Legal
Privacy Policy
Last updated: April 16, 2026
This Privacy Policy describes how Sublimino (“we,” “us,” or “our”) collects, uses, and shares information about you when you use the Sublimino website and services (the “Service”). We aim to be clear and plain-spoken about our practices. If anything here is unclear, please email [email protected].
1.Information We Collect
We collect the following categories of information:
- Account information. Your email address, name (optional), password hash, profile photo (optional), and account preferences.
- Generation prompts. The goals, descriptions, voice preferences, and other input you submit when requesting a custom hypnosis session.
- Generated content. The scripts and audio sessions we produce for you, linked to your account.
- Usage data. Pages visited, sessions played, device type, browser type, and general interaction patterns, logged to help us understand and improve the Service.
- Billing information. Payment card data is collected and processed directly by Stripe; we receive transaction metadata (amount, status, last four digits) but never see your full card number.
- Device and log data. IP address, approximate location derived from IP, browser user agent, and timestamps, logged for security and diagnostic purposes.
- Communications. Messages you send via our contact form or support channels.
2.How We Use Your Information
We use your information to:
- Provide, maintain, and operate the Service, including generating custom sessions based on your prompts.
- Personalize your experience, such as remembering your preferred voice, library organization, and playback history.
- Process payments and manage subscriptions.
- Send transactional emails (receipts, password resets, session-ready notifications) and service updates.
- Send product announcements and marketing messages, which you can unsubscribe from at any time.
- Analyze usage to improve the Service, diagnose issues, and develop new features.
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms.
- Comply with legal obligations and enforce our rights.
We do not use your prompts or generated content to train third-party general-purpose AI models. Prompts submitted to language model providers (such as Anthropic) are subject to those providers' data-use commitments, which currently exclude use for model training when submitted via their API.
3.How We Share Your Information
We do not sell your personal information. We share information only with the following categories of service providers (“sub-processors”), and only as needed to operate the Service:
- Supabase — authentication, database, and audio file storage.
- Stripe — subscription management and payment processing.
- Anthropic — language model inference for script generation.
- ElevenLabs — voice synthesis for session audio.
- Resend — transactional and marketing email delivery.
- PostHog — product analytics and event tracking.
- Vercel — web application hosting.
- Railway — audio processing infrastructure.
Each sub-processor is bound by a data processing agreement and processes your information only as instructed by us. We may also disclose information in response to valid legal process, to protect our rights and the safety of users, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you of any change in data handling).
4.Data Retention
We retain account and generation data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within thirty (30) days, except where we are required to retain certain records for legal, tax, or security purposes (for example, billing records are retained for up to seven years as required by law).
Server logs and analytics data are typically retained for up to twenty-four (24) months in identifiable form and are aggregated or anonymized thereafter.
5.Security
We take reasonable steps to protect your information, including TLS encryption in transit, encryption at rest for sensitive fields, access controls limited to authorized personnel, and regular security reviews of our code and infrastructure. We also rely on the security practices of our sub-processors, which include SOC 2 compliance for Supabase, Stripe, and Vercel.
No system is perfectly secure. If we learn of a security incident affecting your information, we will notify you and applicable authorities as required by law.
6.Your Rights and Choices
You have rights over your personal information. Depending on your jurisdiction these may include the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Export a machine-readable copy of your data (data portability).
- Object to or restrict certain processing.
- Withdraw consent for marketing communications at any time by clicking “unsubscribe” or by emailing us.
To exercise any of these rights, visit your account settings or email [email protected]. We will respond within thirty (30) days. You also have the right to lodge a complaint with your local data protection authority.
7.Cookies and Similar Technologies
We use strictly necessary cookies to keep you signed in and remember your preferences, and analytics cookies (via PostHog) to understand how the Service is used. You can control cookies through your browser settings; blocking strictly necessary cookies may impair your ability to use the Service. We do not use third-party advertising cookies or cross-site tracking.
8.Children
Sublimino is intended for adults. You must be at least 18 years old to create an account. We do not knowingly collect information from children under the age of 13, and we do not provide the Service to individuals under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.
9.International Users
Sublimino is operated from the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, processed, and stored in the United States and other countries where our sub-processors operate. Where required, we rely on standard contractual clauses or equivalent safeguards to protect cross-border transfers.
EEA/UK residents (GDPR). Our legal bases for processing include contract performance (providing the Service), legitimate interests (improving the Service, preventing fraud), consent (marketing where required), and compliance with legal obligations. You have the rights described above and may contact our data protection lead at the email below.
California residents (CCPA/CPRA). We do not sell or share personal information for cross-context behavioral advertising. You have the right to know, delete, correct, and limit the use of sensitive personal information. We do not discriminate against users who exercise their privacy rights.
10.Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or via a notice in the Service, and we will update the “Last updated” date above. We encourage you to review this page periodically.
11.Contact
For any privacy questions, requests, or concerns, email [email protected] or reach out via our contact page. We take privacy seriously and will do our best to help.