Acceptance of this policy
This Privacy policy (“Policy”) explains how JoyMatrixe (“we”, “us”, “our”) collects, uses, stores, and shares information about you when you visit joymatrixe.com or any sub-domain we publish (the “Service”).
By using the Service, you confirm that you have read and understood this Policy and our Terms of service. If you do not agree with any part of this Policy, please do not use the Service.
What this policy covers
This Policy applies to information we collect:
- When you visit joymatrixe.com or any page we host.
- When you write to us through the contact form, by email, or by post.
- When you interact with our AI guide.
- Through the limited cookies and analytics described in section 06.
It does not apply to third-party websites we link to. Those sites have their own policies, which we encourage you to read.
Our three privacy principles
Everything we do is shaped by three quiet commitments:
- Collect as little as possible. If we do not need a piece of information to serve you, we do not ask for it.
- Keep it close. Where possible, processing happens in your browser, on your device, not on our servers.
- Make it easy to leave. You can ask us to delete what we hold at any time, and we will do so without argument.
Information we collect
We collect a deliberately small amount of information, in the following categories:
1. Information you give us directly. This is the only category we control end to end.
- Your name, if you choose to include one in a contact form or email.
- Your email address, when you write to us.
- The contents of any message, letter, or note you send us.
2. Information collected automatically when you visit the site.
- Technical identifiers such as your IP address (truncated), browser type and version, operating system, referrer, and approximate country (derived from the IP).
- Usage information such as which pages you visited, in what order, and for roughly how long.
- Event information such as the time of the request and any error messages returned.
3. Information you choose to enter into our tools.
- Reflections, journal entries, breath counts, gratitude notes, and any other text you type into a practice. These stay in your browser and are not transmitted to us.
- If you use the AI guide, the prompts and replies are sent to our language-model provider so that a response can be generated. We have configured this provider to not retain or train on your conversations.
What we do not collect. We do not collect your real name, postal address, phone number, date of birth, government identifier, payment information, biometric data, or precise location. We do not use third-party advertising identifiers, and we do not run third-party advertising trackers on the site.
How we use your information
We use the information we collect for the following specific purposes only:
- To reply to you when you write to us, and to keep a record of that conversation for a reasonable time.
- To operate the site: route requests to the nearest server, render pages, and protect against abuse.
- To understand which practices and essays are useful, through aggregated analytics. We use this to write more of what readers find helpful, and less of what they do not.
- To keep the site secure: detect spikes in traffic, block obvious abuse, and investigate incidents.
- To meet our legal obligations, such as keeping basic business records for tax purposes.
We will never use your information to:
- Build a profile of you for advertising.
- Sell or rent your information to any third party.
- Make automated decisions about you that have legal or similarly significant consequences.
Personalised advertising and opt-out
JoyMatrixe does not run personalised advertising, and we do not allow third-party advertising networks to set cookies or read identifiers on joymatrixe.com. We do not use the Google AdSense, Meta Pixel, TikTok Pixel, or any equivalent system.
On the rare occasion we link to a third-party resource (for example, a research paper hosted on a partner university site), that site may have its own advertising and tracking practices. You can use the following opt-out tools to manage personalised advertising across the wider web:
Lawful basis for processing (GDPR Art. 6)
Where the GDPR or UK GDPR applies, we rely on the following lawful bases under Article 6 of the regulation:
- Consent (Art. 6(1)(a)) — for non-essential cookies and any optional analytics.
- Contract (Art. 6(1)(b)) — where processing is needed to respond to a request you have sent.
- Legitimate interests (Art. 6(1)(f)) — for keeping the site secure, preventing abuse, and understanding aggregated usage. We balance these interests against your rights and freedoms and offer clear opt-outs where appropriate.
- Legal obligation (Art. 6(1)(c)) — where we are required to keep basic business records.
Where the LGPD applies (Brazil), we rely on the equivalent legal bases set out in Article 7 of Law No. 13.709/2018, including consent, the legitimate exercise of rights in legal proceedings, the protection of credit, and our legitimate interests in operating a safe service — always observing the principles of necessity, adequacy, and free access.
International data transfers
JoyMatrixe is run by a small team based mainly in the United Kingdom. Some of our service providers — for example, our language-model provider for the AI guide — may process data outside the European Economic Area, the United Kingdom, or Brazil.
Where a transfer takes place, we protect it by relying on one of the following safeguards:
- An adequacy decision from the European Commission, the UK Government, or Brazil’s ANPD.
- The Standard Contractual Clauses approved by the European Commission, with supplementary measures where required.
- The UK International Data Transfer Agreement or equivalent contractual instrument.
- Your explicit consent, where the transfer cannot be supported by another safeguard and the law allows this route.
Your rights under the GDPR (EEA / UK)
If you are in the European Economic Area, the United Kingdom, or a country with similar protections, you have the following rights under the GDPR and UK GDPR:
- Right to access the personal data we hold about you (Art. 15).
- Right to rectification of inaccurate or incomplete data (Art. 16).
- Right to erasure, also known as the “right to be forgotten” (Art. 17).
- Right to restrict processing in specific circumstances (Art. 18).
- Right to data portability in a structured, commonly used format (Art. 20).
- Right to object to processing based on legitimate interests or for direct marketing (Art. 21).
- Right not to be subject to a solely automated decision, including profiling (Art. 22).
- Right to lodge a complaint with your local data protection authority.
To exercise any of these rights, write to privacy@joymatrixe.com. We will respond within one month. You may also complain to your national supervisory authority: in the UK, the Information Commissioner’s Office (ico.org.uk), or in your country’s lead regulator.
Your rights under the LGPD (Brazil)
If you are in Brazil, you have the following rights under the Lei Geral de Proteção de Dados (Law No. 13.709/2018):
- Confirmation of the existence of processing (Art. 18, I).
- Access to your data (Art. 18, II).
- Correction of incomplete, inaccurate, or outdated data (Art. 18, III).
- Anonymisation, blocking, or deletion of unnecessary or excessive data (Art. 18, IV).
- Portability of your data to another service or product provider (Art. 18, V).
- Deletion of personal data processed with consent (Art. 18, VI).
- Information about public and private entities with whom your data has been shared (Art. 18, VII).
- Information about the possibility of refusing consent and the consequences of doing so (Art. 18, VIII).
- Revocation of consent at any time (Art. 18, IX).
- Complaint to the Autoridade Nacional de Proteção de Dados (ANPD) (Art. 18, X).
To exercise any of these rights, write to privacy@joymatrixe.com. You may also file a complaint directly with the ANPD through gov.br/anpd.
Your rights in other regions
If you are in California (United States), you may have additional rights under the California Consumer Privacy Act (CCPA / CPA), including the right to know what categories of personal information we collect, the right to delete, and the right to opt out of any sale or sharing. JoyMatrixe does not sell or share personal information, so the right to opt out has nothing to apply to — but we will still respond to verifiable requests within 45 days.
If you are in another region with local data-protection laws, please write to us. We will do our best to honour the spirit of your local law even where it is not formally applicable.
How long we keep your data
We keep data only as long as we have a clear reason to keep it:
- Messages you send us: kept for up to 24 months, then deleted unless we have a lawful reason to keep them longer.
- Server logs: kept for up to 30 days, in aggregated form for security and capacity planning.
- Aggregated analytics: kept indefinitely, but stripped of any identifier that could be traced back to you.
- Anything you typed into a tool: not stored at all by us; it remains on your device until you clear it.
How we protect your data
We use a layered set of safeguards to protect information:
- Transport encryption. All traffic to and from joymatrixe.com is encrypted with TLS 1.3.
- At-rest encryption. Our databases are encrypted on disk.
- Access control. Only the small JoyMatrixe team can read messages you send us, and only through password-protected accounts with two-factor authentication.
- Vendor vetting. We choose service providers that publish strong security practices and sign data-processing agreements with us.
- Incident response. If we ever have reason to believe your data has been compromised, we will notify you and the relevant supervisory authority within the timeframes required by the GDPR, UK GDPR, and LGPD.
Honest note. No system is perfectly secure. If you ever have a concern about how your data has been handled, please write to privacy@joymatrixe.com. We will treat it as the urgent matter it is for you.
Children and minors
The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and you believe your child has provided information to us, please write to privacy@joymatrixe.com and we will delete it promptly.
Between ages 13 and 16, the GDPR requires parental consent in some member states. If we know you are in that age range, we will ask for verifiable parental permission before enabling any optional data collection.
Third-party services we use
We choose service providers carefully. The current list is short and stays at this length on purpose:
- Hosting and content delivery. A small European provider that stores and serves our pages and audio.
- Email. A privacy-focused transactional email service for contact-form submissions.
- Language model provider. Used only for the AI guide. We have configured the provider not to retain or train on conversations, and to delete inputs after the request completes.
- Aggregated analytics. A self-hosted, IP-truncated analytics tool. No third-party analytics provider receives your data.
For more information about how Google collects and processes data when you visit partner sites, see policies.google.com/technologies/partner-sites.
Changes to this policy
We may revise this Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, where the change is meaningful, we will note it on our contact page and with a small banner at the top of the site for at least 30 days.
The current version of this Policy will always be available at joymatrixe.com/privacy, along with a short note describing what changed in each update. Continued use of the Service after a change means you accept the revised Policy.
How to reach our privacy team
JoyMatrixe is run by a small team. For any privacy question, request, or complaint, please write to us. A real person reads every message.
Postal correspondence is welcomed at: JoyMatrixe, Data Protection Lead, PO Box 6412, Edinburgh EH3 9AB, United Kingdom.
EU representative. For GDPR purposes, our UK-based team acts as our main establishment. You may also contact the Information Commissioner’s Office (UK), CNIL (France), BfDI (Germany), or your national supervisory authority.
Brazil representative. For LGPD purposes, complaints may be addressed to the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
Back to the contact page