Headscovery
Porn Dependence ADHD Coming soon
About
Methodology Evidence Blog FAQ
Log in Account Start
Headscovery
Our programs Porn Dependence ADHD Coming soon Learn more About Methodology Evidence Blog FAQ
Log in Account Start
Legal

Privacy Policy

Last updated 29 June 2026

This policy explains what personal data Headscovery handles, why, and the choices you have. We deliberately collect very little, and we never sell your data or use it for advertising.

On this page

  1. Who we are
  2. The data we collect
  3. Health-related data and your consent
  4. Why we process data and our legal bases
  5. Who we share data with
  6. International data transfers
  7. How long we keep your data
  8. Your rights
  9. Cookies and similar technologies
  10. Data security
  11. Age requirement
  12. Changes to this policy
  13. How to contact us

Who we are

Headscovery provides guided self-help programs for behavioral change. This policy covers personal data of people who visit our website and purchase our programs.

The data controller is Simone Astarita, contactable at hello@headscovery.com. Registered address available on request. For any privacy matter you can reach us at hello@headscovery.com.

The data we collect

We collect as little as possible. Your account is your email, with no password: you sign in with a one-time link we email you (a magic link), and the email you use at checkout is your account. There is no profile to create.

  • Contact and order data. When you buy a program, our payment provider (Stripe) collects your email address, name, billing country, and payment details, and shares your email and order information with us so we can give you access.
  • The fact of your purchase. That you bought a specific program. Because our programs address health-related behaviors, this is sensitive data, handled as described in section 3.
  • Technical data. Like any website, our hosting provider records standard server information such as IP address and browser type, for security and reliable delivery.
  • Usage statistics (only with your consent). On public pages, if you agree through our consent banner, we use Google Analytics to produce aggregate statistics about how the site is used. It does not load until you accept, we run it with Google Signals and advertising features off, and it is never used inside the program. If you decline, no analytics is collected.
  • Program progress. Which modules you open and mark as complete, and where you left off, linked to your account so you can continue across your devices. Because it reflects your engagement with a health-related program, we treat it as sensitive data, as described in section 3.
  • On-device preferences. A small marker in your browser remembers minor choices such as your light or dark theme and whether you have answered the cookie banner. It stays on your device and is never sent to us.

We do not collect anything you write. Exercises in our programs are done on your own notebook or document and are never submitted to us.

Health-related data and your consent

Our programs address health-related behaviors. Under Article 9 of the GDPR, the fact that you purchase one of our programs, and your progress through it, is data concerning your health and, depending on the program, your sex life. We treat it with particular care:

  • We process it only on the basis of your explicit consent, which you give at checkout before payment.
  • We use it only to give you access to the program you bought, to save your progress so you can continue where you left off, and to provide support.
  • We never sell it, never share it for advertising, and never use it to profile you.
  • You can withdraw your consent at any time (see section 8). Withdrawal does not affect processing already carried out and may mean we can no longer provide the program.

Why we process data and our legal bases

  • To provide the program and give you access — performance of our contract with you (Art. 6(1)(b)), and for the health-related aspect, your explicit consent (Art. 9(2)(a)).
  • To process payment and meet tax and accounting duties — compliance with a legal obligation (Art. 6(1)(c)).
  • To keep the website secure and working — our legitimate interest (Art. 6(1)(f)).
  • To produce aggregate statistics with analytics — your consent (Art. 6(1)(a)), which you give through our banner and can withdraw at any time.

Who we share data with

We share data only with service providers that help us run the service and act on our instructions:

  • Stripe — payment processing.
  • Supabase — sign-in, and storage of your account, access, progress and consent records, hosted in the EU.
  • Resend — delivering the one-time sign-in link emails.
  • Netlify — website hosting and delivery.
  • Google (Google Analytics) — aggregate usage statistics, only if you consent. Google acts as our processor for this; advertising features and Google Signals are off.

We do not sell your data, and we do not share it with advertisers or data brokers. We may disclose data if required by law or to protect our rights or someone's safety.

International data transfers

Some providers are based outside the European Economic Area, including in the United States. Where data is transferred outside the EEA, it is protected by appropriate safeguards such as the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

How long we keep your data

  • Order and payment records — kept for as long as tax and accounting law requires.
  • Email, access and progress information — kept while your access to the program is active and for a reasonable period afterwards.
  • Analytics data — collected only with your consent and kept for a short period in Google Analytics (we use the shortest retention available), then deleted automatically.

When data is no longer needed, we delete it or make it anonymous.

Your rights

Under the GDPR you have the right to access your data, correct it, ask us to delete it, restrict or object to its processing, receive it in a portable format, and withdraw any consent you have given.

To exercise any of these, email hello@headscovery.com. We will respond within the time limits set by law.

You also have the right to lodge a complaint with your local data protection authority. In Italy this is the Garante per la protezione dei dati personali (garanteprivacy.it).

Cookies and similar technologies

We keep cookies to a minimum and use no advertising or cross-site tracking cookies. Analytics cookies are set only if you accept them in our consent banner, which you can reopen at any time with the Cookie settings control in the footer. For details, see our Cookie Policy.

Data security

We work only with established providers that apply recognized security standards. For example, Stripe handles card data under the PCI-DSS standard. No method of transmission or storage is completely secure, but we take reasonable measures to protect your data.

Age requirement

Our programs are intended for adults. They are not directed at anyone under 18, and we do not knowingly collect data from minors.

Changes to this policy

We may update this policy from time to time. We will change the date at the top, and any significant change will be made clear on this page.

How to contact us

For any question about this policy or your data, email hello@headscovery.com.

Back to home
Headscovery
Instagram
hello@headscovery.com

Navigate

Porn Dependence About

Understand

Methodology Evidence base Blog FAQ

Legal

Privacy Policy Terms of Service Cookie Policy Consumer Health Data

Headscovery is not a clinical service and does not replace professional psychotherapy.

© 2026 Headscovery

A quick word on analytics

We would like to use Google Analytics to understand, in aggregate, how this site is used, so we can make it better. It loads only if you agree, never sets advertising cookies, and is never used inside the program. See our Cookie Policy and Privacy Policy.