SHIP YOUR FIRST APP KIT

Your privacy

Ship Your First App Kit · Last updated 18 September 2026

A little about this notice

Your companion is a place to keep your next steps, notes and little wins together. This notice explains how TheCozyDev handles your information when you buy the kit, sign in to the companion or ask for help. Other TheCozyDev apps have their own policies.

What we collect

Your account: your email address, account identifier, any display name held in your profile, and records needed to verify your email and manage sign-in sessions. You sign in with an email code, rather than a password you create for the companion.

Your saved work: the notes you write, task and checkbox progress, and when that work was updated. Please leave passwords, payment details and private information about other people out of your notes.

Your purchase: Stripe provides your checkout email, payment and checkout references, the product purchased and payment status so we can unlock the right account. We also keep your checkout consent, the terms version, purchase details and a copy of your confirmation email so we can record what you agreed to and help with order questions. We can also view order and billing information in Stripe to handle payments, records and support. Card details are entered into Stripe; the companion does not store your full card number or security code.

Your messages: if you contact us, we receive your email address, message and anything you choose to attach.

Technical records: our hosting, account, payment and email providers process information such as IP addresses, browser or device details, request times, sign-in events, errors and email delivery records to deliver and protect their services.

Why we use it

We use your account, purchase and saved work to provide the kit and companion you bought, restore your place and answer service questions. Our legal basis is carrying out our contract with you, or taking steps you request before a purchase.

We use relevant technical and account records to prevent abuse, investigate faults and keep the service secure. Our legal basis is our legitimate interest in running a safe, reliable service. We use support correspondence to resolve your request; general enquiries and necessary follow-up rely on our legitimate interest in helping people who contact us.

We keep information needed for accounting, tax and other legal duties because we have a legal obligation to do so. Where necessary, we may retain relevant records to establish or defend a legal claim, relying on our legitimate interest in protecting our business and customers.

An email address and a matching purchase are needed for paid companion access. Notes are optional. Buying the kit or requesting a sign-in code does not sign you up to a marketing list. We do not sell your personal information.

Who helps us run things

Supabase provides accounts, the database and private file storage. It holds account information, notes, progress and the purchase record used for access. Cloudflare hosts and delivers the companion. Resend sends sign-in and purchase-confirmation emails and processes recipient addresses, message content, attachments and delivery information.

Stripe handles checkout and payments and has its own responsibilities for uses such as payment security and legal compliance. Framer hosts the shop and these policy pages, including the companion demonstration video. Proton provides our support inbox.

The person running TheCozyDev can access information when needed for support, maintenance, security and legal duties. Other members cannot read your notes or progress through their accounts. We may also share necessary information with professional advisers or authorities when legally required or needed to deal with a claim.

Provider information: Supabase; Cloudflare; Resend; Stripe; Framer; Proton.

Where your information is handled

The companion database is hosted in Supabase’s London region. This does not mean every part of the service stays in the UK: our providers and their service partners may handle information in other countries, including the United States and countries in Europe.

Where information is transferred outside the UK, the relevant protection may be UK adequacy regulations or contractual safeguards for that transfer. The data-processing agreements for Supabase, Resend and Cloudflare include standard contractual clauses and the UK Addendum where applicable. Email thecozydev@proton.me for information or a copy of the safeguards relevant to your data. Stripe, Framer and Proton explain their international handling in their privacy information linked above.

How long we keep it

We keep your account, notes and progress while we provide your account so you can return to your saved work. You can remove or change your notes in the companion, or email us to request account closure and deletion. Closing an account is different from cancelling a purchase or requesting a refund.

We keep the minimum purchase record needed to recognise your entitlement while access continues, including the consent and confirmation record for your order. Some transaction records must be kept after account closure for applicable accounting and tax obligations, or while a payment dispute or legal claim is being resolved. We keep support correspondence while handling the request and any related complaint or claim, then delete information that is no longer needed.

For account-closure requests, we check your identity and remove your account and saved work unless there is a lawful reason to retain particular information, which we will explain. Retained purchase records are kept separately from notes and progress; closing your account does not automatically erase records that we must keep. Operational logs and email delivery records follow our providers’ service and security retention arrangements. Resend currently provides 30-day email data retention on our plan; providers may separately retain information for fraud prevention or legal duties. Deletion from the live account may not immediately remove restricted backup or security records; these remain subject to the relevant provider’s retention and deletion arrangements. We do not keep extra copies indefinitely simply because storage is available.

Storage on your device

The companion uses browser storage to keep your sign-in session available between visits. This is needed for account access; signing out removes the local session. You can also clear site data in your browser. Doing so signs you out but does not delete your account or saved work on the server. We use this storage to provide account access, not to follow you around other websites. The shop, Stripe checkout and linked services are separate websites and may use their own cookies or similar technology, as explained by those services. Continuing to browse does not give consent to optional tracking.

Your choices and rights

If this notice changes: we will update this page when our handling of information changes and show the revised date here. Where a change materially affects your information, we will bring it to your attention in the companion or by email as appropriate.

TheCozyDev ☕

Independent iOS development, one cozy commit at a time.

© 2026 TheCozyDev