Your information

Privacy Notice

What you write in your Room is yours. Here is exactly what we hold, why we hold it, and what Teri can and cannot see.

Before the legal language, the short version.

What you write in your Room is yours. Teri cannot read it. Not by opening a screen, not by running a query, not by asking someone to fetch it. The only thing she ever sees is an Opening, which is a piece of writing you have deliberately chosen to share with her.

A real person reads what you share, and a real person writes back. Nothing you receive is generated and sent to you by a machine. Teri does sometimes use a private writing tool to help her think through a difficult reply before she writes it herself, and section 8 explains exactly how that works, because you should know it before you write rather than after.

We do not sell anything to anyone. We do not track you around the internet. Nothing you write is scored, rated, diagnosed or profiled, and no model is trained on it.

On the public pages, before you sign in, we count how the site is used, in the way any shop counts who comes through the door. The moment you sign in, that stops. There is no measurement of any kind inside your Room, and the count from before is never joined to your account. Section 4.7 explains it, and the [Cookie Policy] explains it in full.

If you have bought a place in In My Room for your young person, this notice does not govern their account. They have their own, written for them. And you will not be able to read what they write. Section 4.8 explains exactly what you can and cannot see, and why it is built that way.

There are two limits to all this, and we would rather tell you plainly than bury them. If something you share makes us seriously concerned that a child or an adult at risk is in danger, we may have to pass that concern on; section 12 explains how. And when you close your room, what you have written is not destroyed on the spot, it is moved into a restricted archive for five years; section 13 explains why, and what you can still ask us to delete.


1. Who we are and how to reach us

Teri Potter, trading as The True Self, is the data controller for the personal information described in this notice. That means she decides what is collected and why, and she is accountable for it.

ControllerTeri Potter, trading as The True Self
Legal formSole trader
Address for correspondenceTeri Potter t/a The True Self, c/o TWP Accounting, The Old Rectory, Church Street, Weybridge, Surrey KT13 8DE
Email about your informationprivacy@thetrueself.me
General enquirieshello@thetrueself.me
ICO registrationZC211707
Professional membershipMember of the International Practitioners of Holistic Medicine (IPHM), membership IPHMNM14755
Data protection contactTeri Potter

We have assessed whether we need to appoint a Data Protection Officer and concluded that we do not, because of the small scale of what we do. We keep that assessment written down and we will look at it again if the space grows. Teri Potter is personally accountable for data protection here, and she is the person who will answer if you write to us.

Because we handle special category data, we keep an Appropriate Policy Document as required by Schedule 1 of the Data Protection Act 2018, and we have carried out a Data Protection Impact Assessment for this space. You can ask to see either.

Our processor. The space is built and maintained for us by The KBI Group, who act as our data processor under a written contract. They keep the software running and secure. They do not use anything you write for their own purposes, and they are bound by the same confidentiality this notice describes.

2. What this notice covers

This notice covers:

  • the public website at thetrueself.me (our older address, thetrueself.app, redirects here)
  • A Place to Land at placetoland.me, the private space you sign into
  • The Village, the parents' community inside it
  • your account, and the arrangement under which you buy a place for a young person
  • emails we send you about your membership
  • messages you send us by email or through the contact form

It does not cover In My Room. Your young person's space has its own privacy notice, written for them and addressed to them, at inmyroom.me. If you are buying them a place, please read it. Section 4.8 below explains how the two fit together.

It does not cover other websites we link to. If you follow a link to a resource, an organisation or a crisis service, that organisation has its own privacy notice and we have no control over it.

S.A.F.E. Practice™ at safepractice.me is not yet open. When it opens it will have its own notice, and this one will be updated to point to it.

3. Who this space is for

A Place to Land is for adults aged 18 or over who are parenting or caring for a young person. You must be 18 or over to hold an account.

Young people do not have accounts in A Place to Land. Nothing in this space collects a child's contact details, login or device information. Young people aged 13 and over may hold their own account in In My Room, which is a separate space with its own notice, and section 4.8 explains the relationship between the two.

The counting on the public pages described in section 4.7 does not know or ask who is visiting, identifies nobody of any age, and is never joined to an account.

This space is written for people in the United Kingdom, and most of the people using it are here. You are welcome to join from elsewhere. If you do, please read section 12, because what Teri is able to do if she becomes seriously worried about you or your young person is different outside the UK.

4. The information we hold

4.1 Information you give us when you join

WhatWhy we have it
Your first nameSo the space can greet you as a person rather than an account
Your email addressTo sign you in, to reach you about your membership, and to reset your password
Your passwordStored only as a one way hash. Nobody here can read it, including us
The date you accepted these terms and this notice, and which versionTo show what you agreed to and when
The date you acknowledged the crisis informationSo we know you saw where to go if something is urgent

We do not ask for your surname, your address, your date of birth, your phone number, your child's name or your child's age. We do not need them.

4.2 Information about your membership

WhatWhy we have it
Which period you are in, when it started, when it ends, whether it is active, paused or finishedTo give you what you have paid for and to answer you if you ask
Your Stripe customer and payment identifiersTo link your account to your payment record
Whether you joined using a code, and which kindTo make codes work and to stop them being reused beyond their limit

We never see or store your card details. Payment is taken by Stripe, who are regulated for exactly this. Card numbers go from you to Stripe and never touch our systems. We can see that a payment succeeded or failed, the amount, and the last four digits Stripe shows us. Nothing more.

4.3 What you write, and what you say

This is the part that matters most, so it gets its own detail.

Your entries. Everything you write in your Room. Stored as text, with the date you wrote it and the date you last changed it.

Your voice notes. If you leave a voice note, we hold the recording. If you ask for it to be turned into text, we hold that text as well. You choose, each time, whether to keep the audio, the text, or both. A voice note is treated exactly like an entry: private to you unless and until you share it.

Your Openings. When you choose to share a piece of writing or a voice note with Teri, the space takes a copy at that moment and stores it as an Opening. The copy is separate from the original. If you later edit or delete the original in your Room, the Opening does not change, because Teri may already have read it and replied to it.

Teri's replies. What she writes or records back, and when.

Your Village posts. Anything you write or record in the parents' community, together with your comments and the posts you have liked. This is not private. Every member of the parents' community can read it, and so can Teri. It is stored with your account and it is yours, but it was never confidential and we do not pretend otherwise.

Safeguarding records. If a concern is raised, we record the concern, what was done about it and when. Section 12 explains this.

4.4 Special category data, and why we are careful

Under UK GDPR, information about a person's physical or mental health is "special category" data and gets stronger protection.

We cannot know in advance what you will write. Realistically, a parent writing honestly about a hard season may write about their own mental health, their child's, a diagnosis, a hospital appointment, medication, self harm, or a relationship in trouble. Any of that would be special category data. So would your voice, if it were used to identify you.

So we treat everything you write or record in this space as special category data by default, whether or not it turns out to be. That is why we ask for your explicit consent before you write anything, and why the security described in section 10 applies to every word.

4.5 Information about other people

When you write about your child, your partner, your own parents or anyone else, you are writing personal information about someone who has not given us anything and may not know this space exists.

We handle that carefully:

  • We do not build any record about the people you write about. There is no profile of your child anywhere in this system. Their words exist only inside yours.
  • We do not ask for their names and we do not index or search on them.
  • We do not contact them, ever, unless section 12 applies.
  • Their information is kept and deleted on exactly the same terms as yours.

Please write what you need to write. We mention this only so you know what happens to it.

4.6 Technical information

WhatWhy we have it
Sign in events, and the date your session last refreshedTo keep your account secure and to spot anything unusual. Your sign in expires after 14 days of not being used, and you are asked to sign in again. That is about the security of your session and has nothing to do with the length of your membership
A keyed hash of the IP address associated with certain actionsTo investigate abuse or a security incident. We hash it with a secret key so that the address cannot be worked out by anyone who sees the log. It is still your personal data and we still treat it as such
An audit record of every action Teri takes that touches your record, such as reading an Opening, sending a reply, or opening something in the archiveSo there is an honest trail, and so we can answer you truthfully if you ask who did what
Error and performance logs from the hosting platformTo find and fix faults

There is no measurement of any kind inside the private space. No page view counting, no session recording, no heat mapping, no funnel, no behaviour scoring. Nobody is watching how long you spent on a screen, which pages you opened, how often you came back or how long you sat before writing. The measurement described in section 4.7 stops at the sign in page and does not follow you through it.

4.7 If you only visit the public website

On the public pages we measure how the site is being used, so that we can make it better. This is the one place in the whole of The True Self where anything about usage is counted, and we would rather describe it plainly than leave you to guess. The security and audit records in section 4.6 are a different thing, kept for a different reason, and they are not measurement.

What is counted

WhatWhy
Which pages are viewed, and in what orderTo see which pages help people understand what this is, and which ones lose them
Where a visit came from, for example a search, a link, a newsletter or a social postTo know where the people who need this are finding it
Roughly where in the world a visit came from, at country levelTo know whether this is being read outside the UK
The type of device and browserSo the site works properly on what people actually use
How far people get through the joining pages on our own site, up to the point we hand you over to StripeTo find out where the process is confusing, which is the only reason we would want to know

What is not counted, and never will be on our watch

  • Nothing follows you to any other website. There is no cross site tracking, no advertising network, no Meta pixel and no Google Ads tag.
  • Nothing records your screen. No session replay, no mouse tracking, no keystroke capture.
  • Nothing builds a picture of you. No profile, no scoring, no inference about who you are or what you might need.
  • Nothing about the measurement is ever used to make a decision about an individual, and nothing triggers an email, an offer or a follow up. If you get as far as the payment page and change your mind, nobody will chase you. Stripe's own records tell us a simple total of payments begun and not completed. Nothing on your device tells us who stopped, and there is no basket anywhere with your name on it.

How it works, and how to say no. The information is turned into counts and totals, and the individual level records behind those counts are not kept once they have been counted. We rely on the statistical purposes exception in Schedule A1 paragraph 5 of PECR, which permits this on the basis of clear information and a simple way to object, rather than a consent banner. There is a link on every public page that switches the counting off for you, free and in one click. From then on nothing is counted, and the only thing kept is a small record that you objected, so that we stop and never have to ask you again. The [Cookie Policy] sets out the conditions in full.

Where it stops. The counting identifier is discarded the moment you create your account, which is the first point at which you become a named person to us rather than a number, and it is never joined to your account. Nothing we counted before you trusted us is ever attached to your name.

If you use the contact form or email us, we hold what you send and our reply.

4.8 Your young person's account, and what you can see of it

If you buy a place in In My Room for a young person aged 13 or over, we hold a record linking your account to theirs. That link exists so that we know who is paying, so that we can reach you about the membership, and so that a safeguarding concern can be routed properly.

What you can see

  • that their membership is active, when it started and when it ends
  • anything they choose to show you

What you cannot see, ever

  • their private writing and voice notes
  • what they choose to share with Teri
  • what Teri writes back to them
  • anything they post in the young people's community
  • how often they sign in, how long they spend, or what they open

There is no parent view and no route to one. It was not built, and building it later would break the promise this whole space rests on. A young person who believes a parent might read what they write does not write the true thing.

They are told all of this, in their own words, before they write anything, including that you can see whether their account is active. Nobody here is monitored without knowing it. If that ever changed, they would be told first and would see a clear and continuous sign in the app for as long as anyone could see anything of theirs. That is what the ICO's Children's Code requires, and we would do it anyway.

What we will tell you. We will contact you about payment, about the membership ending, if their account is closed, and if there is a safeguarding concern, unless telling you would put them at greater risk or the concern is about your household. Section 8 of the [Safeguarding Policy] sets out exactly how that judgement is made, and it is worth reading before you buy rather than after.

Their rights are their own. A young person can ask us for a copy of what we hold about them, ask us to correct or delete it, or close their account, without your permission and without us telling you they asked.

5. Where the information comes from

Almost all of it comes directly from you. The rest comes from Stripe, which tells us whether a payment succeeded and when, and gives us an aggregate count of payments begun and not completed, and from our own systems, which record technical and security events.

We do not buy data. We do not enrich your record from other sources. We do not use data brokers.

6. Why we are allowed to hold it

UK GDPR requires a lawful basis for ordinary personal data, and a separate additional condition for special category data. Here is ours, in full.

WhatLawful basis (Article 6)Additional condition for special category data (Article 9)
Your account details and membership recordContract, Article 6(1)(b). We cannot give you the space without themNot applicable
Taking paymentContract, Article 6(1)(b)Not applicable
Your entries, your voice notes, your Openings and Teri's replies, while your room is openContract, Article 6(1)(b)Explicit consent, Article 9(2)(a)
Holding your record in the restricted archive after your room closes (section 13)Legitimate interests, Article 6(1)(f): being able to answer a complaint or defend a claim years later, meeting the record keeping conditions of our professional indemnity insurance, and giving you your history back if you return. We have weighed this against your privacy, which is why the archive is restricted, time limited and auditedLegal claims, Article 9(2)(f)
Counting how the public pages are used, before you sign in (section 4.7)Legitimate interests, Article 6(1)(f): understanding whether the public site explains this well enough for the people who need it. We have weighed this against your privacy, which is why the output is aggregate, the individual level records are discarded, nothing follows you off the site, and there is a one click opt out. Under PECR this runs on the statistical purposes exception in Schedule A1 paragraph 5, not consentNot applicable. Nothing measured here is special category data, and none of it is joined to an account
Your posts in the parents' VillageContract, Article 6(1)(b). The community is part of what you boughtExplicit consent, Article 9(2)(a), given in the same way and at the same time as for your writing. You choose what to post, and nothing obliges you to use the Village at all
Moderating the Village, reviewing reports, removing contentLegitimate interests, Article 6(1)(f): keeping the community safe for the people in it, which is also a duty on us under the Online Safety Act 2023Article 9(2)(g), substantial public interest, safeguarding, where the content engages it. Otherwise Article 9(2)(e), data you have manifestly made public within the community
Holding the link between your account and your young person'sContract, Article 6(1)(b), and legitimate interests, Article 6(1)(f), in being able to route a safeguarding concern properlyNot applicable to the link itself
Keeping the space secure, preventing abuse, keeping audit recordsLegitimate interests, Article 6(1)(f): running a service people can trust. We have weighed this against your privacy and consider the impact minimalNot applicable
Keeping financial recordsLegal obligation, Article 6(1)(c) (tax law)Not applicable
Acting on a serious safeguarding concernRecognised legitimate interest, Article 6(1)(ea): safeguarding vulnerable individuals, and disclosure to a public body carrying out a public task. Where someone's life is at risk and they cannot give consent, vital interests, Article 6(1)(d)Substantial public interest, Article 9(2)(g), read with the safeguarding condition at Schedule 1 Part 2 paragraph 18 of the Data Protection Act 2018. Where a person is physically or legally incapable of consenting, Article 9(2)(c)
Complying with the specific reporting duty on everyone under section 38B of the Terrorism Act 2000Legal obligation, Article 6(1)(c)Article 9(2)(g) as above
Defending or bringing a legal claimLegitimate interests, Article 6(1)(f)Article 9(2)(f), legal claims

On consent. You give explicit consent when you tick the second box on the join page, which is separate from the box confirming you have read this notice and the terms. That consent is what allows us to hold what you write while your room is open, and you can withdraw it at any time. Section 11 explains what happens when you do.

Being straight with you about what withdrawal does and does not do. Withdrawing your consent stops us using your writing to run your membership, and your membership will end. It does not by itself empty the archive described in section 13, because the archive rests on a different footing, which is our need to be able to answer a complaint or defend a claim. You can still ask us to delete, and section 11 explains what we will and will not be able to do. We would rather set that out here than let you discover it at the point of leaving.

7. What we do with it

  • Give you a private place to write, and keep what you write safe
  • Let you share an Opening with Teri when you choose to, and deliver her reply back to you
  • Turn a voice note into text when you ask for it
  • Take payment for your membership
  • Send you the transactional emails listed below
  • Give you the resources Teri has made available to you
  • Keep the space secure and working
  • Meet our legal, professional and insurance obligations

That is the whole list. We do not do anything else with it.

7.1 The emails we send

We send only what is necessary to run your membership: confirming your email address, confirming you are in, telling you Teri has written back, telling you a period is nearly up, telling you a payment failed, telling you an export is ready.

We never put your words, or Teri's reply, in an email. The notification says something is waiting. It does not say what. Email is not a private enough place for either.

We do not send marketing. There is no newsletter, no offers, no re-engagement campaign. If that ever changes we will ask you first, separately, and you will be free to say no without it affecting anything.

7.2 What we never do

  • We never sell, rent or share your information with anyone for their own purposes
  • We never use anything you write to advertise, promote or illustrate this space, even anonymised, unless you have separately and specifically agreed in writing
  • We never send you a reply that a machine has written. There is no chatbot here, and nothing is delivered to you that Teri has not read, written and approved
  • No machine ever scores, ranks, rates, tags, diagnoses, profiles or assesses you or your writing. The one human judgement that is ever made about what you share is the safeguarding judgement described in section 12, and that is made by Teri, deliberately, and written down
  • We never make an automated decision about you that has a legal or similarly significant effect
  • We never train any model on your writing or your voice, and every supplier we use is contractually forbidden from doing so

One honest exception, and it is nowhere near your writing. Stripe runs automated fraud checks on card payments, which is normal and is how card fraud is stopped. That check looks at the payment and the device it came from. It never sees anything you have written, and it cannot. If a payment is ever declined by that check you can ask us to look at it and we will put it in front of a person. Stripe explains its checks at stripe.com/privacy.

8. Where technology sits, and where it does not

We want to be exact about this, because it is the question people most want answered and the one most often fudged.

Every reply you receive is written by Teri. She reads your Opening herself, she writes the answer herself, and she approves it before it is sent. Nothing reaches you that she has not meant.

She may use a private writing assistant to help her think. When she is working out how to answer something hard, she may put what you shared into a writing tool and ask it how it would respond, in the same way another practitioner might talk something through with a colleague, or write three drafts before finding the right one. She then puts that aside and writes to you in her own words. It helps her order her thinking. It does not do the answering, and no output of it is ever sent to you unchanged.

What that means for your information:

  • The tool is engaged only with an Opening, which is something you have already chosen to share. It never touches your private entries, because nothing can.
  • It is used under a written agreement that forbids the supplier from training on your words or using them for any purpose of their own.
  • The supplier is listed in section 10 like every other supplier, so you can see who it is.
  • Teri is accountable for every word that reaches you, whatever helped her get there.

Elsewhere in the space, technology may also be used for two ordinary things: generating general writing prompts, which are the same for everybody and are not about you; and turning your voice note into text, if you ask for it. Neither of those produces a reply to you, and neither of them reads your entries for any other purpose.

What is never true here. No machine analyses what you write for mood, risk or sentiment. Nothing is summarised behind your back. Nothing is used to build a picture of you. No machine decides anything about you.

The single exception is a human one, and it is not automated at all: when Teri reads an Opening she does think about whether anyone is in danger, because section 12 obliges her to. That is a person exercising judgement about something you chose to show her, and it is the only assessment of any kind that happens here.

[TO CONFIRM: the writing assistant and the voice transcription service both need to be named here and in section 10, on a business account with a data processing agreement and training switched off. Until Teri confirms which tools she uses and on what account, this section describes the practice accurately but cannot name the supplier.]

9. The privacy wall

This is a promise about how the software is built, not just about how we behave.

  • Your entries can be read only by an account signed in as you. This is enforced at the database level by row level security, so the rule holds no matter which screen, query or route is used.
  • There is no policy of any kind that grants Teri's account access to your entries. Not a read policy, not a view, not a function that bypasses the rules, not an administrative override in her side of the space, not an export. The build was tested to prove that Teri's own account, querying the entries table directly, gets nothing back while entries exist.
  • The wall holds in the archive too. When your room closes and your record moves to the archive described in section 13, your private entries and unshared voice notes go with it in a form Teri cannot open. What she can reach in the archive is only what she could already see while you were here: the Openings you chose to share, her own replies, and any safeguarding record.
  • She sees an Opening only once you have shared it.
  • Once an Opening is shared, neither of you can edit it. What was said is said.
  • Every time she opens an Opening, sends a reply, or opens anything in the archive, that is written to an audit record.

The one thing we will not pretend. Any system that stores information has somebody who can reach the database underneath it, or the software could never be repaired. That is true here and it is true everywhere, and a policy that claimed otherwise would be lying to you. So, plainly: our engineers at The KBI Group hold infrastructure level access to the database. They use it only to fix a fault or answer a security question, only when there is no other way, under a contract that forbids anything else, and every occasion is logged. They have no interest in your writing and no reason to open it. What we can promise absolutely is that Teri has no such access, and no route to it, which is the promise that actually matters when you sit down to write.

If anyone ever asks for this to be changed so that private entries can be read from Teri's side of the space, the answer is no, and the instruction to refuse is written into the build itself.

10. Who else is involved, and how your information is protected

We use a small number of carefully chosen suppliers. Most of them are processors, which means they act only on our documented instructions and cannot use your information for their own ends, and each of those is bound by a written data processing agreement. Stripe is different, and is a controller in its own right for the payment data it holds. The table says which is which.

SupplierWhat they doWhere the data sitsNotes
[HOSTING AND DATABASE PROVIDER, TO CONFIRM]Hosts the site, the database, the file storage and the background functions[EU or UK region, TO CONFIRM at launch]Everything you write lives here, encrypted
Stripe Payments UK, Ltd. and Stripe Payments Europe, LimitedTakes paymentUnited Kingdom and Ireland, with processing and support in the United StatesStripe is a controller in its own right for the payment data it holds, and is authorised by the Financial Conduct Authority. Its own privacy policy applies to that, and it is at stripe.com/privacy
ResendSends the transactional emails listed in 7.1United StatesReceives your email address and the plain text of the notification. Never your writing
[ANALYTICS PROVIDER, TO CONFIRM]Counts how the public pages are used, as section 4.7 describes[TO CONFIRM]Sees the public pages only. Never sees anything inside the private space, and never receives anything connected to an account. Acts only on our instructions, and is contractually forbidden from using the information for its own purposes or joining it to anything else it holds
[WRITING ASSISTANT, TO CONFIRM]Helps Teri draft a reply, as section 8 describes[TO CONFIRM]Sees only an Opening you have already shared. Contractually forbidden from training on it
[VOICE NOTE TRANSCRIPTION, TO CONFIRM]Turns a voice note into text when you ask for it[TO CONFIRM]Sees only the recording you asked to have transcribed
The KBI GroupBuilds and maintains the spaceUnited KingdomAccess to production data only where strictly necessary to fix a fault, logged when it happens

We do not use Meta pixels, advertising networks, session recording tools, chat widgets or third party font services on any part of this site. We do not use Google Analytics.

If that ever changes. We have no advertising or retargeting on this site today. If we ever introduce any, it would need your consent rather than an opt out, so you would see a proper choice before anything was set, this notice and the [Cookie Policy] would be reissued first, and saying no would be exactly as easy as saying yes.

Others we may have to tell. We may disclose information where the law requires it, for example to a court, the police, a local authority or a regulator, or where section 12 applies. We may also have to disclose it to our insurer or our legal advisers if a claim or complaint is made. We would tell you if we were allowed to.

If the business ever changes hands, your information could transfer to whoever takes it on. If that ever happens we will tell you before it does, and you will be able to close your room and take everything with you first.

Transfers outside the UK. Where a supplier processes information outside the UK, we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on UK adequacy regulations where they apply. We keep copies of these arrangements and you can ask to see the relevant one.

Security measures.

  • Encrypted in transit (TLS) and at rest
  • Row level security on every table, so access rules are enforced by the database rather than by the interface
  • Passwords of at least 12 characters, stored only as one way hashes
  • Two factor authentication is compulsory on Teri's account, and on any account with administrative access
  • Sessions expire after 14 days of not being used
  • Resources and voice recordings are held in a private store and served only through links that expire
  • The archive is held separately, is not visible anywhere in the running space, and is opened only for a specific reason that is written down at the time
  • An audit trail of every administrative action that touches your record
  • Access limited to the smallest possible number of people, which today means Teri and, for maintenance, The KBI Group

Breaches. If something goes wrong and there is a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware, and we will tell you directly, plainly, and without waiting to be asked, if the risk to you is high.

11. Your rights

You have the following rights over your information. All of them are free to use, and using one will never affect how you are treated here.

RightWhat it means here
AccessAsk for a copy of everything we hold about you, including anything in the archive. Much of it is already available to you in the space, and you can export it yourself at any time from your account
RectificationAsk us to correct anything inaccurate, such as your name or email
ErasureAsk us to delete what we hold. See below
RestrictionAsk us to stop using your information while a concern is looked into, without deleting it
PortabilityGet your writing in a readable, machine usable file. The export in your account does this in a click
ObjectionObject to anything we do on the basis of legitimate interests, including the archive
Withdraw consentWithdraw your consent to us holding what you have written, at any time

How to use them. Do it in the space where you can, or write to privacy@thetrueself.me. We will answer within one month. If a request is genuinely complicated we may take up to two further months, and we will tell you within the first month if that happens and why. We will not charge you, and we will not make you justify yourself.

We may need to check you are who you say you are before we act, which usually means replying from the email address on the account. If we have to ask you to confirm who you are, or to tell us more about what you are looking for, the clock pauses until you answer.

Erasure, in practice, said honestly.

  • Ask us to delete and we will delete everything we are not obliged to keep. That includes your private entries and unshared voice notes, always, because nothing about them could ever be the subject of a complaint or a claim; Teri has never seen them.
  • Where we cannot delete, we will say so and say why. UK GDPR Article 17(3)(e) allows us to keep personal data to the extent it is necessary for the establishment, exercise or defence of legal claims. The Openings you shared, Teri's replies and any safeguarding record are the record of what we did for you, and they are what we would need if you or anyone else ever questioned it. We will keep only what is genuinely necessary, only for as long as section 13 says, and we will tell you exactly what has been kept.
  • You can object at any time, and if you do we will look at your particular circumstances rather than applying a policy at you.
  • Deletion from the live system happens straight away. Copies held in routine backups cycle out within [30 days, TO CONFIRM with KBI], and are never restored except to recover from a failure.
  • The minimum financial record the law requires us to keep for six years survives everything. That is the fact of a payment and its amount, not anything you wrote.

Withdrawing your consent. You can withdraw your consent at any time, by telling us or by closing your room. Your membership will end and we will stop using your writing to run it. We will refund the unused part of any period you have paid for. What happens to the writing itself is set out in section 13 and in the paragraphs just above, and we would rather you read that before you join than discover it on the way out.

Your right to complain to us. You have a legal right under section 164A of the Data Protection Act 2018 to complain to us about how we have handled your information, and we have a legal duty to make that easy. Write to privacy@thetrueself.me or use the complaints form at thetrueself.me/complaint. We will acknowledge within 5 working days, and in any event well within the 30 days the law allows, look into it properly, and tell you what we have done about it.

Complaining to the regulator. If we cannot put it right, you can complain to the Information Commissioner's Office at ico.org.uk, on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You can go to them directly at any point. You do not need our permission and you do not have to come to us first.

12. Safeguarding, and the limits of confidentiality

We would rather be honest about this in advance than surprise you with it later. The [Safeguarding Policy] sets it out in full; this is the summary.

Teri holds professional obligations that do not switch off because the writing happens on a screen. In a small number of situations she may have to act on something shared with her, including passing a concern to someone outside this space.

When that might happen. Where what you have shared gives serious concern that:

  • a child is suffering, or is at risk of suffering, significant harm
  • an adult at risk is being abused or neglected
  • you or someone else is at immediate risk of death or serious injury
  • there is a risk of serious harm to another person
  • the law compels disclosure, for example a court order, or the duty that section 38B of the Terrorism Act 2000 places on everyone

How it would happen.

  • She would use judgement, not a rule. Writing honestly about how hard things are, about anger, exhaustion, despair or thoughts you are frightened of, is not in itself a safeguarding concern. It is the reason this space exists.
  • Wherever it is safe and possible, she would talk to you first, and tell you what she was going to do and why.
  • She would share the minimum necessary, with the appropriate service.
  • Anything she does is recorded in the safeguarding log: the concern, the action taken, the date.
  • A concern can only ever arise from something you chose to share. She cannot see your private entries, so she cannot act on them.

If you are outside the United Kingdom, what she can do is different and more limited. In most countries she has no route to a local safeguarding service and no standing to be heard by one. What she would do instead is tell you directly what worries her, give you the emergency and crisis routes for where you are, ask you to make the call yourself, and stay with you in writing while you do. Where there is a UK connection, for example a child ordinarily resident here, she would contact the relevant UK authority. If she felt she could not hold the risk responsibly at a distance, she would say so and end the arrangement rather than pretend otherwise. The [Safeguarding Policy] sets this out in full.

Safeguarding records are kept for five years from the date recorded where they concern an adult, and until the child's 25th birthday, or five years, whichever is later, where they concern a child. They are not deleted when you close your room. They are held separately from everything else, seen only by Teri, and never shared except as described above. We keep them because a safeguarding record that disappears is no use to the person it was meant to protect, and because we may have to account for what we did.

If you are in danger right now, this is not the right place to turn. In the UK, call 999. For urgent health advice call NHS 111. Samaritans are on 116 123, day or night. Shout is a text line, text SHOUT to 85258. If you are elsewhere, findahelpline.com lists verified services all over the world, and the Terms of Use carry a fuller list.

13. How long we keep things, and what happens when you close your room

13.1 The archive, and why it exists

When you close your room, what you have written is not destroyed on the spot. It is moved into a restricted archive and kept for five years from the day you close, and then deleted.

We know that is not what most people expect, so here is why:

  • Insurance and professional record keeping. Teri's professional indemnity cover requires accurate records of professional services to be kept for at least five years. Without a record, the cover that protects you as well as her does not work as it should.
  • Complaints and claims arrive late. Somebody might raise a concern about how they were treated two or four years after they left. If everything has been destroyed, neither of you has anything to point to, and that is worse for you than for us.
  • People come back. If you return using the same email address, your history can be returned to you rather than lost, and you do not have to start from nothing or repeat yourself.

13.2 What the archive is, and what it is not

  • It is not visible anywhere in the running space. It is not a screen anybody browses.
  • Your private entries and unshared voice notes go into it in a form Teri cannot open. The privacy wall does not stop at the door. She never saw them while you were here and she does not see them afterwards.
  • What she can reach is only what she could already see: the Openings you chose to share, her own replies, and any safeguarding record.
  • It is opened only for a specific reason recorded at the time, which means a complaint, a claim, a safeguarding matter, or your own request to have your history back. Every occasion is logged.
  • After five years it is deleted, in full, without anyone having to ask.

13.3 You can still ask

Everything in section 11 still applies. If you ask us to delete, we will delete your private entries and unshared voice notes without argument, and we will delete anything else that is not genuinely needed to answer a complaint or defend a claim. Where we keep something, we will tell you what and why. If you would rather nothing at all were kept, say so and we will look at your circumstances properly rather than quoting a policy at you.

13.4 The full retention table

WhatHow longWhy
Your entries and voice notes, while your room is openFor as long as your room is openThey are yours
Your entries and unshared voice notes, after you closeHeld in the archive, unreadable by Teri, for 5 years from closing, then deletedSo they are there if you return. Deleted on request at any time
Your Openings and Teri's replies, after you closeHeld in the archive for 5 years from closing, then deletedInsurance, professional record keeping, and being able to answer a complaint or defend a claim
Your account and profile5 years from closing, then deletedTo be able to reconnect an archive to you if you return, and to answer a complaint
Membership and payment records6 years from the end of the tax year in which the last payment fellRequired by tax law
Your Village posts and commentsRemoved from the community when you close your room, then held in the archive for 5 yearsSo the community is not left with orphaned posts, and so a moderation decision can still be reviewed
Reports, moderation decisions and appeals12 months, unless a safeguarding record or a legal claim requires longerLong enough to review or appeal a decision
The link between your account and your young person'sFor as long as either account is open, then 5 yearsSo we know who paid, and so a safeguarding record can be understood later
Safeguarding records about an adult5 years from the date recordedProfessional obligation, insurance, and being able to account for what we did
Safeguarding records about a childUntil the child's 25th birthday, or 5 years, whichever is laterOrdinary safeguarding practice. A person may need the record of what happened to them long after they have grown up
Public site measurement, at individual levelDiscarded once it has been counted, and in any event within [TO CONFIRM, KBI]It exists only to become a total. Once it is a total there is no reason to keep the row it came from
Public site measurement, as aggregate totalsKept as long as it is useful, and holds nothing that identifies anybodyCounts of pages and visits, with no person behind them
Audit and security logs12 monthsLong enough to investigate an incident, short enough not to be a second record of you
The audit records of who opened the archive, and of any safeguarding actionFor as long as the archive or the safeguarding record itselfA log that expires before the thing it is logging is no log at all
Email correspondence with us24 monthsTo keep track of a conversation, then gone
Records of consent and the version you acceptedFor as long as your account exists, plus 12 monthsTo be able to show what you agreed to

If your membership is paused, nothing is deleted and nothing is archived. Your room and everything in it stays exactly as it is until you come back.

14. Cookies

On the public pages, we set what is needed to count how the site is used, as section 4.7 describes, and there is a one click opt out on every page. No advertising, no tracking pixels, no cross site tracking, no third party fonts.

Once you sign in, the space uses only what is needed to keep you signed in and to take payment safely, plus one thing that is not strictly necessary: if you change how the space looks or reads, we remember that choice so you do not have to set it every time, and there is a switch in your account to turn that off. No counting of any kind happens once you are inside.

The full detail is in the [Cookie Policy].

15. Changes to this notice

If we change this notice we will change the version number and the date at the top, and keep the previous versions available.

If a change materially affects what we do with what you have written, we will tell you by email before it takes effect, and where the law requires it we will ask for your consent again rather than assume it.

16. Getting in touch

Please write to privacy@thetrueself.me, or to Teri Potter t/a The True Self, c/o TWP Accounting, The Old Rectory, Church Street, Weybridge, Surrey KT13 8DE.

A person will read it and a person will answer it.


The True Self · Privacy Notice, for parents and carers · Version 3.0 · [DATE] Related documents: [Terms of Use] · [Village Community Standards] · [Cookie Policy] · [Safeguarding Policy] · [In My Room Privacy Notice]