How Lifemax Club handles your data.
A privacy policy nobody can read is a dishonest privacy policy. This one is written plainly, in the first person, because one person runs Lifemax Club and one person is answerable for everything below.
I am the data controller for everything described here. There are no staff. If you write to reodannathan@gmail.com, I read it.
Membership is open at $19.99 a month. The free 30-minute call is open too, and it does not take a card. This page describes every part of the system, including the member areas you only reach after paying.
Joining happens on a Stripe Checkout page the site opens for you, and payments are processed for me by Stripe. Stripe handles card data on its own pages under its own privacy policy — card numbers never reach this site, the member service, or me.
00The short version
- The site sets no cookies, runs no analytics, and carries no tracking pixel, tag manager, session recorder or heatmap. There is no advertising script on any page.
- The public pages make two off-site requests: Google Fonts, and my own service on Cloudflare when you open the calendar or press Join — which then sends you on to Stripe's own checkout page. On the member pages, "Continue with Google" sends you to Google's own sign-in page. All of it is named and explained below.
- Everything I store about you sits with Cloudflare: one Workers KV store holds your record and nearly everything else, and the chat is kept in Cloudflare Durable Objects, one per channel — as are the emailed sign-in codes and their counters, one per email address, where codes are switched on. There is no other database.
- Membership now has an account: an email address and a password — or, where it is offered, your Google account instead of a password. The password is stored only as a hash. An earlier version of this page said there were no accounts and no passwords. That is no longer true, and section 4 says exactly what changed.
- Some of it is shown to other members by default: your nickname and avatar wherever you appear; your level and XP on the leaderboard and on your profile; and a line in the room when you complete a pillar or reach a milestone level. One switch in Settings takes you off the leaderboard and cuts your profile down to your nickname, avatar and join month; another stops the wins. Section 5 is the whole list.
- Nothing is uploaded and nothing is graded. Quests are completed by a quiz or on a call with me. There is no proof box, and nothing in the member area takes a file or a photo.
- Almost nothing expires on its own. These do: the login rate-limit counters, within an hour; the payment reference created during signup, after seven days; a one-minute marker that stops two answers to the same quiz being marked at once; your notifications, after 90 days; and the short-lived sign-in records in section 4 — an emailed code after 15 minutes, a half-finished sign-up after a day, the code-sending counters within an hour, the count of wrong code tries after a day, and a Google sign-in in progress after 10 minutes. Everything else is deletion I do by hand, on request. I say so rather than pretend a cron job exists.
- Where Malaysia's PDPA and the UK/EU rules disagree, I hold myself to the stricter one.
01What happens when you just open the site
Opening a page does not create a record with me. Three things do happen, and you should know about all three.
Server logs. The site is hosted on Cloudflare Pages and the member service runs on Cloudflare Workers. Cloudflare keeps its own request logs for both — your IP address, the page or endpoint requested, the time, and your browser's user-agent string. These are Cloudflare's logs, on its retention schedule, and I use them for nothing except working out why something broke.
Google Fonts. The public pages load two typefaces from fonts.googleapis.com and
fonts.gstatic.com. That request tells Google your IP address and your browser. I get nothing
from it and I do not ask Google for anything about you — but the request is real, it leaves your device,
and pretending otherwise would be a lie by omission.
Almost nothing is stored on your device. No cookie, and nothing in local or session storage from the member area. Close the tab and the only trace this site leaves in your browser is your own history. Three exceptions. The free quest page, Five Honest Numbers, keeps what you type into its card in your own browser's local storage, so closing the tab halfway does not lose it — it never leaves your device and I never see it. My own control page holds my admin key in session storage while I am signed in — that is my device, not yours. And if you press "Continue with Google", that tab keeps one random value in its session storage for the minute or so the sign-in takes, so the sign-in can only finish in the tab that started it — nobody can send you a finished sign-in of their own. It is deleted the moment it is used, it never leaves your device except to be checked, and it says nothing about you.
Stripe's checkout. Pressing Join sends you to a checkout page on Stripe's own site. Whatever Stripe stores in your browser there is under Stripe's privacy policy, not this one.
02What I collect when you book a call
The booking form asks for five things, and here they are exactly as stored:
- Name
- Whatever you want me to call you (80 characters)
- Country you'll call from
- From a list, so I know which time zone you are in
- How I reach you
- Email · phone/WhatsApp · Instagram · other — your choice
- That contact's value
- The address, number or handle itself (120 characters)
- Anything I should know
- Free text, optional (500 characters)
Plus the slot you picked and the time you submitted. If you choose phone, the dial code for your country is added to the front of the number you typed.
Nothing else is captured. No IP address is stored in your booking record. No browser fingerprint. No referrer. The form does not phone anyone else.
The calendar shows that a slot is taken. It never shows who took it. Booked slots are drawn struck through so the site does not make a busy week look like a quiet one, but the only thing sent to your browser is a timestamp.
No automatic email is sent. There is no email service wired into this. I contact you personally, using the method you chose, before your call.
The waiting list is closed. There is no waiting-list form anywhere on the site any more. If you left your email on it before it closed, I still hold that address, the date you left it, and which part of the site you left it on. Nothing else. It is not a newsletter, it is not passed to anyone, and it is deleted the moment you ask.
Do not put medical details in the note box. The question is about what you have already tried and what keeps failing, not your health. If you write something about your health, sexuality, religion, or anything else the law treats as special-category data, I hold it only because you chose to write it — and it is deleted the moment you ask.
03What I hold once you are a member
You join on Stripe's checkout, then you create an account with an email address and a password (or with Google, where that is offered), then you answer six questions and pick a nickname. Your member record, and the few records kept beside it, hold this:
- Your name
- From checkout, or from you
- Your nickname
- What you choose to be called in the room. This is the only name other members ever see.
- Your email
- Used to log in, and how I reach you
- Your password
- Stored as a hash only — see section 4
- How you sign in
- Whether the account was made with a password or with Google, when, and when your email address was confirmed — by a code I emailed you, or by Google. If you use Google, also the ID number Google gives your Google account — see section 4
- Your access token
- 22 random characters, generated for you
- Your six answers
- The onboarding questions, listed below
- The date you joined
- Set automatically
- Your country and time zone
- Set in Settings. They show call times on your own clock, and they decide your "next midnight" after a failed quiz — UTC if you have not set one
- Your briefing ticks
- Which of the 48 briefings you have marked watched yourself
- Your quiz record
- For each quiz you sit: how many attempts, your last score out of four, when you last sat it, when you may next try, and when you passed. The answers you picked are not stored
- Your completed quests
- Which quests are complete, when, and how — by quiz, or marked by me after a call — and, if I ever correct a call mark I made by mistake, the date of that correction
- Your XP ledger
- Which quest was completed and when, the XP it paid, and the bonus for each pillar you complete. Your level is worked out from this every time it is shown; it is not stored on its own
- Your avatar
- The mark, colour and frame you choose in Settings, stored as three choices from a fixed list. There is no image upload
- Your leaderboard setting
- Shown or hidden. You are shown unless you hide yourself
- Your wins setting
- On or off. It is on unless you turn it off
- Your notifications
- Each one's type, its text — for a reply or a mention, a short quote of what was written — who it came from (nickname and avatar), a link, when, and whether you have read it. Each is deleted automatically 90 days after it is made. Alongside them, a small record of what you have read, which call reminders and briefing notices you have already had, and which wins have already been posted, so nothing is sent twice
- Your invite record
- Your invite code, and for each person who joins through it: who, when, whether their first month has been paid, and the free months they have earned you — applied or waiting. If you joined through someone's invite, the same record holds whose invite it was and your Stripe subscription and customer references, so I can see when your first month is paid
- My note
- A short private note I can keep on your record, up to 500 characters. It is part of your own record, so it is not hidden from you; it is never shown to another member
- Your to-do items
- Whatever you write in your own list
- Your posts and comments
- Everything you put in the room, including wins posted for you
- Your chat messages
- What you wrote, in which channel, when, and the nickname you had at the time. Kept in that channel's own storage, not in your member record
- Your booked calls
- Which slots you took, and when
The six questions. When you join I ask your age; which pillar is your actual problem; what you have already tried that did not stick; how many hours a week you have; what better looks like in twelve weeks; and anything else I should know, which is optional. Only I read these. They are never shown to another member and never shown in the room. Answer them for me, not for an audience.
Briefing ticks are yours and prove nothing. Ticking a briefing off as watched is you telling yourself you watched it. It is stored because it is useful to you, not because it means anything. It pays no XP. I do not treat it as proof and neither should you.
Quizzes, not proof. A quest is completed by passing its quiz — four questions, all four right — or by covering it with me on a call, and I mark it done. Quizzes open in January. Nothing is uploaded and nothing is graded. When you sit a quiz, the record above is all that is kept: counts, a score, times. Which answers you chose is never stored, and a failed attempt tells you how many were right, never which.
Completed quests stay completed. A completed quest is stored against your record with its date and the XP it paid, and it stays yours even if you leave. The same goes for a completed pillar. A quiz completion is never undone. A call mark is undone only if I made it by mistake, and the record keeps the date of that correction rather than quietly editing it away.
Why the game data is held. The XP ledger is how your level and your pillars are shown to you, and it is what the leaderboard, your profile and your wins are drawn from. The avatar, the leaderboard setting and the wins setting exist so you decide how you appear. Your time zone exists so "try again tomorrow" means your tomorrow.
Why invites are recorded. The member who invited you earns a free month when your first month is paid, and not before. To know when that happens I keep whose invite you used and check your subscription with Stripe until the first real payment goes through, or until it is cancelled first. The same check looks for your email address and Stripe customer among current and past members, because the free month is for someone new.
Your to-do list is private. It is stored on your record so it is there when you come back. No other member sees it, and I do not read it. It is a scratchpad, not a submission.
04Your account, your password, and your private link
This is the part that changed, so read it properly.
Your private link is what actually authenticates you. It carries a 22-character token in its address, and that token is the whole of your authentication. Logging in with your email and password does one thing: it recovers that link and hands it back to you. It is not a second factor and it does not add a second lock. Anyone holding the link is you, as far as the system is concerned.
- Someone with your link can read your name, your email, your six answers, your completed quests, quiz record and XP, your notifications, your invite link, your to-do list and your calls — and can post and chat as you.
- The link will sit in your browser history, and in whatever app I sent it to you in.
- Do not screenshot the address bar and do not paste the link anywhere.
- The member area is marked
noindex, nofollowand sends no referrer, so the token is not handed to any site you click through to. Neither of those protects you from forwarding it yourself. - The token travels in the web address, which means it can appear in Cloudflare's request logs.
- Lost it, or think somebody else has it? Tell me. I close it and issue a new one the same day.
Your password is never stored. What is stored is a PBKDF2-SHA256 hash at 100,000 iterations with a random 16-byte salt unique to you. The password you typed is not written to the record, not written to any log, and never sent back to anyone — including me. I cannot look up your password because there is nothing to look up.
Resetting your password. Where the reset page offers it, you can reset it yourself with a six-digit code emailed to your account address — see "Emailed codes" below. Whether or not it does, you can email me at reodannathan@gmail.com and I send you a link that lets you set a new one. It works once and expires after an hour. Either way, setting a new password clears the lockout your failed attempts caused.
Emailed codes. Where it is switched on, making an account needs a six-digit code I email to the address you give, so nobody can make an account on an address that is not theirs; and the reset page can send one to reset your password. The emails are sent for me by Resend (section 7), which receives your email address and the text of that one email — the code — and nothing else about you. The code is stored only as a keyed hash, works once, and expires after 15 minutes; five wrong tries and it is dead, and no address takes more than ten wrong tries in a day, however many codes it is sent. To stop the codes being used to flood an inbox, I count how many are sent to each address and from each IP address, and those counters expire on their own within an hour; the count of wrong tries against an address is kept for a day, and holds only the times, never what was typed. A half-finished sign-up waiting for its code — the name and address you typed and a hash of your password, never the password — is deleted when the code arrives, or on its own after a day. The reset page gives the same answer whether or not an address has an account, so it cannot be used to find out who is a member. These emails are the only automated email this site sends, and they are never used for anything else.
Continue with Google. Where it is offered, you can sign in with your Google account instead of a password. If you choose it, Google tells me your email address, whether Google has verified it, your name as it is on your Google account, and the ID number Google uses for that account. I keep the ID number and your email address on your record so the same Google account opens the same membership; I use your name only if I do not already have one from checkout. I do not receive your Google password, your contacts, your calendar, your files, your photo, or anything from your inbox, and I cannot post or act as you on Google — the only permission asked for is "openid email profile", which is sign-in and nothing more. While the sign-in is in progress, a one-use record of it sits in the same KV store and expires after 10 minutes; its last step, handing the sign-in back to the tab that started it, is a one-use record that expires after 2 minutes. Google signs you in under its own privacy policy; what it does with the fact that you signed in somewhere is Google's, not mine. You can stop using Google at any time: reset a password by email, or ask me.
Login attempts are rate-limited. To stop somebody guessing their way into an account, failed logins are counted two ways: by the IP address the attempt came from, and by the email address it was made against. Both counters live in the same Cloudflare KV store as your record, and both expire on their own within an hour. Nothing about a login attempt is kept beyond that, and it is never used to profile you or work out where you are.
05What other members can see about you
By default: your nickname and your avatar wherever you appear, and your level and your XP. Here is exactly where, and how to turn each part down.
The room and the chat. The room is where members post, comment, and reply once beneath a comment; the chat is seven channels, General and one per pillar. Everything you write in either is visible to every other member, under your nickname. Write with that in mind — a room is not a private message.
The leaderboard, unless you hide yourself. You are on it by default. It shows your nickname, your avatar, your level and your XP. It never shows your real name, and never a breakdown by pillar. Hiding yourself is one switch in Settings; it works at once, and you can switch back whenever you like.
Your profile. Any member can open it by clicking your nickname or avatar. While you are on the leaderboard it shows your nickname, your avatar, the month you joined, your level, your XP, which pillars you have completed, and how many quests you have completed in all. If you have hidden yourself, it shows only your nickname, your avatar and the month you joined — and the avatar without its frame, because frames are earned by level.
Wins, unless you turn them off. When you complete a pillar or reach a milestone level, a short line saying so — "Completed Health — all 8 lessons.", or "Reached level 10." — is posted to the room under your nickname. That is on by default. Turn it off in Settings and nothing more is posted; turning it back on never posts what happened in between. A win already posted is a post like any other of yours, and you can delete it. Wins are their own switch: hiding yourself from the leaderboard does not stop them.
Mentions and replies. When someone replies to you or writes @ and your nickname, in the room or the chat, you get a notification with a short quote of what they wrote. Nobody else sees your notifications.
If you joined through an invite, the member who invited you is told your nickname when your first paid month earns him his free one, and his invite page counts you. He never sees your real name, your email or your payment details.
Never shown to another member: your real name, your email address, your password or anything derived from it, your private link, your country and time zone, your six onboarding answers, your to-do list, your quiz attempts and scores, which individual quests you have completed, your XP by pillar, your briefing ticks, your notifications, your booked calls, and my note on your record.
There is no public wall. Nothing in the room, the chat, the leaderboard or a profile is visible to the open internet — only to members who are signed in.
I can delete anything in the room or the chat. A post, a comment, a reply, a message — mine or yours. There is no appeal process and I am not going to pretend there is one.
06Live calls and recordings
Calls run on Zoom. Zoom sees your name as you enter it, your audio, your video if you turn it on, and your IP address, under its own privacy policy. There are two kinds: the one-to-one calls you book from the diary, as many as there are free slots, and the weekly community call open to every member.
- The weekly community call is recorded — it runs on Zoom, and the recording is made on my own machine and kept by me rather than in Zoom’s cloud — and posted for members who could not attend.
- Anything with you in it is recorded only if everyone on the call agrees, that session. One "no" governs the call.
- Consent is per session, not per membership. You are asked each time.
- Camera off is always fine and costs you nothing. Attendance is never conditional on being recorded.
- Your one-to-one calls are not recorded unless you and I both agree to it, on that call, for that call. The terms say the same thing, deliberately.
- If you want to be cut afterwards, you ask and it is done — removed within 7 days, everywhere.
Nothing said in a crisis or a private disclosure is ever recorded, quoted, or repeated anywhere.
07Who else touches your data
- Cloudflare, Inc.
- Hosts the website files on Cloudflare Pages, runs the booking and member service, stores every record in Workers KV — including your password hash and the login rate-limit counters — and keeps the chat, and the emailed codes with their counters, in Durable Objects. Sees everything in sections 2, 3 and 4, plus request logs: IP, page, time, browser.
- Google LLC
- Serves two typefaces on the public pages, and hosts my email. Sees your IP and browser on page load, and whatever you write to me. If you choose "Continue with Google", runs that sign-in and tells me what section 4 lists.
- Resend
- Sends the six-digit sign-up and password-reset codes, where emailed codes are switched on. Sees your email address and the text of that email, and nothing else.
- Stripe, Inc.
- Runs the checkout page the site sends you to, takes the payment, runs an invited friend's 30-day free month and applies the free months invites earn. Sees your name, email and card details — on Stripe's pages, not mine. I read back from it whether a payment went through.
- Zoom Video Communications
- Hosts the live calls. Sees your display name, audio, video and IP.
I do not sell your data. I do not share it for advertising. I have never run an ad pixel and there is no list to sell you to.
Your data is held outside the EU, and it leaves your country. I am in Malaysia and that is where I read it. Cloudflare runs a global network. Stripe, Google, Resend and Zoom are American companies. Each of these providers publishes data-processing terms incorporating the European Commission's Standard Contractual Clauses, and those clauses are what these transfers rest on. If you want the current links, ask and I will send them.
08How long I keep things
The things that leave the system without me doing it by hand are the ones section 00 names: the login rate-limit counters, the seven-day payment reference, the one-minute quiz marker, your notifications after 90 days, and the short-lived sign-in records. Nothing else deletes itself. Everything else below is a commitment I keep by hand, and I would rather say that than imply machinery I have not built.
- Booking records — call happened
- 90 days after the call, then deleted
- Booking records — call didn't happen
- 30 days, then deleted
- Waiting-list email, from before the list closed
- Until I have told you the first pillar's briefings are filmed, or until you ask me to remove it — whichever comes first
- Your member record, while a member
- For as long as you are one
- Your member record, after you leave
- Kept, so you can come back to it and so the dates on your passes stay true. Deleted the day you ask me to delete it, and not before
- Your password hash and salt
- Deleted with your record
- Your quiz record, completed quests, XP ledger, avatar, time zone and settings
- Part of your member record — kept and deleted with it, as above
- My note on your record
- Deleted with your record
- Your notifications
- 90 days each — they expire on their own. The small record of what you have read and been sent is deleted with your record
- Your invite record
- Deleted with your record. A free month already earned or applied stays earned
- Your to-do items
- Deleted with your record, or on request at any time
- Your posts and comments in the room, wins included
- Deleted on request, or by you; otherwise they stay in the room
- Your chat messages
- They stay in their channel until you ask me to remove them, or I do. Removing a message hides it from every member at once, but its text stays in that channel's storage, where only I can reach it. I would rather tell you that than call it deleted
- Login rate-limit counters
- Under an hour — these expire on their own
- An emailed sign-up or reset code
- 15 minutes, or the moment it is used
- A sign-up waiting for its code
- One day, or the moment the code arrives
- Code-sending counters
- Under an hour — these expire on their own
- Wrong code tries against an address
- One day — the times only, never what was typed
- A Google sign-in in progress
- 10 minutes, or the moment it finishes
- Your Google account ID
- Kept with your record, and deleted with it
- The quiz marker
- One minute — it exists only while an answer is being marked
- Recordings that include you
- Removed within 7 days of you asking
- Anything you emailed me
- Deleted with your record, unless a tax or legal record needs it
- Payment records
- 7 years — a tax obligation, not a choice. Held by Stripe and by me.
Deleting a post, a message or a to-do item does not rewrite your record. Your completed quests, their dates and the XP they paid stand and say what they said. The system does not make you choose between your privacy and your own record.
09Why I'm allowed to hold it
If the UK GDPR or the EU GDPR applies to you, this is the ground I rely on for each thing:
- Your booking details
- Contract — steps you asked me to take before a contract, Art. 6(1)(b)
- Member record, account, country and time zone, quiz record, completed quests and XP ledger
- Contract — I cannot run the school without them, Art. 6(1)(b)
- Your avatar
- Contract — it is part of how the member area shows you your own record, Art. 6(1)(b)
- Your posts, comments and chat messages, and your notifications
- Contract — the room, the chat and the bell are part of what you join, Art. 6(1)(b)
- Showing you on the leaderboard and your profile, and posting your wins
- Legitimate interests — a room where members can see who is doing the work is part of what you join. The two switches in Settings are your objection, and they take effect at once, Art. 6(1)(f)
- Invite records
- Contract — the offer the two of you took up, Art. 6(1)(b); and legitimate interests for checking that an invited friend is new, Art. 6(1)(f)
- Your six onboarding answers
- Contract — they are how I make the thing useful to you, Art. 6(1)(b)
- Payment and billing records
- Contract, and legal obligation for the tax records, Art. 6(1)(b) and (c)
- Password hash and login rate limiting
- Legitimate interests — keeping other people out of your account, Art. 6(1)(f)
- Emailed codes, and signing in with Google
- Contract — letting you into the account you paid for, Art. 6(1)(b); and legitimate interests for confirming an address is really yours and limiting how often codes are sent, Art. 6(1)(f)
- Server and request logs
- Legitimate interests — running and defending a working service, Art. 6(1)(f)
- Google Fonts
- Legitimate interests — serving the page as built, Art. 6(1)(f)
- A waiting-list email left before the list closed
- Consent — you gave it to be told one thing, Art. 6(1)(a)
- Recording anything with you in it
- Consent, asked per session, withdrawable at any time, Art. 6(1)(a)
- Anything sensitive you volunteer
- Explicit consent only, Art. 9(2)(a) — withdraw it and I delete it
Withdrawing consent, or objecting, does not undo what was lawful before. It stops everything after.
10Your rights, and how to use them
If you are in the UK or the EU, you can ask me to: give you a copy of everything I hold on you; correct anything wrong; delete it; stop or limit what I do with it; hand it to you in a machine-readable form; or object to anything I do on legitimate-interests grounds. You can withdraw consent to a recording at any moment. You can complain to your national data protection authority — in the UK, the Information Commissioner's Office at ico.org.uk.
If you are in Malaysia, the Personal Data Protection Act 2010 gives you the right to make a data access request and a data correction request. I do not charge a fee for either. You can complain to the Personal Data Protection Department (JPDP) under the Ministry of Digital.
Everyone else: ask me for the same things. I am not going to check your passport before answering a reasonable request.
Where the two regimes differ, I apply the stricter one to everybody. The PDPA does not give a general right to erasure; I give you one anyway.
To ask for something, email reodannathan@gmail.com and say what you want. You do not need a form, a subject line, or a reason.
- "Send me everything you have on me." You get it, readable and machine-readable.
- "Delete me." Your posts and comments in the room, and your chat messages, are stored separately from your member record and are not covered by this — say "and my posts" and the posts and comments go too and the chat messages are removed from every channel, as section 8 describes; otherwise they stay under your nickname. Everything else — your member record, your account, your quiz record, completed quests and XP ledger, your avatar and settings, your notifications, your invite record, my note, your to-do list, your booking and your token — is erased. Payment records stay for the tax period; nothing else does. This ends your membership, because there is nothing left to run it on.
- "Delete this one thing." Fine, and it does not affect anything else.
- "Take my posts out of the room." Done. You can also delete your own posts, wins included, yourself.
- "Take me off the leaderboard." One switch in Settings does it at once, and cuts your profile down too. Or ask me.
- "Cut me out of that recording." Done within 7 days.
- "I'm locked out." I reopen it by hand — or, where the reset page offers it, reset it yourself with an emailed code.
- "Take me off the old waiting list." Done, and it is the whole record gone.
I answer within 30 days, and in practice usually the same week. Deleting your data is not the same as cancelling your subscription, and cancelling is not the same as deleting your data — ask for whichever one you actually want, or both.
11Marketing
I do not run a mailing list. There is no newsletter, no automated sequence, and no "we may contact you about offers" clause. The only automated email this site sends is a sign-in code you asked for, and it carries nothing else. The waiting list, now closed, was only ever for telling you one thing once — that the first pillar's briefings are filmed. I will not use your data for direct marketing, and I will not pass it to anyone else for theirs. If that ever changes, I will ask you first, and Malaysia's PDPA requires me to.
Invites are yours to send. Your invite link is something you choose to pass on. I never contact the people you send it to, and nothing about them reaches my records unless they join.
12Younger members
Lifemax Club has no age limit. What I hold about a younger member is exactly what I hold about anyone else — the list in section 3, and nothing extra. One of the six onboarding questions asks your age, and that is the only reason I know it.
Two things I ask rather than enforce. If you are under 18, tell a parent or guardian you have joined before your first call. And if a parent or guardian asks me what I hold about you, or asks me to delete it, I will do it — the same way I would if you asked me yourself.
Nothing on this site is written for children, and nothing here is a substitute for the people responsible for you. If you need someone right now, the numbers on the help page are free, staffed, and open to anyone of any age.
13Security, and what I will not claim
What is true:
- Everything runs over HTTPS.
- Your records live in Cloudflare Workers KV, encrypted at rest by Cloudflare.
- Your password is stored only as a PBKDF2-SHA256 hash, 100,000 iterations, with a random 16-byte salt unique to you. The plaintext is never stored, never logged, and never returned.
- Failed logins are rate-limited by IP and by email, so nobody guesses their way in.
- Your access token is 22 characters, either from a cryptographic random source or derived by HMAC from a secret only my server holds — more entropy either way than a password you would have chosen.
- Nothing you type is ever written into a page as raw HTML.
What I will not claim: this is one person's system. There is no security team, no SOC 2 report, no penetration test and no bug bounty.
Your password protects the recovery of your link. It does not protect the link itself. The link is the key, and a key that travels in a web address is a key that can be forwarded, screenshotted, and left in a browser history. I am telling you that plainly instead of calling this "secure login".
A set of member records in a key-value store is a small target defended by a small amount of machinery, and the honest summary is that it is competently built rather than institutionally hardened. Do not put anything in the room, the chat, or your to-do list that you could not survive being read.
If something leaks in a way that could hurt you, I tell you and I tell the relevant regulator — within 72 hours where the law requires it. I do not sit on it and I do not wait to see if anyone notices.
14Changes to this page
If I change what I collect, who touches it, or how long I keep it, I update this page, change the date at the top, and tell every current member directly. I will not make a material change quietly and rely on you re-reading a page you have already read.
Version 2.0 is a material change. Version 1.0 described a school with paths, cohorts and no accounts, and it said in two places that there were no passwords. There are now. Sections 3, 4, 5 and 13 are where the difference lives.
Version 3.0 is a material change too. PROTOCOL is now called Lifemax Club, and four things are added to what I hold: your avatar, your leaderboard setting, your XP ledger, and quest proof with my notes on it. The leaderboard is new, and it is opt-in. One-to-one calls are no longer earned — you book as many as the diary has free slots. The website moved from Netlify to Cloudflare Pages, so Netlify no longer handles anything of yours. Version 2.0 also gave the password hash as 210,000 iterations; the real figure is 100,000, and sections 4 and 13 now say so. Sections 0, 1, 2, 3, 5, 6, 7, 8, 9, 10 and 11 are where the rest of the difference lives.
Version 4.0 is a material change as well. Proof filing, which version 3.0 said would open in January, is gone: a quest is completed by a quiz or on a call, and a quiz keeps your attempts and score, never your answers. The leaderboard is now shown by default instead of opt-in — hide yourself in Settings at any time — and I tell every current member directly, as this section promises. New here: member profiles, wins posted to the room, notifications and their 90-day expiry, invite records, your country and time zone, and my note on your record. Joining now runs through a Stripe Checkout page the site opens rather than a payment link. This page also now says what it should have said before: the chat is kept in Cloudflare Durable Objects, and the free quest page keeps what you type in your own browser. Sections 0, 1, 3, 4, 5, 7, 8, 9, 10, 11 and 13 are where the difference lives.
Version 4.1 adds two ways into your account, each of which works only once I have switched it on: "Continue with Google", and six-digit codes emailed through Resend to confirm your address and to reset a password. It also says that the waiting list is closed. Sections 0, 1, 2, 3, 4, 7, 8, 9, 10 and 11 are where the difference lives.
15Contact
Reodan Nathan, sole proprietor · Malaysia
reodannathan@gmail.com
One person. No staff. No ticket queue.