This Privacy Policy explains how Shimrit Bukelman, operating under the brand Master Your Path ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use the Freedom Intelligence Field (the "Field") and any related products, courses, memberships or communications.
We are based in Berlin, Germany, and we handle your data in line with the EU General Data Protection Regulation (GDPR) and German data protection law.
We've tried to write this in plain language rather than legalese. If anything is unclear, please email us at support@shimritnativ.com.
1. Who is the data controller
The data controller for your personal data is:
Shimrit Bukelman
Operating under the brand Master Your Path
Berlin, Germany
support@shimritnativ.com
2. What personal data we collect
We only collect the data we actually need to run The Field, communicate with you, and comply with the law. That includes:
2.1 Data you give us directly
- Contact data: your first name, last name, and email address when you sign up for the Free Preview, purchase the Reset or Unlimited, or contact support.
- Payment data: processed by our payment provider (ThriveCart, with Stripe or PayPal as the processor). We do not see or store your full card number.
- Account data: your login credentials, your subscription status, your preferences.
- Conversation data: the messages you write to The Field and The Field's replies, plus any structured records The Field creates (for example, your Day 1 State Reset record).
- Support communications: emails, WhatsApp messages, or other communications you send us.
2.2 Data collected automatically
- Usage data: when you log in, which day of the Reset you completed, which processes you started, session timestamps.
- Technical data: IP address, browser type, device type, operating system. Used for security, fraud prevention, and to keep the app working properly.
- Cookies: only strictly necessary cookies to keep you logged in. See section 8 below.
2.3 Data from third parties
- Kajabi: when you buy the Reset through our Kajabi checkout, Kajabi shares your name, email, and purchase details with us so we can grant you access.
- ThriveCart: similar handoff of name/email/purchase for other checkout paths.
3. Why we use your data and our legal basis
Under GDPR, we can only use your personal data if we have a valid legal basis. Here's what we use your data for, and why we're allowed to:
| What we do | Legal basis |
|---|---|
| Provide The Field to you (account access, chat, memory across sessions, Day records) | Performance of a contract |
| Take payment and manage subscriptions | Performance of a contract |
| Send you service emails (welcome, receipts, reminders, cancellations) | Performance of a contract |
| Send you marketing emails (only if you consented) | Your consent |
| Improve The Field (anonymised analytics, aggregated patterns) | Legitimate interest |
| Detect abuse, fraud, or safety issues | Legitimate interest |
| Comply with legal obligations (tax, accounting, requests from authorities) | Legal obligation |
You can withdraw your consent for marketing emails at any time by clicking the unsubscribe link at the bottom of every email or emailing us. Withdrawing consent doesn't affect our right to have processed your data before you withdrew it.
3.1 Sensitive information you may share in conversations (GDPR Article 9)
The Field is a coaching-adjacent inner-work space, so it's normal for conversations to touch on emotional states, stress, relationships, or your general wellbeing. Some of what you share may qualify as "special category" personal data under GDPR Article 9 — most often information about your health (including mental or emotional health).
Our legal basis for processing this kind of information is your explicit consent (GDPR Article 9(2)(a)), given when you tick the acceptance box on the Terms & Privacy welcome screen inside The Field before starting your first session. You can withdraw this consent at any time by emailing us at support@shimritnativ.com and asking us to delete your data. If you withdraw, you may no longer be able to use The Field, because processing your messages is essential to how the service works.
Additional safeguards we apply to conversation content:
- Conversations are stored encrypted at rest in our EU-hosted database (Neon, Frankfurt).
- Individual conversations are not read by our team except in the narrow situations described in section 12 below.
- Anthropic (our AI provider) does not use your conversations to train its models under our commercial arrangement.
- We do not use conversation content for marketing, profiling, or automated decision-making that has legal or similarly significant effects on you.
- The Field is not a medical device and is not intended to diagnose, treat, or manage any medical or mental-health condition. Please see the Terms & Conditions section on this.
If you would prefer not to share sensitive information at all, you are free to keep your conversations at a more general level. You are always in control of what you write.
4. Third-party processors — who else touches your data
We use a small number of trusted third-party services to run The Field. Each of them is a "data processor" under GDPR — they process your data on our behalf, according to a signed data processing agreement, and they are not allowed to use your data for their own purposes.
| Provider | What they do for us | Data location |
|---|---|---|
| Anthropic | Powers the AI that responds inside The Field (Claude language model). Your messages are transmitted to Anthropic's API to generate replies. | United States (with EU Standard Contractual Clauses in place) |
| Vercel | Hosts The Field app and landing pages. | EU / global (edge network with EU regions) |
| Neon | Managed PostgreSQL database — stores your account and conversation history. | EU (Frankfurt) |
| GoHighLevel (GHL) | CRM and marketing emails. | United States (with EU Standard Contractual Clauses) |
| Kajabi | Course delivery and website hosting for the marketing site. | United States (with EU Standard Contractual Clauses) |
| ThriveCart | Checkout and subscription management. | United States (with EU Standard Contractual Clauses) |
| Stripe / PayPal | Payment processing (via ThriveCart or Kajabi). | EU / United States |
| Zapier | Automations that connect the above services together. | United States (with EU Standard Contractual Clauses) |
We do not use your conversations to train third-party AI models. Anthropic does not use API traffic to train its models under our commercial arrangement.
5. International transfers
Some of the providers listed above are based in the United States or process data outside the EU/EEA. Where personal data is transferred outside the EU/EEA, we rely on:
- Standard Contractual Clauses approved by the European Commission, and
- Where relevant, additional technical and organisational safeguards such as encryption in transit and at rest.
6. How long we keep your data (retention)
- Account and conversation data: for the duration of your active subscription or membership, plus 90 days after cancellation or account closure.
- Payment records and invoices: kept for 10 years to comply with German tax and accounting law.
- Marketing contacts: until you unsubscribe or ask us to delete your data.
- Support communications: up to 2 years after the last interaction.
- Preview session data (Free Preview): 12 months, then deleted.
You can ask us to delete your data earlier — see section 7 below.
7. Your rights under GDPR
If you're in the EU (and often even if you're not, because we apply GDPR globally), you have the following rights:
- Right of access — ask us for a copy of the personal data we hold about you.
- Right of rectification — ask us to correct data that's wrong or out of date.
- Right of erasure ("right to be forgotten") — ask us to delete your data. We'll do it unless we're legally required to keep it (for example, invoices for tax reasons).
- Right of restriction — ask us to pause processing your data while we look into a request.
- Right of portability — ask us for a machine-readable export of the data you gave us.
- Right to object — object to processing based on legitimate interest, or to direct marketing.
- Right to withdraw consent — at any time, for anything based on consent (like marketing emails).
- Right not to be subject to automated decision-making — The Field's AI-generated responses are not "decisions" about you (they're conversation), but if we ever introduce a fully automated decision that has legal or significant effects on you, you'll have the right to human review.
To exercise any of these rights, email us at support@shimritnativ.com. We will respond within 30 days (usually faster). We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with a supervisory authority. In Germany, this would typically be your local state data protection authority. For Berlin, that's the Berliner Beauftragte für Datenschutz und Informationsfreiheit — datenschutz-berlin.de.
8. Cookies and similar technologies
The Field uses only strictly necessary cookies. Specifically:
- A session cookie / local storage entry that keeps you logged in.
- A short-lived cookie for CSRF protection on form submissions.
- Cookies set by our payment providers (Kajabi, ThriveCart, Stripe/PayPal) when you check out — those are covered by their own privacy policies.
We do not use marketing cookies, cross-site tracking cookies, or third-party analytics that identify you personally. If we ever add analytics, we will use privacy-preserving tools (like Plausible or Fathom) and update this policy.
9. Meta advertising and pixels
If you visit our landing pages via a Meta (Facebook or Instagram) ad, Meta may set its own pixel on your visit. This helps us understand which ads convert without identifying you personally to us. You can control Meta's tracking through your Meta account settings and browser controls. Meta's own privacy policy applies to that processing: facebook.com/privacy/policy.
10. Security
We take reasonable technical and organisational measures to protect your data, including:
- Encryption in transit (HTTPS across all pages and API calls).
- Encryption at rest for the database.
- Access controls: only Shimrit and a small number of trusted team members can access member data, and only when needed for support, safety, or legal reasons.
- Regular reviews of who has access to what.
No system is 100% secure. If a data breach happens that affects your personal data and is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR.
11. Age of members
The Field is intended for adults. You must be at least 18 years old to use The Field. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, please email us and we'll delete the account and the associated data.
12. Confidentiality of your conversations
The messages you exchange with The Field are private to you. We do not read individual conversations unless:
- You explicitly ask us to as part of a support request,
- We are investigating a safety concern or a possible breach of our Terms & Conditions, or
- We are legally required to (for example, by a valid court order).
Aggregated, anonymised patterns across many conversations may be used to improve The Field's guided processes. We take care to strip identifying information before doing this.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will email active members at least 30 days before the changes take effect, and we will update the "Last updated" date at the top of this page. Continued use of The Field after the changes take effect means you accept the updated Policy.
14. How to reach us
For any privacy-related questions, requests, or concerns, please email us at support@shimritnativ.com.
Shimrit Bukelman
Operating under the brand Master Your Path
Berlin, Germany
Your data is one of the most personal things you can share. We treat it that way.