Privacy Policy
How Matrix Codes / Matilda collects, uses, shares, and protects personal data across the app, events, referrals, payments, and support.
Last updated: 8 May 2026
1. Who We Are
Matrix Codes / Matilda provides educational personal-development tools, assessments, events, memberships, and related support.
For the purposes of UK data protection law, Matrix Codes is the controller of the personal data described in this policy unless this page says otherwise.
2. What This Policy Covers
This policy explains how we handle personal data collected through our website, public event pages, app, referrals and affiliate programme, paid offers, support channels, community features, and related internal tools.
It is written with UK GDPR, the Data Protection Act 2018, and PECR in mind. If you use the service from outside the UK, equivalent local laws may also apply.
3. Privacy Contact
For privacy requests or questions, contact us through our Contact page.
If you contact us about privacy, please include enough detail for us to identify your account and understand your request.
4. Age Policy
Matilda is for adults aged 18 and over. The service is not aimed at children and should not be used by anyone under 18.
If we learn that we have collected personal data from a child in a way that should not have happened, we will take reasonable steps to delete or restrict that data as appropriate.
5. Personal Data We Collect
We may collect account and contact data such as your name, email address, login details, and account metadata.
We may collect profile and onboarding data such as your display name, profile details, onboarding responses, preferences, and access settings.
We may collect assessment and progress data such as your assessment answers, self-rated and tested scores, Hidden Gap outputs, spider charts, roadmaps, reports, and related progress signals.
We may collect session and journey data such as issue text, session inputs, codes, beliefs, emotions, rewrites, ratings, session summaries, journey activity, and progress history saved to your account.
We may collect AI interaction data such as prompts, context, outputs, and limited technical usage data needed to generate assessments, sessions, summaries, and related features.
We may collect event data such as registration details, attendance-related records, VIP ticket access, replay access, chat or Q&A content, reminder status, and event support interactions where those features are used.
We may collect community, messaging, support, and internal review data such as community posts, private messages, attachments, support requests, moderation records, and internal admin notes where used.
We may collect referral and affiliate data such as referral codes, referral attribution, reward records, PayPal payout email, commission ledger entries, payout history, fraud-review records, and related tax or compliance information if needed.
We may collect payment and subscription data such as Stripe customer, subscription, invoice, checkout, and payment references, but we do not store full card details on our servers.
We may collect marketing and attribution data such as email capture details, communication preferences, referral links, UTM-style source information, and similar campaign attribution data.
We may collect technical and security data such as browser or device information, IP-derived information, logs, error data, timestamps, and anti-abuse or fraud signals.
6. Why We Use Personal Data
We use personal data to create and manage accounts, deliver app features, save your progress, and provide assessments, sessions, roadmaps, journeys, events, and paid access.
We use personal data to generate AI-assisted outputs, provide support, moderate community features, operate referrals and affiliate payouts, prevent fraud or misuse, send service messages, improve the product, and meet legal, accounting, tax, and compliance obligations.
Where allowed, we may also use personal data to send marketing communications or event follow-up. Marketing can be turned off using unsubscribe tools or by contacting us.
7. Lawful Bases
We usually process personal data because it is necessary to perform our contract with you, for example to run your account, provide paid access, save session history, process payments, or manage event registration.
We also process data where necessary for our legitimate interests, including service administration, security, fraud prevention, product improvement, support, moderation, referral attribution, and business operations, provided those interests are not overridden by your rights.
We rely on consent where required, for example for certain marketing activity or non-essential cookies or similar technologies where consent is legally needed.
We may also process personal data to comply with legal obligations, including accounting, tax, payment, and law-enforcement or regulatory requirements.
8. AI Processing
Some user inputs may be processed by AI providers to generate responses, assessment interpretations, session outputs, summaries, or related features.
AI outputs are provided for educational and informational purposes only. They are not therapy, crisis support, diagnosis, medical advice, financial advice, legal advice, or tax advice.
Please do not use Matilda for emergencies or crisis situations, and do not rely on the service as a substitute for qualified professional help.
9. Sharing and Service Providers
We share personal data with service providers where needed to operate the service, including Supabase for database, auth, storage, and related infrastructure, Stripe for payments and subscriptions, and OpenAI or other AI providers for supported AI features.
We may also use Airtable for internal content or operational workflows, GoHighLevel or similar CRM/webhook tools for event or marketing operations, PayPal as a payout destination for affiliate commissions, hosting and infrastructure providers, analytics or anti-abuse tools where added, and professional advisers such as lawyers, accountants, auditors, or insurers.
We may disclose data where required to regulators, tax authorities, payment providers, law enforcement, courts, or other third parties where the law requires it or where reasonably necessary to protect rights, safety, or the integrity of the service.
10. International Transfers
Some of our service providers may process personal data outside the UK. Where that happens, we take reasonable steps to ensure appropriate safeguards are used as required by law.
This may include contracts, transfer mechanisms, or other recognised safeguards appropriate to the type of transfer and provider involved.
11. Cookies, Local Storage, and Tracking
We use cookies and similar browser storage, including localStorage and sessionStorage, for essential account and product functions, referral attribution, event flow continuity, preferences, and limited operational tracking.
See our Cookie Policy for more detail.
12. Marketing and Unsubscribe
We may send service communications needed to run your account, event registration, purchases, security, billing, or support. These are not the same as optional marketing.
Where marketing is sent, we will do so where permitted by law and you can unsubscribe using the link in the message or by contacting us.
13. Retention
We generally keep account and profile data while your account remains active and for a reasonable period afterwards where needed for support, security, dispute resolution, or lawful business records.
Payment, accounting, subscription, payout, commission, and fraud-review records may be kept for longer where needed for accounting, tax, legal, compliance, fraud-prevention, or audit reasons.
Assessment, session, journey, event, support, moderation, and admin records may be kept while relevant to the service relationship and for a reasonable period afterwards unless deleted sooner, subject to legal or operational limits.
14. Your Rights
Depending on the law that applies, you may have rights to request access, correction, deletion, restriction, objection, portability, and withdrawal of consent where processing depends on consent.
You may also complain to the UK Information Commissioner's Office if you believe your personal data has been handled unlawfully.
15. Limits on Deletion
Deletion is not always absolute. We may need to keep some data where required for accounting, fraud prevention, security, legal claims, payment records, tax reporting, compliance, or to enforce our agreements.
Where full deletion is not possible, we may restrict further use and retain only what is reasonably necessary for those purposes.
16. Security
We use administrative, technical, and organisational measures intended to reduce the risk of unauthorised access, loss, misuse, or disclosure.
No online service can promise absolute security, and you are also responsible for protecting your password and account access.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version here and may update the effective date.
Your continued use of the service after an update may mean the updated policy applies, to the extent permitted by law.