Last updated: September 10, 2026
This Privacy Policy explains how Samudra Global School for Living Yoga, operating as Yoga Alchemy (“we”, “us”), collects, uses, stores and shares personal information through www.yogaalchemy.com, its member area and connected account services. It covers registration, sign-in, yoga courses, memberships, events, purchases and communications. Yoga Alchemy is responsible for the personal information it processes to operate these services.
For privacy questions or requests, contact info@yogaalchemy.com. For account assistance, contact support@yogaalchemy.com. You can read this policy without creating an account. This revision replaces earlier versions of our privacy notice.
Google, Apple and passkey data · Sharing · Retention · Your rights and deletion
1. Information We Collect and Why
- Account and profile: email address, verification status, account identifiers, name and profile details you provide or authorize a sign-in provider to supply. We use these to create and secure your account, display your profile and provide member access. Provider profiles, avatars and history are explained in Section 2.
- Memberships and purchases: chosen plans or products, subscription status, orders, billing/contact details and payment references. We use these to process purchases, manage access, renewals, refunds, customer support and accounting.
- Practice and preferences: course and lesson progress, saved preferences and account settings, including time zone. We use these to resume your practice, personalize the member experience and display relevant daily content.
- Forms and communications: information you submit through contact, application, newsletter or other service forms, and messages you send to support. We use it to respond, process your request and maintain the related correspondence. The information required depends on the form you choose to complete.
- Technical and security information: IP address, browser/device information, request and sign-in times, session identifiers, errors and verification events. We use these to operate the website, diagnose problems, protect accounts and limit abuse. We do not obtain your unrelated browser history through Google sign-in.
Card details entered in our Stripe payment flow are processed by Stripe. Yoga Alchemy does not store full payment card numbers or card security codes. We retain relevant customer, payment and subscription references and transaction records. Stripe also processes information under its privacy policy.
2. Google, Apple, Passkeys and Account Profiles
This section applies to registration and sign-in on www.yogaalchemy.com and the Yoga Alchemy member app. The information below describes the data we access, store and use for each sign-in method, including imported profile details and their history.
Sign in with Google
When you choose Google, we request the OpenID Connect permissions openid, email and profile. We receive and store your Google account identifier, email address and email verification status. When Google supplies them, we also store your name, given and family names, profile picture URL and language/locale information. We use these details to identify your account and populate or update your Yoga Alchemy profile. We download and store a resized copy of the profile picture when available. Your Google password, Gmail messages, Google Drive files, contacts, Google Calendar and browsing history are not accessed through these permissions.
We use this information to authenticate you, maintain the link to your account, display your account name and avatar, and help authorized administrators resolve account and profile issues. We update provider details when you use that provider again. A name you have edited yourself is protected from automatic replacement; the imported provider details and their earlier versions remain separately recorded. Connecting a provider to an existing account requires verification of that account. We process authentication tokens to verify the sign-in response; our current implementation does not persist Google access, refresh or identity tokens for ongoing access to Google services.
Sign in with Apple
When you choose Apple, we request name and email permission. We receive and store an app-associated Apple account identifier, email address and email verification status. The email may be an Apple private relay address if you choose Hide My Email. When Apple supplies your name, usually on initial authorization, we store the given and family names and may use them to populate your Yoga Alchemy profile. We retain the previously received details when later sign-ins omit them. Sign in with Apple does not provide a profile photo, and we do not receive your Apple password, payment information, photos, contacts or iCloud files.
We also process verified notifications from Apple about authorization revocation, Apple account deletion and changes to private email forwarding. These records include the account identifier, event type and time, processing outcome and, for forwarding updates, the relay email and forwarding status. We use them to protect your account, invalidate affected sessions and respect forwarding changes. Our current sign-in implementation does not persist Apple access, refresh or identity tokens.
Provider profiles, avatars and change history
We store the latest profile received from each linked provider and record an earlier or new version when the stored profile or avatar changes. These records include the provider and account identifier, the profile fields supplied, the associated avatar reference, and the time the version was recorded. Changes you make to your Yoga Alchemy name and time zone are also recorded with their source. This is a history of account profile changes, not your Google or Apple browsing, search, email or activity history. Authentication tokens, authorization codes and unrelated provider data are excluded from these profile records.
We use the history to distinguish provider updates from your own edits, understand account changes and assist with support and account management. Updating a name or photo does not automatically erase previous versions. If a provider omits a field on a later sign-in, we may retain the previously received value. We store the source picture URL and a processed avatar copy; a failed image download may leave the previous avatar in place.
Passkeys and email verification
After verifying your account, you can register a passkey and use it for future sign-ins. We store a credential identifier, public key, account association, a label, creation and last-use times, and technical security information such as a signature counter and whether the credential supports backup. During setup, your browser or passkey manager receives your Yoga Alchemy email as the account label and a random account handle.
Yoga Alchemy does not receive or store your passkey private key, fingerprint, facial scan, device PIN or device password. Your device or passkey provider performs local user verification and supplies a cryptographic response that we verify. If your passkeys are synchronized across devices, that synchronization is managed by your chosen provider under its own privacy policy.
For email sign-in and verification, we process your email address, verification requests, expiring codes or links, and security information such as request times, IP address and browser/session identifiers. We use these to deliver access messages, verify requests and limit abuse.
Use, sharing and protection of authentication data
We do not sell Google or Apple user data, including imported profiles, avatars and their history, or passkey records, use them for targeted advertising, share them with advertising networks or data brokers, or use them to train generalized artificial intelligence or machine-learning models. Signing in does not authorize unrelated access to your Google or Apple account.
Google or Apple processes the authorization you initiate under its own privacy policy. Our hosting, database, storage and security providers process the account details, imported profiles, avatar copies and history necessary to run these features on our behalf. Authorized administrators can inspect provider profiles and historical versions for account support and management. Email delivery, payment and support providers may receive relevant account and contact information when delivering the services you request; we do not provide them with authentication secrets or passkey credentials for those purposes. When our server retrieves a Google profile image, the image host receives the requested image URL and normal server connection information, including our server IP address. We serve the stored copy through our access-controlled avatar endpoint. Other disclosures are described in Section 4.
We protect authentication exchanges with HTTPS, verify provider signatures and sign-in responses, use expiring challenges and session controls, and limit access to account records. Avatar downloads are restricted to approved HTTPS hosts and public network addresses, with file size and image dimension limits. Downloaded images are decoded, resized and re-encoded before storage, rather than serving the original image file. Avatar files are held in private storage and served through an authenticated endpoint with no-store caching instructions. Current avatars are accessible only to their owner and administrators; historical avatars and the profile history interface require administrator access. Passkey sign-ins require verification of a cryptographic response against the stored public key. These measures reduce risk but cannot guarantee absolute security.
Retention, revocation and deletion
We retain your account email, linked provider identifiers, latest imported profiles, stored avatar copies and profile change history while needed to operate and support your account. The current profile feature does not automatically delete historical versions after a fixed number of days. A profile update, sign-out or revocation of Google or Apple access does not itself erase stored profiles, previous avatars or history. You may request their deletion as described below. Passkey records remain until removed or until the account is deleted, subject to necessary legal or security retention. Authentication tokens processed during Google and Apple sign-in are not stored as long-term credentials. Security and Apple notification records may be retained for account protection, investigation of abuse or legal obligations; they are not used for advertising.
You can remove a registered passkey in Account security. This removes the server-side credential; you may also need to delete its saved entry in your device or passkey manager. You can revoke Google access in your Google Account connections, or manage Sign in with Apple and email forwarding in your Apple Account settings. Revoking a provider connection does not itself delete your Yoga Alchemy account, purchase records or subscription, and does not necessarily end every existing Yoga Alchemy session.
To request access, correction, removal of a provider association, deletion of imported profile details, stored avatar copies or profile history, or deletion of your Yoga Alchemy account, email info@yogaalchemy.com. These requests are handled by our team after verifying your identity; changing your displayed name or photo is not a deletion request. A deletion request can cover the current provider profile, historical versions and associated avatar files, not only the visible account fields. We remove data no longer needed when fulfilling the request, and explain any records that must be retained for accounting, legal claims or necessary security purposes. Backup copies may remain until the applicable backup cycle ends and are restricted to backup and recovery purposes. If you later sign in with the provider again, the provider may supply profile data again. Retention also depends on the purposes and exceptions described in Section 6.
3. Cookies, Daily Content and Communications
We use cookies and browser storage for sessions, sign-in security, account access and preferences. Authentication cookies hold identifiers or security tokens, not your Google or Apple password, biometric data or passkey private key. Blocking essential cookies may prevent sign-in and other features you request.
For Daily Rhythm, the browser supplies its time zone so we can show the appropriate local day. The time-zone cookie may remain for up to one year unless you clear it or it is refreshed. This does not require GPS permission. Other session and preference cookies have their own expiration periods and can be managed through your browser.
Creating an account or using Google, Apple or a passkey does not itself subscribe you to marketing. Promotional messages follow your marketing choices and applicable consent requirements. You can unsubscribe using the link in a marketing email or by contacting us. Essential access, security, purchase and subscription messages are separate from marketing.
Third-party content, such as an embedded video, may cause your browser to communicate with that provider and disclose connection information such as your IP address and browser details. External websites and services apply their own privacy policies. These interactions are separate from the Google or Apple information imported for your Yoga Alchemy account.
4. Who Can Receive Your Information
Personnel and service providers receive the information necessary for their role in delivering the service: hosting and database/storage providers operate the site and account records; security providers help protect it; email-delivery providers send requested messages; Stripe processes payments; and support tools help us handle your requests. We limit access to the relevant purpose. Google and Apple handle the authorization you initiate under their own privacy policies.
Authorized administrators can view imported profiles and profile history for account management and support. The current avatar is restricted to its owner and administrators, and historical avatars are restricted to administrators. Your display name may appear in member features where you choose to participate; this does not make your imported profile history public.
We do not sell Google or Apple user data, imported profiles, avatars, profile history or passkey records. We do not share that information with advertising networks or data brokers, use it for targeted advertising, or use it to train generalized AI or machine-learning models. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements where applicable.
We may disclose information when required by law, to respond to a valid legal process, or as necessary to protect the rights and safety of users and the service. A business transfer may require transfer of relevant records, subject to applicable law and the privacy commitments governing those records. We will not treat a business transfer as permission for unrelated use of Google user data.
5. Security and International Processing
We use HTTPS, authenticated access controls and role-based restrictions to protect account information. Section 2 explains the additional controls for Google/Apple sign-in, passkeys and stored avatars. No website or transmission method can guarantee absolute security.
Information may be processed where Yoga Alchemy and its service providers operate, including countries outside your country of residence. Applicable laws may differ. Transfers subject to European, UK or Swiss data protection requirements must use an applicable lawful transfer mechanism and safeguards. Acknowledging this policy does not itself authorize an otherwise unlawful transfer. Contact us for information about the providers and transfer arrangements relevant to your data.
6. How Long We Keep Information
We retain account information while needed to provide and support your account. Imported provider profiles, avatar copies and profile history are retained as described in Section 2; the current history feature has no fixed-day automatic deletion schedule. Updating a profile or revoking a provider connection does not automatically remove its historical records.
Purchase and accounting records may remain after account closure where needed for applicable legal obligations, refunds, disputes or legal claims. Support correspondence and security records are retained according to the purpose of the request, investigation or obligation. Marketing preferences may be retained as necessary to honor an unsubscribe request. These purposes do not require every category of data to be kept for the same period.
You can request deletion at any time. Our team verifies your identity, removes data no longer needed and explains any applicable retention exception. Backup copies may remain until their backup cycle ends and are restricted to backup and recovery purposes. We do not promise immediate deletion from every backup or automatic deletion that the service does not perform.
7. Your Choices, Rights and Deletion Requests
Email info@yogaalchemy.com to request access, correction, an export or deletion of your personal information, including your account, provider links, imported profiles, current and historical avatars, and profile history. Tell us which account and data your request concerns. We may need proportionate information to verify your identity; do not send passwords, payment card details or identity documents unless a specific secure verification process requires them.
Depending on your location and applicable law, you may also have rights to restrict or object to processing, receive portable data, withdraw consent, or complain to your data protection authority. Withdrawing consent does not affect processing that was lawful before withdrawal. We respond within applicable legal time limits and explain any lawful exception.
You can edit available profile fields in account settings and remove passkeys in Account security. Editing visible details does not erase their history. Google access can be revoked in Google Account connections; Apple access and private email forwarding can be managed in Apple Account settings. Revocation is distinct from deleting your Yoga Alchemy account or cancelling a paid subscription.
8. Grounds for Processing
Where European, UK or similar data protection rules apply, we process information as necessary to provide the account, purchases and services you request; to meet legal obligations; for legitimate interests such as account security, fraud prevention and support where those interests are not overridden by your rights; or with your consent where required, such as certain marketing activities. Choosing Google or Apple authorizes that provider to supply the information described during sign-in. It does not authorize unrelated advertising uses.
9. Children
Account registration and purchases are intended for adults aged 18 or over. We do not knowingly collect account information from children under 18. If you believe a child has provided personal information through these services, contact us so we can review and remove it where appropriate.
10. Policy Changes and Contact
We update this policy when our practices change and show the revision date above. For material changes, including changes to how we use Google user data, we will provide an appropriate notice through the service or another suitable channel and obtain additional consent where required.
Privacy contact and data controller: Samudra Global School for Living Yoga, operating as Yoga Alchemy, info@yogaalchemy.com. Account support: support@yogaalchemy.com. See also our Terms of Service and contact page.