Privacy notice
Privacy should be understandable and deliberate.
Committed Marriage uses individual accounts to protect course access, Journal activity, saved progress, and optional reflections. Membership checkout is handled by Stripe; Committed Marriage does not store full card numbers or payment credentials.
Course account data
Signed-in learners can save lesson completion, membership access, Journal activity, and optional reflections. Authenticated requests pass through a server-side service to user-owned Supabase records. Active enrollment or membership access is checked before premium course or Journal state can be read or changed.
Two-account privacy
One marriage enrollment may cover two separate accounts, but each person keeps an individual login and controls their own private data. Journal entries are not made visible to a spouse automatically. If accounts are unlinked, each person keeps their own private writing and other user-owned data; shared relationship-space material is handled according to the feature’s visible unlinking notice.
Private reflections
Private Journal and reflection text is encrypted by the server before it is stored using application-managed AES-256-GCM. This is not end-to-end encryption or a zero-knowledge system: authorized application services can decrypt content for a feature you request, account export, or other documented product operations. Private writing is not sent to analytics, advertising, marketing profiles, Reader Intent, or lifecycle email, and it is never shared with a partner automatically.
Journal AI choices
The Journal Privacy Center lets an account lock new AI processing or require a fresh choice for each fixed-purpose request. Its processing history is content-free: it may show the action and general scope class, status, model family, token counts, cost, and timestamps, but not Journal text or private source identifiers. Locking is prospective; a provider request already running may finish.
Device-only preferences and free tools
The course may remember listening position and reading mode on the current device. The free weekly check-in keeps responses in the open browser tab only; it does not transmit or save them, and refreshing or closing the page clears them.
Reader identity and consent
Before permission, the public reading experience does not create a persistent behavioral identity. If you allow thoughtful personalization, Committed Marriage creates a first-party anonymous reader identifier for about one year and a separate session identifier for about six hours. These identifiers stay on this Site, use SameSite cookie behavior, and are not used for fingerprinting or cross-site identity.
Your choice is versioned and can be changed through Privacy choices in the footer. Turning personalization off removes the reader and session identifiers from this browser. Page-level reading behavior may support future guidance, but private Journal text, course responses, private check-in answers, spouse content, and safety-resource reading are excluded.
Payments and communications
Stripe processes course checkout, optional Journal-plan enrollment, renewal, cancellation, and refunds. Committed Marriage stores the Stripe identifiers, accepted terms version, and entitlement state needed to provide access, but not full payment-card details. The $199 course checkout does not create an annual Journal subscription; a recurring plan begins only after a separate opt-in.
After a full course refund, paid access is removed from both covered accounts. Before that happens, a reasonable export opportunity is offered for private writing. Private content remains subject to the account’s deletion choices and documented retention behavior. Transaction records may be retained when needed for accounting, fraud prevention, dispute handling, or law. Course-purchase suppression is authoritative for post-purchase marketing, and private Journal activity never changes Reader Intent or nurture messaging.
Current product boundaries
Committed Marriage does not claim end-to-end encryption or zero knowledge. Client-held encryption keys are not part of the current product. Journal still-photo upload is supported for Full Journal accounts: photos are compressed, stripped of device metadata, and encrypted before private storage. Journal video and voice are not supported. Photo attachments are not yet included in Journal exports, and a separate photo backup-and-restore workflow has not been released, so members should keep their original photos.
Product notice. This page describes current technical behavior. Formal processor details, retention periods, regional rights, contact information, and legal-policy language still require counsel review.