Privacy

How Lifemax Club handles your data.

A privacy policy nobody can read is a dishonest privacy policy. This one is written plainly, in the first person, because one person runs Lifemax Club and one person is answerable for everything below.

Version 4.1 Last updated 22 September 2026 Controller: Reodan Nathan, Malaysia

I am the data controller for everything described here. There are no staff. If you write to reodannathan@gmail.com, I read it.

Membership is open at $19.99 a month. The free 30-minute call is open too, and it does not take a card. This page describes every part of the system, including the member areas you only reach after paying.

Joining happens on a Stripe Checkout page the site opens for you, and payments are processed for me by Stripe. Stripe handles card data on its own pages under its own privacy policy — card numbers never reach this site, the member service, or me.

00The short version

01What happens when you just open the site

Opening a page does not create a record with me. Three things do happen, and you should know about all three.

Server logs. The site is hosted on Cloudflare Pages and the member service runs on Cloudflare Workers. Cloudflare keeps its own request logs for both — your IP address, the page or endpoint requested, the time, and your browser's user-agent string. These are Cloudflare's logs, on its retention schedule, and I use them for nothing except working out why something broke.

Google Fonts. The public pages load two typefaces from fonts.googleapis.com and fonts.gstatic.com. That request tells Google your IP address and your browser. I get nothing from it and I do not ask Google for anything about you — but the request is real, it leaves your device, and pretending otherwise would be a lie by omission.

Almost nothing is stored on your device. No cookie, and nothing in local or session storage from the member area. Close the tab and the only trace this site leaves in your browser is your own history. Three exceptions. The free quest page, Five Honest Numbers, keeps what you type into its card in your own browser's local storage, so closing the tab halfway does not lose it — it never leaves your device and I never see it. My own control page holds my admin key in session storage while I am signed in — that is my device, not yours. And if you press "Continue with Google", that tab keeps one random value in its session storage for the minute or so the sign-in takes, so the sign-in can only finish in the tab that started it — nobody can send you a finished sign-in of their own. It is deleted the moment it is used, it never leaves your device except to be checked, and it says nothing about you.

Stripe's checkout. Pressing Join sends you to a checkout page on Stripe's own site. Whatever Stripe stores in your browser there is under Stripe's privacy policy, not this one.

02What I collect when you book a call

The booking form asks for five things, and here they are exactly as stored:

Name
Whatever you want me to call you (80 characters)
Country you'll call from
From a list, so I know which time zone you are in
How I reach you
Email · phone/WhatsApp · Instagram · other — your choice
That contact's value
The address, number or handle itself (120 characters)
Anything I should know
Free text, optional (500 characters)

Plus the slot you picked and the time you submitted. If you choose phone, the dial code for your country is added to the front of the number you typed.

Nothing else is captured. No IP address is stored in your booking record. No browser fingerprint. No referrer. The form does not phone anyone else.

The calendar shows that a slot is taken. It never shows who took it. Booked slots are drawn struck through so the site does not make a busy week look like a quiet one, but the only thing sent to your browser is a timestamp.

No automatic email is sent. There is no email service wired into this. I contact you personally, using the method you chose, before your call.

The waiting list is closed. There is no waiting-list form anywhere on the site any more. If you left your email on it before it closed, I still hold that address, the date you left it, and which part of the site you left it on. Nothing else. It is not a newsletter, it is not passed to anyone, and it is deleted the moment you ask.

Do not put medical details in the note box. The question is about what you have already tried and what keeps failing, not your health. If you write something about your health, sexuality, religion, or anything else the law treats as special-category data, I hold it only because you chose to write it — and it is deleted the moment you ask.

03What I hold once you are a member

You join on Stripe's checkout, then you create an account with an email address and a password (or with Google, where that is offered), then you answer six questions and pick a nickname. Your member record, and the few records kept beside it, hold this:

Your name
From checkout, or from you
Your nickname
What you choose to be called in the room. This is the only name other members ever see.
Your email
Used to log in, and how I reach you
Your password
Stored as a hash only — see section 4
How you sign in
Whether the account was made with a password or with Google, when, and when your email address was confirmed — by a code I emailed you, or by Google. If you use Google, also the ID number Google gives your Google account — see section 4
Your access token
22 random characters, generated for you
Your six answers
The onboarding questions, listed below
The date you joined
Set automatically
Your country and time zone
Set in Settings. They show call times on your own clock, and they decide your "next midnight" after a failed quiz — UTC if you have not set one
Your briefing ticks
Which of the 48 briefings you have marked watched yourself
Your quiz record
For each quiz you sit: how many attempts, your last score out of four, when you last sat it, when you may next try, and when you passed. The answers you picked are not stored
Your completed quests
Which quests are complete, when, and how — by quiz, or marked by me after a call — and, if I ever correct a call mark I made by mistake, the date of that correction
Your XP ledger
Which quest was completed and when, the XP it paid, and the bonus for each pillar you complete. Your level is worked out from this every time it is shown; it is not stored on its own
Your avatar
The mark, colour and frame you choose in Settings, stored as three choices from a fixed list. There is no image upload
Your leaderboard setting
Shown or hidden. You are shown unless you hide yourself
Your wins setting
On or off. It is on unless you turn it off
Your notifications
Each one's type, its text — for a reply or a mention, a short quote of what was written — who it came from (nickname and avatar), a link, when, and whether you have read it. Each is deleted automatically 90 days after it is made. Alongside them, a small record of what you have read, which call reminders and briefing notices you have already had, and which wins have already been posted, so nothing is sent twice
Your invite record
Your invite code, and for each person who joins through it: who, when, whether their first month has been paid, and the free months they have earned you — applied or waiting. If you joined through someone's invite, the same record holds whose invite it was and your Stripe subscription and customer references, so I can see when your first month is paid
My note
A short private note I can keep on your record, up to 500 characters. It is part of your own record, so it is not hidden from you; it is never shown to another member
Your to-do items
Whatever you write in your own list
Your posts and comments
Everything you put in the room, including wins posted for you
Your chat messages
What you wrote, in which channel, when, and the nickname you had at the time. Kept in that channel's own storage, not in your member record
Your booked calls
Which slots you took, and when

The six questions. When you join I ask your age; which pillar is your actual problem; what you have already tried that did not stick; how many hours a week you have; what better looks like in twelve weeks; and anything else I should know, which is optional. Only I read these. They are never shown to another member and never shown in the room. Answer them for me, not for an audience.

Briefing ticks are yours and prove nothing. Ticking a briefing off as watched is you telling yourself you watched it. It is stored because it is useful to you, not because it means anything. It pays no XP. I do not treat it as proof and neither should you.

Quizzes, not proof. A quest is completed by passing its quiz — four questions, all four right — or by covering it with me on a call, and I mark it done. Quizzes open in January. Nothing is uploaded and nothing is graded. When you sit a quiz, the record above is all that is kept: counts, a score, times. Which answers you chose is never stored, and a failed attempt tells you how many were right, never which.

Completed quests stay completed. A completed quest is stored against your record with its date and the XP it paid, and it stays yours even if you leave. The same goes for a completed pillar. A quiz completion is never undone. A call mark is undone only if I made it by mistake, and the record keeps the date of that correction rather than quietly editing it away.

Why the game data is held. The XP ledger is how your level and your pillars are shown to you, and it is what the leaderboard, your profile and your wins are drawn from. The avatar, the leaderboard setting and the wins setting exist so you decide how you appear. Your time zone exists so "try again tomorrow" means your tomorrow.

Why invites are recorded. The member who invited you earns a free month when your first month is paid, and not before. To know when that happens I keep whose invite you used and check your subscription with Stripe until the first real payment goes through, or until it is cancelled first. The same check looks for your email address and Stripe customer among current and past members, because the free month is for someone new.

Your to-do list is private. It is stored on your record so it is there when you come back. No other member sees it, and I do not read it. It is a scratchpad, not a submission.

04Your account, your password, and your private link

This is the part that changed, so read it properly.

Your private link is what actually authenticates you. It carries a 22-character token in its address, and that token is the whole of your authentication. Logging in with your email and password does one thing: it recovers that link and hands it back to you. It is not a second factor and it does not add a second lock. Anyone holding the link is you, as far as the system is concerned.

Your password is never stored. What is stored is a PBKDF2-SHA256 hash at 100,000 iterations with a random 16-byte salt unique to you. The password you typed is not written to the record, not written to any log, and never sent back to anyone — including me. I cannot look up your password because there is nothing to look up.

Resetting your password. Where the reset page offers it, you can reset it yourself with a six-digit code emailed to your account address — see "Emailed codes" below. Whether or not it does, you can email me at reodannathan@gmail.com and I send you a link that lets you set a new one. It works once and expires after an hour. Either way, setting a new password clears the lockout your failed attempts caused.

Emailed codes. Where it is switched on, making an account needs a six-digit code I email to the address you give, so nobody can make an account on an address that is not theirs; and the reset page can send one to reset your password. The emails are sent for me by Resend (section 7), which receives your email address and the text of that one email — the code — and nothing else about you. The code is stored only as a keyed hash, works once, and expires after 15 minutes; five wrong tries and it is dead, and no address takes more than ten wrong tries in a day, however many codes it is sent. To stop the codes being used to flood an inbox, I count how many are sent to each address and from each IP address, and those counters expire on their own within an hour; the count of wrong tries against an address is kept for a day, and holds only the times, never what was typed. A half-finished sign-up waiting for its code — the name and address you typed and a hash of your password, never the password — is deleted when the code arrives, or on its own after a day. The reset page gives the same answer whether or not an address has an account, so it cannot be used to find out who is a member. These emails are the only automated email this site sends, and they are never used for anything else.

Continue with Google. Where it is offered, you can sign in with your Google account instead of a password. If you choose it, Google tells me your email address, whether Google has verified it, your name as it is on your Google account, and the ID number Google uses for that account. I keep the ID number and your email address on your record so the same Google account opens the same membership; I use your name only if I do not already have one from checkout. I do not receive your Google password, your contacts, your calendar, your files, your photo, or anything from your inbox, and I cannot post or act as you on Google — the only permission asked for is "openid email profile", which is sign-in and nothing more. While the sign-in is in progress, a one-use record of it sits in the same KV store and expires after 10 minutes; its last step, handing the sign-in back to the tab that started it, is a one-use record that expires after 2 minutes. Google signs you in under its own privacy policy; what it does with the fact that you signed in somewhere is Google's, not mine. You can stop using Google at any time: reset a password by email, or ask me.

Login attempts are rate-limited. To stop somebody guessing their way into an account, failed logins are counted two ways: by the IP address the attempt came from, and by the email address it was made against. Both counters live in the same Cloudflare KV store as your record, and both expire on their own within an hour. Nothing about a login attempt is kept beyond that, and it is never used to profile you or work out where you are.

05What other members can see about you

By default: your nickname and your avatar wherever you appear, and your level and your XP. Here is exactly where, and how to turn each part down.

The room and the chat. The room is where members post, comment, and reply once beneath a comment; the chat is seven channels, General and one per pillar. Everything you write in either is visible to every other member, under your nickname. Write with that in mind — a room is not a private message.

The leaderboard, unless you hide yourself. You are on it by default. It shows your nickname, your avatar, your level and your XP. It never shows your real name, and never a breakdown by pillar. Hiding yourself is one switch in Settings; it works at once, and you can switch back whenever you like.

Your profile. Any member can open it by clicking your nickname or avatar. While you are on the leaderboard it shows your nickname, your avatar, the month you joined, your level, your XP, which pillars you have completed, and how many quests you have completed in all. If you have hidden yourself, it shows only your nickname, your avatar and the month you joined — and the avatar without its frame, because frames are earned by level.

Wins, unless you turn them off. When you complete a pillar or reach a milestone level, a short line saying so — "Completed Health — all 8 lessons.", or "Reached level 10." — is posted to the room under your nickname. That is on by default. Turn it off in Settings and nothing more is posted; turning it back on never posts what happened in between. A win already posted is a post like any other of yours, and you can delete it. Wins are their own switch: hiding yourself from the leaderboard does not stop them.

Mentions and replies. When someone replies to you or writes @ and your nickname, in the room or the chat, you get a notification with a short quote of what they wrote. Nobody else sees your notifications.

If you joined through an invite, the member who invited you is told your nickname when your first paid month earns him his free one, and his invite page counts you. He never sees your real name, your email or your payment details.

Never shown to another member: your real name, your email address, your password or anything derived from it, your private link, your country and time zone, your six onboarding answers, your to-do list, your quiz attempts and scores, which individual quests you have completed, your XP by pillar, your briefing ticks, your notifications, your booked calls, and my note on your record.

There is no public wall. Nothing in the room, the chat, the leaderboard or a profile is visible to the open internet — only to members who are signed in.

I can delete anything in the room or the chat. A post, a comment, a reply, a message — mine or yours. There is no appeal process and I am not going to pretend there is one.

06Live calls and recordings

Calls run on Zoom. Zoom sees your name as you enter it, your audio, your video if you turn it on, and your IP address, under its own privacy policy. There are two kinds: the one-to-one calls you book from the diary, as many as there are free slots, and the weekly community call open to every member.

Nothing said in a crisis or a private disclosure is ever recorded, quoted, or repeated anywhere.

07Who else touches your data

Cloudflare, Inc.
Hosts the website files on Cloudflare Pages, runs the booking and member service, stores every record in Workers KV — including your password hash and the login rate-limit counters — and keeps the chat, and the emailed codes with their counters, in Durable Objects. Sees everything in sections 2, 3 and 4, plus request logs: IP, page, time, browser.
Google LLC
Serves two typefaces on the public pages, and hosts my email. Sees your IP and browser on page load, and whatever you write to me. If you choose "Continue with Google", runs that sign-in and tells me what section 4 lists.
Resend
Sends the six-digit sign-up and password-reset codes, where emailed codes are switched on. Sees your email address and the text of that email, and nothing else.
Stripe, Inc.
Runs the checkout page the site sends you to, takes the payment, runs an invited friend's 30-day free month and applies the free months invites earn. Sees your name, email and card details — on Stripe's pages, not mine. I read back from it whether a payment went through.
Zoom Video Communications
Hosts the live calls. Sees your display name, audio, video and IP.

I do not sell your data. I do not share it for advertising. I have never run an ad pixel and there is no list to sell you to.

Your data is held outside the EU, and it leaves your country. I am in Malaysia and that is where I read it. Cloudflare runs a global network. Stripe, Google, Resend and Zoom are American companies. Each of these providers publishes data-processing terms incorporating the European Commission's Standard Contractual Clauses, and those clauses are what these transfers rest on. If you want the current links, ask and I will send them.

08How long I keep things

The things that leave the system without me doing it by hand are the ones section 00 names: the login rate-limit counters, the seven-day payment reference, the one-minute quiz marker, your notifications after 90 days, and the short-lived sign-in records. Nothing else deletes itself. Everything else below is a commitment I keep by hand, and I would rather say that than imply machinery I have not built.

Booking records — call happened
90 days after the call, then deleted
Booking records — call didn't happen
30 days, then deleted
Waiting-list email, from before the list closed
Until I have told you the first pillar's briefings are filmed, or until you ask me to remove it — whichever comes first
Your member record, while a member
For as long as you are one
Your member record, after you leave
Kept, so you can come back to it and so the dates on your passes stay true. Deleted the day you ask me to delete it, and not before
Your password hash and salt
Deleted with your record
Your quiz record, completed quests, XP ledger, avatar, time zone and settings
Part of your member record — kept and deleted with it, as above
My note on your record
Deleted with your record
Your notifications
90 days each — they expire on their own. The small record of what you have read and been sent is deleted with your record
Your invite record
Deleted with your record. A free month already earned or applied stays earned
Your to-do items
Deleted with your record, or on request at any time
Your posts and comments in the room, wins included
Deleted on request, or by you; otherwise they stay in the room
Your chat messages
They stay in their channel until you ask me to remove them, or I do. Removing a message hides it from every member at once, but its text stays in that channel's storage, where only I can reach it. I would rather tell you that than call it deleted
Login rate-limit counters
Under an hour — these expire on their own
An emailed sign-up or reset code
15 minutes, or the moment it is used
A sign-up waiting for its code
One day, or the moment the code arrives
Code-sending counters
Under an hour — these expire on their own
Wrong code tries against an address
One day — the times only, never what was typed
A Google sign-in in progress
10 minutes, or the moment it finishes
Your Google account ID
Kept with your record, and deleted with it
The quiz marker
One minute — it exists only while an answer is being marked
Recordings that include you
Removed within 7 days of you asking
Anything you emailed me
Deleted with your record, unless a tax or legal record needs it
Payment records
7 years — a tax obligation, not a choice. Held by Stripe and by me.

Deleting a post, a message or a to-do item does not rewrite your record. Your completed quests, their dates and the XP they paid stand and say what they said. The system does not make you choose between your privacy and your own record.

09Why I'm allowed to hold it

If the UK GDPR or the EU GDPR applies to you, this is the ground I rely on for each thing:

Your booking details
Contract — steps you asked me to take before a contract, Art. 6(1)(b)
Member record, account, country and time zone, quiz record, completed quests and XP ledger
Contract — I cannot run the school without them, Art. 6(1)(b)
Your avatar
Contract — it is part of how the member area shows you your own record, Art. 6(1)(b)
Your posts, comments and chat messages, and your notifications
Contract — the room, the chat and the bell are part of what you join, Art. 6(1)(b)
Showing you on the leaderboard and your profile, and posting your wins
Legitimate interests — a room where members can see who is doing the work is part of what you join. The two switches in Settings are your objection, and they take effect at once, Art. 6(1)(f)
Invite records
Contract — the offer the two of you took up, Art. 6(1)(b); and legitimate interests for checking that an invited friend is new, Art. 6(1)(f)
Your six onboarding answers
Contract — they are how I make the thing useful to you, Art. 6(1)(b)
Payment and billing records
Contract, and legal obligation for the tax records, Art. 6(1)(b) and (c)
Password hash and login rate limiting
Legitimate interests — keeping other people out of your account, Art. 6(1)(f)
Emailed codes, and signing in with Google
Contract — letting you into the account you paid for, Art. 6(1)(b); and legitimate interests for confirming an address is really yours and limiting how often codes are sent, Art. 6(1)(f)
Server and request logs
Legitimate interests — running and defending a working service, Art. 6(1)(f)
Google Fonts
Legitimate interests — serving the page as built, Art. 6(1)(f)
A waiting-list email left before the list closed
Consent — you gave it to be told one thing, Art. 6(1)(a)
Recording anything with you in it
Consent, asked per session, withdrawable at any time, Art. 6(1)(a)
Anything sensitive you volunteer
Explicit consent only, Art. 9(2)(a) — withdraw it and I delete it

Withdrawing consent, or objecting, does not undo what was lawful before. It stops everything after.

10Your rights, and how to use them

If you are in the UK or the EU, you can ask me to: give you a copy of everything I hold on you; correct anything wrong; delete it; stop or limit what I do with it; hand it to you in a machine-readable form; or object to anything I do on legitimate-interests grounds. You can withdraw consent to a recording at any moment. You can complain to your national data protection authority — in the UK, the Information Commissioner's Office at ico.org.uk.

If you are in Malaysia, the Personal Data Protection Act 2010 gives you the right to make a data access request and a data correction request. I do not charge a fee for either. You can complain to the Personal Data Protection Department (JPDP) under the Ministry of Digital.

Everyone else: ask me for the same things. I am not going to check your passport before answering a reasonable request.

Where the two regimes differ, I apply the stricter one to everybody. The PDPA does not give a general right to erasure; I give you one anyway.

To ask for something, email reodannathan@gmail.com and say what you want. You do not need a form, a subject line, or a reason.

I answer within 30 days, and in practice usually the same week. Deleting your data is not the same as cancelling your subscription, and cancelling is not the same as deleting your data — ask for whichever one you actually want, or both.

11Marketing

I do not run a mailing list. There is no newsletter, no automated sequence, and no "we may contact you about offers" clause. The only automated email this site sends is a sign-in code you asked for, and it carries nothing else. The waiting list, now closed, was only ever for telling you one thing once — that the first pillar's briefings are filmed. I will not use your data for direct marketing, and I will not pass it to anyone else for theirs. If that ever changes, I will ask you first, and Malaysia's PDPA requires me to.

Invites are yours to send. Your invite link is something you choose to pass on. I never contact the people you send it to, and nothing about them reaches my records unless they join.

12Younger members

Lifemax Club has no age limit. What I hold about a younger member is exactly what I hold about anyone else — the list in section 3, and nothing extra. One of the six onboarding questions asks your age, and that is the only reason I know it.

Two things I ask rather than enforce. If you are under 18, tell a parent or guardian you have joined before your first call. And if a parent or guardian asks me what I hold about you, or asks me to delete it, I will do it — the same way I would if you asked me yourself.

Nothing on this site is written for children, and nothing here is a substitute for the people responsible for you. If you need someone right now, the numbers on the help page are free, staffed, and open to anyone of any age.

13Security, and what I will not claim

What is true:

What I will not claim: this is one person's system. There is no security team, no SOC 2 report, no penetration test and no bug bounty.

Your password protects the recovery of your link. It does not protect the link itself. The link is the key, and a key that travels in a web address is a key that can be forwarded, screenshotted, and left in a browser history. I am telling you that plainly instead of calling this "secure login".

A set of member records in a key-value store is a small target defended by a small amount of machinery, and the honest summary is that it is competently built rather than institutionally hardened. Do not put anything in the room, the chat, or your to-do list that you could not survive being read.

If something leaks in a way that could hurt you, I tell you and I tell the relevant regulator — within 72 hours where the law requires it. I do not sit on it and I do not wait to see if anyone notices.

14Changes to this page

If I change what I collect, who touches it, or how long I keep it, I update this page, change the date at the top, and tell every current member directly. I will not make a material change quietly and rely on you re-reading a page you have already read.

Version 2.0 is a material change. Version 1.0 described a school with paths, cohorts and no accounts, and it said in two places that there were no passwords. There are now. Sections 3, 4, 5 and 13 are where the difference lives.

Version 3.0 is a material change too. PROTOCOL is now called Lifemax Club, and four things are added to what I hold: your avatar, your leaderboard setting, your XP ledger, and quest proof with my notes on it. The leaderboard is new, and it is opt-in. One-to-one calls are no longer earned — you book as many as the diary has free slots. The website moved from Netlify to Cloudflare Pages, so Netlify no longer handles anything of yours. Version 2.0 also gave the password hash as 210,000 iterations; the real figure is 100,000, and sections 4 and 13 now say so. Sections 0, 1, 2, 3, 5, 6, 7, 8, 9, 10 and 11 are where the rest of the difference lives.

Version 4.0 is a material change as well. Proof filing, which version 3.0 said would open in January, is gone: a quest is completed by a quiz or on a call, and a quiz keeps your attempts and score, never your answers. The leaderboard is now shown by default instead of opt-in — hide yourself in Settings at any time — and I tell every current member directly, as this section promises. New here: member profiles, wins posted to the room, notifications and their 90-day expiry, invite records, your country and time zone, and my note on your record. Joining now runs through a Stripe Checkout page the site opens rather than a payment link. This page also now says what it should have said before: the chat is kept in Cloudflare Durable Objects, and the free quest page keeps what you type in your own browser. Sections 0, 1, 3, 4, 5, 7, 8, 9, 10, 11 and 13 are where the difference lives.

Version 4.1 adds two ways into your account, each of which works only once I have switched it on: "Continue with Google", and six-digit codes emailed through Resend to confirm your address and to reset a password. It also says that the waiting list is closed. Sections 0, 1, 2, 3, 4, 7, 8, 9, 10 and 11 are where the difference lives.

15Contact

Reodan Nathan, sole proprietor · Malaysia
reodannathan@gmail.com

One person. No staff. No ticket queue.