Privacy Policy
Effective date: May 28, 2026
1. Who we are
Controller: Blackthorn Visions Ltd
Business ID: 3005647-8
Address: Ruotutie 16, 02610 Espoo, Finland
Website: anomalyda.com
Privacy contact: ida@blackthornvisions.com
If you have questions about this Privacy Policy or want to exercise your data protection rights, contact us at the email address above.
2. What personal data we collect
We may collect the following categories of personal data.
A. Account data
When you create an account, we may collect:
- name or display name;
- email address;
- login credentials or authentication identifiers;
- account settings;
- account creation date;
- last login information;
- security and authentication logs.
Passwords, where used, should be stored in hashed form through our authentication provider. We do not intentionally store plain-text passwords.
B. Waitlist and marketing data
When you join a waitlist or subscribe to updates, we may collect:
- email address;
- name, if provided;
- product or course interest;
- consent status;
- subscription preferences;
- timestamps and source of signup.
C. Contact and support data
When you contact us, submit a form, or request support, we may collect:
- name;
- email address;
- message content;
- attachments, if any;
- information needed to answer your request;
- communication history.
D. Purchase, refund, and payment-related data
When you make a purchase or request a refund, we may collect and store:
- name;
- email address;
- billing details;
- purchased product;
- price, currency, tax/VAT information where applicable;
- order ID;
- Paddle order, transaction, or subscription reference;
- invoice and receipt information;
- access entitlement status;
- refund request, refund status, chargeback, or cancellation status;
- optional refund feedback if you choose to provide it.
Payments are processed by Paddle, who acts as the Merchant of Record for all Anomalyda orders. We do not store full payment card numbers on our own servers.
E. Course progress and learning data
When you use a course or digital product, we may collect:
- products you have access to;
- modules, lessons, or sections viewed;
- progress percentage;
- completion status;
- last viewed lesson;
- exercise interactions;
- quiz or task responses, if applicable;
- badge or completion-card status.
F. Technical and usage data
When you use the Service, we may collect:
- IP address;
- device and browser information;
- approximate location derived from technical data;
- pages viewed;
- referral source;
- session information;
- log data;
- cookie and similar technology identifiers;
- error, performance, and security logs.
G. User-submitted content
If the Service allows you to submit text, answers, prompts, feedback, files, exercise inputs, or other content, we may process the content you submit.
Please do not submit sensitive personal data unless it is necessary and you understand that it will be processed as part of the Service.
3. Why we use personal data and legal bases
We process personal data for the purposes below.
| Purpose | Examples | Legal basis under GDPR |
|---|---|---|
| Provide the Service | accounts, login, access control, course delivery, progress tracking | Contract necessity |
| Process purchases and refunds | checkout, receipts, invoices, payment references, refund handling, access entitlements | Contract necessity; legal obligation for accounting/tax records |
| Manage waitlists and product updates | waitlist emails, launch notifications, subscribed updates | Consent, or legitimate interest where permitted |
| Respond to contact and support requests | answering emails, troubleshooting, resolving issues | Contract necessity or legitimate interest |
| Improve the Service | bug fixing, usability improvements, product analytics | Legitimate interest, or consent where required |
| Security and fraud prevention | logs, abuse detection, access control, payment fraud handling | Legitimate interest; legal obligation where applicable |
| Legal compliance | tax, accounting, consumer law, data protection requests | Legal obligation |
| Marketing | newsletters, product announcements, offers | Consent, or legitimate interest where permitted by law |
Where we rely on consent, you may withdraw your consent at any time. Withdrawal does not affect processing that happened before consent was withdrawn.
4. How we collect personal data
We collect personal data:
- directly from you when you create an account, join a waitlist, contact us, make a purchase, request a refund, or use the Service;
- automatically through cookies, logs, analytics, and security tools;
- from Paddle when needed to confirm purchases, refunds, disputes, subscriptions, and access rights;
- from service providers that help us operate the Service.
5. Cookies and similar technologies
We may use cookies and similar technologies for:
- essential site functionality;
- login and account sessions;
- checkout and security;
- remembering preferences;
- analytics and performance measurement;
- marketing or conversion tracking, if enabled.
Essential cookies are needed for the Service to work.
For non-essential analytics or marketing cookies, we will ask for consent where required by law and provide a way to manage cookie preferences.
6. Payment processing
We use Paddle as our payment provider and Merchant of Record. This means Paddle sells the product to you, takes payment, handles tax compliance, issues invoices, and processes refunds on our behalf.
When you pay for a product, Paddle may process personal data such as your name, email address, billing address, payment method information, IP address, transaction details, invoice details, tax information, and fraud-prevention information.
We receive limited payment-related information needed to confirm the purchase, issue access, handle accounting records, manage refunds, and provide support.
We do not store full card numbers on our own servers.
7. Service providers and recipients
We may share personal data with trusted service providers where necessary to operate Anomalyda. These may include:
- hosting and database providers;
- authentication providers;
- payment processors;
- email and waitlist tools;
- analytics providers;
- customer support tools;
- security and error monitoring tools;
- development and deployment tools;
- professional advisers, such as accountants or legal advisers;
- public authorities where required by law.
Service providers may process personal data only for the purposes we instruct them to, unless they act as independent controllers under their own legal obligations.
Current or expected providers may include:
| Provider | Purpose | Data involved |
|---|---|---|
| Lovable / Lovable Cloud | App development, hosting or deployment support, payment integration infrastructure if enabled | Technical project data, app configuration, payment-flow metadata, and limited operational data as applicable |
| Paddle | Merchant of Record for all orders: checkout, payments, taxes, invoices, refunds, compliance, customer portal, subscription management | Name, email, billing address, payment method information, transaction, invoice, refund, chargeback, and subscription-related data |
| Supabase or equivalent | Authentication, database, storage, access control | Account, entitlement, progress, and form data |
| Cursor or equivalent development tools | Development and code assistance | Source code and technical debugging information; production personal data should not be intentionally entered unless necessary and lawfully covered |
| Gmail / Google Workspace | Support and transactional emails | Email, name, message, preferences |
| Lovable Analytics | Usage analytics, performance | Technical and usage data |
This list is reviewed periodically and updated when our service providers change.
8. International transfers
We are based in the European Union, but some service providers may process data outside the EU/EEA.
Where personal data is transferred outside the EU/EEA, we use safeguards required by applicable data protection law, such as:
- European Commission adequacy decisions;
- Standard Contractual Clauses;
- Data Processing Agreements;
- additional technical and organisational safeguards where appropriate.
9. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or allowed by law.
Typical retention periods:
| Data type | Typical retention |
|---|---|
| Account data | As long as the account exists, then deleted or anonymised unless retention is required |
| Course progress | As long as your account or product access exists, unless you reset or delete it |
| Purchase, refund, and invoice data | Retained as required for accounting, tax, refund, fraud-prevention, and legal purposes |
| Waitlist data | Until you unsubscribe, request deletion, or the waitlist purpose ends |
| Marketing subscription data | Until you unsubscribe or we stop sending the relevant communications |
| Contact/support messages | As long as needed to handle the request and maintain reasonable business records |
| Security logs | For a limited period needed for security, fraud prevention, and abuse investigation |
| Analytics data | According to the analytics tool settings, preferably aggregated or anonymised where possible |
If you request deletion, we will delete or anonymise your personal data unless we need to keep certain information for legal, accounting, tax, security, dispute-resolution, or legitimate business reasons.
10. Your data protection rights
Depending on your location and applicable law, you may have the right to:
- access your personal data;
- receive a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion of your data;
- restrict processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- withdraw consent;
- request data portability;
- lodge a complaint with a data protection authority.
To exercise your rights, contact us at ida@blackthornvisions.com.
We may need to verify your identity before responding to a request.
We will respond to GDPR rights requests without undue delay and generally within one month, unless the request is complex or we are legally allowed more time.
11. Data export requests
Anomalyda may provide a "Request my data export" feature in the account area.
At first, exports may be handled manually. A data export may include, where applicable:
- account information;
- purchased products and access entitlements;
- course progress;
- waitlist or marketing preferences;
- relevant support or contact information;
- other personal data connected to your account.
Some data may be excluded where disclosure would affect the rights of others, reveal security-sensitive information, or conflict with legal obligations.
12. Account deletion
You may request deletion of your account by contacting us or using any account deletion feature we provide.
Deleting your account may remove your access to purchased products, saved progress, completion status, and account history.
We may retain certain data where necessary for legal, accounting, tax, security, fraud-prevention, refund, dispute-resolution, or compliance reasons.
13. Marketing communications
If you join a waitlist or subscribe to updates, we may send you relevant product announcements, launch updates, educational materials, or offers.
You can unsubscribe from marketing emails at any time by using the unsubscribe link in the email or contacting us.
We may still send non-marketing messages, such as purchase confirmations, account notices, security messages, or important service updates.
14. Security
We use reasonable technical and organisational measures to protect personal data, such as access controls, authentication, encryption where appropriate, service-provider controls, logging, backups, and administrative safeguards.
No online service can be guaranteed to be completely secure. You are responsible for keeping your login credentials safe and notifying us if you suspect unauthorized access.
15. Children's privacy
The Service is intended for adults and is not directed to children.
We do not knowingly collect personal data from children under the age at which parental consent is required under applicable law. If you believe a child has provided personal data to us, contact us so we can take appropriate action.
16. Automated decision-making
We do not currently use personal data for automated decision-making that produces legal or similarly significant effects on you.
We may use automated systems for ordinary operational purposes, such as fraud detection, access control, security monitoring, analytics, or spam prevention.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will take reasonable steps to notify users, such as posting a notice on the website, sending an email, or showing an in-app notice.
The updated Privacy Policy will apply from the effective date stated at the top.
18. Complaints
If you are in the EU/EEA and believe that our processing of your personal data violates data protection law, you have the right to lodge a complaint with your local data protection authority.
In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.
We would appreciate the chance to address your concern first, but you are not required to contact us before contacting a supervisory authority.
19. Contact
For privacy questions or rights requests, contact:
Blackthorn Visions Ltd
Business ID: 3005647-8
Ruotutie 16, 02610 Espoo, Finland
Website: anomalyda.com
Email: ida@blackthornvisions.com