Legal

Privacy Notice

Last updated: September 3, 2026

1. Who is responsible for your data

PickAReset is operated by Elizabeth Wanyoike, who acts as the data controller for the personal data described in this notice. You can reach us at support@pickareset.com.

2. What we collect

  • Account data — email address and sign-in credentials when you create an account or join the email list.
  • Questionnaire and protocol data — the wellness goals, schedule, and lifestyle answers you provide, and the fasting/refeed protocol generated from them.
  • Check-in data — energy, hunger, mood, sleep, bloating, headache, and fasting-history entries you log.
  • Support messages — correspondence when you contact us or use the AI Bio-Coach.
  • Usage and device data — a device identifier used for trial and entitlement checks, timezone, and basic telemetry needed to operate the app.

Payment card details are collected and processed by Paddle, our Merchant of Record — we never see or store your full card details.

3. Why we use it (and our legal basis)

  • To create your account and deliver your personalized protocol (performance of a contract).
  • To provide reminders, insights, and the AI Bio-Coach (performance of a contract).
  • To secure the service and prevent fraud or trial abuse (legitimate interests).
  • To improve the product through aggregated trends (legitimate interests).
  • To send marketing emails you have opted into (consent, which you can withdraw).
  • To meet legal obligations such as tax and accounting records (legal obligation).

4. Who we share it with

  • Service providers / subprocessors — hosting, database, email delivery, and analytics providers that process data on our behalf under contract.
  • Merchant of Record (Paddle) — for the sale of the product, subscription and payment management, tax compliance, and invoicing.
  • Professional advisers — legal and accounting advisers where needed.
  • Authorities — where disclosure is required by law.

We do not sell your personal data.

5. International transfers

Some service providers process data outside the UK/EEA. Where they do, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.

6. Retention

We keep personal data only for as long as needed for the purposes above — for example, account data while your account is active, and transaction records for the period required by tax law. Data is deleted or anonymised when no longer needed.

7. Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict, or port your data, to object to processing, and to withdraw consent. You can change your sign-in email from your account page, and contact us at any time to exercise other rights. If you are in the UK/EEA, you also have the right to complain to your supervisory authority; we respond to requests within one month.

8. Security

We use appropriate technical and organisational measures — including encryption in transit, row-level access controls, and least-privilege access — to protect your data.

9. Cookies and local storage

We use essential browser storage to keep you signed in, remember your protocol and trial state, and run the fasting timer. We do not use advertising or marketing cookies. You can clear this storage at any time through your browser settings, though the app may not function fully without it.