Legal and privacy
Privacy policy
How The Boudoir Method collects, uses, protects, shares, retains, and deletes account, learning, commerce, community, coaching, and sensitive-media data.
Policy version 2026-08-09-draft · Published August 9, 2026
Who this policy covers
This policy covers visitors, students, members, instructors, critique reviewers, affiliates, and authorized staff who use The Boudoir Method website and authenticated workspace. The service is intended only for adults age 18 or older.
Data we collect
- Account and identity data, including email, profile, verification status, role assignments, consent versions, and security events.
- Learning data, including enrollments, lesson and video progress, assignments, submissions, critiques, certificates, saved items, follows, and community participation.
- Commerce data, including product, order, subscription, refund, dispute, affiliate, and compensation records. Full payment-card data is handled by Stripe and is not stored in our application database.
- Private content and metadata submitted for review, including images, permitted attachments, content notices, visibility choices, attestations, moderation reports, and access logs.
- Technical and operational data needed for security and reliability, such as request identifiers, audit events, limited telemetry, and hashed access context where configured.
How we use data
- Authenticate accounts, enforce role and resource access, deliver purchased learning, coaching, critique, downloads, and certificates.
- Process payments and provider-confirmed commerce events; calculate authorized compensation and affiliate attribution.
- Protect sensitive content, investigate reports, prevent abuse, meet legal obligations, and preserve append-only consent, access, audit, critique, and financial histories.
- Send transactional messages and, only with consent, optional learning, community, or marketing communications.
- Improve accessibility, reliability, and product performance using appropriately minimized operational data.
Providers and disclosures
We use Supabase for authentication, PostgreSQL data, private object storage, and server functions; Stripe for checkout, subscriptions, refunds, disputes, and customer billing tools; Mux when configured for protected video processing and signed playback; Resend when configured for transactional email; and Sentry when configured for error monitoring. Calendar or meeting providers may be connected for coaching only after an authorized instructor connection is active.
- Providers receive only data needed for the service they perform and remain subject to their own terms and privacy commitments.
- We may disclose information when required by law, to protect people or the service, or in a business transfer subject to appropriate safeguards. We do not sell private submission images.
Sensitive media and storage
Submission originals, review derivatives, critique media, certificates, and protected downloads are stored in non-public buckets. Access is authorized server-side and delivered through short-lived signed access. Review derivatives may be re-encoded and location metadata removed. Original-file access by authorized people is recorded with a reason.
- Private attachments such as RAW or PSD files do not have a general browser-rendering path.
- Email notifications do not include private image previews.
- A visibility grant is separate from the rights-and-consent attestation and can be revoked prospectively.
Retention and deletion
We retain account and learning data while an account or entitlement is active and as needed to deliver the service. Requests to delete or export data are recorded in privacy request history. Deletion may remove or de-identify eligible profile and content data while retaining records that must remain for fraud prevention, taxes, payments, disputes, consent evidence, legal claims, safety, and append-only audit or critique integrity.
- Withdrawal or deletion of a submission does not silently rewrite earlier critique, consent, access, or moderation history.
- Provider backups and logs may expire on provider schedules after application deletion.
- Where immediate deletion is not permitted, access is restricted and the reason is recorded.
Your choices and requests
Authenticated users can manage notification and sensitive-content display preferences, view privacy request history, and request an export or deletion from the Privacy workspace. You may also report privacy, rights, takedown, or deletion concerns from the relevant content workflow. Identity verification may be required before a request is completed.
- Marketing consent can be withdrawn without affecting transactional messages.
- Consent and visibility changes apply prospectively; prior lawful processing and immutable evidence remain recorded.
- Questions or requests can be submitted through the authenticated privacy workflow or the Help page.
Security and international processing
We use row-level security, scoped roles, private storage, signed access, server authorization, audited sensitive access, and least-privilege service boundaries. No system can guarantee absolute security. Providers may process data in locations described in their own documentation, subject to their contractual safeguards.
Changes
Material policy changes receive a new version. Where required, the application records acceptance of the new version before continued use of affected features.