Privacy Policy

Last updated: March 2026

1. Introduction

Got Me Well ("we", "us", "our") operates the website gotmewell.com and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Data Controller

Got Me Well is the data controller. Contact: hello@gotmewell.com

3. Data We Collect

  • Account Information: Name, email address, password (hashed).
  • Authentication Data: Google account info if using Google Sign-In.
  • Payment Information: Processed via Stripe. We do not store card details.
  • Usage Data: Feature usage counts, subscription tier, generation history.
  • Uploaded Content: Photos uploaded for personal branding.
  • Generated Content: AI-generated lessons, posts, images, cards.
  • Technical Data: IP address, browser type, device info, cookies.

4. Legal Basis for Processing (GDPR)

  • Consent: Account creation and marketing opt-in.
  • Contractual Necessity: To provide subscribed services.
  • Legitimate Interest: Platform improvement, fraud prevention, security.
  • Legal Obligation: Compliance with applicable laws.

5. How We Use Your Data

  • To provide, maintain, and improve our AI content generation services.
  • To process payments and manage subscriptions.
  • To personalize your experience and content recommendations.
  • To communicate about your account, updates, and support.
  • To detect and prevent fraud or unauthorized access.
  • To comply with legal obligations.

6. Third-Party Services

  • Stripe: Payment processing (PCI-DSS compliant).
  • Google: Authentication services (OAuth 2.0).
  • AI Providers: Text and image generation (prompts only, no personal data).
  • Cloud Storage: Secure storage of uploaded media.

All third-party processors comply with applicable data protection regulations.

7. Data Retention

We retain your data for as long as your account is active. Upon deletion, personal data is removed within 30 days, except where retention is required by law.

8. Your Rights

Under GDPR and applicable laws, you have the right to:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion ("right to be forgotten").
  • Restriction: Restrict processing of your data.
  • Portability: Receive data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw Consent: Withdraw consent at any time.

Contact hello@gotmewell.com to exercise your rights. We respond within 30 days.

9. Cookies

We use essential cookies for authentication and session management. We use localStorage to save your theme preference. We do not use third-party tracking or advertising cookies.

10. International Data Transfers

Your data may be processed outside the EEA. Where this occurs, we ensure appropriate safeguards including Standard Contractual Clauses (SCCs).

11. Security

We implement industry-standard measures: encryption in transit (TLS), hashed passwords (bcrypt), secure API authentication (JWT), and regular security reviews.

12. Children

Our services are not directed to individuals under 16. We do not knowingly collect data from children.

13. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated on our website. Continued use constitutes acceptance.

14. Contact

Questions? Contact us at hello@gotmewell.com