influglow

Privacy Policy

Effective date: September 14, 2026 Last updated: September 14, 2026

1. Introduction

This Privacy Policy explains how mDev Mikołaj Sobieszczański ("we," "us," or "our") collects, uses, discloses, and protects personal data in connection with the website located at https://influglow.com (the "Site") and the online course and related digital products offered through it (collectively, the "Services").

We are the controller of the personal data described in this Policy within the meaning of Regulation (EU) 2016/679 (the "GDPR") and, where applicable, the United Kingdom General Data Protection Regulation as retained in UK law (the "UK GDPR").

By accessing the Site or purchasing access to the Services, you acknowledge that you have read and understood this Policy. If you do not agree with the practices described here, please do not use the Services.

2. Controller identity and contact details

Controller: mDev Mikołaj Sobieszczański Registered address: Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland Email: hello@influglow.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. All privacy inquiries, rights requests, and complaints should be directed to the email address above.

3. Scope of this Policy

This Policy applies to personal data we process when you:

  • visit or browse the Site;
  • create an account in order to access the Services;
  • purchase access to the course or to any other digital product we offer;
  • access course materials, including audio lessons; or
  • contact us by email.

This Policy does not apply to third-party websites, platforms, or services that we link to or reference within our content. Those services operate under their own privacy policies, and we encourage you to review them.

4. Categories of personal data we collect

4.1 Account data

When you create an account, our authentication provider, Clerk, Inc. ("Clerk"), collects and stores on our behalf:

  • your email address;
  • your username;
  • your password, stored in hashed form (we never have access to your password in plain text);
  • a unique account identifier;
  • account creation date, last sign-in date, and sign-in history;
  • the IP address and device or browser information associated with your sign-in events.

4.2 Data received from third-party sign-in providers

If you choose to create an account or sign in using Google, Facebook, or TikTok, that provider transmits to us a limited set of profile information, which typically includes your email address, your name or display name as held by that provider, a unique provider-side identifier, and, where made available, a profile image.

We do not receive your password for those services, and we do not gain access to your contacts, posts, followers, direct messages, analytics, or any other content held by those platforms. The scope of data shared is governed by the permissions you grant at the time of authorization and by the privacy policy of the provider in question.

4.3 Payment and billing data

All payments are processed by Stripe. Depending on your location, your payment is handled by Stripe, Inc. or by Stripe Payments Europe, Limited (collectively, "Stripe").

Payments are taken through Stripe Checkout, a payment page hosted by Stripe. We do not receive, process, or store your full payment card number, card expiry date, or card security code at any time. Those details are transmitted directly from your browser to Stripe.

In connection with a purchase, Stripe collects and processes, and shares with us in summarized form:

  • your name as provided at checkout;
  • your email address;
  • your billing address, including country;
  • the last four digits of your payment card, the card brand, and the country in which the card was issued;
  • the transaction amount, currency, date, and status;
  • for installment purchases, the payment schedule and the status of each scheduled payment;
  • your IP address at the time of the transaction;
  • a tax identification number, where you provide one in order to obtain a business invoice.

We also collect and retain the location evidence required by applicable value added tax rules for electronically supplied services, which may include your billing country, the country of your card issuer, and your IP address.

Stripe issues transaction documents directly to your email address: a receipt for one-time purchases, and an invoice following each successful payment under an installment plan.

Stripe additionally acts as an independent controller for certain purposes, including fraud prevention and compliance with its own legal obligations. Please refer to the Stripe Privacy Policy at https://stripe.com/privacy for details of that processing.

4.4 Course access data

Following a successful payment, we record the status and scope of your entitlement to the Services. This information is stored against your account record at Clerk and includes the product purchased, the date access was granted, the date on which access expires, and, for installment purchases, whether the entitlement remains current as each scheduled payment is taken.

4.5 Technical data

When you access the Site, our hosting provider and our content storage provider automatically collect technical information generated by your browser, including your IP address, the date and time of your request, the pages or files requested, HTTP status codes, referring URL, user agent string, and approximate location derived from your IP address.

Audio lessons are stored in a private bucket and delivered to your browser through short-lived signed links. Requests for those files generate the same categories of technical data described above.

4.6 Correspondence

If you contact us by email, we process the content of your message, your email address, and any information you choose to include, together with our reply.

4.7 Marketing preferences and consent records

If you choose to receive marketing email from us, we record that choice against your account and keep a separate, append-only record of each time you give or withdraw it. That record contains your account identifier, the categories you agreed to, the legal basis on which we were entitled to write to you, the country used to determine that basis, the version of the consent wording you were shown, and the date and time. Where a salt is configured for that purpose, it also contains a salted, irreversible hash of the IP address from which the choice was submitted; we never store the address itself. We keep these records because Article 7(1) of the GDPR places on us the burden of demonstrating that consent was given.

We also process your email address, your first name where you have provided it, and delivery and engagement data generated by our email provider, such as whether a message was delivered, opened, or reported as spam.

4.8 Data we do not collect

We do not knowingly collect special categories of personal data within the meaning of Article 9 of the GDPR, and we ask that you do not send such information to us. We do not purchase personal data from data brokers, and we do not enrich or append your account record with data obtained from external sources.

5. Purposes of processing and legal bases

We process personal data only where a valid legal basis applies. The following table sets out each purpose and the corresponding legal basis under Article 6(1) of the GDPR and the UK GDPR.

PurposeCategories of dataLegal basis
Creating and maintaining your account, authenticating your sign-inAccount data, sign-in provider dataPerformance of a contract, Art. 6(1)(b)
Processing your purchase and granting access to the ServicesPayment and billing data, course access dataPerformance of a contract, Art. 6(1)(b)
Administering installment payment schedules and adjusting access accordinglyPayment data, course access dataPerformance of a contract, Art. 6(1)(b)
Delivering course materials, including audio lessonsAccount data, technical dataPerformance of a contract, Art. 6(1)(b)
Responding to your inquiries and providing supportCorrespondence, account dataPerformance of a contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
Issuing receipts and invoices, maintaining accounting records, and meeting tax and value added tax obligationsPayment and billing data, tax location evidenceCompliance with a legal obligation, Art. 6(1)(c)
Sending marketing email about new lessons, creator tips, and offersEmail address, first name, marketing preferencesConsent, Art. 6(1)(a)
Demonstrating that consent to marketing email was given and, where applicable, withdrawnConsent recordsCompliance with a legal obligation, Art. 6(1)(c), read with Art. 7(1)
Preventing, detecting, and investigating fraud, unauthorized access, and abuse of the ServicesTechnical data, payment data, course access dataLegitimate interests, Art. 6(1)(f)
Maintaining the security, availability, and integrity of the SiteTechnical dataLegitimate interests, Art. 6(1)(f)
Establishing, exercising, or defending legal claimsAll categories, as relevantLegitimate interests, Art. 6(1)(f)

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your interests or fundamental rights and freedoms. You have the right to object to such processing as described in Section 12.

Marketing email is never sent to anyone who has not been shown the choice. Consent is requested through a checkbox that is separate from, and never bundled with, acceptance of our Terms of Service, and it can be changed at any time in your account settings, under Email Preferences. Creating an account does not by itself subscribe you to anything.

How that checkbox is presented depends on where you are when you create your account. If you are in the European Economic Area or the United Kingdom, or in any other country whose law requires consent before commercial email may be sent, the box is empty and you are subscribed only if you tick it yourself. Where local law permits commercial email to be sent without prior consent, the box is presented already ticked and you may untick it before your account is created; at present we apply this only to the United States, under the CAN-SPAM Act of 2003. In either case the choice is visible on the form, it is never hidden or pre-selected for anyone whose law requires consent first, and unticking it is a single click.

Which of the two applies is determined from the country associated with your IP address at the moment of sign-up. Where that country cannot be determined, or is one we do not recognise, we ask for consent. We record which basis applied to you, together with the country used to reach that conclusion, so that we can demonstrate afterwards on what footing we were entitled to write to you.

Withdrawing consent stops marketing email only. Messages about your purchase, your access to the Services, and your account are sent on the basis of our contract with you rather than your consent, and are not something you can be unsubscribed from for as long as that contract is in force. Marketing and service email are sent from separate subdomains so that the two remain distinguishable.

We do not carry out behavioral advertising, we do not build marketing profiles, and we do not share your address with anyone for their own marketing.

6. Cookies and similar technologies

We use only those cookies and similar technologies that are strictly necessary for the operation of the Site and the delivery of the Services. Strictly necessary cookies do not require consent under Article 5(3) of Directive 2002/58/EC or under the Privacy and Electronic Communications Regulations 2003.

Cookie or technologySet byPurposeDuration
Session and authentication cookiesClerkMaintain your signed-in state and protect against session hijackingSession and up to 7 days
Fraud prevention and payment cookiesStripeDetect fraudulent payment activity and enable secure checkoutUp to 1 year
Infrastructure cookiesVercel, CloudflareLoad balancing, routing, and protection against automated abuseSession to 1 year

We do not currently operate analytics cookies, advertising cookies, retargeting pixels, or session recording technologies on the Site. If we introduce any of these, we will present a consent banner allowing you to accept or reject non-essential categories before any such technology is activated, and we will amend this Policy accordingly.

Most browsers allow you to block or delete cookies through their settings. Blocking strictly necessary cookies will prevent you from signing in and accessing the Services.

7. Automated decision-making and profiling

Stripe applies automated risk scoring to payment transactions in order to detect and prevent fraud. This assessment may result in a transaction being declined. This processing is carried out for the purposes of fraud prevention and is necessary for the performance of the contract between you and us, and for compliance with the legal obligations to which Stripe is subject.

If a transaction of yours is declined by these means, you may contact us at hello@influglow.com to request human review of the decision, to express your point of view, and to contest the outcome.

We do not carry out any other automated decision-making that produces legal effects concerning you or that similarly significantly affects you, and we do not engage in profiling for marketing or behavioral advertising purposes.

8. Recipients of personal data

We disclose personal data to the following categories of recipients, each of which acts as our processor under a written data processing agreement, except where indicated otherwise.

RecipientRoleData disclosedPrimary processing location
Clerk, Inc.Authentication and account managementAccount data, sign-in provider data, course access data, technical dataUnited States
Stripe, Inc. and Stripe Payments Europe, LimitedPayment processing, invoicing, tax determination, fraud prevention (also acts as an independent controller for certain purposes)Payment and billing data, email address, technical dataUnited States, Ireland
Vercel, Inc.Website and application hostingTechnical dataUnited States and European Union regions
Cloudflare, Inc.Storage and delivery of course audio filesTechnical dataGlobal content delivery network
Google LLC (Gmail)Transmission and hosting of email correspondenceCorrespondence, email addressUnited States
Resend, Inc.Delivery of marketing email and management of subscription preferencesEmail address, first name, marketing preferences, delivery and engagement dataEuropean Union (Ireland)
Google LLC, Meta Platforms, Inc., TikTok Technology LimitedThird-party sign-in, where you elect to use itAuthentication identifiersVaries by provider
Our accountant and, where required, tax authoritiesAccounting and tax complianceBilling and transaction dataPoland
Legal advisers, auditors, and competent authoritiesLegal compliance and defense of claimsAs required in the specific casePoland, European Union

We do not sell personal data, and we do not disclose personal data to third parties for their own independent marketing purposes.

In the event that our business, or any part of it, is transferred, merged, or acquired, personal data may be transferred to the acquiring party. We will notify you of any such transfer and of any resulting change to this Policy.

9. International transfers

Several of our service providers are established in the United States, or process data on infrastructure located outside the European Economic Area and the United Kingdom. Where personal data is transferred outside the EEA or the UK, we rely on one or more of the following safeguards:

  • the adequacy decision adopted by the European Commission in respect of the EU-US Data Privacy Framework, and the UK Extension to that framework, where the recipient is certified under it;
  • Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) of the GDPR, together with the UK International Data Transfer Addendum where the transfer is subject to the UK GDPR;
  • supplementary technical and organizational measures where our transfer risk assessment identifies them as necessary.

You may request further information about the safeguards applied to a specific transfer, and a copy of the relevant documentation, by writing to hello@influglow.com.

10. Retention periods

We retain personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by law.

CategoryRetention period
Account data and course access dataFor as long as your account remains open. If you request deletion of your account, we delete it as described in Section 12.
Accounting records, including invoices and receipts5 years from the end of the calendar year in which the tax payment deadline fell, as required by Polish tax and accounting law
Records maintained for value added tax purposes in respect of supplies to customers in the European Union10 years from the end of the year in which the transaction was carried out, as required by Council Implementing Regulation (EU) No 282/2011
Payment records held by StripeIn accordance with Stripe's own retention schedule and its legal obligations as a regulated payment institution
Server and access logsRetains logs for 1 day
Email correspondence24 months from the close of the matter, or longer where required for the defense of legal claims
Marketing contact data held by our email providerUntil you withdraw consent, after which your address is removed from the sending list without undue delay
Consent records evidencing that consent was given or withdrawn3 years from withdrawal, or from the closure of your account, as evidence that the processing was lawful
Data retained for the establishment, exercise, or defense of legal claimsUntil expiry of the applicable limitation period

Where we are required to retain certain records by law, the deletion of your account will not remove those records. In such cases we restrict processing of the retained data to the purpose that requires its retention.

11. Security

We implement technical and organizational measures appropriate to the risk, including:

  • encryption of data in transit using TLS across the Site and all connections to our service providers;
  • storage of passwords in hashed and salted form by our authentication provider, with no access to plain text passwords by us;
  • storage of course audio files in a private bucket that is not publicly accessible, with delivery only through short-lived signed links issued to authenticated users;
  • role-based access control and multi-factor authentication on the administrative accounts we hold with our service providers;
  • selection of service providers that maintain recognized security certifications and contractual security commitments.

No method of transmission or storage is entirely secure. While we take the protection of your personal data seriously, we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 of the GDPR.

12. Your rights

Subject to the conditions and exceptions set out in the GDPR and the UK GDPR, you have the following rights:

  • Right of access (Article 15). To obtain confirmation as to whether we process personal data concerning you, and to receive a copy of that data together with the information set out in this Policy.
  • Right to rectification (Article 16). To have inaccurate personal data corrected and incomplete data completed. You may correct most account information directly within your account settings.
  • Right to erasure (Article 17). To obtain the deletion of your personal data where one of the grounds in Article 17(1) applies. This right does not extend to data we are required by law to retain.
  • Right to restriction of processing (Article 18). To require that we limit our processing of your personal data in the circumstances specified in that Article.
  • Right to data portability (Article 20). To receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to have that data transmitted to another controller where technically feasible.
  • Right to object (Article 21). To object at any time, on grounds relating to your particular situation, to processing carried out on the basis of our legitimate interests.
  • Right to withdraw consent (Article 7(3)). Where processing is based on consent, to withdraw that consent at any time, and to do so as easily as it was given. For marketing email you can do this yourself at any moment, either through the unsubscribe link carried in every such message or under Email Preferences in your account settings; no request to us is needed. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint. As set out in Section 15 below.

How to exercise your rights. Send your request to hello@influglow.com from the email address associated with your account. We may ask you for additional information in order to verify your identity where we have reasonable doubts as to who is making the request. We respond within one month of receipt. That period may be extended by up to two further months where the request is complex or where we have received a number of requests, in which case we will inform you of the extension and the reasons for it within the first month. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.

Account deletion. To delete your account, send a request to hello@influglow.com from the email address associated with the account. Upon verification, we delete your account and the associated account data from our authentication provider. Please note that deletion of your account terminates your access to the Services, including any remaining period of paid access, and does not entitle you to a refund except as provided in our Terms of Service or as required by applicable consumer law. Accounting and tax records relating to your purchase are retained as set out in Section 10.

13. Age requirement

The Services are intended solely for individuals aged 18 or over. We do not knowingly collect personal data from anyone under the age of 18. By creating an account, you represent that you are at least 18 years old.

If you believe that a person under the age of 18 has provided us with personal data, please contact us at hello@influglow.com. We will delete the account and the associated data promptly upon verification.

14. Additional disclosures for California residents

The following section applies to residents of the State of California, to the extent that the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), applies to our processing. Terms used in this section have the meanings given to them in the CCPA.

Categories of personal information collected. In the preceding twelve months we have collected the following categories of personal information, as described in detail in Section 4: identifiers, including name, email address, account identifier, and IP address; commercial information, including records of products purchased and transaction history; internet or other electronic network activity information, including server log data; and geolocation data, limited to approximate location inferred from IP address and to billing country.

Sources. We collect personal information directly from you, automatically from your device when you use the Site, and from our service providers, namely our authentication provider, our payment processor, and any third-party sign-in provider you elect to use.

Business purposes. We use personal information for the purposes set out in Section 5.

Sensitive personal information. We do not collect or process sensitive personal information as defined by the CCPA.

Sale and sharing. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding twelve months, including the personal information of any consumer under 16 years of age.

Your rights. Subject to the CCPA, you have the right to know what personal information we have collected about you and how we have used and disclosed it; the right to request deletion of your personal information; the right to request correction of inaccurate personal information; the right to opt out of the sale or sharing of personal information, which we do not carry out; and the right not to receive discriminatory treatment for exercising any of these rights. We do not offer financial incentives in exchange for personal information.

Submitting a request. Send your request to hello@influglow.com. We verify requests by matching the email address used to submit the request against the email address held on your account, and we may request further information where necessary. An authorized agent may submit a request on your behalf on provision of written authorization signed by you, and we may require you to verify your identity directly.

Opt-out preference signals. Because we do not sell or share personal information, we do not process opt-out preference signals such as Global Privacy Control. We do not respond to browser "Do Not Track" signals, as no common standard for their interpretation has been established.

15. Complaints

If you have a concern about how we handle your personal data, we ask that you contact us first at hello@influglow.com so that we may address it directly.

You also have the right to lodge a complaint with a supervisory authority.

Poland, and our lead supervisory authority for the purposes of the GDPR: President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) ul. Stawki 2, 00-193 Warsaw, Poland https://uodo.gov.pl

European Economic Area: You may lodge a complaint with the supervisory authority of the Member State of your habitual residence, your place of work, or the place of the alleged infringement.

United Kingdom: Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom https://ico.org.uk

16. Changes to this Policy

We may amend this Policy from time to time in order to reflect changes to our Services, to the technologies we use, or to applicable law. The date at the top of this document indicates when it was last revised.

Where a change is material, we will notify registered users by email or by a prominent notice on the Site before the change takes effect. Your continued use of the Services after the effective date of a revised Policy constitutes acceptance of that revision, except where your consent is required by law, in which case we will obtain it separately.

17. Contact

Questions, requests, and complaints relating to this Policy should be addressed to:

mDev Mikołaj Sobieszczański Pl. Solny 14 lok. 3 50-062 Wrocław Poland hello@influglow.com