Legal

Privacy Policy

Effective date: May 28, 2026

1. Who we are

Controller: Blackthorn Visions Ltd
Business ID: 3005647-8
Address: Ruotutie 16, 02610 Espoo, Finland
Website: anomalyda.com
Privacy contact: ida@blackthornvisions.com

If you have questions about this Privacy Policy or want to exercise your data protection rights, contact us at the email address above.

2. What personal data we collect

We may collect the following categories of personal data.

A. Account data

When you create an account, we may collect:

  • name or display name;
  • email address;
  • login credentials or authentication identifiers;
  • account settings;
  • account creation date;
  • last login information;
  • security and authentication logs.

Passwords, where used, should be stored in hashed form through our authentication provider. We do not intentionally store plain-text passwords.

B. Waitlist and marketing data

When you join a waitlist or subscribe to updates, we may collect:

  • email address;
  • name, if provided;
  • product or course interest;
  • consent status;
  • subscription preferences;
  • timestamps and source of signup.

C. Contact and support data

When you contact us, submit a form, or request support, we may collect:

  • name;
  • email address;
  • message content;
  • attachments, if any;
  • information needed to answer your request;
  • communication history.

D. Purchase, refund, and payment-related data

When you make a purchase or request a refund, we may collect and store:

  • name;
  • email address;
  • billing details;
  • purchased product;
  • price, currency, tax/VAT information where applicable;
  • order ID;
  • Paddle order, transaction, or subscription reference;
  • invoice and receipt information;
  • access entitlement status;
  • refund request, refund status, chargeback, or cancellation status;
  • optional refund feedback if you choose to provide it.

Payments are processed by Paddle, who acts as the Merchant of Record for all Anomalyda orders. We do not store full payment card numbers on our own servers.

E. Course progress and learning data

When you use a course or digital product, we may collect:

  • products you have access to;
  • modules, lessons, or sections viewed;
  • progress percentage;
  • completion status;
  • last viewed lesson;
  • exercise interactions;
  • quiz or task responses, if applicable;
  • badge or completion-card status.

F. Technical and usage data

When you use the Service, we may collect:

  • IP address;
  • device and browser information;
  • approximate location derived from technical data;
  • pages viewed;
  • referral source;
  • session information;
  • log data;
  • cookie and similar technology identifiers;
  • error, performance, and security logs.

G. User-submitted content

If the Service allows you to submit text, answers, prompts, feedback, files, exercise inputs, or other content, we may process the content you submit.

Please do not submit sensitive personal data unless it is necessary and you understand that it will be processed as part of the Service.

3. Why we use personal data and legal bases

We process personal data for the purposes below.

PurposeExamplesLegal basis under GDPR
Provide the Serviceaccounts, login, access control, course delivery, progress trackingContract necessity
Process purchases and refundscheckout, receipts, invoices, payment references, refund handling, access entitlementsContract necessity; legal obligation for accounting/tax records
Manage waitlists and product updateswaitlist emails, launch notifications, subscribed updatesConsent, or legitimate interest where permitted
Respond to contact and support requestsanswering emails, troubleshooting, resolving issuesContract necessity or legitimate interest
Improve the Servicebug fixing, usability improvements, product analyticsLegitimate interest, or consent where required
Security and fraud preventionlogs, abuse detection, access control, payment fraud handlingLegitimate interest; legal obligation where applicable
Legal compliancetax, accounting, consumer law, data protection requestsLegal obligation
Marketingnewsletters, product announcements, offersConsent, or legitimate interest where permitted by law

Where we rely on consent, you may withdraw your consent at any time. Withdrawal does not affect processing that happened before consent was withdrawn.

4. How we collect personal data

We collect personal data:

  • directly from you when you create an account, join a waitlist, contact us, make a purchase, request a refund, or use the Service;
  • automatically through cookies, logs, analytics, and security tools;
  • from Paddle when needed to confirm purchases, refunds, disputes, subscriptions, and access rights;
  • from service providers that help us operate the Service.

5. Cookies and similar technologies

We may use cookies and similar technologies for:

  • essential site functionality;
  • login and account sessions;
  • checkout and security;
  • remembering preferences;
  • analytics and performance measurement;
  • marketing or conversion tracking, if enabled.

Essential cookies are needed for the Service to work.

For non-essential analytics or marketing cookies, we will ask for consent where required by law and provide a way to manage cookie preferences.

6. Payment processing

We use Paddle as our payment provider and Merchant of Record. This means Paddle sells the product to you, takes payment, handles tax compliance, issues invoices, and processes refunds on our behalf.

When you pay for a product, Paddle may process personal data such as your name, email address, billing address, payment method information, IP address, transaction details, invoice details, tax information, and fraud-prevention information.

We receive limited payment-related information needed to confirm the purchase, issue access, handle accounting records, manage refunds, and provide support.

We do not store full card numbers on our own servers.

7. Service providers and recipients

We may share personal data with trusted service providers where necessary to operate Anomalyda. These may include:

  • hosting and database providers;
  • authentication providers;
  • payment processors;
  • email and waitlist tools;
  • analytics providers;
  • customer support tools;
  • security and error monitoring tools;
  • development and deployment tools;
  • professional advisers, such as accountants or legal advisers;
  • public authorities where required by law.

Service providers may process personal data only for the purposes we instruct them to, unless they act as independent controllers under their own legal obligations.

Current or expected providers may include:

ProviderPurposeData involved
Lovable / Lovable CloudApp development, hosting or deployment support, payment integration infrastructure if enabledTechnical project data, app configuration, payment-flow metadata, and limited operational data as applicable
PaddleMerchant of Record for all orders: checkout, payments, taxes, invoices, refunds, compliance, customer portal, subscription managementName, email, billing address, payment method information, transaction, invoice, refund, chargeback, and subscription-related data
Supabase or equivalentAuthentication, database, storage, access controlAccount, entitlement, progress, and form data
Cursor or equivalent development toolsDevelopment and code assistanceSource code and technical debugging information; production personal data should not be intentionally entered unless necessary and lawfully covered
Gmail / Google WorkspaceSupport and transactional emailsEmail, name, message, preferences
Lovable AnalyticsUsage analytics, performanceTechnical and usage data

This list is reviewed periodically and updated when our service providers change.

8. International transfers

We are based in the European Union, but some service providers may process data outside the EU/EEA.

Where personal data is transferred outside the EU/EEA, we use safeguards required by applicable data protection law, such as:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses;
  • Data Processing Agreements;
  • additional technical and organisational safeguards where appropriate.

9. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or allowed by law.

Typical retention periods:

Data typeTypical retention
Account dataAs long as the account exists, then deleted or anonymised unless retention is required
Course progressAs long as your account or product access exists, unless you reset or delete it
Purchase, refund, and invoice dataRetained as required for accounting, tax, refund, fraud-prevention, and legal purposes
Waitlist dataUntil you unsubscribe, request deletion, or the waitlist purpose ends
Marketing subscription dataUntil you unsubscribe or we stop sending the relevant communications
Contact/support messagesAs long as needed to handle the request and maintain reasonable business records
Security logsFor a limited period needed for security, fraud prevention, and abuse investigation
Analytics dataAccording to the analytics tool settings, preferably aggregated or anonymised where possible

If you request deletion, we will delete or anonymise your personal data unless we need to keep certain information for legal, accounting, tax, security, dispute-resolution, or legitimate business reasons.

10. Your data protection rights

Depending on your location and applicable law, you may have the right to:

  • access your personal data;
  • receive a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion of your data;
  • restrict processing;
  • object to processing based on legitimate interests;
  • object to direct marketing;
  • withdraw consent;
  • request data portability;
  • lodge a complaint with a data protection authority.

To exercise your rights, contact us at ida@blackthornvisions.com.

We may need to verify your identity before responding to a request.

We will respond to GDPR rights requests without undue delay and generally within one month, unless the request is complex or we are legally allowed more time.

11. Data export requests

Anomalyda may provide a "Request my data export" feature in the account area.

At first, exports may be handled manually. A data export may include, where applicable:

  • account information;
  • purchased products and access entitlements;
  • course progress;
  • waitlist or marketing preferences;
  • relevant support or contact information;
  • other personal data connected to your account.

Some data may be excluded where disclosure would affect the rights of others, reveal security-sensitive information, or conflict with legal obligations.

12. Account deletion

You may request deletion of your account by contacting us or using any account deletion feature we provide.

Deleting your account may remove your access to purchased products, saved progress, completion status, and account history.

We may retain certain data where necessary for legal, accounting, tax, security, fraud-prevention, refund, dispute-resolution, or compliance reasons.

13. Marketing communications

If you join a waitlist or subscribe to updates, we may send you relevant product announcements, launch updates, educational materials, or offers.

You can unsubscribe from marketing emails at any time by using the unsubscribe link in the email or contacting us.

We may still send non-marketing messages, such as purchase confirmations, account notices, security messages, or important service updates.

14. Security

We use reasonable technical and organisational measures to protect personal data, such as access controls, authentication, encryption where appropriate, service-provider controls, logging, backups, and administrative safeguards.

No online service can be guaranteed to be completely secure. You are responsible for keeping your login credentials safe and notifying us if you suspect unauthorized access.

15. Children's privacy

The Service is intended for adults and is not directed to children.

We do not knowingly collect personal data from children under the age at which parental consent is required under applicable law. If you believe a child has provided personal data to us, contact us so we can take appropriate action.

16. Automated decision-making

We do not currently use personal data for automated decision-making that produces legal or similarly significant effects on you.

We may use automated systems for ordinary operational purposes, such as fraud detection, access control, security monitoring, analytics, or spam prevention.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

If we make material changes, we will take reasonable steps to notify users, such as posting a notice on the website, sending an email, or showing an in-app notice.

The updated Privacy Policy will apply from the effective date stated at the top.

18. Complaints

If you are in the EU/EEA and believe that our processing of your personal data violates data protection law, you have the right to lodge a complaint with your local data protection authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.

We would appreciate the chance to address your concern first, but you are not required to contact us before contacting a supervisory authority.

19. Contact

For privacy questions or rights requests, contact:

Blackthorn Visions Ltd
Business ID: 3005647-8
Ruotutie 16, 02610 Espoo, Finland
Website: anomalyda.com
Email: ida@blackthornvisions.com