Data Policy
What we do with your data.
This page is maintained by Lilac Productions LLC, doing business as Lilac Creative, to explain what we collect on lilaccreative.io and the member hub, why we collect it, who helps us process it, and how you can ask us to change or delete it. Plain English, no legal cosplay.
Last updated: June 28, 2026
On this page
01
What we collect.
We only collect what's needed to run the site, our member hub, and our client work:
- Account info when you sign up: name (or display name), email, password hash, optional profile photo and bio.
- Membership & billing data if you join the Academy: subscription status and the last four digits of your card. Full card numbers go directly to Stripe — we never see or store them.
- Learning activity inside the member hub: courses started, lessons completed, reflections you write, AI chat history with Lilac AI, knowledge-check attempts, bookmarks, and discussion posts.
- Messages you send us through the contact form, replies, or email.
- Basic technical data your browser sends automatically: IP address, device/browser type, and pages visited.
We do not collect government IDs, precise location, health data, or biometric data.
02
Why we collect it.
- To create and secure your account.
- To deliver courses, save your progress, and personalize your hub.
- To process Academy subscriptions and send required billing receipts.
- To respond when you contact us.
- To detect abuse and keep the site running.
- To send the newsletter or course updates — only if you opted in. You can unsubscribe from any email.
We don't sell your data. We don't run advertising. We don't profile you for third-party marketing.
03
Who processes it.
A handful of trusted vendors help us run the platform. Each one only receives the data it needs to do its job:
- Lovable Cloud (built on Supabase) — our database, authentication, and file storage. Your account, profile, and learning data live here.
- Stripe — processes Academy payments. Stripe receives your billing details directly; we receive subscription status and the last four digits of your card.
- Lovable AI Gateway (Google Gemini models) — powers the Ask Lilac AI assistant, lesson summaries, knowledge checks, and newsletter drafting. Your prompts and lesson context are sent to the model to generate a response and are not used to train it.
- Lovable Cloud email delivery — sends our transactional and newsletter email from notify.lilaccreative.io. It receives your email address and the message content.
- YouTube (Google) — embeds recorded talks and webinars. Playing an embedded video sets YouTube's own cookies.
- Google Search Console — gives us aggregate search statistics for lilaccreative.io (queries, clicks, impressions). It does not identify individual visitors.
- Firecrawl — used by our admin tools to read public web pages when importing courses, events, and news links. No member data is sent.
Read Aloud uses your own browser's built-in text-to-speech. Nothing is sent to an outside audio service. Website analytics are first-party: page views and activity events are stored in our own database. We do not use Google Analytics or any third-party advertising tracker.
04
AI features & your content.
When you use Ask Lilac AI, knowledge checks, or auto-generated lesson intros, your message and the related lesson content are sent to our AI provider to generate a response. These conversations are saved to your account so you can return to them later. We do not use member content to train third-party models.
Reflections you write in lessons are private to you and our admins, and are compiled into your end-of-course report. They are never shown to other members.
06
Retention & deletion.
Canceling a paid plan ends future billing and paid-content access at the end of your paid period. It does not close your account or delete anything — your profile, progress, reflections, and free access stay exactly as they are.
Closing your account is a separate step. When you close it, we deactivate access and then remove your personal data on the schedule below.
Deletion requests. You can ask us to delete your data at any time, whether or not you have closed your account. We complete deletion within 90 days of a confirmed request or account closure.
Records we must keep. Payment, invoice, and tax records are retained for as long as the law requires, even after deletion. Those records are kept only for that purpose and are not used for anything else.
Public posts you've made in member discussions may be anonymized rather than deleted so replies from others remain coherent. You can request full removal of those too.
07
Your rights & requests.
You can ask us at any time to:
- See a copy of the data we hold about you.
- Correct anything that's wrong.
- Delete your account and personal data.
- Export your reflections and course reports.
- Unsubscribe from non-essential emails.
Email Contact@lilaccreative.io from the address on your account. We aim to respond within 14 days.
08
How we protect it.
Data is transmitted over HTTPS. Passwords are hashed — we can't see them. Database access is restricted by row-level security policies, so members can only read and write their own data, and admin-only data stays admin-only. Stripe handles payment card data on its own PCI-compliant infrastructure.
No system is perfect. If something goes wrong, we'll tell affected users directly and explain what happened and what we're doing about it.
09
Children.
This site and the Academy are built for working professionals. We don't knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we'll remove it.
10
Changes to this page.
When we change anything material — new vendors, new data collected, changed retention — we'll update the "last updated" date at the top and, for active members, send a heads-up by email.
11
Contact.
Questions, requests, or concerns about your data: Contact@lilaccreative.io.
You can also reach us through the contact page.
Data controller: Lilac Productions LLC (d/b/a Lilac Creative), Nixa, Missouri, USA. Email is our contact channel of record for privacy requests.