Designed to Heal 360 — Privacy Notice
Effective Date: September 5, 2026 · Last Updated: September 5, 2026
This notice explains what personal information Designed to Heal 360 collects, why we collect it, who we share it with, how long we keep it and what rights you have.
1. Who we are
Designed to Heal 360 is operated by Lea Curley (trading as Designed to Heal 360), based in the State of Texas, United States.
Lea Curley is the data controller for personal information collected through the Designed to Heal 360 application and website, and decides how and why that information is processed.
You can reach us with any privacy question through the contact method provided within the application.
2. Information we collect
Depending on how you use Designed to Heal 360, we may collect:
- Account information — your email address, name or display name, password credentials (stored in hashed form by our authentication provider), and sign-in method.
- Profile and personalization — the pathway you choose (health, faith or both), conditions or sensitivities you record, allergen exclusions, reminder times and preferences.
- Wellness content you create — check-ins, symptom and lifestyle ratings, journal entries, reflections, saved Scriptures, prayer requests, meal plans, favourites and course progress.
- Community content — posts, comments, prayer reactions and kindness offers you choose to share in a circle.
- Support and correspondence — messages you send us, including reports of content or copyright concerns.
- Technical and usage data — IP address, device and browser type, approximate location derived from IP, pages viewed, and error/diagnostic logs.
- Purchase records — the membership plan, subscription status, billing period and payment provider identifiers. We do not collect or store your card number.
3. Why we use it, and our legal basis
Providing your account, saving your check-ins, journal and other content, and delivering the features you have selected — performance of our contract with you.
Personalizing your experience (meal suggestions, learning content, pathway-aware daily content) — performance of our contract with you.
Processing memberships, renewals, cancellations and refunds through our payment provider — performance of our contract with you and compliance with legal obligations such as tax and accounting.
Security, fraud prevention, abuse and moderation of community areas — our legitimate interests in keeping the service and its members safe.
Improving and troubleshooting the service using aggregated or diagnostic data — our legitimate interests in operating a reliable product.
Sending optional reminders, product updates or marketing where you have opted in — your consent, which you can withdraw at any time.
Meeting legal, regulatory or law-enforcement obligations — compliance with a legal obligation.
Health-related information you enter is treated as sensitive. We process it only to provide the tracking and reflection features you have chosen to use — that is, on the basis of your explicit consent, given by choosing to record it. You may delete individual entries or your whole account at any time.
4. Who we share it with
We do not sell your personal information. We share it only with:
- Paddle.com Market Ltd — our Merchant of Record and payment processor. Paddle handles checkout, payments, subscription billing, sales tax, invoicing, returns and payment-related customer service, and acts as an independent controller for that data. See paddle.com/legal/privacy.
- Hosting and infrastructure providers, including Supabase (database, authentication and storage) and Cloudflare (hosting and content delivery), acting as our processors.
- AI service providers used to power optional AI-assisted features, which process only the content needed to generate a response and do not receive your account credentials.
- Email delivery providers used for account, security and reminder messages.
- Professional advisers such as legal and accounting advisers, where necessary.
- Authorities or third parties where required by law, or to protect the rights, safety or property of Designed to Heal 360, our members or the public.
- A successor entity, if the business is transferred, merged or acquired.
5. International transfers
Designed to Heal 360 is operated from the United States, and our providers may process data in the United States and other countries.
Where personal information is transferred from the United Kingdom or European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision.
6. How long we keep it
Account, profile and wellness content is kept for as long as your account remains open, so your history stays available to you.
If you delete your account, your personal content is deleted or anonymised, ordinarily within 30 days, except where we must keep records longer.
Purchase and tax records are retained for the period required by law (generally up to 7 years).
Security and diagnostic logs are typically retained for up to 12 months.
7. Your rights
Subject to the law where you live, you may request access to the personal information we hold about you, correction of inaccurate information, deletion, restriction of or objection to processing, a portable copy of information you provided, and withdrawal of any consent you gave.
You can edit or delete most of your content directly in the app, and delete your whole account from the You page.
To exercise any right, contact us through the support method within the application. We aim to respond within one month.
If you are in the UK or EEA, you also have the right to complain to your local supervisory authority. Residents of some US states, including Texas and California, have similar rights and will not be discriminated against for exercising them.
8. Security
We use appropriate technical and organisational measures, including encryption in transit, encrypted storage, row-level database security so members can only reach their own records, role-restricted administrative access and audit logging of administrative actions.
Administrators cannot read your private journal entries or private health records.
No method of transmission or storage is completely secure, so please use a strong, unique password and avoid posting information publicly that you would not want other members to see.
9. Cookies and similar technologies
We use strictly necessary cookies and local browser storage to keep you signed in, remember your preferences and keep the service secure. These are required for the app to work.
Our payment provider may set cookies needed to operate the checkout and prevent fraud.
We do not use advertising cookies. If we later add analytics or marketing cookies, we will ask for your consent first and provide controls to manage them. You can also clear or block cookies in your browser, though signing in may then stop working.
10. Children
Designed to Heal 360 is intended for adults. It is not directed at children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information to us, please contact us and we will delete it.
11. Changes to this notice
We may update this notice as the service evolves. When we make material changes, we will update the date above and, where appropriate, notify you within the application.
© 2026 Léa Curley. Designed to Heal 360™. All rights reserved.