Privacy Policy — REWIRED

REWIRED — LEGAL

Privacy Policy

Effective date: 2026-07-13 · Last updated: 2026-07-13

1. Who we are, and what this policy covers

This policy is provided by the individual seller operating under the pen name "James Brown" (referred to as "we", "us", or "our"). We are the data controller for the personal data described in this policy.

This policy covers:

Defined terms. The "Ebook" is Rewired: The Science of Breaking the Porn Cycle (152-page PDF + EPUB). The "Program" is the 84-day web program. The "Bundle" is the Ebook plus 3 months (90 days) of Program access, with an optional month-by-month extension afterward.

2. The short, honest version

Privacy is architecture here, not a promise bolted on afterward.

The rest of this document is the detailed version of those four sentences.

3. What we collect, and where it comes from

We collect data from you directly — we never buy data about you or receive it from data brokers.

Source Data Why
Your purchase (Hotmart checkout) Name, email address, billing country, order details (product, amount, date). Payment is handled entirely by Hotmart and its payment processors — we never see or store your card number. To process your order and deliver what you bought.
Ebook delivery (Hotmart's content delivery) Your email, linked to your download links. To deliver the Ebook files.
Program account (Supabase) Your email address and your entitlement dates (purchase date, access-until date). Login is by passwordless magic link sent to your email — there is no password to store. To know who has Program access and until when, and to let you log in.
Transactional email (Resend) Your email address and delivery logs for the emails we send (welcome email, magic links). To deliver the emails that make the product work.
Hosting (Netlify) Standard, short-lived server access logs, which include IP addresses. Netlify deletes these automatically within 30 days. We do not export or analyze them per user. Security and keeping the sites running.
Support (email) Whatever you choose to include when you write to us. To answer you.

What we deliberately do not collect: journal entries, check-ins, or any Program progress data (device-only); analytics or advertising cookies; precise location; social login identities (we do not offer "Sign in with Google/Apple" — deliberately, so that no third party learns you use this product through login).

4. Sensitive data: what buying this product reveals, and how we protect it

This is the most important section of this policy.

The plain truth: purchasing a product called Rewired: The Science of Breaking the Porn Cycle can reveal information about your sex life and your health. Under EU law (GDPR Article 9) that makes the fact of your purchase "special category data". Under several US state laws (including Washington's My Health My Data Act) it is "consumer health data". We treat it that way, without trying to argue otherwise.

What we commit to:

  1. We never use the customer list for ad targeting. We do not upload it, hashed or otherwise, to Meta, Google, TikTok, or any other advertising platform ("custom audiences", "lookalikes", or anything similar).
  2. There are no advertising pixels or conversion trackers on the store, the checkout, the landing page, or the Program app — no Meta Pixel, no Google tag with purchase events, nothing that tells a third party that you specifically bought this product.
  3. We never sell your data. We never have and we never will.
  4. We never share it, except with the four service providers listed in Section 6, who process it strictly on our instructions under data processing agreements, only to deliver the product to you.
  5. Marketing email, if we ever send any, is separate opt-in only. Buying the product does not put you on a marketing list.

Your explicit consent. Because the purchase itself reveals sensitive information, we ask for your explicit consent at checkout: an unticked checkbox with wording substantially like — "I understand that purchasing this product reveals information about my health and sex life, and I explicitly consent to its processing for the sole purpose of delivering my purchase and providing Program access. I can withdraw consent and request deletion at any time (support@rewire.ink)." We record the consent text version and timestamp, and nothing else.

You can withdraw this consent at any time (Section 8). Withdrawing it means we delete your data; it does not affect the lawfulness of processing before withdrawal, and it may mean we can no longer provide Program access (we cannot grant access to an email we no longer store).

4a. Consumer Health Data disclosures (Washington My Health My Data Act, Nevada SB 370, and similar laws)

This subsection provides the disclosures required for "consumer health data" under Washington's My Health My Data Act (MHMDA) and Nevada's consumer health data law. The same disclosures are also published as a separate, stand-alone Consumer Health Data Privacy Policy, linked from our homepage, as Washington guidance recommends.

Connecticut residents: Connecticut law requires consent to process sensitive data such as this. The explicit-consent checkbox described above, plus strict minimization (we process only what is reasonably necessary to deliver what you bought), is how we comply. You have the rights described in Section 8.

6. Who processes data for us, and where it goes

We use exactly four service providers ("processors"). Each is bound by a data processing agreement (DPA) and acts only on our instructions.

Processor Role Location / data flow DPA International-transfer mechanism
Hotmart Checkout, orders, payments, ebook delivery EEA/UK customer data is processed by Hotmart B.V. (Netherlands, EEA); onward transfers within the Hotmart group (incl. Brazil) rely on Standard Contractual Clauses. hotmart.com/en/legal EEA establishment + SCCs
Supabase Login (magic links) + entitlements database Region-selectable; an EU region (Frankfurt) is recommended and under evaluation. supabase.com/legal/dpa SCCs + UK Addendum (not DPF-certified); publishes its own Transfer Impact Assessment
Resend (Plus Five Five, Inc.) Transactional email United States resend.com/legal/dpa EU-US Data Privacy Framework + UK Extension; SCCs as fallback
Netlify Hosting (landing + Program app) United States (global CDN) netlify.com/v3/static/pdf/netlify-dpa.pdf EU-US Data Privacy Framework + UK Extension + Swiss DPF

International transfers. Some of these providers process data in the United States. Where they do, transfers from the EU/UK rely on the EU-US Data Privacy Framework (currently valid; an appeal against it is pending before the EU Court of Justice) and/or Standard Contractual Clauses, as noted above. You can obtain copies of the safeguards through the DPA links in the table.

We share data with no one else — no ad platforms, no data brokers, no "partners". If a court or authority ever lawfully compels disclosure, we will disclose only what is legally required and, where allowed, tell you.

7. How long we keep data

Data Retention Why
Order records (Hotmart) For as long as tax and accounting law requires — under Argentine commercial law, generally about 10 years. If you request erasure, the record is redacted so it no longer identifies you, and only the anonymous sale record remains. Legal obligation
Active entitlement (email + access dates, Supabase) While your access is active, plus 12 months Support and optional extension purchases
Expired entitlement / login account Deleted within 12 months after access ends Data minimization
Email delivery logs (Resend) The provider's standard log retention period; we keep no separate copies Deliverability and debugging
Server access logs (Netlify) Deleted automatically by Netlify within 30 days Provider policy
Email suppression list (opt-outs) Kept for as long as needed to keep honoring your opt-out We can't remember not to email you if we forget you asked
Consent records (version + timestamp) As long as the related data is kept Proof of consent
Backups Deleted data leaves database backups automatically as backups rotate and expire Standard backup rotation

8. Your rights, and how to use them

Wherever you live, you can ask us to:

How: email support@rewire.ink from the email address you purchased with. That is also how we verify identity — we deliberately do not ask for ID documents, because collecting more data to delete data would defeat the point. If you write from a different address, we will confirm through the purchase email.

When: we answer within 30 days. (Washington consumer-health-data requests: within 45 days as stated in Section 4a; we aim for 30 across the board.)

How deletion actually works — honestly: deletion is currently a manual, verified process. When we confirm your request, we delete your row(s) in our access database and your login account (Supabase), remove your contact and check the suppression list at our email provider (Resend), and request erasure of your personal data from the order records at our checkout platform (Hotmart), which may keep an anonymized sale record for accounting and legal purposes. Netlify logs expire on their own within 30 days. Backup copies disappear as backups rotate. Your journal and check-ins are on your device, not ours — you can delete them in the Program's settings or by clearing the site's data in your browser. We confirm by email when deletion is complete.

No automated decision-making. We do not make any automated decisions about you and we do not profile you.

Complaints. If you are unhappy with how we handled your data or your request: in the EU, you can complain to your national data protection authority (list at edpb.europa.eu); in the UK, to the ICO (ico.org.uk); in the US, to your state Attorney General; and you can always write to us first — we would rather fix it.

9. EU/UK representative

We are finalizing our approach to EU and UK availability and, where the law requires it, the appointment of an Article 27 GDPR / UK GDPR representative. Until that is confirmed, EU and UK customers can reach us for any data-protection matter at support@rewire.ink, and we will honor the rights described in Section 8. Pending legal review

10. Children

This product is for adults. You must be 18 or older to purchase or use it. We do not knowingly collect personal data from anyone under 18, and never from children under 13. If we learn that a minor has provided us data, we will delete it and terminate the account. If you believe a minor has used the product, contact support@rewire.ink.

11. California disclosures (CalOPPA)

12. Do Not Sell or Share

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Full stop, no exceptions, no "except as described above". This has always been true and we intend to keep it true.

Because we do not sell or share, there is nothing for an opt-out to opt you out of. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a valid opt-out request — it simply finds nothing to turn off.

13. Changes to this policy, and how to reach us

If we change this policy in any material way (for example, adding a cookieless analytics tool), we will post the updated version here with a new "Last updated" date and, for material changes affecting existing customers, notify you by email before the change takes effect. We will never use a policy change to retroactively do something with your data that this policy currently rules out — in particular, Sections 4 and 12 (no ads, no selling) are commitments, not settings.

Contact:

If you are struggling right now: in the US, call or text 988 (Suicide & Crisis Lifeline). Elsewhere, find a helpline at findahelpline.com.