Privacy Policy
Effective September 5, 2026
This explains what we collect when you use The Twenty Minute Marriage, why we collect it, who else sees it, and how to get it back or get rid of it. We do not sell your personal information, and we never have.
1. Who we are
The Twenty Minute Marriage is operated by Ben Magnone Consulting LLC, Waddell, Arizona. Questions about anything here go to team20@magnoneconsulting.com.
2. What we collect
When you create an account. Your email address, a password (stored only as a cryptographic hash — we cannot read it), and the display name you choose, which is visible to other members on the community wall.
What you do in the app. Which days you logged a workout, your current and longest streak, your rest days, any grace days you use, and which challenge you are enrolled in.
What you tell the nutrition page. The answers you give the calorie calculator and the daily calorie target it produces. These are derived from details about your body, so we treat them as sensitive even where the law does not require us to.
Your commitments. The promises you choose, the times and numbers you set, the name you sign them with, and which reminders you asked for.
What you post. Anything you write on the community wall, your replies, and the boosts and reactions you give. This is visible to other members by design.
Purchases. The product, the amount, the date and your email address. We never see or store your card number — Stripe handles payment details and we only receive a reference to the completed transaction.
Notifications. If you turn on push, a subscription token from your browser and your device’s time zone, so a reminder can arrive at the right hour where you are.
Technical basics. Standard server logs kept by our hosting provider, and the date you were last active.
3. What we do not collect
No card numbers. No location tracking. No advertising identifiers, no third-party advertising or analytics trackers, and no cross-site profiling. We do not buy data about you from anybody.
4. Why we hold it
To run the thing you signed up for: serve your workout, count your streak, show the community wall, work out your nutrition targets, send the emails and reminders you asked for, deliver what you bought, and answer you when you write in. We also look at aggregate numbers — how many people finished a day, how many joined — to understand whether the programme works. That is counting, not profiling.
5. Email and notifications
Challenge emails have an unsubscribe link and honour it immediately; you can also just reply and ask, and a person will action it. Transactional messages — a receipt, a password reset — are not marketing and continue regardless. Push notifications are off until you turn them on and can be turned off in the app or in your device settings at any time.
6. Who else sees your data
We use a small number of service providers. They process data on our behalf and may not use it for their own purposes:
- Supabase — the database and login system where your account lives.
- Vercel — hosting and server logs.
- Stripe — payments. They handle your card; we do not.
- Resend — sending email.
- Apple, Google and Mozilla — whichever operates your browser’s push service, to deliver a notification to your device.
- YouTube — movement demo videos are embedded, so opening a workout page may set cookies from Google. That is their processing, under their policy.
- ManyChat — only if you first message us on Instagram.
We will also disclose information if the law genuinely requires it. If the business is ever sold, your data moves with it and you will be told before anything changes.
7. Other members
Your display name and anything you post on the wall are visible to every signed-in member, and your name and streak appear on the leaderboard. Your email address, your nutrition numbers, your commitments and your purchases are never shown to other members. If you would rather not be identifiable, change your display name — it is yours to set.
8. Cookies and local storage
We use a cookie to keep you signed in, and your browser’s local storage to remember small conveniences: your equipment, your streak while signed out, whether you dismissed the home-screen prompt. None of it is advertising, and there is no third-party tracker on the site. Embedded YouTube players set their own cookies, as above.
9. How long we keep it
Your account data lasts as long as your account. Ask us to delete it and we will, within 30 days. Two things survive: records of purchases, which we are required to keep for tax and accounting, and unsubscribe records, because that list is the only way we can be sure not to email you again.
10. Your rights
Wherever you live, you can ask us for a copy of what we hold, ask us to correct it, or ask us to delete it. Email team20@magnoneconsulting.com and we will answer within 30 days. There is no bot on the other end.
If you are in California, the CCPA gives you those rights explicitly, plus the right not to be discriminated against for using them. We do not sell or share personal information as those terms are defined, so there is nothing for you to opt out of.
11. Security
Everything travels over HTTPS. Passwords are hashed and salted by our login provider and are not readable by us. Database access is restricted per member, so one member’s account cannot read another’s. No system is perfect, and we will tell you promptly if something happens that affects you.
12. Children
This is for adults. You must be 18 or over to have an account, and we do not knowingly collect anything from children. If you believe a child has signed up, write to us and we will remove the account.
13. Changes
If we change anything substantive we will update the date at the top and tell you by email. Continuing to use the app after that means you accept the new version.
See also our Terms of Service and Assumption of Risk.