Privacy Policy
Last updated: 25 April 2026
This policy explains how ReflectionGuide (the "Service", operated by Fivesmiths Limited, "we", "us", "our") collects, uses, and protects personal data when you use the Service. It is written to align with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
Please read this policy carefully. If you do not agree with it, you should not use the Service.
1. Who we are
Fivesmiths Limited is the controller responsible for personal data processed through the Service.
Registered office: One Central Square, Central Square, Cardiff, Wales, CF10 1FS.
Company number: 13985094.
For privacy questions, contact [email protected].
2. Scope of this policy
This policy applies to personal data we collect through our website, web application, billing flows, and support channels relating to the Service.
3. Personal data we collect
We collect the following categories of personal data:
- Account data: name, email address, profession, and credentials provided through our authentication provider.
- Billing data: subscription tier, billing interval, and limited payment metadata returned by our payment processor. We do not store full card numbers.
- Reflective content: scenario notes, answers to guided prompts, draft reflections, and exports you generate within the Service.
- Technical and usage data: IP address, device and browser information, log timestamps, and high-level usage events used for security and service improvement.
- Support data: messages you send to us and metadata associated with those communications.
4. How we collect data
We collect data directly from you when you create an account, use the guided reflection process, subscribe, or contact us. We also collect limited technical data automatically when you use the Service.
5. Why we use personal data and our lawful bases
We process personal data on the following lawful bases under UK GDPR:
- Performance of a contract — to provide your account, deliver the guided reflection process, store your drafts, and provide the subscription you have signed up for.
- Legitimate interests — to maintain security, prevent abuse, improve the Service, and provide support, balanced against your rights and expectations.
- Consent — for non-essential cookies and similar technologies, and for any optional marketing communications you opt in to.
- Legal obligation — to comply with tax, accounting, regulatory, and other legal requirements.
6. Reflective content and user-submitted content
ReflectionGuide is designed to support anonymised reflective writing. You must not enter information that identifies a patient, service user, colleague, organisation, or any third party, unless you are clearly entitled to do so for the purpose for which you are using the Service.
We may use automated checks within the Service to flag content that appears to contain potentially identifying information. These checks are for safety and compliance support — you remain responsible for reviewing and editing your content before saving, sharing, exporting, or submitting it.
Reflective content you submit is treated as your content and is processed in line with this policy. We do not use your reflective content to train third-party models for our own commercial purposes.
7. Cookies and similar technologies
We use cookies, browser storage, and similar technologies to operate the Service and, where applicable, to understand usage. Strictly necessary technologies are always active; non-essential categories are off until you provide consent. See our Cookie Policy for details and to manage your preferences.
8. Third-party processors and service providers
We rely on the following processors to deliver the Service. We have written agreements in place that require them to handle personal data appropriately and only on our instructions.
- Hosting, infrastructure, and managed PostgreSQL database: Replit, Inc. (cloud hosting and managed PostgreSQL).
- Authentication, account management, and account-related transactional emails: Clerk, Inc..
- Payments, subscription billing, and customer portal: Stripe Payments Europe, Ltd..
- Analytics: We do not currently use third-party analytics providers. If we add analytics in future, they will be listed here, set out in our Cookie Policy, and (where required) only loaded with your consent.
9. International transfers
Some of our processors may transfer personal data outside the United Kingdom. Where this happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or other lawful transfer mechanisms.
10. How long we keep data
We keep personal data only for as long as is necessary for the purposes set out in this policy, to provide the Service, to comply with legal obligations, and to resolve disputes.
- Account and reflective content: retained while your account is active. If you delete your account, your account profile and reflective content are removed from active systems within 90 days, after which residual copies in routine encrypted backups age out on the normal backup rotation.
- Billing and tax records: retained for the period required by UK tax and accounting law (currently 6 years from the end of the relevant accounting period).
- Support correspondence: retained for up to 24 months after the matter is resolved, unless a longer period is needed to handle a dispute or legal claim.
- Security and audit logs: retained for up to 12 months for security, abuse prevention, and integrity purposes.
11. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and audit logging. No service is completely secure and we cannot guarantee absolute security.
12. Your rights under UK GDPR
Subject to the conditions in UK data protection law, you have the right to:
- Access the personal data we hold about you.
- Have inaccurate personal data corrected.
- Have personal data erased in certain circumstances.
- Restrict or object to certain processing.
- Receive a copy of certain data in a portable format.
- Withdraw consent where processing is based on consent.
13. How to contact us
For privacy questions or to exercise your rights, contact [email protected]. We will respond within the timeframes required by UK data protection law.
14. How to complain to the ICO
If you are not satisfied with how we have handled your personal data, you have the right to complain to the Information Commissioner's Office (ICO). Information about how to complain is available at https://ico.org.uk/make-a-complaint/.
15. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page indicates when it was most recently changed. Material changes will be communicated through the Service or by email where appropriate.
For practical guidance on how to make a data rights request, see our Privacy requests page.