Privacy Policy
I'm The Boss of Me · Last updated: 24 August 2026
Privacy Policy — "I'm The Boss of Me"
In short
Everything a young person writes in the workbook stays on their own device unless account storage is switched on. It is off unless someone turns it on, turning it off deletes the whole stored copy, and no screen or tool we operate displays what a young person writes. Apart from that, we hold only what we need to run an account and confirm a purchase: an email address, a name for the account holder, and whether the App has been paid for.
This policy explains the detail, including for parents and guardians.
1. Who is responsible for your data (the "data controller")
Karen Whelan, sole trader trading as SOULution
- Address: 25 Slí na Coille, Tramore Road, Waterford, X91 DDX9, Ireland
- Email: hello@thebossofme.ie
For any privacy question or request, contact hello@thebossofme.ie.
We are not required to appoint a Data Protection Officer, but Karen Whelan is the responsible contact for data protection matters.
2. What a young person writes: on the device, and optionally with the account
By default, everything a young person writes in I'm The Boss of Me lives only on the device it was written on. We receive none of it, and if the app is deleted or the phone is lost, that writing is gone.
The account holder can choose to turn on account storage. With it on, a copy of the workbook is kept with the account, so that a lost, broken or replaced phone does not mean a lost journal. It is off unless it is switched on, and nothing is uploaded before that.
What is stored when account storage is on
- Journal entries — the date, the title, the text of the entry, the mood word if one was chosen, and the writing prompt if one was chosen.
- Workbook answers — the text typed into the chapter and pathway questions.
- Wheel of Life — the 1–5 ratings and the written reflections beside them.
- Progress signals — the mood word chosen on a given day, which sections have been opened, challenge-day ticks, which affirmations have been shown, and when the app was last opened.
The name typed into the workbook's welcome screen is not stored, and there is no server-side copy of it.
What it is used for
Keeping the workbook safe with the account, restoring it on a new device, and choosing which of Karen's affirmations to show. It is never used for advertising, profiling, model training, or sale or sharing of any kind, and no report or analytics view includes it.
Who can see it
The young person, signed in on their own account. Access rules in the database allow the account owner and no one else; there is no screen in the app, the admin tools, or the reporting tools that can display a journal entry, a workbook answer or a wheel reflection.
What we will not claim. The people who run this service hold database credentials that can technically read any row, including a journal entry. Nothing in the app can do it — but the database can, and we are not going to tell you otherwise. That access is limited to the small number of people who operate the service, and is used only to fix a fault that cannot be fixed another way, or where the law requires it.
We cannot currently promise you a record of it. Reads of the database are not logged today, so if someone with those credentials looked, there would be no audit trail to show you. We would rather say that plainly than print a promise we cannot keep. Changes to the *structure* of the database are logged; reads of your writing are not.
If a parent or guardian holds the account
For under-16s the account is held by a parent or guardian. Anyone who can sign in to the account can read what is stored with it — including journal entries.
This is a real change, and it is the most important thing to understand before agreeing. While everything stayed on the device, we could not have handed a young person's journal to anyone, because we never had it. With account storage on, a parent or guardian who knows the account password can read it simply by signing in. We are not able to prevent that, and we are not going to pretend otherwise.
If you are the young person using this workbook: you are allowed to say no to account storage, and nothing in the app is locked, hidden or reduced if you do. Everything keeps working exactly as it does now — it just stays on your device. If you want a copy you can keep without it being readable by whoever holds the account, use Print / Save as PDF instead.
If you are the parent or guardian: the private space this workbook offers is part of how it works. Turning on account storage protects the writing from a lost phone, and it also makes it readable by you. That is a trade worth talking about with the young person before you make it, rather than after.
Turning it off
Account storage can be turned off at any time in Settings. Turning it off deletes the entire server copy at that moment — journal, answers, reflections and signals together. The copy on the device is untouched. No reason is required.
Deleting the account deletes the stored copy with it.
With account storage off
- We cannot read, recover, restore, or export this content — not even if you ask us to.
- If the device is lost or reset, the browser data is cleared, or the app is removed, the content is permanently lost.
- Content does not sync between devices.
We recommend using the in-app Print / Save as PDF feature to keep a copy of anything you want to preserve.
The Teen Check-In is separate
Agreeing to account storage does not turn on the Teen Check-In, and turning either off does not affect the other. Each has its own switch in Settings and its own section of this policy (see section 2a).
2a. The Check-In questions
Sometimes we ask whether you'd like to answer a short set of questions about how things are going for you. You'd answer them once near the start and once after you've been through the chapters and pathways.
Answering is optional, and so is being asked. You choose once, and if you say no we don't ask again. Nothing in the app is locked, hidden, shortened or changed because of what you choose. You can change your mind either way at any time in Settings.
What we store if you say yes
- Your answer to each of the ten statements — a number from 1 to 5.
- Your answer to the 1 to 10 question about how much you feel like the boss of you.
- The one optional sentence at the end, if you choose to write one.
- Which version of the questions you answered, whether it was the first or the second time, and the date.
You can skip any question. A skipped question is stored as nothing at all — not as a zero and not as a "declined to answer", so a skipped question and a low answer can never be mistaken for one another.
What we do not store
We do not store a score, a total, or an average for you. No total is calculated anywhere — not on your device, not on our servers, and not in any report. There is no column for one.
We do not compare your two sets of answers to each other and keep the result. We do not attach your answers to anything else you do in the app, and we do not use them to change what the app shows you.
What it is for
To find out whether the programme actually helps.
Your answers are combined with everyone else's and looked at as totals across many people. Reports never show one person's answers, and where too few people have answered for a total to be meaningful or anonymous, no number is shown at all. The sentence you can write at the end is not included in any report.
What it is not for
It is not a test, an assessment, a screening tool or a diagnosis. It does not decide anything about you, it is never shown back to you, and nobody reads your individual answers to form a view about you or to decide what you should do.
We do not use it for advertising, for profiling, or to train any AI model.
Deleting it
Go to Settings → The check-in questions and turn it off. Your answers are deleted at that moment — both the ratings and the sentence. They are not hidden, archived, or kept "in case you change your mind". If you delete your account, the answers go with it.
3. What we do collect, and why
| Data | Why | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Email address | To create and secure the account, sign you in, send account emails (confirmation, sign-in link, password reset), and provide support | Performance of a contract |
| Account holder's name | To personalise account correspondence and identify the account holder | Performance of a contract |
| Age / guardian confirmation and terms acceptance, with timestamp | To record that the account holder confirmed they are 16+ or a parent/guardian, and accepted these terms — a legal and safeguarding requirement | Legal obligation; legitimate interests (safeguarding, record of consent) |
| Purchase and entitlement status (whether paid, when, and whether access was granted by purchase or a complimentary code) | To give you the access you paid for, and for accounting | Performance of a contract; legal obligation (tax records) |
| Authentication data (encrypted password, session tokens, sign-in timestamps) | To keep the account secure | Performance of a contract; legitimate interests (security) |
| Basic technical and error logs (e.g. server error records) | To keep the service working and secure | Legitimate interests (service reliability and security) |
We do not use advertising or analytics trackers, we do not profile users, and we do not carry out automated decision-making.
4. Payment information
Payments are processed by PayPal. Card and bank details are entered directly with PayPal and we never see or store them. We receive only confirmation that a payment succeeded, the amount, and a transaction reference, which we link to the account.
PayPal is an independent controller of the data you give it. See PayPal's own privacy statement.
5. Children's and young people's data
The App is intended for young people aged 13–18, and the account holder must be 16 or over (or a parent/guardian acting for a 13–15 year old).
We have deliberately minimised children's data:
- We hold no account in a child's name. The account belongs to the adult or the 16+ user.
- We never receive the young person's writing — it stays on the device (section 2).
- The personalisation name a young person enters is stored on the device only and is deliberately kept separate from the account holder's name held on our servers.
- There is no chat, no messaging, no social feed, and no way for anyone to contact a young person through the App.
- We do not knowingly collect personal data directly from children.
If you believe a child's personal data has reached us in error, contact hello@thebossofme.ie and we will delete it promptly.
6. Who we share data with (processors)
We do not sell or rent personal data. We share it only with service providers who process it on our instructions:
| Provider | Purpose | Where |
|---|---|---|
| Supabase | Accounts, authentication, database (account and entitlement records) | EU region |
| PayPal | Payment processing | EU / international |
| Netlify | Website and app hosting | International (CDN) |
| Resend | Sending account and service emails (see section 6a) | International |
Each is bound by a data processing agreement. Where data is transferred outside the EEA, transfers are made under appropriate safeguards such as the European Commission's Standard Contractual Clauses.
We may also disclose data where required by law, or to establish, exercise, or defend legal claims.
6a. Email we send you
We email the account holder — the adult who created the account. We never email a young person, and we hold no contact details for them.
We send two kinds of message:
- Account emails, which are necessary to provide the service: confirming your account, signing you in, resetting your password, and confirming access after a purchase.
- Service emails about the workbook you bought, such as how to get started. You can stop these at any time.
No email we send ever contains anything a young person has written. Journal entries, reflections, mood selections and Wheel of Life ratings are stored only on their own device and never reach our servers, so there is nothing of theirs that could be included.
Every non-essential email carries an unsubscribe link, and unsubscribing takes effect immediately. You can also change your email preferences at any time in Settings inside the app. We keep a record of what we sent you, and of your choice to opt out, so that we can honour it and evidence that we did.
We do not currently send marketing email. If that changes, this policy will be updated first and we will ask for your consent separately.
7. Cookies and similar technologies
We use only what is necessary to make the App work. We do not use advertising, marketing, or third-party analytics cookies.
- Essential storage: authentication tokens to keep you signed in.
- Local storage on your device: workbook content, progress, and settings (never sent to us — see section 2).
Because we use only strictly necessary storage, we do not display a consent banner for advertising or tracking cookies.
8. How long we keep data
- Account data: for as long as the account is open, and then deleted within 30 days of a deletion request.
- Purchase and transaction records: retained for 6 years to meet Irish tax and accounting obligations, even after account deletion.
- Email delivery logs: short retention by our email provider for deliverability and security purposes.
- On-device content: retained on your device until you delete it. We hold none of it.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data ("right to be forgotten"), subject to records we must keep by law;
- restrict or object to processing;
- data portability — receive your data in a portable format;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority.
To exercise any right, email hello@thebossofme.ie. We will respond within one month. We may need to verify your identity first.
Note: because we never hold workbook content, an access or portability request will return only account data (email, name, purchase status, consent record). Workbook content can be exported by you directly from the App.
Complaints: you may lodge a complaint with the Irish Data Protection Commission — dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 — or with the supervisory authority in your EU country of residence.
10. Security
We protect data using: encryption in transit (HTTPS); encrypted password storage handled by our authentication provider (we never see or store raw passwords); database access controls so account records are only accessible to the account owner; server-side-only granting of purchase access, so access cannot be altered from a browser; and secrets held server-side only.
No system is perfectly secure, but the architecture deliberately minimises what could be exposed: the most sensitive material — a young person's writing — never leaves the device.
11. Changes to this policy
We may update this policy. Material changes will be notified by email or in-app before taking effect. The "last updated" date above always reflects the current version.
12. Contact
Email: hello@thebossofme.ie Post: SOULution, 25 Slí na Coille, Tramore Road, Waterford, X91 DDX9, Ireland