UK GDPR & Privacy Policy

Last updated: 5 May 2026

This Privacy Policy explains how MaxyblaqEasyLife (“we”, “us”, “our”), the operator of Prompt Doctor, collects, uses and protects your personal data when you use our website and services. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025 (DUAA).

1. Who we are (Data Controller)

Data controller: MaxyblaqEasyLife
Address: 85 King Richard Street, Coventry, United Kingdom
Phone: +44 7365 970415
Email: support@maxyblaqeasylife.com

2. Personal data we collect

  • Account data: name, email address, hashed password, profession, theme preference.
  • Content data: prompts you submit, analyses generated, notes, lessons completed, marketplace purchases.
  • Billing data: Stripe customer ID and subscription status (card details are processed by Stripe and never stored by us).
  • Technical data: IP address, browser type, device, pages visited, timestamps, referrer.
  • Cookies & similar technologies: see our Cookie Policy.

3. How we use your data and our lawful bases

  • Contract (Art. 6(1)(b) UK GDPR): to create your account, deliver the service, process payments and provide customer support.
  • Legitimate interests (Art. 6(1)(f)): to secure the service, prevent fraud and abuse, improve product quality and run aggregate analytics. The DUAA recognises certain processing — including service security and product improvement — as a recognised legitimate interest.
  • Legal obligation (Art. 6(1)(c)): to keep tax, accounting and consumer-rights records.
  • Consent (Art. 6(1)(a)): for non-essential cookies and marketing communications. You can withdraw consent at any time.

4. AI processing

Prompts you submit are sent to third-party AI providers (e.g. OpenAI, Google) via the Lovable AI Gateway solely to generate the analysis you requested. We do not authorise these providers to train their models on your prompts. Do not submit special category data (health, biometrics, etc.) or other people’s personal data.

5. Sharing your data

  • Hosting and database: Lovable Cloud / Supabase (EU region).
  • Payments: Stripe Payments Europe Ltd.
  • AI inference: OpenAI, Google (via Lovable AI Gateway).
  • Email: transactional email providers.
  • Authorities, where required by law.

6. International transfers

Where data leaves the UK, we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment where required.

7. Retention

  • Account data: while your account is active and 6 months after deletion.
  • Analyses & notes: until you delete them or close your account.
  • Billing records: 6 years (UK tax law).
  • Server logs: up to 90 days.

8. Your rights

Under the UK GDPR and DUAA you have the right to:

  • Access your personal data and receive a copy.
  • Rectify inaccurate data.
  • Erase your data (“right to be forgotten”).
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time.
  • Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

Under the DUAA we operate a clear complaints process: email support@maxyblaqeasylife.com and we will respond within one month.

9. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you using solely automated means. AI-generated analyses are advisory only.

10. Security

We use TLS in transit, encryption at rest, role-based access control, row-level security in our database and regular backups.

11. Children

The service is not directed at children under 13 and we do not knowingly collect their data.

12. Changes

We will update this policy when our practices change and notify you of material changes by email or in-app notice.

13. Contact

Questions or rights requests: support@maxyblaqeasylife.com or write to 85 King Richard Street, Coventry, United Kingdom.