Privacy Policy
Last updated:
This Privacy Policy explains what personal data Berine Metabolic collects, how we use it, how we protect it, and the rights you have. Our content is readable worldwide, and we honor the rights in §7 for everyone, wherever you live. Our products are currently offered for sale only in the United States; §4 and §6 describe how we handle visits from elsewhere.
1. Who We Are
Berine Metabolic is an educational platform operated by Integralife (the “data controller” for GDPR purposes). You can reach us at support@berine.io.
2. What We Collect
| Category | What | Why | Legal basis (GDPR) |
|---|---|---|---|
| Account data | Email, name, password hash | Account creation and authentication | Contract performance |
| Purchase data | Stripe customer ID, purchase date, amount | Order fulfillment and chargeback defense | Contract performance |
| Course progress | Module completion, knowledge-check scores, timestamps | Progress tracking and learning analytics | Legitimate interest |
| Health-adjacent data | Self-reported diagnosis status, optionally provided during onboarding or community participation | Personalization and community context | Consent, given when you choose to provide it; withdrawable at any time |
| Course inputs | Metrics you log, self-assessments, notes, and reflections you enter while using the course | Saving your work, showing progress, and powering in-course review | Contract performance; entries are optional and deletable in-app |
| Device / browser data | User agent, viewport, and IP address. When you sign in, an anonymized (truncated) IP address and your user agent are stored with your session record for security; analytics processing of IP is anonymized. | Debugging, security, accessibility optimization | Legitimate interest |
| Security records | Short-lived email-verification and password-reset tokens (reset tokens expire in 1 hour, verification tokens in 24 hours), rate-limit counters, and an authentication event log that records a hashed form of your email address | Account security and abuse prevention | Legitimate interest |
| Email subscription | Email address, subscription status and double opt-in confirmation timestamp, IP address at signup, and the page and signup source you subscribed from | Newsletter delivery | Consent |
| Business / inquiry data | When you contact us through our work-with-us form: your name, work email, organization, and role, plus the engagement details you choose to share (for example, U.S. states for licensure coverage, staffing or timeline parameters, event type, dates, location, audience size, and any free-text scope or notes) | Responding to and scoping professional-services inquiries | Legitimate interest (pre-contractual steps) |
We do not collect Protected Health Information (PHI) and Berine Metabolic is not subject to HIPAA. If you choose to share health-adjacent information in the community, that disclosure is governed by the community guidelines in our Terms of Service.
Inquiry details you send through the work-with-us form are delivered to our team by email (via Resend) so we can respond, and a copy is stored in our application database so we can track and follow up on inquiries. We send you an automated acknowledgment. We use this information to evaluate and scope a possible engagement; submitting the form does not create a contract or any professional relationship (see our Terms of Service). We retain inquiry records while we are evaluating or performing the potential engagement and for up to twenty-four (24) months after our last correspondence about it, after which they are deleted; you can request earlier deletion at any time via support@berine.io.
3. How We Use Your Data
- To create and authenticate your account.
- To fulfill course purchases and provide course access.
- To track your progress through course content.
- To send transactional emails (purchase confirmations, password resets, course-access notifications).
- To send marketing emails, only after you confirm a double-opt-in subscription.
- To improve the platform: fixing bugs, optimizing performance, improving accessibility.
- To respond to support requests and to investigate reported abuse or security incidents.
- To respond to professional-services inquiries submitted through the work-with-us form, and to send you an acknowledgment of your inquiry.
We do not sell personal data. We do not share personal data with advertisers. We do not use your data to train third-party AI models.
4. Analytics
We use PostHog for product analytics, error monitoring, and feature flags. On the public marketing site, PostHog runs in cookieless mode: our analytics set no cookies and write no identifier to your browser’s local or session storage. We record anonymous, within-session usage events such as page views, clicks, performance metrics, and approximate location (country and region, derived from your IP address at the moment an event is received, never a precise location). Because our analytics store nothing on your device, we do not present a cookie-consent banner.
We do not use this data for advertising, we do not sell it, we do not combine it with any other data set or use it to track you across other websites, and we do not use session replay on the public site. Identified analytics exist only behind sign-in: on the authenticated course app and in purchase processing, events such as purchases, refunds, and course progress are linked to your account ID so we can operate the product. This never extends to the public marketing site, and signed-in users can turn analytics off in the app’s Data & privacy settings.
Visitors from the EEA, the UK, and Switzerland. This website is intended for users in the United States; we do not offer our products or services to individuals in the European Economic Area, the United Kingdom, or Switzerland. To the extent European data protection law applies to any of this processing, we rely on our legitimate interests in understanding and improving our website (Article 6(1)(f) GDPR / UK GDPR), and you may object at any time using the contact below.
You can opt out at any time by emailing support@berine.io, by enabling your browser’s “Do Not Track” or Global Privacy Control signal (which we honor), or by using a tracker-blocking extension.
5. Third-Party Data Processors
We use the following processors to deliver the service. Each is contractually bound to process data only on our instructions and where required has signed a Data Processing Agreement (DPA).
| Processor | Purpose | Data shared | DPA |
|---|---|---|---|
| Cloudflare | Hosting, CDN, DDoS protection | Request metadata | Yes (standard) |
| Neon | Application database (PostgreSQL) | All stored application data | Yes |
| Stripe | Payment processing | Email, payment method (tokenized) | Yes (standard) |
| Better Auth | Authentication | Email, password hash | Self-hosted (no DPA needed) |
| Buttondown | Email marketing / newsletter | Email, subscription status and confirmation timestamp, signup source and interests, referring page, IP address at signup | Yes |
| Resend | Transactional email and delivery of work-with-us inquiries | Email, name, and inquiry details you submit | Yes |
| PostHog | Product analytics (cookieless on the public marketing site) | Anonymous usage events, device/browser data, approximate location (country/region, from IP), performance metrics | Yes |
6. Data Residency & Cross-Border Transfers
Berine Metabolic is a United States company with no establishment in the European Economic Area, the United Kingdom, or Switzerland. Our website and services are operated from the United States, and personal data we collect is processed and stored in the United States by us and by our service providers (application data in the Neon database; Cloudflare may process requests at its global edge, but persistent application data remains in the U.S.).
If you access our website from outside the United States, you are providing information directly to a U.S. company; this is not an international data transfer that we make on your behalf, and no separate transfer mechanism applies to our own collection of your data.
Where our service providers themselves receive personal data originating in the EEA, the UK, or Switzerland, they rely on their own transfer mechanisms. Several of our providers, including Cloudflare, Stripe, PostHog, and Neon (via Databricks), are self-certified under the EU-U.S. Data Privacy Framework, the UK Extension to it, and the Swiss-U.S. Data Privacy Framework. Others, including Buttondown and Resend, incorporate the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum into their data processing agreements. You can review each provider’s current status on the Data Privacy Framework list at dataprivacyframework.gov and in the provider’s published data processing agreement.
7. Your Rights
You have the following rights regarding your personal data, regardless of where you live:
- Access. Request a copy of the personal data we hold about you. We will respond within thirty (30) days.
- Correction. Request that we correct inaccurate personal data.
- Deletion. Email us to delete your account and associated data; account deletion is handled by request today rather than a self-serve control. Signed-in learners can separately delete their course data (progress, notes, logged numbers, reflections, and saved tools) at any time from the app’s Data & privacy panel. Purchase records are retained for the period required by tax and consumer-protection law (see §8).
- Portability. Request a machine-readable export of your personal data (GDPR Article 20).
- Opt-out of sale. Berine does not sell personal data. This statement is included for CCPA compliance.
- Withdraw consent. Withdraw consent for health-adjacent data processing or for email subscriptions at any time.
- Complain to a regulator. If you are in the EU, UK, or another jurisdiction with a data-protection authority, you have the right to lodge a complaint with that authority.
To exercise any of these rights, email support@berine.io. We may ask you to verify your identity before fulfilling certain requests.
8. Data Retention
| Data | Retention period | Reason |
|---|---|---|
| Account data | Until you request deletion | Service delivery |
| Purchase records | 7 years after purchase | Tax and consumer-protection compliance |
| Course progress | Until you request deletion | Service delivery |
| Health-adjacent data | Until deletion or consent withdrawal | User control |
| Email subscription | Until unsubscribe | Consent-based |
| Business inquiries | Up to 24 months after last correspondence | Inquiry follow-up |
| PostHog analytics | 12 months rolling | Product improvement |
9. Security
We use industry-standard technical and organizational measures to protect personal data, including encryption in transit (TLS), password hashing, principle-of-least-privilege access controls, and regular dependency-vulnerability monitoring. No system is perfectly secure; if you believe your account has been compromised, contact support@berine.io immediately.
10. Children
Berine Metabolic is not directed at children under sixteen (16) and does not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, contact us and we will delete it.
11. Cookies
Our public marketing site sets no analytics cookies: PostHog runs in cookieless mode (see §4) and stores nothing in your browser. We do not set advertising, retargeting, or cross-site tracking cookies anywhere.
The only cookie we use is a first-party session cookie set when you sign in, which is required to keep you signed in; disabling it will prevent sign-in. You can block or clear cookies through your browser settings; doing so will not affect access to our public content.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered users. The “Last updated” date at the top of this page reflects the most recent revision. Previous versions are preserved in the source-code repository’s version history.
13. Contact
Privacy questions, data-rights requests, and complaints can be sent to support@berine.io.