THE LIFE CLOCK

Privacy

The Life Clock asks you for the dates of your own life. That's an unusual amount of trust for a $19 tool to ask for, so this page tells you exactly what is held, where, by whom, for how long, and how to get it back or have it gone.

In effect from 3 August 2026

Who's responsible

Me. Delfina Kalden, trading as shethemystic, is the data controller for The Life Clock. Nobody else decides what happens to your information.

Write to me at delfinakalden@gmail.com about anything on this page.

The short version

What's collected, and why

The free calculator

You type a birthday, it tells you where you're standing. That calculation happens inside your own browser and the date is never sent to me, never stored, and never logged. Close the tab and it's gone. This is worth being clear about: the most personal thing on the free page never leaves your device.

If you give me your email for the writing

There's a form on the front page where you can leave your email address to hear from me. If you use it, I hold that address and use it to send you writing. That's it — no profiling, no selling, no passing it around. Every email has an unsubscribe link and leaving takes one click.

When you buy

Payment runs through Stripe. Stripe collects your name, email address, card details and billing country, and does the actual payment. I never see or hold your full card number — what comes back to me is your email address, Stripe's customer and session references, and whether the payment succeeded.

That email address is what your access is attached to. It's stored with the date access was granted, and, if a purchase is ever refunded, the date it was revoked. Refunded records are kept rather than deleted, so that a refund and a later repurchase both leave a clean, honest trail.

Inside the Clock

This is the part that matters most, so here it is in full. When you use the Clock, it saves:

All of it is saved as a single document attached to your user account, in the database, and it saves as you type so you never lose an evening's work. It's there so you can come back to it — that's the whole point of a map you keep.

A life map can end up holding things the law treats as especially sensitive: an illness, a bereavement, a faith, a marriage, a leaving. I never ask you for any of that, and the Clock never requires it. Every free-text box is yours to fill or leave empty, and a one-word label works as well as a paragraph.

Where what you write does touch on those things, you're the one who chose to write it, and that choice — your explicit consent — is what allows me to store it. You can change it or ask me to delete it at any time.

Signing in

There's no password. You ask for a code, it arrives by email, and it opens the app. Your email address and those codes are handled by Supabase, which runs the sign-in system. Once you're in, your browser stores a sign-in token so you're not asked again every time you open a tab. That token is strictly necessary for the product to work at all — it isn't tracking, and it isn't shared with anyone.

Emails I send you

Two of them: the access email when you buy, and the sign-in code when you ask for one. They're sent through Resend, which handles delivery and keeps the usual delivery records (that a message was sent, delivered, or bounced).

Analytics on the marketing page

The front page — the one selling the Clock — carries two analytics tools. The app you sign into does not. Once you're inside the product you paid for, nothing is measuring you.

Google Analytics counts visits and a few events: that the page was viewed, that the calculator was used, that a checkout button was clicked. It records the fact of the click, not your birthday.

Microsoft Clarity does something more, and I want to name it plainly rather than bury it in a list:

Clarity records session replay. That means it captures how you moved through the marketing page — mouse movement, clicks, taps, scrolling, how long you stayed — and reconstructs it as a replay I can watch back, along with heatmaps of where people click.

I use it to find out where the page confuses people. It runs on the marketing page only, never inside the signed-in app, so it cannot see your map, your reading or anything you've written. Microsoft, who run Clarity, mask text typed into form fields by default.

If you'd rather not be recorded at all, the opt-outs are further down this page.

The ordinary technical record

Vercel hosts the site and, like every web host, keeps short-lived server logs: IP addresses, times, which page was requested, which browser asked. They're there so the site can run and so I can see when something breaks.

Why I'm allowed to hold it

Under UK and EU data protection law, every use of your information needs a lawful basis. Here are mine, in plain terms:

Who else touches your data

I use a small number of services to run this. They process data on my instructions, under contract, and none of them is allowed to use your information for their own purposes.

Stripe
Takes the payment and holds the card details I never see. stripe.com/privacy
Supabase
Runs the sign-in system and the database where your access record and your map are stored. supabase.com/privacy
Resend
Sends the access email and the sign-in codes. resend.com/legal/privacy-policy
Vercel
Hosts the site and the small server functions behind checkout and sign-in. vercel.com/legal/privacy-policy
Google Analytics
Counts visits and events on the marketing page. policies.google.com/privacy
Microsoft Clarity
Heatmaps and session replay on the marketing page. privacy.microsoft.com/privacystatement

That's the whole list. I don't sell your data, I don't share it with advertisers, and I don't hand it to anyone else unless the law actually requires it.

Where it goes

Most of these companies are based in the United States, so your information will be processed outside the UK and the EU. They each operate under recognised safeguards for that — standard contractual clauses, and where applicable the EU–US and UK–US Data Privacy Framework.

How long it's kept

Your rights, and how to use them

If you're in the UK or the EU these are legal rights; wherever you are, I'll honour them anyway. You can:

How: email delfinakalden@gmail.com from the address you bought with, or tell me what that address was, and say what you'd like. No form, no template, no fee.

You'll hear back within three working days and it'll be done within 30 days, which is the legal limit and much longer than it usually takes me.

Cookies and how to switch the tracking off

Inside the app, the only thing stored in your browser is the sign-in token that keeps you signed in. Without it the product can't work, so there's nothing to turn off there.

On the marketing page, Google Analytics and Microsoft Clarity each set their own identifiers. If you'd rather they didn't:

Children

The Life Clock is built for adults looking back over a life with some length to it. It isn't for children, and I don't knowingly collect anything from them. Please don't buy it or give me your email if you're under 16.

If you think a child has given me their information, write to me and I'll delete it.

Keeping it safe

Everything travels encrypted. The database is set up so that your row can only be read by you when you're signed in — not by other buyers, and not by anyone browsing the site. The keys that could read more than that live on the server and are never sent to a browser.

No system is perfect and I won't pretend otherwise. If something ever went wrong in a way that put your information at risk, I'd tell you, and I'd tell the regulator where the law requires it.

When this page changes

It changes when the tools change. The date at the top tells you which version you're reading. If something material changes — a new processor, a new kind of data, a longer retention — I'll email buyers rather than quietly editing the page.

Reaching me

delfinakalden@gmail.com. One person, one inbox. Ask me anything on this page and I'll answer it in plain words.

Terms · Refunds