Privacy Policy
Effective Date: 28 Nov 2025
1. Introduction
GenderJourney.xyz ("we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal and health information. This Privacy Policy explains how we collect, use, store, and protect your data in compliance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
- EU General Data Protection Regulation (EU GDPR) where applicable
Data Controller: Gender Journey Ltd
Company Number: 16877382
ICO Registration Number: ZC049881
Registered Office: 128 City Road, London, United Kingdom, EC1V 2NX
Contact Email: [email protected]
Service Location: United Kingdom
2. Information We Collect
2.1 Account Information (Required)
When you create an account, we collect:
- Email Address - Used as your username and for account communications
- Password - Stored using industry-standard bcrypt hashing
- Preferred First and Last Name - How you wish to be addressed
- Legal First and Last Name - Optional, defaults to preferred name if not provided
- Date of Birth - For age verification (minimum age: 16 years)
- Gender Identity - To personalize your experience
- Subscription Plan - Free, Egg Cracking (£1/month), or Hatched (£3/month)
2.2 Special Category Health Data (Optional)
Under UK GDPR Article 9, health data is classified as "special category data" requiring explicit consent and additional protections. You may optionally provide:
- Blood Test Results - PDF uploads or Medichecks API imports with biomarker values, reference ranges, and laboratory information
- Hormone Medications - Drug type, dosage, frequency, start/end dates, prescription information
- Blood Pressure Readings - Systolic, diastolic, pulse, reading dates, and notes
- Weight and Height Measurements - Weight in kg, height in cm, BMI calculations, and notes
- Surgery Records - Surgery type, consultant name, location, cost, dates, and notes
- Voice Recordings - Audio files with optional pitch frequency analysis (encrypted)
- Photos - Progress photos stored in your private photo journey
- Health Scores - Calculated indicators based on your health data (opt-in, for informational purposes only)
- UK Gender Recognition Certificate (GRC) Application Data - Documents, statutory declarations, and application metadata
- Diary Entries - Personal journal entries about your journey
Legal Basis for Processing Health Data: We process your health data under UK GDPR Article 9(2)(a) - explicit consent. By creating an account and uploading health information, you provide explicit consent for us to process this data solely for the purposes described in this policy. You may withdraw consent at any time by deleting your data or account.
2.3 Social Features Data (Optional - "My Connect")
If you enable "My Connect" social features, we collect:
- Display Name and Pronouns - Public profile information
- Profile Photo - Optional public or private photo
- Bio - Optional personal description
- Posts, Comments, and Reactions - Content you share with the community
- Friend Connections - Users you connect with
- Community Memberships - Communities you join
- Direct Messages - End-to-end encrypted conversations with connections
- Content Moderation Data - AI and human moderation results for safety
2.4 Technical and Usage Data
- Session Cookies - Essential for authentication and security (strictly necessary)
- Login Activity - Login timestamps, login count, active sessions for security
- PWA Installation Data - Whether you installed the Progressive Web App
- Service Worker Cache - Offline functionality for PWA
- Browser Local Storage - Feature flags, UI preferences (stored locally only)
- Two-Factor Authentication (2FA) Data - If enabled: SMS number, email, or authenticator app secret
2.5 Payment Information
Payment processing is handled by Stripe (PCI DSS Level 1 certified). We store:
- Stripe Customer ID - Links your account to Stripe
- Payment Method ID - Tokenized reference (not actual card numbers)
- Subscription Status - Active, cancelled, past due, etc.
- Billing History - Invoice dates and amounts
We never store full credit card numbers, CVV codes, or raw payment details.
3. How We Use Your Information
3.1 Service Provision
- Provide access to your personal health tracking dashboard
- Store and display your health data securely
- Calculate health indicators and insights (opt-in only)
- Generate hormone reports and blood test summaries
- Facilitate My Connect social features (if enabled)
- Process payments and manage subscriptions
3.2 Communication
- Transactional Emails - Account verification, password resets, security alerts (required)
- Service Notifications - Medication reminders, prescription reminders (if configured)
- Push Notifications - My Connect interactions, friend requests, reminders (opt-in)
- Newsletters - Product updates and community news (opt-in only, never automatic)
3.3 Security and Safety
- Detect and prevent unauthorized access
- Monitor for suspicious activity and fraud
- Moderate user-generated content for safety (AI-assisted + human review)
- Enforce Terms of Service and Acceptable Use Policy
3.4 Legal Compliance
- Comply with UK GDPR, Data Protection Act 2018, and other applicable laws
- Respond to lawful requests from authorities
- Protect our legal rights and interests
We do NOT use your data for:
- ❌ Marketing or advertising to third parties
- ❌ Selling or renting your personal information
- ❌ Training AI models (except for content moderation of your own posts)
- ❌ Profiling or automated decision-making that affects your rights
4. Data Security and Encryption
4.1 Encryption at Rest
All Personal Health Information (PHI) is encrypted at rest using AES-256-CBC encryption. This includes:
- Blood test data (files, samples, test results, biomarker values)
- Hormone medications (drug types, doses, dates)
- Blood pressure and weight readings
- Surgery records
- Voice recordings and pitch frequency data
- User personal data (names, date of birth, gender identity)
- Addresses
- GRC application documents and metadata
4.2 Encryption in Transit
- TLS 1.3 - All data transmitted between your browser and our servers
- Cloudflare SSL - Production environment uses Cloudflare Origin Certificates
- End-to-End Encryption - Direct messages in My Connect are encrypted
4.3 Access Controls
- Your data is accessible only by you - No staff access to encrypted PHI
- Role-Based Access Control (RBAC) - Administrative functions are restricted
- Two-Factor Authentication (2FA) - Optional additional security layer
- Session Management - Automatic logout after inactivity, ability to logout all sessions
- Account Lockout - Immediate lockout on unauthorized access reports (requires photo ID to unlock)
4.4 Infrastructure Security
- PostgreSQL Database - Running in Docker containers with encrypted volumes
- Laravel Framework - Industry-standard PHP framework with built-in security features
- Regular Security Updates - Dependencies and infrastructure are kept up-to-date
- Backup Encryption - Database backups are encrypted and stored securely
5. Third-Party Data Processors
We use the following third-party services to provide our platform. Each processor is bound by Data Processing Agreements (DPAs) and complies with UK GDPR:
5.1 Payment Processing
- Stripe - Payment processing, subscription management
- Data Shared: Email, name, payment method tokens, subscription status
- Location: USA (EU-US Data Privacy Framework certified)
- Privacy Policy: stripe.com/privacy
5.2 Email Services
- Mailjet - Transactional emails, verification codes, notifications
- Data Shared: Email address, name, email content
- Location: EU (GDPR compliant)
- Privacy Policy: mailjet.com/privacy-policy
5.3 Authentication
- Google OAuth - Optional social login
- Data Shared: Email, name, profile photo (only if you choose Google login)
- Location: USA (EU-US Data Privacy Framework certified)
- Privacy Policy: policies.google.com/privacy
5.4 Content Moderation
- OpenAI - AI-assisted content moderation for My Connect posts
- Data Shared: Post content only (no PHI, no personal identifiers)
- Location: USA
- Privacy Policy: openai.com/policies/privacy-policy
- Note: We only send post text for moderation. Your health data is never sent to OpenAI.
5.5 Health Data Integration
- Medichecks - Optional blood test import (if you connect your Medichecks account)
- Data Shared: Your Medichecks login credentials (stored encrypted), blood test results
- Location: UK
- Privacy Policy: medichecks.com/privacy-policy
5.6 Push Notifications
- Web Push Protocol (VAPID) - Browser-native push notifications
- Data Shared: Push subscription endpoint, notification content
- Location: Your browser vendor (Google, Apple, Mozilla)
- No third-party service - uses browser standards
We do NOT share your health data with any third parties except as explicitly listed above and only to the extent necessary to provide the service.
6. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
6.1 Right to Access (Article 15)
You can access all your data at any time through your account dashboard. For a complete data export, contact [email protected].
6.2 Right to Rectification (Article 16)
You can update your personal information through your profile settings at any time.
6.3 Right to Erasure / "Right to be Forgotten" (Article 17)
You can delete your account and all associated data at any time via your profile settings. Deletion is permanent and irreversible. All data is deleted within 30 days.
6.4 Right to Restrict Processing (Article 18)
You can disable specific features (e.g., My Connect, health scores, voice pitch tracking) to restrict processing of certain data types.
6.5 Right to Data Portability (Article 20)
You can export your data in machine-readable formats (JSON, PDF) through your account dashboard or by contacting [email protected].
6.6 Right to Object (Article 21)
You can object to processing of your data for specific purposes by disabling features or deleting your account.
6.7 Right to Withdraw Consent (Article 7(3))
You can withdraw consent for processing health data at any time by deleting your health records or account. This does not affect the lawfulness of processing before withdrawal.
6.8 Right to Lodge a Complaint
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Gender Journey Ltd is registered with the ICO under registration number: [Your ICO number]
7. Data Retention
- Active Accounts: Data is retained as long as your account is active
- Deleted Accounts: All data is permanently deleted within 30 days of account deletion
- Inactive Accounts: Accounts inactive for 3+ years may be deleted after email notification
- Backup Retention: Encrypted backups are retained for 90 days for disaster recovery
- Legal Obligations: Some data may be retained longer if required by law (e.g., financial records for 7 years)
8. International Data Transfers
Your data is primarily stored in the United Kingdom. Some third-party processors are located in the USA and EU. All international transfers are protected by:
- EU-US Data Privacy Framework - For US-based processors (Stripe, Google, OpenAI)
- Standard Contractual Clauses (SCCs) - EU Commission-approved data transfer agreements
- Adequacy Decisions - For transfers to countries with adequate data protection (EU)
Note: Our service is not available in the United States due to political considerations. US residents cannot create accounts.
9. Children's Privacy
Our service is not intended for children under 16 years of age. We do not knowingly collect data from children under 16. If you are under 16, do not create an account or provide any personal information. If we discover that a child under 16 has provided personal information, we will delete it immediately.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification - 30 days before changes take effect
- In-app notification - Banner on your dashboard
- Updated "Last Updated" date - At the top of this policy
Continued use of the service after changes take effect constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related questions, concerns, or requests, please contact us:
- Email: [email protected]
- Data Protection Officer: [email protected]
- Support: Via the "Contact Support" link in your account
Response Time: We aim to respond to all privacy requests within 30 days as required by UK GDPR.
By using GenderJourney.xyz, you acknowledge that you have read, understood, and agreed to this Privacy Policy.