Privacy Policy
Last Updated: August 26, 2025
This Privacy Policy describes how Sublmnl ("we," "us," or "our") collects, uses, and discloses information when you use our website and services at https://sublmnl.ca/ (the “Service").
By accessing or using the Service, you agree to the collection, use, and disclosure of your information in accordance with this policy.
We are committed to protecting the personal information of our users in compliance with applicable privacy laws, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the European Union’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), Quebec’s Law 25, and other applicable international data protection regulations.
1. Information We Collect
We collect information to provide, personalize and improve our Service.
Information You Provide to Us:
- Account Information: When you create an account, we collect information such as your email address and a password.
- Personal Input for Affirmations: A central feature of our Service involves you entering your personal "desires" or "goals" to generate customized subliminal audio tracks. This input may include sensitive personal information. We treat this data with a high standard of care, applying strict access controls and data handling practices to protect your privacy.
- Payment Information: If you purchase a track or subscription, our third-party payment processor, Stripe, will collect your payment information (e.g., credit card details). We do not directly store your full payment card details on our servers.
- Communications: When you contact us for support or inquiries, we collect the content of your communications and any contact information you provide.
Information We Collect Automatically:
- Usage Data: We collect information on how the Service is accessed and used ("Usage Data"). This may include your device's Internet Protocol (IP) address, browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
- Cookies and Tracking Technologies: We use cookies and similar tracking technologies to track the activity on our Service and hold certain information. For more details, please refer to our Cookie Policy.
2. How We Use Your Information
We use the collected information for various purposes:
- To Provide and Maintain the Service: Including processing your requests for custom subliminal audio tracks based on your inputted desires.
- To Manage Your Account: To allow you to access and manage your account and track your downloads.
- For Analytics and Performance: To monitor the usage of our Service and gather valuable analytics to improve our offerings.
- To Communicate with You: To send you service-related notifications, updates, and respond to your inquiries.
- For Security: To detect, prevent, and address technical issues or fraudulent activity.
- For Legal Compliance: To comply with legal obligations and enforce our Terms of Service.
3. Sharing Your Information
We do not sell your personal information. We may share your information in the following situations:
- With Service Providers: We may employ third-party companies and individuals to support our Service. These include Payment Processors, Hosting and Infrastructure Providers, Analytics Providers, and AI Content Generation Providers, such as OpenAI, whose API we use to generate your personalized affirmations. We send the category you select and the personal goal(s) you input to this provider strictly to generate affirmations in real time. This input may include sensitive personal information. The data is not used to train the AI model and is not retained after processing.
- For Business Transfers: If Sublmnl is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
- For Legal Reasons: We may disclose your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation.
- Protect and defend the rights or property of Sublmnl.
- Prevent or investigate possible wrongdoing in connection with the Service.
- Protect the personal safety of users of the Service or the public.
- Protect against legal liability.
- Aggregated or Anonymized Data: We may share aggregated or anonymized information that does not directly identify you with third parties for research, marketing, analytics, or other purposes.
4. Data Related to Your Desires and Affirmations
When you use the Service to generate subliminal affirmations, you provide selected inputs such as a category (e.g., health, career) and a freeform personal goal. This input may include sensitive personal information and is treated with care and respect for your privacy.
To create personalized affirmations, we transmit your selected inputs to a third-party AI service - currently OpenAI - using their API. This means that the processing of your input (i.e., generating the affirmations) occurs outside of Sublmnl’s proprietary infrastructure, on OpenAI's systems. We do not train the AI model with your data; it is a pre-trained model that responds in real-time using only the current input you provide.
We use a fixed prompt structure that includes your selected category and goal. No additional personal information or chat history is used in this process.
Before sending your input to OpenAI, we format it but do not otherwise pre-process, enrich, or store it beyond what is needed to complete the request. Once we receive the generated affirmations, we integrate them into audio tracks locally and deliver them to you.
We implement safeguards to avoid linking this input to your identity during processing. We do not share your specific desires or affirmations with any third parties in a way that directly identifies you, except as required to provide the service or comply with applicable law.
5. Data Security
The security of your data is important to us. We implement multiple safeguards to protect your personal information, including:
- End-to-end encryption for data transmitted between your device and our servers
- Encryption at rest for stored personal data
- Strict access controls, ensuring that only authorized personnel can access sensitive information
While we use commercially reasonable and industry-standard security practices, no method of transmission over the Internet or electronic storage can be guaranteed 100% secure. We continuously review and update our practices to help protect your data, but we cannot guarantee absolute security.
6. International Data Transfer
Your information, including Personal Data, may be transferred to - and processed on - servers located outside of your province, territory, or country, including in jurisdictions such as the United States, where privacy and data protection laws may differ from those in your home region.
Some of our key service providers, including Vercel (for hosting), Stripe (for payment processing), and OpenAI (for generating personalized affirmations), are based in or process data in the United States and other countries. As a result, your Personal Data may be subject to the laws of those jurisdictions.
By using our Service and submitting your information, you consent to this international transfer, processing, and storage of your Personal Data. We take appropriate steps to protect your data across borders, including the use of contractual data processing agreements and other safeguards required under applicable laws such as the GDPR and PIPEDA, to ensure your data receives a comparable level of protection wherever it is processed.
7. Your Data Protection Rights
Depending on your location and the laws that apply to you, you may have certain rights regarding your personal data. Below is an overview of your rights under applicable data protection frameworks:
7.1. Your Rights Under PIPEDA (Canada)
- Access the personal information we hold about you, subject to limited exceptions.
- Request corrections to any inaccuracies in your personal information.
- Withdraw your consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions and reasonable notice.
- Be informed about the purposes for which your personal information is collected, used, or disclosed.
We are required to respond to access requests in writing within 30 days of receipt.
7.2. Your Rights Under Quebec’s Law 25 (Canada)
- The right to be informed of automated decision-making that affects you.
- The right to request human intervention in such decisions.
- Enhanced transparency regarding how your personal information is collected and transferred.
- The right to data portability (effective from September 2024).
7.3. Your Rights Under GDPR (European Union & UK)
- Access your personal data.
- Correct inaccuracies in your data.
- Erase your personal data (“right to be forgotten”).
- Restrict or object to certain types of processing.
- Receive your data in a portable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local data protection authority.
7.4. Your Rights Under CCPA/CPRA (California Residents)
- Know what personal information is being collected and how it is used.
- Access your personal information.
- Request deletion of your personal information.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal data.
- Not be discriminated against for exercising any of your privacy rights.
We do not sell your personal information.
7.5. Other Jurisdictions
If you reside in a jurisdiction with data protection laws not specifically listed above (such as India, New York, or other U.S. states), we will comply with the applicable laws of your region to the extent required. You may contact us at hello@sublmnl.ca to inquire about your rights or submit a request.
Exercising Your Rights
To exercise any of the above rights, please contact us at hello@sublmnl.ca. We may request verification of your identity before processing your request. We will respond within the timeframes required by applicable law.
8. Children’s Privacy
Our Service is not intended for individuals under the age of 16, and we do not knowingly collect personally identifiable information from anyone under that age. In accordance with applicable data protection laws, including the U.S. Children’s Online Privacy Protection Act (COPPA) and the EU General Data Protection Regulation (GDPR), we do not permit individuals under the age of 16 to use the Service or submit personal information without verifiable parental consent.
If you are a parent or guardian and believe that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from a child under the age of 16, we will take steps to delete that information promptly.
9. Data Retention
We retain personal information only as long as necessary to provide our Service, fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements.
- Account Information (name, email, password) is stored to enable login and is retained as long as your account is active. To delete your account and associated data, email us at hello@sublmnl.ca. Upon request, we will delete your account and all associated personal data, including stored audio tracks, unless retention is required by law.
- Desires and Affirmation Inputs (e.g., your selected category and goal) are used solely to generate your personalized audio and are deleted immediately after the track is created. We do not store this input or the raw affirmations returned by the AI.
- Final Audio Tracks are stored and linked to your account so you can access them after creation.
- Payment Information is handled securely by our payment processor, Stripe. We do not store full payment card details on our servers. Stripe retains this data in accordance with its own privacy and retention policies.
10. Privacy Officer Contact Information
We have designated a Privacy Officer responsible for overseeing compliance with applicable privacy laws, including PIPEDA, Quebec’s Law 25, and the GDPR.
Privacy Officer
Nitasha Asdhir
Founder, Sublmnl
If you have any questions, concerns, or requests regarding your personal information or this Privacy Policy, please contact us using the details above.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us: hello@sublmnl.ca