Privacy Notice and Data-Protection Policy
Effective Date: August 3, 2026 (Archived Version: July 15, 2026)
Operating Entity: Puppy Drum II LLC, a Virginia limited liability company, doing business as I Did The Hard Work.
Platform: Primary domain (ididthehardwork.com), associated subdomains, digital product interfaces, micro-applications, Personal Reflection Vaults, and educational services operated by Puppy Drum II LLC.
Privacy Contact & Legal Email: [email protected]
Mailing Address: PO Box 26, Quinby, VA 23423
Privacy Requests & Consent Withdrawals: Submitted via email.
Your Privacy at a Glance
The Charter Journey invites deep, personal, and potentially sensitive self-reflection. Our privacy practices are built around the following core commitments:
- Your original reflective writing remains yours. Purchasing access does not transfer ownership of your written essays.
- We use your Vault content solely to deliver the service. Content is used only to operate features you request, maintain system functionality, protect the Platform, and comply with law.
- We do not sell your reflective content or share it for targeted advertising. We do not monetize your private entries, nor profile you for commercial offers.
- Vault entries are strictly private. We do not provide individual Vault responses to employers, dating platforms, prospective partners, family members, or data brokers.
- No public AI model training. We do not authorize external AI providers to use Vault content, whether directly identified or pseudonymous, to train unrelated public or general-purpose artificial intelligence models.
- The Charter verifies process completion only. The Charter and public verification system certify recorded completion of the reflection sequence, not your moral character, emotional health, safety, faith, or future behavior.
- Pseudonymous Architecture: We use internal account tokens to decouple your billing identity from coursework processing during ordinary use. While pseudonymous, records may be re-linked if necessary for authentication, support, security, or legal compliance.
1. Scope of This Notice
This Privacy Notice applies to personal information processed by Puppy Drum II LLC d/b/a I Did The Hard Work through the Platform. It applies to Platform visitors, account holders, Charter Journey participants, and Charter holders.
This Notice does not govern third-party payment processors, booksellers, external video platforms, or external websites operating under independent privacy policies. The Terms of Purchase govern your account agreement; this Notice governs our data handling practices.
2. Our Role and Privacy Approach
Puppy Drum II LLC acts as the business or data controller responsible for personal information processed through the Platform. We collect only information reasonably needed to operate and protect the service.
Pseudonymous Does Not Mean Anonymous: Pseudonymous information is associated with an internal account identifier rather than a direct legal name. Because pseudonymous records can be re-linked to an identifiable person using administrative access controls, we treat all pseudonymous account and Vault data as protected personal information.
3. Information We Collect
- 3.1 Account and Contact Information: Name, chosen display name, email address, minimum age attestation (21+), account credentials, internal account tokens, purchase history, and timestamped acceptance records.
- 3.2 Payment and Transaction Information: Payments are processed directly by our payment processor (Stripe). Puppy Drum II LLC does not store card numbers, CVVs, or bank credentials. We receive transaction status, amounts, timestamps, payment IDs, and limited billing metadata required for tax, accounting, and fraud prevention.
- 3.3 Charter Journey Progress Data: System records tracking completion of the foundational questions with shadow probes, progress through the core learning modules (guided essays), quiet pauses, reassessment exercises, generated Clarity Reports, and Charter verification status.
- 3.4 Personal Reflection Vault Content (Sensitive Data): Narrative text voluntarily entered into your Vault concerning personal history, conflict, boundaries, emotional patterns, and faith. This writing may reveal sensitive details such as religious beliefs, relationship history, or health-related reflections.
- 3.5 Technical and Usage Data: IP address, browser type, operating system, approximate geographic location (country/state level), session tokens, module load times, system error logs, and security telemetry.
- 3.6 Support and Privacy Communications: Contact information, message contents, support notes, and correspondence records.
4. How Information Flows Through the Platform
- 4.1 Enrollment: Account data is registered; Stripe processes billing details; Puppy Drum II LLC receives transaction confirmation and generates a pseudonymous internal account token.
- 4.2 Coursework & Storage: Entries submitted during an authenticated session are encrypted and stored under your account token. Automated system logic evaluates progress and presents Reference Responses.
- 4.3 Charter Verification: Upon automated recording of full program completion, a unique Charter ID is generated. Public verification remains inactive by default unless explicitly enabled by you.
- 4.4 Re-linking Records: Authorized personnel may re-link account tokens to billing identities strictly for technical support, security investigation, fraud prevention, or legal compliance.
5. How and Why We Use Information
We process personal information to:
- Deliver the Purchased Service: Authenticate users, operate the Vault, process essays, enforce quiet pauses, generate Clarity Reports, and issue Charters.
- Process Transactions: Confirm payments, maintain tax records, and handle dispute or refund requests.
- Support and Communicate: Respond to inquiries, send security alerts, announce expiration dates, and process privacy requests.
- Protect System Integrity: Prevent account sharing, block automated AI essay completion scripts, detect forgery, and maintain security.
- Comply with Law: Satisfy tax, accounting, statutory consumer protection, and legal discovery obligations.
Identifiable narrative Vault entries are never used for targeted advertising, public marketing, external research, or model training.
6. Required Sensitive-Data Consent
Because Vault entries may voluntarily reveal religious beliefs, mental health reflections, or intimate personal details, the Platform requires explicit consent prior to initial Vault access.
At checkout, prior to initial login, you will/must acknowledge your understanding and acceptance of the Platform's terms of service and privacy policy. By affirmatively checking the box and proceeding, you consent to Puppy Drum II LLC processing potentially sensitive information you voluntarily enter into the Vault solely to operate the Charter Journey, maintain the Vault, generate requested features, and administer Charter eligibility as described herein.
You may withdraw consent at any time via email to [email protected]. Because Vault features require data processing to function, withdrawing consent will result in closure of the Vault and deletion of all narrative entries, subject to statutory retention exceptions.
7. Automated and AI-Assisted Processing
- 7.1 Permitted System Automation: Rules-based algorithms and automated language tools may be used to assist or otherwise facilitate comparison of submitted essay density against benchmark standards, organize response themes, present Reference Responses, generate Clarity Reports, and verify program completion.
- 7.2 External AI Safeguards: If external automated services process pseudonymous narrative text to generate educational feedback, those providers are contractually bound to confidentiality, data deletion, and a strict prohibition against using inputs or outputs to train public AI models.
- 7.3 Non-Clinical Scope: The Platform and the output resulting from processing of submitted content is instructional and informational. The Platform does not provide psychological diagnosis, medical evaluation, moral verdicts, or employment screening.
8. Human Access Restrictions
Vault entries are not routinely read or manually reviewed by human staff. Authorized personnel may access limited Vault entries strictly when necessary to:
- Resolve a technical failure or restore corrupted data at your request;
- Investigate security breaches, automated account misuse, or system abuse; or
- Comply with a valid court order, subpoena, or legal obligation.
Not a Crisis Service: Human access is not real-time. The Vault is not monitored for emergency safety, self-harm, or domestic violence. If you are in danger, contact emergency services (911) immediately.
9. Cookies and Technical Storage
We deploy essential session cookies and local storage tokens strictly necessary for user authentication, security, progress saving, and payment routing. We do not use cross-site tracking cookies, third-party advertising pixels, or behavioral marketing trackers. Disabling essential session cookies may prevent successful login and Vault operation.
10. Information Disclosure and Vendors
We disclose limited personal data only to contracted service providers who assist in operating the Platform under strict data protection agreements. As of the effective date of this document, the following vendors and third-party service providers are involved in processing or providing relevant information related to the administration of accounts:
- Payment Processing: Stripe (billing and transaction metadata).
- Cloud Infrastructure & Database: DigitalOcean (encrypted database and application hosting).
- Transactional Email: Postmark (service notices and password resets).
- Legal & Compliance: Professional advisors, auditors, or law enforcement when mandated by valid legal process.
We do not sell, rent, or trade personal information to data brokers, advertisers, employers, or social platforms.
11. Charter Verification and Public Display
- Private by Default: Charter issuance and public verification links are private by default.
- Public Verification Page: If you explicitly choose to enable public verification, the verification page displays only: (a) your selected display name; (b) Charter ID; (c) issuance date; and (d) verification status (Active/Revoked).
- Vault Protection: The public verification page never displays underlying Vault essays, question scores, Clarity Reports, email addresses, or billing data. Public verification can be deactivated at any time via your account settings.
12. Data Retention and Scheduled Deletion
- Active Access Period (12 Months): Account and Vault data remain accessible during your 12-month license period.
- 90-Day Export & Grace Window: Following license expiration, your account enters a 90-day grace period. During this time, you may log in to export your original Vault entries or renew access.
- Automated Vault Deletion: At the conclusion of the 90-day grace period, active narrative Vault entries are scheduled for automated deletion from active database systems.
- Encrypted Backups: Residual encrypted backup copies rotate out and are permanently overwritten within 90 days following active database deletion, except where an active legal hold applies.
- Transaction & Consent Audit Logs: Tax, billing, Terms acceptance, and sensitive data consent records are retained for seven (7) years following account closure to satisfy accounting and legal defense requirements. Minimal pseudonymous Charter verification IDs survive deletion to prevent forgery and maintain system verification integrity.
13. Security Practices
We maintain administrative, technical, and physical safeguards appropriate for sensitive personal reflection data:
- Encryption of all data in transit (TLS 1.3) and at rest (AES-256);
- Segmented database architecture isolating billing records from coursework;
- Role-based administrative access restricted by multi-factor authentication; and
- Regular vulnerability assessments and access audit logging.
While we maintain rigorous security protocols, no digital system is 100% impenetrable. You are responsible for safeguarding your login credentials and signing out on shared devices.
14. Your Privacy Rights and Requests
Depending on your state of residence, you may have statutory rights to: (a) confirm whether we process your data; (b) access or export a copy of your Vault entries; (c) correct inaccurate account data; (d) request deletion of your data; or (e) withdraw sensitive data consent.
- Submitting Requests: Submit requests by emailing [email protected].
- Verification: We verify identity by requiring an authenticated account login or email control confirmation from the registered address.
- Response Timeline: We respond to verified requests within forty-five (45) days. If a request or appeal is denied, appeal instructions and applicable state regulator contact details will be provided.
15. Users Under 21
The Platform is strictly restricted to individuals aged 21 and older. We do not knowingly collect data from minors. If we discover an account created by an individual under 21, access will be immediately terminated, and associated Vault data deleted. A parent or third party may notify us of an underage account at [email protected].
16. Changes to This Privacy Notice
We reserve the right to update this Privacy Notice to reflect operational, technical, or legal changes. Material updates will be announced on the Platform with an updated Effective Date. Continued use of the Platform after an update constitutes acknowledgment of the revised terms.
17. Contact Us
For privacy questions, data requests, consent withdrawals, or appeals, contact us at:
Puppy Drum II LLC d/b/a I Did The Hard Work
Attn: Data Privacy
PO Box 26, Quinby, VA 23423
Email: [email protected]