Effective Thursday 27th August 2026, last revised Wednesday 30th September 2026. We built a business on privacy rights - the fifth of our own options is the law this page answers to.
This is the long version. We wrote it because we ask you to trust us with the story of a ban - screenshots, account history, the thing that actually happened - and a business that files privacy-rights requests for a living should be able to survive its own privacy policy being read closely. Nothing here contradicts the short promises we make elsewhere on the site; it explains them, names the laws behind them, and tells you exactly which companies touch your data and what each one sees. If anything on this page is unclear, email hello@appealmyban.com and a person will answer.
appealmyban.com is a consumer advocacy service. We help people who have been banned from dating apps prepare and submit appeals and complaints - to the platform itself, and where the case warrants it, to bodies like the Better Business Bureau, a state Attorney General’s consumer protection office, an EU-certified out-of-court dispute settlement body, or a data protection regulator. Doing that work means holding personal data: yours.
Under the EU General Data Protection Regulation (GDPR) and the UK GDPR, the party that decides why and how personal data is processed is called the data controller. For everything described in this policy, the controller is the operator of appealmyban.com.
The controller is Learnmind.ai LLC, a limited liability company registered in the State of New Mexico, United States, of 8206 Louisiana Blvd NE, Ste A #6298, Albuquerque, NM 87113, USA. It is wholly owned by the founding operator, who remains personally accountable for everything in this policy.
Dated note, Thursday 3rd September 2026: this section previously said the service was run by its founding operator in a personal capacity while the operating company completed registration, and promised that the entity would be named here with a dated note recording the change rather than quietly swapped out. This is that note. The controller named above is unchanged in substance: the same person is accountable, under a company name instead of his own. Learnmind.ai LLC is established outside the UK and EEA. We have not yet appointed an Article 27 representative; if you are in the UK or EEA and wish to raise anything about your data, write to the address below and it reaches the accountable person directly.
For every question, request, or complaint about your data, there is one door: hello@appealmyban.com. It reaches the same person who handles your case. We have not appointed a Data Protection Officer, because the law does not require one for a service of this size and nature, and we will not pretend to have compliance infrastructure we do not have. What we do have is a single accountable operator, a short list of processors, and this document.
This policy covers three things:
It does not cover the places your Filings go. When we submit an appeal to Tinder, a complaint to the BBB, or a request to a regulator, the recipient processes what it receives under its own privacy rules, as its own controller. We choose what goes into each Filing - and we keep it to what the filing requires - but once a platform or public body holds it, their policy governs their copy. The same is true of the dating apps themselves: what Match Group or Bumble does with the data they already hold about you is between you, them, and - if we’re doing our job - the regulator.
It also does not cover other websites we link to. The guides on this site link out to platform policies, statutes, and regulators’ pages. Following a link takes you somewhere with its own rules.
One boundary worth stating plainly: nothing in this policy is legal advice, and this policy does not create obligations beyond those the law already imposes - but where this page promises more than the legal minimum (and in several places it does), we consider ourselves bound by the promise.
Privacy policies fail when they hide behind vocabulary. Here is ours, in plain English:
This section is the inventory. For each category: what it is, where it comes from, why we process it, the legal basis by its proper name, and how long it lives. The one-line summary of the whole section: we collect what you give us to run your case, plus the minimum a website and a payment need to function, and nothing else.
What it is: your name, email address, and country of residence; which app banned you and roughly when; the ban notice as you received it; the identifiers tied to the banned account (the email, phone number, or login method the account used); relevant billing facts (whether you had an active paid subscription, and with which store or processor); and your account of events - what happened, in your own words. If you choose to answer it, one optional question too: whether you asked ChatGPT or another AI about us before buying.
Where it comes from: you, directly, through the intake form or by email. We never buy, scrape, or infer intake data. If you leave a field blank, it stays blank until you fill it.
Why we process it: to assess whether we can honestly take your case, to prepare your Filings, and to submit them to the bodies you authorise. Every required field on the intake form maps to something a Filing actually needs. The one optional question, about AI assistants, is for us: it tells us how people find us, it is marked optional, and it never goes into a Filing.
Legal basis: Article 6(1)(b) GDPR - processing necessary for the performance of a contract with you, or to take steps at your request before entering one. The intake you send before paying is the “steps at your request” part; everything after is the contract itself.
How long: if you become a customer, intake data joins your case file and follows the case-file clock - deleted twelve months after your case closes, or earlier on request. If you send an intake and never proceed, it follows the correspondence clock: deleted within twelve months. The full schedule is in section 12.
What it is: the material your case is built from. Typically: screenshots of the ban notice and any error messages; screenshots or exports of relevant conversations or account history; records of your subscription and payments to the platform; copies of any appeal you already sent and any reply you received; and your narrative - the honest account of events we ask every customer for.
Where it comes from: you. We do not pull data from platforms, and we cannot - we have no access to your banned account, and we never ask for your account password. If a platform sends us something in response to a Filing made on your behalf, that response joins the case file too.
Why we process it: to draft Filings that are specific and true. An appeal built on evidence beats an appeal built on adjectives, which is the entire premise of this service. We read what you send, select what each Filing requires, and put only that in.
Legal basis: Article 6(1)(b) GDPR - contract. Where your evidence happens to contain special category data, section 6 applies on top.
How long: the case-file clock - twelve months after case close, or earlier on request.
What they are: the documents we produce for you - drafts, revisions, and the final submitted copies, together with proof of submission (a confirmation email, a reference number, a screenshot of a submission portal).
Where they come from: us, built from your intake and evidence. You confirm the facts; we write the words - and you are copied on every Filing as it goes out, so you hold a copy of everything submitted in your name.
Why we process them: to run your case, and to be able to prove - to you, to the recipient body, or in a dispute - what was submitted, where, and when. Deadlines and submission proof are the skeleton of an appeals case.
Legal basis: Article 6(1)(b) GDPR - contract - for the drafting and submission; Article 6(1)(f) - our legitimate interest in evidencing the work we did and defending it if challenged - for keeping the submitted copies and proofs during the retention window.
How long: the case-file clock - twelve months after case close, or earlier on request.
What it is: email between you and us; our emails to and from platforms and bodies about your case; your confirmation of the facts, questions, chasers, and outcomes.
Where it comes from: the conversation itself. Email is our main channel and there is no ticketing system and no chat widget, so the mailbox is where a case lives day to day. There is one read-only portal at appealmyban.com/track, which shows you your own stage, next action, routes and timeline; it holds no password, and it is a window onto the case record described in section 9 rather than a second copy of it.
Why we process it: to run your case, keep our word on deadlines, and hold a record of what was agreed. When a platform says “we never received your appeal”, the timestamped correspondence is the answer.
Legal basis: Article 6(1)(b) GDPR - contract - and Article 6(1)(f) - our legitimate interest in evidencing that deadlines were met and the work was done as described.
How long: correspondence tied to a case follows the case-file clock. Correspondence with no open case - a question you asked and we answered, an intake that went nowhere - is deleted within twelve months.
What it is: the record that you paid, when, how much, and for which service - plus, from Stripe, a payment confirmation and the last four digits of the card. That is the whole of it. Your full card number, CVC, and expiry never touch our systems. They go from your browser to Stripe directly; we could not see them if we wanted to.
Where it comes from: Stripe, our payment processor, at the moment you pay.
Why we process it: to deliver what you paid for, to honour the refund policy, and to keep the financial records tax law obliges every business to keep.
Legal basis: Article 6(1)(b) GDPR - contract - for taking and reconciling the payment; Article 6(1)(c) - a legal obligation - for retaining the transaction record as long as tax and accounting law requires.
How long: the transaction record is kept for the statutory period, typically six to seven years depending on jurisdiction, and held minimal - the financial facts stay, the case content does not stay with them.
What it is: whatever you type into the contact form or a form attached to one of our guides - usually a name, an email address, and a message - plus your email address and message when you simply write to us.
Where it comes from: you. Forms on this site are delivered to our mailbox by Resend (see section 9); emailing us goes to the same place without the relay.
What we keep beyond the email: one enquiry record per address, stored on our Stripe account alongside the case records (section 9). It holds your email address, your name if you gave one, which form you used and when, how many times you have written, the referrer that first brought you to the site, and the last message you sent. It exists so that somebody who has asked us three things is not treated as three strangers, and so we can tell which parts of the site are actually reaching people.
Why we process it: to answer you. That is the entire purpose. Writing to us does not put you on a mailing list, because there is no mailing list, and a message you write is answered by a person, never by an automated sequence. Two exceptions are written down rather than hidden. If you fill in the intake and never reach the payment page, you get a single email telling you the details are saved and nothing was charged: one email, once, ever, with a line telling you how to have your address deleted the same day. And if you ask for a free letter or statement by email, the form says before you type that we will check in to ask how it went: up to three short emails over the following week, none once you have paid or written to us, and each with a one-click unsubscribe.
Legal basis: Article 6(1)(f) GDPR - our legitimate interest in responding to people who contact us - ripening into Article 6(1)(b) if the exchange becomes pre-contract intake.
How long: the correspondence clock - deleted within twelve months if no case comes of it.
What it is: the minimum any website visit generates. Our site is a set of static pages served by Cloudflare Pages. To deliver a page to your browser, Cloudflare’s servers necessarily see your IP address, the page requested, and standard browser headers, and keep short-lived operational logs of that traffic for security and delivery - the same way every host on the internet does. We build nothing on top of these logs: no visitor profiles and no fingerprinting. The measurement tools we do run, session recording included, are separate, and section 9 names each one.
Where it comes from: your browser’s requests, handled by our hosting provider.
Why it exists: serving the site, keeping it up, and defending it against attack. We look at aggregate operational information (is the site up, is it under attack) - not at individual visitors.
Legal basis: Article 6(1)(f) GDPR - the legitimate interest in operating and securing a website. This is the textbook case for that basis.
How long: operational logs live on Cloudflare’s side under its retention practices, briefly. We keep no copy.
The shadowban test. The shadowban test at /blog/shadowban-test/ is treated exactly the same way as the free check below. It keeps the options you tap (the app, what you see, how it started, which easy-to-check cause you picked, whether the app showed you anything, and whether it has seen another account of yours), how far you got, the cause it said fits and which link you pressed at the end, with the same extras and the same limits as the free check. These records carry a marker that keeps them out of the free check’s numbers, and nothing in them is a score or a prediction.
What it is: the options you tap in the free check at /check/, the app name if you type one under “Another app”, how far through the check you got, the score and routes it showed you, and which of its buttons you pressed at the end. With them we keep the page on this site you started the check from (or the website that sent you), how you first found the site (the website or campaign link that first brought you here), whether you were on a phone or a computer, your browser’s language setting, and the country Cloudflare reports for the connection.
What it is not: it carries no name, no email address, no IP address and no cookie. Each run of the check is given a random number so that your later answers update the same record; that number is not linked to you, to your browser, or to anything else we hold.
Where it comes from: the check page, which sends each answer as you give it. The score itself is still worked out on your own device.
Why we process it: to see which apps, bans and situations people actually bring, where the check loses them, and which guides are missing, so that what we write next answers real questions. It is never used to contact anyone, and it is never joined to an enquiry or a case.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in improving the free information we publish. Nothing in the record identifies you, but we apply the rules to it anyway rather than argue they do not reach us.
How long: two years at most, then deleted automatically. You can ask us to delete yours sooner; because nothing in the record points to you, tell us roughly when you ran the check and what you answered, and we will find and delete it.
If you ask for the letter by email: that is an enquiry, covered by 4.6 above. Your address, the letter and a summary of your answers go to our inbox, with a copy to the company’s main inbox, so a reply can pick up where the check left off. That enquiry is not linked back to the anonymous record. The email links to a letter page, and the link carries your answers as the check’s own option codes (no name, no email address). What you type on that page stays in your browser and is never sent to us. Of the measurement tools in section 9, that page loads Google Analytics and nothing else: it counts that the page was opened, that a first fact was typed and that the letter was copied, and it is given the page’s address without your answers. Nothing you type reaches it. The same letter can be asked for from a box on our articles, with two or three answers instead of the whole check. It is handled exactly the same way, and the copy in our inbox notes which article it came from.
If you go on to the intake: the intake form fills in what the check already asked you, from the copy your browser kept for the visit (section 15), and a summary of your check answers travels with your intake into your case file (4.1). You can change any of it before you send.
What it is: the authority you sign after paying, so that we can act for you and platforms write to us and not to you. It holds the name you typed, the app and account email you confirmed, an optional phone number, your drawn signature, and a record of the signing: the time, your browser and system, and the email address you verified with a one-time code. Two details are kept in our records and are never printed on the document that goes to a platform: the IP address the signing came from and your browser’s raw identification string. The one-time code itself is stored only as a keyed hash and expires after 15 minutes.
Where it comes from: you, on the signing page, and your browser as you sign.
Why we process it: to show a platform or body that we act with your written authority, and to prove, if anyone asks, that it was you who signed. The signed PDF is attached to your first Filing, so the platform or body it goes to receives it.
Legal basis: Article 6(1)(b) GDPR, because the authority is part of doing what you hired us to do, and Article 6(1)(f), our legitimate interest in being able to prove that a Filing was made with your authority.
How long: with your case file (section 12). It is saved on your case file, in our records database and in our own encrypted archive, and the code email is sent by the email provider named in section 9.
The absences are as load-bearing as the inventory, so here they are in writing:
Most privacy policies skip this. Ours can’t, because of what our customers’ data actually is.
The GDPR’s Article 9 sets a higher bar for “special categories” of personal data: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic and biometric data; health data; and data concerning a person’s sex life or sexual orientation. A ban story can brush against several of these without anyone intending it to. The bare fact of which app banned you can carry a signal about sexual orientation. A narrative might mention a health condition that explains a missed deadline, or a conversation screenshot might reveal beliefs, orientation, or health information - yours or a third party’s. We would rather name this openly than process it in silence.
The UK GDPR mirrors Article 9, and our handling is identical for UK customers. For California residents, the CCPA’s “sensitive personal information” concept overlaps with this; section 18 covers it, and the short version is the same: used only to provide the service you asked for, never for anything else.
EU and UK law requires a lawful basis for every act of processing, chosen from Article 6 GDPR’s list. Policies often wave at this vaguely. Here is exactly which bases we use, and for what - and, as importantly, which we don’t.
| Basis | What it means | Where we use it |
|---|---|---|
| Art. 6(1)(b) - contract | Processing necessary to perform our contract with you, or to take pre-contract steps you asked for | Intake, the case file, drafting and submitting Filings, case correspondence, taking payment |
| Art. 6(1)(c) - legal obligation | Processing the law itself requires of us | Keeping payment and transaction records for the tax-law period |
| Art. 6(1)(f) - legitimate interests | Processing necessary for a real interest of ours, only where it doesn’t override your rights | Answering people who contact us; keeping submitted Filings and proofs to evidence our work; operating and securing the website |
| Art. 6(1)(a) - consent | You freely agree, and can withdraw at any time | Rarely needed, because we don’t track or market. Explicit consent under Art. 9(2)(a) covers sensitive detail you choose to include (section 6) |
Where we rely on legitimate interests, we have done the balancing the law requires, and the reasoning is not mysterious: answering an email you sent us, keeping proof of a Filing you commissioned, and serving a webpage you requested are interests that align with yours rather than compete with them. If you disagree in your specific circumstances, you have a right to object - section 16 explains how, and we take the objection seriously rather than treating it as a form to survive.
Bases we do not use: vital interests (Art. 6(1)(d)) and public task (Art. 6(1)(e)) have no place in a service like this, and we do not stretch “legitimate interests” to cover marketing, profiling, or data sharing, because we do none of those.
Three categories of recipient. There is no fourth.
The point of the service is submitting Filings, and a Filing is by definition a disclosure. Depending on your case and only on the routes you authorise, recipients can include: the platform that banned you; the Better Business Bureau; a state Attorney General’s consumer protection office; an EU-certified out-of-court dispute settlement body under the Digital Services Act; or a privacy regulator such as the ICO or an EU data protection authority. Each body receives what its filing requires and nothing more - we do not send your whole case file anywhere. You are copied on every Filing as it goes out, so you always know exactly what a recipient holds.
The seven companies in section 9: Resend, Stripe, Cloudflare and Google Fonts, which process data on our instructions for a defined job under their published data processing terms, and the measurement tools listed with them, Reddit, Google Analytics and Microsoft Clarity, whose table rows there say exactly what each one sees and never sees.
We do not sell personal data, rent it, trade it, or share it for advertising - not “with partners”, not “in anonymised form for research”, not at all. The only circumstance in which anyone else receives your data is a legal compulsion we cannot refuse: a court order or an enforceable demand from a competent authority. If that ever happens, we disclose the minimum the order compels, we push back on overbroad demands, and we tell you - unless the law forbids us from telling you, in which case we tell you the moment the prohibition lifts. If the business itself is ever sold or wound up, case data does not go to a buyer without you being told first and this policy’s promises travelling with the data.
Seven companies touch data for us. This is the complete list - if it ever grows, this table grows first. For each: the job it does, what actually passes through it, and what never does.
| Processor | Job | What it sees | What it never sees |
|---|---|---|---|
| Resend | Relays website form submissions to our mailbox | The contents of a form you submit (intake, contact, or guide forms), in transit to our email, plus the technical metadata delivery requires | Your case file beyond that first submission, payment details, our email archive |
| Stripe | Payment processing, and hosting the case record and enquiry record on our account | Your card details (which go to Stripe directly, never through us), name, email, amount, the technical signals Stripe uses for fraud prevention, and the case record we keep against your customer entry: your reference, stage, next action, routes, the intake summary, the case timeline and any evidence files you upload through the portal | Our email archive, and anything you send us by email rather than through the site |
| Cloudflare | Hosts the website (Cloudflare Pages) and routes our email domain | Visitor requests to the site (IP address, page, browser headers) in operational logs; email passing through domain routing in transit; the free check’s anonymous answers (section 4.8), kept in its database | A stored case archive - no customer database lives on it, and the check answers it holds carry no name, email address or IP address |
| Google Fonts | Serves the site’s typefaces | Your browser’s request for a font file: IP address and browser details for that request. Google states the Fonts API sets no cookies | Who you are, what you typed, anything from forms, cases, or payments |
| Advertising measurement and retargeting | That a browser visited a page here, which page, and whether it reached the payment page, tied to a Reddit advertising identifier, plus any email address on the page, scrambled by Reddit into an irreversible code before it leaves, so Reddit can tell whether the visitor is one of its own users | Your name, your intake, or the words you write | |
| Google Analytics | Traffic and funnel measurement | Pages viewed, how you arrived, device and approximate location, and which steps of the intake you completed | Your name, your email, your case, or the text of anything you write |
| Microsoft Clarity | Session replay and heatmaps | A recording of how the page was used: mouse movement, scrolling, clicks and which fields were focused | What you TYPE. Every input, textarea and select on this site is masked before the recording leaves your browser |
Three honest footnotes to that table.
Stripe wears two hats. For running your payment on our behalf, Stripe is our processor. But payment companies also process some data as controllers in their own right - for fraud prevention, and for the financial-compliance duties banking law puts on them directly. That part of Stripe’s processing is governed by Stripe’s privacy policy, not ours. Every business that takes cards has this footnote; most don’t print it.
Resend is a delivery service, not an archive. Its job is carrying a form submission, and the emails we send you, from our systems to a mailbox. It processes the submission for delivery under its own published terms at resend.com. The working copy of your data lives in our mailbox and, for a case, in the case record on our Stripe account; never with the delivery service.
Our automated emails tell us whether they arrived. The acknowledgement, the free letter, case updates and follow-ups carry a one-pixel image, and their links pass through links.send.appealmyban.com, our own address at Resend, before landing on the page. That tells us when an email was opened and which link was clicked. We use it for one thing: knowing whether a message reached you before we repeat it or chase. It is never used for advertising and never shared. Some mail apps, Apple Mail among them, load the image on delivery, so “opened” can mean delivered rather than read. Setting your mail app to block remote images stops the pixel. Emails a person writes to you from our mailbox carry none of this.
Google Fonts is the widest-known name on the list and the smallest data event. A font request is a request for a file of letter shapes. It carries your IP address because every internet request does. It is the only thing on this site that talks to Google, and it carries nothing you have typed.
Email is our main channel, so it deserves its own honest paragraph rather than a euphemism about “communication platforms”.
Your case runs out of two places and no others: an access-controlled mailbox operated by the same person who answers you, and a case record on our Stripe account holding your reference, stage, routes, timeline, intake summary and any files you upload. Both are covered by section 9; neither is sold, shared, or copied into a third system. Mail to our domain arrives via Cloudflare’s email routing. Transport between mail providers uses TLS encryption in transit, which is the standard the entire email system runs on; like all ordinary email, it is not end-to-end encrypted. For the material in a typical case file - a ban screenshot, a narrative, a draft appeal - we consider well-secured email a proportionate home, and it has a virtue portals lack: you hold your own complete copy of everything, automatically, forever.
If something in your evidence feels too sensitive for email, say so before sending it. We will tell you honestly whether the case needs it at all - often it doesn’t, and the cheapest protection for a piece of data is not collecting it.
We serve customers wherever dating apps ban people, and our processors are global companies, so data crosses borders. Here is how, and under what protection.
All seven companies named in section 9 are US-headquartered, and each may store or process data in the United States or other countries outside yours. For customers in the EU, UK, and other jurisdictions with transfer rules, that makes these “international transfers” in the legal sense, and they are lawful only under recognised safeguards. Ours travel under the standard mechanisms these processors maintain:
In plain English: the contracts under which Stripe, Cloudflare, Resend, and Google handle data commit them to European-standard protections even where the data physically sits on a US server. We do not transfer your data to any country under no safeguard at all, and we do not use processors that ask us to.
One transfer in this service is different in kind, and you control it: the Filings themselves. If your case targets a US platform or a US consumer-protection body, the Filing necessarily goes to the United States - that is the service working as described, not a processor arrangement. You choose the routes knowing where each Filing goes.
Data we no longer need is risk with no upside, so the schedule is short and the default at the end of every clock is deletion, not archive. The clocks:
| Category | Kept for | Why that long |
|---|---|---|
| Case files (intake, evidence, drafts, Filings, proofs, case correspondence) | 12 months after your case closes - or earlier on request | Platforms and bodies sometimes respond late, reopen, or dispute what was filed; a year covers the realistic tail, then the file goes |
| Correspondence with no open case | 12 months | People often return to a stalled intake; after a year, they haven’t |
| Payment records | The statutory tax period - typically 6–7 years | Tax law requires it; held minimal - the transaction facts survive, the case content does not travel with them |
| Website technical logs | Briefly, on Cloudflare’s side, under its operational retention | Security and delivery; we keep no copy and build nothing on them |
| Rights-request records (the fact that you asked, and our answer) | 12 months after resolution | To evidence that we honoured the request - a deletion we can’t prove is a promise we can’t keep |
Three rules sit on top of the table:
Security sections are where policies reach for words like “bank-grade” and “military-standard”. We won’t. We hold no security certifications, we have not commissioned an external audit, and a one-operator service claiming an ISO 27001 programme would be decorating. What we actually do is proportionate, real, and listed:
The honest limit: no one can promise zero risk - not us, not the certified giants. What we promise is a small, well-locked surface, and section 21’s commitment about what happens if the lock ever fails.
Article 22 GDPR gives you rights against decisions with legal or similarly significant effects made solely by automated means. This section is short because the answer is short: we make no automated decisions about you, significant or otherwise.
Whether we take your case is a human judgment. You confirm the facts of your case; a person writes the words. Every Filing is drafted for your specific facts and read by a human before it goes out - the facts the whole pipeline rests on are the ones you confirmed yourself. We do no profiling, no scoring, no algorithmic triage of intakes. If that ever changes in any respect, this section will describe the logic involved and your rights around it before the change takes effect.
The irony is not lost on us that many of our customers are here precisely because an automated system banned them with no meaningful human review. Not running one ourselves is both a compliance fact and the closest thing this page has to a mission statement.
We set no cookies of our own. The measurement tools we run do. Reddit, Google Analytics and Microsoft Clarity each set their own cookies or browser storage to count a visit and to tell a returning browser from a new one. They are not needed for the site to work, and you can refuse or delete them in your browser settings, or use its Do Not Track or private window, with no effect on anything you can do here.
We would rather write that plainly than run the tools and keep the old sentence about setting none. If you want the measurement off entirely, browser-level blocking works and we do not try to defeat it.
What the free check keeps. The shadowban test sends the same kind of record, described in 4.8. The check works out your score on your own device. As you answer, it also sends us the answers themselves, with no name, email address, IP address or cookie attached, so we can see which apps and situations people bring and write the guides that are missing. Section 4.8 lists exactly what is kept, and the two-year limit. Nothing you type in the check reaches us except an app name you choose to enter, and your email address only if you ask for the letter to be emailed to you.
Browser storage is functional only. Where a page uses your browser’s storage (localStorage or sessionStorage), for instance the check remembering your progress for the rest of your visit, so a refresh or the back button does not wipe your answers and the intake form can fill in what you already told the check, or the letter page keeping the facts you type into your letter so you can come back to it, that copy lives on your device, is not an identifier and is not tracking. You can clear it any time through your browser’s site-data settings, with no effect beyond the page forgetting your progress.
Third parties on the page: font files come from Google Fonts, and Google states the Fonts API sets no cookies. Our pages also load the measurement tools named in section 9: Reddit, Google Analytics and Microsoft Clarity. What each of them sees, and what it never sees, is set out there. Our host, Cloudflare, serves the pages themselves; if it ever needs to present a security challenge to defend the site from an attack, that is the host’s protective machinery, strictly necessary and not tracking.
EU and UK law gives you eight rights over your data. Services that file GDPR requests at platforms all day have no business making these hard to use in return, so here is each one, what it means against us specifically, and how to use it. Every one is exercised the same way: one email to hello@appealmyban.com saying what you want. No forms, no portal, no fee.
You have the right to know what happens to your data before it happens. This document is that right, honoured in advance - and section 23 commits us to keeping it current and never changing it retroactively. If anything remains unclear after reading, asking counts as exercising this right and gets a plain answer.
Ask, and we send you a copy of everything we hold about you: your intake, your case file, our correspondence, the payment facts - together with the purposes, recipients, and retention periods, which in our case simply restates this policy with your file attached. We are professionally fluent in subject access requests; ours to answer are easy because the inventory is small and this page already discloses the metadata.
If anything we hold about you is wrong - a misspelled name, a wrong date, an error in how we’ve recorded your account of events - tell us and we correct it. In this service the right has real teeth: an error in your case file could end up in a Filing, so we want corrections faster than you want to send them. If an error already went out in a submitted Filing, we correct the record with the recipient too.
The “right to be forgotten”, and the right this business was partly built on - we send Article 17 requests at platforms for a living, so watch how simple honouring one can be. Ask for deletion and everything deletable goes within 30 days: case file, evidence, correspondence, drafts. The sole carve-out is the minimal payment record tax law obliges us to keep for its statutory period - Article 17(3)(b) recognises legal obligations as a ground for retaining exactly that much, and we retain exactly that much. We confirm completion to you in writing. We cannot recall copies already lawfully submitted to a platform or public body at your instruction - but we will tell you who holds what, so you can aim your next Article 17 letter precisely.
You can ask us to hold your data but stop using it - for instance while a correction is checked, or while an objection is considered. In practice: we freeze the case file, pause all work and Filings, and touch nothing except storage until the restriction lifts. Nothing goes out the door in your name while you have us on pause.
For data you provided under our contract, you can have it in a structured, commonly used, machine-readable format - to keep, or to hand to someone else. Our answer is an export of your intake and case materials in ordinary open formats (the documents as files, the structured data as CSV or JSON). Since your case ran over email, you already hold most of it; the export ties it in a bow.
Where we process on legitimate interests (section 7 lists exactly where), you can object on grounds relating to your particular situation, and we must stop unless we can show compelling grounds that override yours. Given what our legitimate-interest processing actually is - answering your emails, evidencing our own work, serving webpages - most objections resolve as deletion requests, which we grant. The marketing branch of Article 21 is absolute: object to direct marketing and it must stop, no balancing. We make that promise trivially, since we send none.
The right not to be subject to solely automated decisions with significant effects. As section 14 sets out, we make none, so there is nothing to invoke this against - but the right exists, we name it, and if our practices ever changed it would bite.
Beyond the eight: you can withdraw consent at any time where consent is the basis (for us, essentially the sensitive-detail consent in section 6) - withdrawal stops future use but doesn’t unwind what was lawfully done before it; and you can complain to a supervisory authority, which section 22 covers, routes and all.
The mechanics, so there are no surprises:
And the standing offer that outranks all mechanics: we would be poor advocates for these laws if we made them hard to use against ourselves. If you think our handling of a request fell short, say so - section 22 gives you the escalation routes, and we fix fast.
The California Consumer Privacy Act, as amended by the CPRA, gives California residents specific rights and requires specific disclosures. Here they are - and because our data practices are the same for everyone, nothing in this section carves California off from the promises made elsewhere; it restates them in the statute’s own vocabulary.
In the CCPA’s category language, over the last twelve months we have collected, or will collect when you use the service:
| CCPA category | What, for us | Source / purpose |
|---|---|---|
| Identifiers | Name, email, country, the identifiers tied to your banned account | From you; to run your case |
| Customer records | The case file and correspondence; payment confirmation and last four digits | From you and from Stripe; to run your case and keep required financial records |
| Commercial information | What you bought from us; your subscription facts with the platform, as you report them | From you; to build refund and appeal arguments |
| Internet activity | Only the hosting logs of section 4.7 - no analytics, no browsing profiles | From your browser’s requests; to serve and secure the site |
| Audio/visual information | Screenshots and images you submit as evidence | From you; to evidence your Filings |
| Sensitive personal information | Only if your narrative or evidence happens to contain it (see section 6) | From you; used solely to provide the service you requested |
Categories we do not collect: biometric information, precise geolocation, protected classifications as a deliberate category (though your narrative may reveal such facts, per section 6), professional or employment information, education information, and inferences drawn to build a profile - we draw none.
We do not “sell” personal information and have not done so in the preceding twelve months. We do not “share” personal information for cross-context behavioral advertising - the CPRA’s term for the pixel-and-retargeting economy this site does not participate in. Because we neither sell nor share, there is no “Do Not Sell or Share My Personal Information” link here; the statute requires the link of businesses that do the thing, and we don’t do the thing. We also do not use or disclose sensitive personal information for any purpose beyond providing the service you asked for, so the “Limit the Use of My Sensitive Personal Information” right is likewise satisfied structurally - though you may invoke it anyway and receive written confirmation. We have no actual knowledge of selling or sharing the personal information of anyone under 16, because we sell and share no one’s, and the service is 18+ besides.
Exercise any of them by emailing hello@appealmyban.com. We verify your identity proportionately (section 17), respond within the statutory windows, and accept requests from an authorised agent with proof of authorisation. We do not require an account, because we don’t have accounts.
A growing list of US states - Virginia, Colorado, Connecticut, Texas, Oregon, and more each year - have consumer privacy laws borrowing the same shape: access, deletion, correction, portability, opt-outs from sale and targeted advertising. Rather than maintain a fifty-state appendix, we apply one rule: everyone, everywhere, gets the full set of rights in section 16 on the same terms. Access, correction, deletion, restriction, portability, and objection - answered within 30 days, free, regardless of whether your state’s statute technically obliges us or whether we technically meet its coverage thresholds. The same goes for customers in Canada, Australia, Brazil, or anywhere else with (or without) a privacy statute: the strongest version of the promise is the one you get. It is administratively simpler than jurisdiction-checking, and it is also just the correct way to run this particular business.
Dating apps are 18+, and so are we. The service is offered only to adults; we do not knowingly collect data from anyone under 18, and nothing on this site is directed at children. If we discover that a case or a message came from a minor, we close it and delete the data on discovery, and we’ll tell the sender why. If you believe a child’s data has reached us, email hello@appealmyban.com and it will be treated as urgent.
A data breach is any incident where personal data is lost, stolen, or accessed by someone who shouldn’t have it. Our architecture keeps the blast radius small - no card numbers to lose, no analytics profiles, case files on short deletion clocks - but small is not zero, so here is the commitment:
If you think we’ve handled your data badly, the fastest fix is the direct one: email hello@appealmyban.com with “complaint” in the subject line, and it gets answered by the accountable person, quickly and without defensiveness. We fix fast - it is the cheapest reputation policy there is.
But your right to complain does not run through us, and we would never suggest it should. The external routes:
This policy will change - the service is young, and honest documents track reality. The rules for how it changes:
links.send.appealmyban.com. Emails a person writes to you carry no tracking. Set out in section 9.One address for everything in this policy - questions, rights requests, corrections, complaints, breach reports, or a paragraph you think we’ve got wrong: hello@appealmyban.com. It is read by the person who runs your case and answers for this document. Post: Learnmind.ai LLC, 8206 Louisiana Blvd NE, Ste A #6298, Albuquerque, NM 87113, USA - though email reaches us faster, and every deadline in this policy runs from the day we receive it either way.
This policy is effective as of Thursday 27th August 2026. We built a business on privacy rights; this page is where we answer to them ourselves.