Privacy policy
What we collect, and what we do not.
1. Your typed answers stay on your device
Three things on this site take answers from you: the free four-question check at /start, the free Ledger at /ledger, and the on-screen Audit after purchase. What you type or tap in them is saved in your own browser (local storage) so you can come back and finish. It is not sent to Life Expansion. It does not pass through the site's server. We cannot read it. The saved result image at /start is drawn inside your browser. Start over, or clearing your browser data, deletes these answers.
2. Speak (microphone)
The Speak button on the free check uses the speech-to-text feature built into your browser or device. When you use it, your browser or device provider (for example Apple or Google) may process the audio under its own privacy terms. Life Expansion does not receive the recording and does not store it. The text that comes back is treated exactly like a typed answer: it is kept in your browser only, as in section 1. Typing works without Speak.
3. What we receive when you buy
Checkout uses Stripe Managed Payments. Link (a Stripe company) is the merchant of record and handles payment, receipts, applicable taxes, transaction support, and certain refunds. 3FOLD LLC supplies and supports the products. We never see your card number.
After payment, Stripe sends you to the download page for the product you bought. That page's address contains your Stripe Checkout Session ID. To open it, our server asks Stripe to confirm that session and receives: the purchase email, the payment status, the refund status, the amount, and the product bought. When you use the recovery form, it also receives the last four digits of the card so it can match your purchase. We use this only to open your downloads, to check on each open that the purchase is still paid and not refunded, and to find your purchase again. The application does not persist purchase information in its own database and does not intentionally include buyer information in application log messages. Stripe, Link, and Vercel process the information required to complete and secure these requests.
The recovery form at /recover sends the email and last four digits you enter to our server, which passes them to Stripe to look up the purchase. To slow guessing, the server keeps a hashed, in-memory count of attempts per network address and per email for at most one hour. Nothing else is kept.
4. Cookies and browser storage
The site uses exactly these four items. The first three are browser storage, not cookies.
- le.free.v2 (local storage): your free-check answers. Kept until you tap Start over or clear browser data.
- le.ledger.v1 (local storage): your free Ledger answers. Same retention.
- le.audit.v1 (local storage): your on-screen Audit answers, your progress, and the Stripe Checkout Session ID of the purchase they belong to. Same retention.
- le_audit (cookie): a signed purchase-access reference, set only after a verified purchase. HTTP-only, SameSite=Lax, Secure on HTTPS, expires after one year. It holds the Checkout Session ID, an expiry time, and a signature, nothing else.
The three local-storage items remain on your device and are not transmitted through the site's server. The cookie is sent to our server with each request so the on-screen Audit can open; it is strictly necessary for the product you bought, so there is no cookie banner. There are no advertising or tracking cookies and no third-party cookies.
5. Limited usage events
To learn where people stop, the site records a small set of events. Each browser event is a request to our own address /api/event whose payload contains only an allowlisted event name. It contains no answers, no email, no account ID, and no checkout-session ID. Server-side events (a completed purchase, an access open, a download) are written the same way, as an event name and a time. The full list of names: landing_view, ledger_view, ledger_read, audit_checkout_click, audit_purchase_complete, audit_access_opened, audit_download_phone, audit_download_print, course_correction_checkout_click, course_correction_purchase_complete, course_correction_download_phone, course_correction_download_print, fear_checkout_click, fear_purchase_complete, fear_download_phone, fear_download_print, audit_started, q1_completed, q2_completed, q3_completed, q4_completed, result_viewed, result_saved.
These events become lines in the hosting provider's runtime logs. Vercel, the hosting provider, necessarily processes technical request information for every request, such as IP address, user agent, route, timestamp, and request ID, and request logs may include page addresses, which for the download page include the Checkout Session ID. Runtime logs are retained according to the Vercel plan, no longer than 30 days. There is no external log drain. No advertising analytics and no cross-site tracking is installed on this site.
6. Who else handles data
Stripe and Link (checkout, receipts, taxes, transaction support, refunds; see the Stripe privacy policy and the Link privacy notice). Vercel (hosting and request logs, in the United States; see the Vercel privacy policy). Your browser or device provider, only if you use Speak (section 2). Fonts are bundled into the site at build time, so no request goes to Google when you visit. We do not sell personal data and we do not share it for advertising.
7. How long
Purchase records live in Stripe for as long as tax and accounting law requires. Our access cookie expires after one year. Runtime logs, including event lines, are kept by Vercel for no longer than 30 days. Recovery-attempt counters last at most one hour in memory. Your answers are kept only by you, for as long as you keep them.
8. Your rights under the GDPR, the UK GDPR, and similar laws
Purposes and legal bases. Delivering what you bought and letting you open it again: performance of a contract with you. Keeping transaction records: our legal obligation under tax and accounting law. Security, fraud prevention, rate limiting, and the limited usage events in section 5: our legitimate interests in running a secure site and knowing where visitors stop, which do not override your rights because no answers or identifiers are used. We do not rely on consent for any of this, and we do not ask for it.
Categories. From buyers: purchase email, payment and refund status, amount, product, last four card digits when you use recovery, Checkout Session ID. From all visitors: the technical request data and event names in section 5. We do not receive your answers.
Recipients and transfers. Stripe, Link, and Vercel, as processors or independent controllers for their own services, in the United States. Stripe and Vercel rely on the EU-US Data Privacy Framework and standard contractual clauses for transfers from the EEA, the UK, and Switzerland.
Retention criteria. Section 7. In short: as long as the law requires for transaction records, one year for the access cookie, up to 30 days for logs, and only as long as you choose for your answers.
Your rights. Access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. Email kentshi7991@gmail.com from your purchase address and we act within one month. Because purchase records sit in Stripe, some requests are fulfilled there, and records we are legally required to keep are kept. You have the right to complain to your data protection authority, for example the authority in the EEA country where you live or, in the UK, the Information Commissioner's Office.
9. California
Where the CCPA and CPRA apply, California residents have the right to know what personal information we collect and how we use it, to delete it, to correct it, and not to be discriminated against for using these rights. Deletion is subject to legal exceptions, such as records we must keep for tax and accounting law or to complete the transaction you asked for. In the last 12 months we collected these categories from buyers: identifiers (email, Checkout Session ID), commercial information (the purchase), and internet activity (technical request data and event names). We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no opt-out to offer. Email kentshi7991@gmail.com. An authorized agent may act for you with written permission. We verify requests by matching the purchase email.
Do Not Track and cross-site tracking. Life Expansion does not track users across third-party websites, and no third party conducts cross-site behavioral tracking through this site. Because the site never engages in that tracking, a Do Not Track or Global Privacy Control signal does not change how the site behaves; there is nothing to switch off.
10. Children
The product is for adults. We do not knowingly collect personal data from anyone under 16.
11. Changes
We may update this policy. The date at the top changes when we do.
Written by the seller in plain language and checked against the site's code on the date above. Not yet reviewed by a lawyer.