Legal
Privacy Policy
This policy explains what kathygademer.com collects, why, and what you can ask us to do about it. It is written to be read, not to be skimmed past.
Last updated September 25, 2026
Who we are
kathygademer.com is operated by Kat and Bones LLC, a Florida limited liability company, which also publishes under the names Power Launch Your Life and Mid-Level Leadership Strategies. In this policy “we”, “us”, and “our” mean Kat and Bones LLC.
For any question about this policy, or to make any request described in it, email kathy@kathygademer.com.
What we collect
We collect only what the site needs in order to work.
When you create an account
- Your email address. This is your account. We use it to send your sign-in codes and your receipts.
- Your name, if you choose to give it. This is optional and you can leave it blank.
We do not use passwords. You sign in with a six-digit code sent to your email. We never store that code — only an irreversible hash of it, which expires after ten minutes and is destroyed once used. There is no password of yours for anyone to steal from us, because we never had one.
When you use the site
- Your IP address and browser user-agent, recorded when a sign-in code is requested and when a session is created. We keep these to detect someone trying to break into an account, and to enforce the limit on how many codes can be requested.
- Which pages were viewed, when, the referring page, and the country the request came from. This is our own traffic counter.
- Your progress through the program — which lessons and steps you have marked complete, and where you stopped, so you can pick up on another device.
- The date you were last active, which is how we know whether someone has stalled and might want a note from Kathy.
When you buy something
- A record of the purchase — what was bought, the amount, any discount or promotion code applied, the tax, and the identifiers Stripe gives us for the payment.
- Which modules you own. Your access does not expire, so we keep this for as long as your account exists.
We never see or store your card details. Payment happens on Stripe’s own checkout pages, not ours. Your card number, expiry, and security code go directly to Stripe and never touch this site. We receive only a confirmation that payment succeeded and a reference number.
When you verify military status
To claim the military discount you enter the .mil email address
of a service member you are connected to, and we send a code there.
We do not keep that address. It is used to send the code and
then discarded. All we record is that verification succeeded, and when.
The service member is usually not our customer and never agreed to be in our
records, so we do not put them in.
When you contact us
If you send a message through the contact form, we receive what you wrote and the email address you gave so we can reply.
What we do not collect
- No advertising or analytics trackers. There is no Google Analytics, no Meta pixel, no advertising network, and no third-party tracking script anywhere on this site. Our traffic counting is our own and stays on our own systems.
- No card or bank details. Those stay with Stripe.
- No passwords. We do not use them.
- No cross-site tracking. We do not follow you around the internet, and we do not build advertising profiles.
- No sensitive categories. We do not ask for, and do not want, your government identifiers, financial account numbers, health information, biometric data, or precise location.
Cookies
This site uses cookies only where something would break without them. There are no advertising cookies and no analytics cookies.
-
kg_session— set when you sign in. It holds a random token, not your identity, and the matching value in our database is stored only as a hash. It is marked HttpOnly and Secure, so scripts in your browser cannot read it. It lasts 30 days, or 24 hours for an administrator, and is revoked the moment you sign out. - Cloudflare Turnstile may set a short-lived cookie when it checks that a form is being submitted by a person. Turnstile is used instead of reCAPTCHA specifically so that the check does not hand your browsing to an advertising company.
Because we set no advertising or analytics cookies, there is no consent banner to click past.
Why we are allowed to use your information
We use what we collect to:
- sign you in and keep your account secure;
- give you the modules you have bought and remember your progress;
- take payment and send receipts;
- answer you when you write to us;
- send you email about the program, if you have asked for it — and stop the moment you ask us to;
- understand in aggregate which pages people read, so Kathy can write more of what helps;
- meet our legal, tax, and accounting obligations.
We do not sell your personal information, and we never have. We do not share it for cross-context behavioral advertising. We do not rent or trade our mailing list.
Who else handles your information
We use a small number of service providers to run the site. Each one only receives what it needs to do its job, and none of them may use your information for their own marketing.
- Cloudflare, Inc. — hosting, content delivery, the Turnstile anti-bot check, and the access control in front of our administration pages.
- Supabase, Inc. — the database holding your account, purchases, and progress.
- Stripe, Inc. — payment processing. Stripe handles your card details under its own privacy policy, as an independent business rather than on our behalf.
- Resend (Plus Five Five, Inc.) — sending your sign-in codes, receipts, and any email you have subscribed to.
We may also disclose information if the law requires it, if we must defend a legal claim, or if the business is sold or transferred — in which case this policy continues to apply until you are told otherwise.
How long we keep it
- Sign-in codes — ten minutes, or fifteen for a military verification code. Destroyed as soon as they are used.
- Sessions — 30 days, or 24 hours for an administrator, and immediately on sign-out.
- Your account, purchases, and progress — for as long as you have an account. Because your access never expires, we have to keep the record of what you own.
- Purchase and tax records — retained after account deletion for as long as tax and accounting law requires.
- Unsubscribe records — kept indefinitely. This is the list that stops us emailing you again, so deleting it would defeat its purpose.
What you can ask us to do
Florida’s Digital Bill of Rights sets its obligations at a size of business far larger than ours, and we are well below that threshold. We are telling you that plainly rather than implying a legal obligation we do not have. We offer the following as a matter of policy anyway, to anyone, wherever you live:
- See it. Ask for a copy of what we hold about you.
- Correct it. Tell us if something is wrong.
- Delete it. Ask us to remove your account and personal information. We will keep only what tax law requires us to keep, and we will tell you what that is. Deleting your account ends your access to any module you bought, and we cannot restore it afterwards.
- Take it with you. Ask for your information in a portable file.
- Stop the email. Every message we send has an unsubscribe link, and it works immediately. You can also just ask us.
Email kathy@kathygademer.com and we will respond within 30 days. We will not charge you, and we will not treat you differently for asking. If we need to confirm it is really you, we will do it through the email address on the account.
If something goes wrong
If personal information in our care is ever breached, we will notify affected individuals within 30 days of determining that it happened, as the Florida Information Protection Act (section 501.171, Florida Statutes) requires, and we will notify the Florida Department of Legal Affairs and any other authority where the law requires it.
How we protect it
Everything travels over an encrypted connection. Sign-in codes and session tokens are stored only as irreversible hashes, so reading our database does not let anyone sign in as you. Codes expire quickly and are rate-limited against guessing. Content you have not bought is not merely hidden in the page — it is never sent to your browser at all. Administration pages sit behind a separate identity check with its own second factor.
No system is perfect, and we will not pretend otherwise. But we have tried to design this one so that a mistake exposes as little as possible.
Children
This site is meant for adults and is not directed to children. We do not knowingly collect information from anyone under 13. If you believe a child has given us information, write to us and we will delete it.
Where your information is held
We operate from the United States and our providers store information in the United States. If you are outside the United States and use this site, your information will be handled there, where privacy law may differ from your own. If you are in the United Kingdom or European Economic Area and want to exercise a right under the law that applies to you, write to us and we will honor it.
Changes
If we change this policy we will change the date at the top. If a change materially affects how we handle information we already hold, we will email account holders before it takes effect.
Contact
Kat and Bones LLC · kathy@kathygademer.com