate the service. No third party collects personal information about your activity across other sites through our sites — we do not run third-party ad or analytics trackers.
- Do Not Track: our sites do not track you across other websites over time, so there is nothing for a DNT signal to switch off. We do not respond to DNT signals because there is no tracking to disable.
- Reviewing and changing your data: Section 8.
- Change notices: Section 13.
- Effective date: at the top of this policy.
12. Do Not Sell or Share
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Full stop, no exceptions, no "except as described above". This has always been true and we intend to keep it true.
Because we do not sell or share, there is nothing for an opt-out to opt you out of. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a valid opt-out request — it simply finds nothing to turn off.
13. Changes to this policy, and how to reach us
If we change this policy in any material way (for example, adding a cookieless analytics tool), we will post the updated version here with a new "Last updated" date and, for material changes affecting existing customers, notify you by email before the change takes effect. We will never use a policy change to retroactively do something with your data that this policy currently rules out — in particular, Sections 4 and 12 (no ads, no selling) are commitments, not settings.
Contact:
- Email: support@rewire.ink
- Postal: Charcas 5121, CABA, Argentina
- Controller: Benjamin Tayar Matijasevich (individual, Argentina)
If you are struggling right now: in the US, call or text 988 (Suicide & Crisis Lifeline). Elsewhere, find a helpline at findahelpline.com.