Skip to main content
Decision Lab
Guides ⌄
Start hereAll guidesReal journeysCase studies
IngredientsUI examplesPricing
Sign in

Product

01Decision Lab02Guides03Case studies04Ingredients05UI examples06Pricing
Sign in →

Privacy,
plainly.

Last updated 29 August 2026. UXologist Ltd is responsible for the personal information described here. Questions and rights requests can be sent to team@theuxologist.com.

What we collect

We collect account details such as your email address and profile information, the content you save or create in private tools, subscription status, marketing preferences and basic technical records needed to keep the service secure and reliable.

While a signed-in member starts a new Decision Lab brief, unfinished answers can be stored only in that browser under a server-generated opaque scope for the authenticated Supabase account. The scope contains no email address, name or sign-in method. Linked sign-in identities for the same account share it; separate accounts receive different scopes. The draft content stays on the device until the member submits the brief, and neither the content nor scope is sent to analytics or application logs. On valid submission, a one-use random marker stays in that browser tab under the same opaque account scope so only the matching success response can remove the exact submitted draft revision. The random marker value contains no raw account or brief details and is not logged or sent to analytics.

If you choose Google account access, The UXologist sends you to Google with a one-use security state, nonce and PKCE challenge. In the normal branded route, Google returns a one-use authorization code directly to theuxologist.com. Our server exchanges it and verifies Google’s signed identity token, then sends that ID token and the temporary Google access token to Supabase solely so Supabase can verify the identity independently and create or access your account. If we deliberately activate the retained recovery route, Google instead returns the code through our Supabase project’s authentication host and Supabase performs that exchange before returning the account session to The UXologist.

Both routes request only the standard openid, email and profile identity scopes. We do not request access to Gmail, Drive, contacts or other Google services, and do not request offline access or a Google refresh token. We do not retain Google provider access credentials: the Google code, ID token and access token are discarded during the request. Google identity metadata such as your name and profile image is not copied into The UXologist profile fields and is not used for authorisation or marketing enrolment.

When a Google address matches an existing verified email account, Supabase may automatically link Google to that account. A different address creates a separate account. A Google-first account may still need Google for later access rather than being able to switch automatically to email. The linked Google identity and its basic metadata remain in Supabase Auth while the link or account remains.

When you request a secure sign-in link, our authentication provider sends the recipient address, sender, subject, message and coarse return destination to Resend for transactional delivery. Resend also records operational delivery, bounce, complaint and security metadata. The message does not include your profile, private work, a private object identifier, or the page’s query string or fragment.

If you make the separate, optional email-marketing choice after the secure link creates a new account or later in Account, it covers the weekly educational note plus occasional product and Practitioner information. We record an affirmative choice only after the secure link confirms your account. We may then use a small set of product-state signals: whether you have completed a first brief, the date of your latest meaningful action, your plan and an explicit upgrade action such as starting checkout. We do not send your private brief text, saved content or inferred behavioural traits to MailerLite.

Before paid Checkout, you provide a billing address to check whether paid access is available in your country and to give Stripe the location it needs for tax treatment. The application and our hosting provider, Vercel, transmit that address securely to Stripe; we do not store it in Supabase.

Stripe stores the billing email, name and address, payment-card details and any optional business tax ID provided during Checkout. The UXologist can access Stripe identifiers, subscription status and limited Stripe billing records rather than your full card details.

Why we use it

  • To create and secure your account through the Google or email route you choose, including sending a sign-in link when requested. This is necessary to take the steps you request before account creation and to perform our account contract with you. Limited delivery and security records also support our legitimate interest in operating a reliable, abuse-resistant service.
  • To provide saved libraries, Decision Lab work, paid features and customer support.
  • To process subscriptions, prevent fraud and keep billing records.
  • To send marketing only where you have chosen to receive it.
  • To understand aggregate product use and improve the service.
  • To meet legal, tax and accounting obligations.

Optional personalisation

After a new member’s first sign-in, we may offer an optional guided setup. Answers remain temporarily in that page’s memory while you move between questions. They are not stored in browser storage, cookies, URLs, analytics or our database unless you review the answers and choose “Turn on personalisation”. Closing, skipping or refreshing discards unconfirmed answers.

If you turn on personalisation, you can provide a preferred name, choose a professional role lens and save a current focus made from a task, product context, journey stage and intended outcome. We rely on your consent for this optional processing. The confirmed choices are stored with your Supabase account and are used only to provide occasional greetings, supporting emphasis, clearly labelled Ingredient suggestions and optional UI-example filter suggestions.

Personalisation is deterministic: it compares your controlled choices with reviewed content categories and mappings. It does not use analytics history, billing or tax information, marketing activity, imported company or job-role fields, private Decision Lab text, saved-item inference, location or sensitive characteristics. It does not change access, evidence, safety, prices, plan order or the complete libraries. We do not send onboarding answers, setup status, personalisation values or recommendation identifiers to Google Analytics, Stripe or MailerLite, and do not use them for campaign targeting.

If you skip, close or complete the introduction, we keep a minimal setup record containing your account ID, whether the introduction was dismissed or completed, and a server-recorded time. We rely on our legitimate interests to remember your choice and avoid repeatedly interrupting you. It is not personalisation consent and is not used for recommendations, analytics or marketing. We keep it until you deliberately reset the introduction in Account, close your account or ask us to delete it. Resetting lets you see the introduction again. Clearing personalisation choices does not remove this setup record, so withdrawing consent does not cause another prompt.

You can change either set of choices without changing whether personalisation is on, pause personalised suggestions while preserving the choices at your request, or clear the entire preference record from Account without losing your account, saved material or Decision Lab work. A saved current focus expires after 90 days unless you confirm it again; a secured daily process clears the expired focus fields. Preferred name and role choices remain until you edit or clear them, close the account, or ask us to delete them. Personalisation uses existing essential account storage and does not add a browser cookie.

Optional analytics

If you accept analytics cookies, we use Google Analytics to understand aggregate use and improve the service. Consent is our basis for this optional analytics processing and for storing or accessing the first-party browser and session cookies. The UXologist relays only approved events from our server; we do not load a Google tag in your browser. Public pages use fixed groups. Ingredient, UI-example and case-study views may include only a stable public editorial identifier, content type and public/member access category so we can understand which content is useful without sending a displayed title or browser URL.

Approved journey events may show successful magic-link account creation or sign-in, a brief start or first completion, an Ingredient save, a draft or completed brief reopened, a share link copied, a fixed membership prompt shown or selected, the fixed Practitioner options viewed or selected, and a Checkout start after Stripe creates a valid session. Successful account, brief, bookmark and Checkout events are emitted only by the confirmed server action. They use only controlled methods, public content types, signed-out/Free/Practitioner access, coarse count bands, draft/completed status and the published numeric GBP plan price. Stripe remains the source of truth for purchases and revenue.

We include a short-lived session number and the visible time since the previous approved event so Google Analytics can report consented visits, active users and engagement; hidden-tab time is not counted. Browser-relayed events can set or renew the session cookie only after the server accepts the full event. We do not send a general page-view event, route, URL or title when Workbench or Saved material opens; only the coarse opening event described above. We do not send account identifiers, profile or billing details, Decision Lab content or identifiers, saved-item names, form text, exact counts, raw URLs, actual page titles, referrers, query strings, fragments, payment details, addresses, tax information, purchase events or subscription-lifecycle events. Google receives the controlled event, browser identifier, session number and engagement interval from our server, not a direct request containing your browser IP, browser or device details.

The browser analytics identifier lasts no longer than 13 months from first consent and is not renewed on activity. The analytics session cookie expires 30 minutes after the latest accepted event. User- and event-level Analytics data is retained for 14 months without resetting on new activity. Google Signals, ads personalisation, remarketing, demographics, granular location/device collection and Ads linking are disabled. You can reject or later withdraw without losing access to the site. Google account access is an essential authentication choice and does not depend on accepting Google Analytics cookies. See the Cookies page for the current cookie list, detailed event categories and controls.

Owner and test browser analytics exclusion

Authorised administrators can set a first-party exclusion on an owner or test browser profile. The fixed exclusion value is not sent to Google and is not a device identifier. It blocks new browser and confirmed server analytics before an identifier or session can be created, persists independently of ordinary analytics consent and uses the existing withdrawal process for prior pseudonymous data.

The control is deliberately per browser profile; we do not fingerprint a physical device to link its browsers.

Who helps us provide the service

We use specialist providers including Supabase for accounts and data storage, Google when you choose Google account access, Resend for transactional authentication-email delivery, Vercel for hosting, Stripe for billing, MailerLite for opted-in marketing and—only after analytics consent—Google Analytics for aggregate site measurement. They process information for the services they provide to us and may use approved international transfer safeguards where data leaves the UK.

Google account access is separate from Google Analytics. Google processes the identity handoff under its own account and privacy terms. In the branded route, The UXologist verifies the returned Google identity and passes the signed identity token plus temporary access token to Supabase only for its independent verification and account-session creation. In the explicit recovery route, Supabase performs the Google exchange. The UXologist does not use the temporary access token to request Gmail, Drive, contacts or other Google-product data; Supabase receives it only as part of the authentication handoff. Resend is used only to send operational account-access messages. Open and click tracking are disabled, and authentication recipients are not added to Resend contacts, broadcasts, marketing automations, MailerLite or Google Analytics. Resend may process authentication-email information in the United States using the safeguards described in its data-processing terms.

How long we keep information

An account-scoped Decision Lab browser draft expires seven days after its latest edit. The application removes it when the same account next opens Decision Lab after expiry, when a successful same-tab creation response proves it came from that exact revision, or when the member discards it. The one-use completion marker is removed with that proof, when the same account returns to the new-brief form, or when the browser tab closes. If browser storage or the browser’s required cross-tab coordination is unavailable, draft storage and automatic cleanup fail closed; brief creation remains available, and any already stored draft remains only until its normal expiry or deliberate site-data clearing. An expired browser item may remain physically on a closed device until that account returns or site data is cleared, but it is no longer restored. An older shared-key draft is quarantined: the current application never reads, parses, copies, migrates or deletes it. It remains only until browser data is cleared or a separately reviewed no-read cleanup is approved.

Resend says sent-email data is normally retained for 30 days. Under its data-processing terms, customer data is deleted within 90 days after the Resend account ends. We restrict access to authentication-email records and use them only for delivery, security and support.

If you leave the hosted Checkout without subscribing, its temporary Stripe customer record and billing address are deleted when the Checkout session expires, normally within 24 hours. After a failed location check or Checkout setup, we attempt deletion immediately. A secured daily cleanup checks for temporary records left by an interrupted request or unsuccessful deletion and normally removes them within 72 hours. Completed transaction records may be retained for defined legal, tax, accounting, security or dispute requirements.

We keep account information while your account is open and for a reasonable period afterwards where one of those requirements applies. We delete information that we no longer need.

Your choices and rights

Revoking The UXologist in your Google Account stops future Google handoffs but does not itself delete your UXologist account. Deleting your UXologist account removes its linked Google identity, subject to any legal retention duties. We do not yet offer self-service unlinking; contact team@theuxologist.com if you want Google unlinked while keeping the account, and we will first make sure another secure access route remains.

You can pause personalised suggestions, or withdraw your personalisation consent by clearing the preference record in Account, unsubscribe from marketing and manage analytics cookies at any time. Pausing stops greetings and suggestions while retaining the choices at your request; clearing deletes them. Neither action changes your account or work.

You can reset the setup introduction from Account. You may separately object to our legitimate-interests use of the minimal setup record by contacting us. We will consider your circumstances and stop that use unless we identify and explain compelling overriding grounds. If the record is deleted, the service may no longer remember that you dismissed or completed the introduction, so the optional and consequence-free prompt may appear again.

Withdrawing analytics consent blocks further Analytics collection and asks Google to delete data associated with the browser’s Analytics identifier where one exists. We remove the identifier from your browser when Google confirms the request.

If the request fails, analytics remains off and we keep the identifier only so you can retry from Manage cookies. The cookie message explains this and how to contact us. We remove the identifier after a successful request; otherwise it still expires no later than 13 months after first consent. Depending on the law that applies, you may also ask to access, correct, delete, restrict or export personal information, or object to how it is used. You may ask us to correct billing information or delete it where no legal, tax or accounting retention duty applies. You can complain to the UK Information Commissioner’s Office if you believe your information has not been handled properly.

Start with the decision

Turn product friction into something you can test.

Try the Decision Lab
The UXologist

Evidence-informed psychology for clearer product decisions.

ExploreGuides for product decisionsBlog and product notesBehavioural psychology ingredientsUI examples from real productsProduct psychology case studiesOnboarding psychology guideUX psychology evidence mapBooks and readingAbout and editorial method
Use The UXologistDecision LabMembership pricingWorkbenchAccount
Policies and controlsPrivacyCookiesTermsCancellation
© 2026 The UXologistUse psychology responsibly.

Cookies on The UXologist

We use essential cookies to make The UXologist work.

We’d also like to use analytics cookies so we can understand how people use the site and make improvements.

View cookies