RegimeLab ("we", "us") operates the website at regimelab.io and the application at my.regimelab.io. We are the data controller for the personal data described in this policy.
RegimeLab is operated by an individual in the United Kingdom.
Contact for any privacy question or request: hello@regimelab.io
This policy covers personal data we hold about visitors to regimelab.io and users of the RegimeLab application. It does not cover the websites of the companies we use to run the service, each of which has its own policy. Those companies are named below.
We hold a deliberately small amount of personal data. The complete list follows.
We do not hold your name, your postal address, your telephone number, or your payment card details. Card details are handled entirely by Stripe and never reach our systems.
To provide the service you have an account for. Your email address, subscription details, watchlist, alert rules, API keys and Telegram identifier exist so the application can sign you in, bill you correctly, and send you the alerts you have asked for. Our lawful basis is performance of a contract.
To contact you about RegimeLab if you joined the waitlist. We hold your email address so that we can get in touch about the product when access opens. We have not sent anything to the waitlist so far. Our lawful basis is legitimate interests, specifically our interest in contacting people who asked to hear from us about the product they asked about. You can ask us to remove your address at any time by emailing hello@regimelab.io, and we will.
To understand where signups come from. The page, campaign and referrer information stored with a waitlist signup tells us which parts of the site bring people in. Our lawful basis is legitimate interests, specifically running the site in an informed way. This data is never used to build a profile of you or to target you individually.
To meet our legal obligations. We keep records of payments for as long as tax and accounting law requires. Our lawful basis is legal obligation.
We use the following companies to run the service. Each processes personal data on our instructions.
| Company | What they do | Where |
|---|---|---|
| Supabase | Database and sign-in. Holds account data, and sends the sign-in links we email you. | United States |
| Stripe | Payments, subscriptions and the billing portal. Holds your card details, which we never see. | United States and Ireland |
| Vercel | Hosts the application. Processes requests, including your IP address in ordinary server logs. | United States |
| Webflow | Hosts the website. | United States |
| Telegram | Delivers alerts to you, if you have connected Telegram. | Various |
Each of these companies uses its own suppliers to deliver its service, and those sub-processors are named in the terms each company publishes. For example, our website host serves the site through a content delivery network, which is why a cookie from that network is set when you visit.
We do not sell personal data. We do not share it with advertisers. We do not use it to build profiles for anyone else.
We may disclose personal data if we are legally required to do so, for example in response to a valid order from a court or regulator.
Most of the companies above are based in the United States, so your personal data is transferred outside the United Kingdom.
Where that happens, the transfer is covered by the safeguards permitted under Article 46 of the UK GDPR. In practice this means the standard contractual clauses together with the UK International Data Transfer Addendum, or, where a provider is certified, the UK extension to the EU-US Data Privacy Framework. Each provider's current data processing terms are published on its own website.
Telegram operates internationally and messages sent through it are subject to Telegram's own terms and privacy policy. Telegram is currently the only channel we deliver alerts through, and connecting it is optional. If you would rather no data of yours reached Telegram, do not connect it. Everything else in the application works without it, and you can read the same information by signing in.
Account data is kept for as long as your account exists. If you delete your account, it is deleted immediately, as described below.
Waitlist data is kept until you ask us to remove it, or until you delete an account registered with the same email address, which removes it at the same time.
Payment records are kept by Stripe, and by us in summary form, for as long as tax and accounting law requires. This is currently six years from the end of the financial year the payment falls in.
Deletion is final. We do not keep scheduled backups of our database, so when you delete your account there is no backup copy from which your data could be recovered.
Under UK data protection law you have the right to ask us for a copy of your personal data, to correct it, to delete it, to restrict how we use it, to object to our using it, and to receive it in a portable form. You can also object to processing we carry out on the basis of legitimate interests, which covers holding your waitlist address and the signup information stored alongside it.
Two of these you can exercise yourself, immediately, without asking us.
Export. The account page has an export button. It returns a file containing your email address, your full profile record, your alert rules, the record of alerts sent to you, your API keys with the key values removed, and any waitlist entries matching your email address.
Deletion. The account page has a delete button, behind a confirmation step where you type DELETE. Deleting your account cancels your subscription and removes your customer record at Stripe, removes any waitlist entries matching your email address, and deletes your account and everything attached to it.
Deletion is immediate and cannot be undone. If you delete your account part way through a paid period, the remainder of that period is not refunded. The confirmation step tells you this before you proceed.
For anything else, contact us at hello@regimelab.io. We will respond within one month, as the law requires. If you are not satisfied with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk.
We do not use analytics cookies, advertising cookies, or tracking of any kind, and there is no consent banner because nothing we set requires consent.
One cookie is set when you visit regimelab.io. It is named _cfuvid, it lasts only for your browsing session, and it is set by Cloudflare, which our website host uses to protect the site from automated abuse and to apply rate limits fairly. It is strictly necessary for the site to work safely and cannot be turned off while you use it. Because it is scoped to our domain as a whole, your browser will also send it to the application, although the application does not set it.
When you sign in to the application, we store a sign-in token in your browser's local storage rather than in a cookie. This is what keeps you signed in between pages and visits. It is strictly necessary for the application to work. It stays on your device until you sign out or clear your browser's storage for the site, and you can remove it at any time through your browser settings, which will sign you out.
We set nothing else on your device.
RegimeLab is not intended for anyone under 18 and we do not knowingly hold personal data about children. If you believe a child has given us personal data, contact us and we will remove it.
If we change this policy we will update the date at the top. If a change materially affects how we use your personal data, we will tell account holders by email before it takes effect.