Privacy Policy

Last updated: 18 August 2026

This is a plain-English explanation of what happens to your information when you read Blue Leaf Journal, write to us, or buy something. It is written to be read, not to be survived.

Who is responsible

Blue Leaf Journal is published by Tomasz Nowak, a sole trader, of 50 Endymion Rd, London SW2 2BT, United Kingdom. For the purposes of UK data protection law, that is the data controller.

Contact for anything on this page: norawhitfield@blueleafjournal.com, or WhatsApp +44 7517 696867.

What we collect

Things you give us.

  • Your email address, if you choose to join the email list or buy something.
  • Your name, if you give it.
  • The content of messages you send by email or WhatsApp.
  • Billing details, if you buy something. Card numbers are handled by the payment provider and never reach us or this website.

Things collected automatically when you read.

  • Standard server logs kept by the host: IP address, browser and device type, pages requested, date and time. These exist so the site can run and stay secure.
  • Analytics data about how pages are used — which article was read, how it was reached, roughly where in the world the reader was. This is aggregated and is not used to identify you.

Things we deliberately do not collect.

We do not ask for health information, and the site has no tracker that records anything about your health. The Quiet Audit is answered on the page and requires no email address; what you think or write while working through it is not transmitted to us unless the page explicitly asks you to send it. If you choose to describe symptoms in a message to us, that information stays in that conversation and is not added to any list or profile.

Why we are allowed to use it

  • Consent — for marketing emails and for non-essential cookies. You can withdraw it at any time.
  • Contract — to deliver something you have bought and to handle refunds.
  • Legitimate interests — to keep the site running and secure, to understand in aggregate which articles are useful, and to answer messages you send us.
  • Legal obligation — to keep records for tax and accounting.

Cookies and analytics

For the full list of cookies in use and how to control them, see our dedicated Cookie Policy. The short version:

Essential cookies keep the site working and are set by WordPress and the caching system. They carry no marketing data.

Analytics is provided through Google Analytics via Site Kit, and search performance data comes from Google Search Console. Google acts as our processor for analytics data. IP addresses are truncated and analytics reporting is aggregated.

You can refuse or delete cookies in your browser settings, and you can install Google’s own opt-out browser add-on at tools.google.com/dlpage/gaoptout. Refusing analytics cookies does not change what you can read here.

Pages may contain links to other sites, and occasionally embedded content such as a video. Embedded content behaves exactly as if you had visited that other site, and that site’s own privacy policy applies.

Who else touches your data

We use a small number of companies to run the journal. Each of them acts on our instructions and none of them may sell your data.

  • Hostinger — website hosting and server logs.
  • Google — analytics and search performance data (Site Kit).
  • Systeme.io — email list, checkout and product delivery, if you sign up or buy.
  • The payment providers used at checkout — card and payment processing.
  • WhatsApp (Meta) — if you choose to message that way. WhatsApp messages are end-to-end encrypted; Meta still processes the fact that a message was sent.
  • Pinterest — where we publish. Pinterest sees your activity on Pinterest, not on this site.

Some of these companies are based outside the UK. Where information is transferred abroad, it is done under the safeguards UK law requires, such as the UK addendum to the standard contractual clauses or an adequacy decision.

How long we keep things

  • Email list: until you unsubscribe, and then a suppression record so we do not email you again by accident.
  • Messages to us: up to two years, so we can pick up a conversation where it left off.
  • Purchase and tax records: six years, because UK tax law requires it.
  • Server logs: as retained by the host, typically weeks rather than years.
  • Analytics: as configured in Google Analytics, no more than 14 months.

Your rights

Under UK GDPR you can ask us to:

  • give you a copy of the information we hold about you;
  • correct it if it is wrong;
  • delete it;
  • restrict or object to how we use it;
  • send it to you or another provider in a portable format;
  • stop marketing emails, at any time, with no reason required — every email has a one-click unsubscribe link.

Write to norawhitfield@blueleafjournal.com and we will deal with it within one month. There is no charge.

If you think we have handled your information badly, tell us first — but you have the right to go straight to the Information Commissioner’s Office at ico.org.uk, or 0303 123 1113.

Children

Blue Leaf Journal is written for adults and is not directed at anyone under 18. We do not knowingly collect information from children.

Security

The site runs over HTTPS. Access to the email platform and the site itself is protected by strong, unique passwords and two-factor authentication where the provider supports it. No system is perfect, and if a breach ever affected your rights we would tell you and the ICO within 72 hours, as the law requires.

Changes

If this policy changes in a way that matters, the date at the top changes and material changes are noted here. Continuing to use the site after that means the current version applies.


Blue Leaf Journal is published by Tomasz Nowak, 50 Endymion Rd, London SW2 2BT, United Kingdom. About · Contact · Terms · Editorial standards · Cookie Policy · Refund Policy · Accessibility · FAQ