This policy explains how Another Session collects and uses personal data when you visit https://anothersession.app or use the Service. We are the data controller for the personal data of account holders. For personal data about your clients that you store inside the Service, you are the controller and we are your processor (see the Data processing addendum).
1. Who we are
Controller: Another Session, operated by Barrie Thompson, based in United Kingdom. Contact: hello@anothersession.app.
2. What we collect
Account data
- Name, email address and password hash.
- Profile preferences such as currency, time zone and rates.
- Subscription status (including any legacy Founding Member or Insider flag) and billing history.
Content you create
- Client records, session entries, notes, packages and payment status you enter into the Service.
Usage data
- Pages viewed, device type, country (derived from IP), referrer and campaign parameters, approximate session duration. Collected via our own first-party analytics and, on the public marketing pages, via Google Analytics 4. We do not use advertising trackers and Google Analytics advertising features are not enabled.
- Technical logs (timestamp, request path, error details) for security and debugging.
Communications
- Emails you send us, support tickets, and email engagement events (delivered, opened, bounced) for transactional and product emails.
3. Why we use it and our legal basis
- To provide the Service. Legal basis: performance of a contract with you.
- To keep the Service secure and prevent abuse. Legal basis: legitimate interests.
- To send transactional emails (sign in, billing, important account notices). Legal basis: performance of a contract.
- To send product updates and occasional marketing about Another Session. Legal basis: legitimate interests, with a clear unsubscribe link in every message. UK and EU users can opt out at any time.
- To meet legal, tax and accounting obligations. Legal basis: legal obligation.
4. Who we share data with
We use a small set of trusted processors to run the Service. They act on our instructions and are bound by data protection contracts.
- Hosting and database: Lovable Cloud (powered by Supabase). Data is stored in EU-region infrastructure.
- Transactional email: Resend, for sending account and product emails.
- Analytics: first-party analytics stored in our own database, plus Google Analytics 4 (Google Ireland Limited) on the public marketing pages. No advertising IDs are collected.
- Payments: subscription payments are processed by Stripe. We never see or store full card numbers.
We do not sell personal data. We do not share it with advertisers. We may disclose data when legally required or to protect rights, property or safety.
5. International transfers
Our processors may transfer data outside the UK or EEA. Where they do, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
6. How long we keep it
- Account and content data: for as long as your account is active. If you close your account, we delete or anonymise it within 90 days, except where we are legally required to keep records (for example, billing records for up to 6 years for UK tax purposes).
- Email logs: 12 months.
- Analytics: aggregated and retained for up to 24 months.
7. Your rights
Under UK GDPR and the EU GDPR you have the right to access, correct, delete, restrict or object to processing, and to data portability. You also have the right to withdraw consent where processing is based on consent. Email hello@anothersession.app to exercise any of these rights. We will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EU.
8. Security
We use encryption in transit (HTTPS), encryption at rest in our database, role-based access controls and row-level security to keep your data safe. No system is perfectly secure, so we encourage strong, unique passwords.
9. Children
The Service is not directed at children. Do not create an account if you are under 18. If you are a coach storing data about a junior client, you must have an appropriate lawful basis (typically the parent's or guardian's consent) before doing so.
10. Changes
We may update this policy from time to time. Material changes will be notified by email or in-product. The current version is always available at /legal/privacy.
11. Contact
Email hello@anothersession.app for any privacy question.