Last updated: 21 August 2026
Hughes Digital Studio Limited of 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF is the "data controller" for the personal data described in this policy. You can contact us about privacy matters at hello@hughesdigitalstudio.co.uk.
jfk_session) to keep
you signed in. It contains no personal data beyond your email address and an expiry date,
and can't be read by any script (including ours) other than our own server. During
checkout, Stripe may set its own cookies for fraud prevention — see
Stripe's privacy
policy. We don't use analytics, advertising, or tracking cookies, so we don't show a
cookie banner — these cookies are all "strictly necessary" and exempt from consent
requirements under UK PECR rules.Records of your pregnancy movements are likely to count as "special category data" (health data) under UK GDPR, which has extra legal protection. We only process this data because you have given your explicit, separate consent to it at sign-up (a dedicated checkbox, distinct from accepting these Terms). You can withdraw this consent at any time by deleting your account from the Account tab, which permanently erases this data.
We use a small number of trusted service providers ("processors") to run the Service:
We do not sell your data, and we do not share it with anyone else, except where required by law (for example, a valid court order).
Stripe and Netlify may process or store data outside the UK/EEA (for example, in the United States). Where that happens, they do so under appropriate safeguards, such as the UK International Data Transfer Addendum or Standard Contractual Clauses.
We keep your account and movement data for as long as your account is active. If you cancel your trial or delete your account from the Account tab, we permanently and immediately delete your account record, all logged movements, and your saved card reference with Stripe. Failed sign-in attempt records are automatically cleared after 15 minutes.
Under UK GDPR, you have the right to:
To exercise any of these rights, email hello@hughesdigitalstudio.co.uk. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), though we'd appreciate the chance to help first.
Passwords are hashed (never stored in plain text) using industry-standard techniques. All traffic to the Service is encrypted with HTTPS. Sign-in sessions use a signed, tamper-proof, HTTP-only cookie that can't be read or altered by JavaScript. Repeated failed sign-in attempts from the same source are temporarily blocked.
The Service is intended for adults (18+) and is not directed at children. We do not knowingly collect data from children.
We may update this policy from time to time. If we make material changes, we'll take reasonable steps to let existing users know (such as an in-app notice) before they take effect.
Questions about this policy, or want to exercise your rights? Email hello@hughesdigitalstudio.co.uk.