We take privacy seriously. This policy explains what personal data we collect when you use mywellnessliving.com, why we collect it, how we keep it safe, and the rights you have over it under UK GDPR and the Data Protection Act 2018.
1. Who we are
My Wellness & Living Ltd (“we”, “us”, “our”) operates mywellnessliving.com. We are the data controller for the personal data described in this policy. If you have any questions, you can reach us at [email protected].
2. What personal data we collect
Depending on how you use the site, we collect:
- Quiz answers — age range, sex, goals, current symptoms, neurodivergent diagnoses or self-identification, dietary information, body metrics (height, weight, activity level), pregnancy/nursing status, medications and allergies. Some of this is “special category” health data and we only process it with your explicit consent (see Section 4).
- Account data — your email address, and a display name if you provide one.
- Order data — items ordered, delivery address, billing address and order history. Payment-card details are processed by Stripe and never touch our servers.
- Recommendation history — the supplement stacks and meal/movement plans we generate for you, so you can return to them in your account.
- Technical data — your IP address, browser type, device type, and pages visited. Used for security, fraud prevention and basic site analytics.
- Communications — emails you send us, customer-service interactions, marketing-list subscriptions.
3. Why we collect it (and on what legal basis)
- To generate your personalised recommendation — this is processing necessary to perform the contract you enter into when you submit the quiz. For the health data elements, we rely on your explicit consent given when you submit the quiz.
- To deliver and support your orders — necessary to perform our contract with you.
- To keep your account secure and prevent fraud — our legitimate interest in protecting our service and our customers.
- To send transactional emails (order confirmations, magic-link sign-in, delivery updates) — necessary for the contract.
- To send marketing emails or post-purchase wellbeing tips — only if you have opted in, and you can withdraw consent at any time via the unsubscribe link.
- To meet our legal obligations — tax records, consumer-protection records, etc.
4. Health data — special category processing
The quiz asks about your physical and mental health, including neurodivergent diagnoses, medications, pregnancy/nursing status and history with disordered eating. Under UK GDPR this is “special category” data and requires a stricter legal basis. We process it on the basis of your explicit consent, given by ticking the submit box on the quiz. You may withdraw consent at any time by emailing us — see Section 9 on your rights, including the right to erasure.
We never share your health data with advertisers and we never use it for any purpose other than generating your recommendation and keeping it accessible in your account.
5. Who we share it with
We use a small set of trusted processors. Each is contractually bound by UK GDPR-compliant data-processing agreements:
- Supabase — hosts our database and authentication. Servers are located in the EU. Stores your account, quiz answers and recommendations.
- Anthropic — provides the Claude AI model that generates your supplement, meal and movement recommendations. Your quiz answers are sent to Anthropic at the moment of generation and are not used for AI model training (under Anthropic's commercial data terms).
- Stripe — processes card payments for orders. Stripe is PCI-DSS Level 1 certified.
- Resend — sends our transactional emails (magic-link sign-in, order confirmations, plan delivery notifications).
- Cloudflare — provides our DDoS protection and content delivery network.
- HMRC, regulators and law enforcement — where we are legally required.
We do not sell your data. We do not share it with advertisers or data brokers. We do not run third-party advertising cookies or tracking pixels.
6. International transfers
Most processing happens in the UK or EU. Where data is transferred outside the UK/EU (for example, to Anthropic or Stripe in the United States), we rely on the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or equivalent adequacy decisions, to keep your data protected to UK-equivalent standards.
7. How long we keep it
- Anonymous quiz submissions (taken without signing up) — kept for 30 days, then deleted.
- Account data and saved recommendations — kept for as long as your account is active, plus 6 years after closure for financial-record obligations.
- Order records — kept for 6 years (UK tax / consumer-protection requirements).
- Marketing preferences — kept indefinitely (so we honour your opt-out), unless you ask us to delete the record.
- Site logs and security data — kept for 90 days.
8. Cookies
We use a small number of cookies. All are essential to the site working — we don't run advertising or third-party tracking cookies.
sb-* — Supabase session cookies that keep you signed in.mwl_claim_token — temporary cookie that links an anonymous quiz to your account if you sign up after taking the quiz. Deleted automatically after sign-in or after 90 days.cf_* — Cloudflare security cookies for bot detection and DDoS protection.
9. Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data (subject to limited legal exceptions such as tax records).
- Restrict or object to certain processing.
- Port your data to another service in a structured, machine-readable format.
- Withdraw consent for any processing based on consent, including the health-data processing for your quiz.
- Complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy with how we have handled your data.
To exercise any of these rights, email [email protected]. We will respond within one month.
10. Security
Your data is encrypted in transit (TLS) and at rest. Access is limited to staff who need it for the purposes set out above and is governed by row-level security policies at the database layer. Payment card details never reach our infrastructure — they are tokenised by Stripe.
We do our best, but no online service is 100% secure. If we ever detect a personal data breach that risks your rights and freedoms, we will notify the ICO within 72 hours and inform affected users without undue delay.
11. Children
Our service is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have collected data from a minor, please contact us and we will delete it.
12. Changes to this policy
We will post any material changes to this policy on this page and update the “last updated” date. For significant changes affecting how we use your data, we will notify you by email before they take effect.
Questions? Email us at [email protected].