Effective October 2, 2026. Version 2026-10-02-v1.
VirtuAmerica LLC operates StormTamers and is responsible for the personal information it handles for this community. Write to legal@virtuamerica.com with a privacy question or request. You can also use the privacy controls in Account. You do not need a paid subscription to raise a privacy concern.
This notice explains community information, sharing and removal. Read it with the site legal notice for site-wide sign-in, storage and provider information. Optional activities explain additional uses before you choose them. Acknowledging this notice does not authorize every optional use of your information.
What we collect and why
We receive information you enter, records created while providing the service, and information returned by a provider you use through a connected feature. We use it for the purposes below.
Another participant may identify you in a message, sharing invitation or report. A connected payment or meeting provider can return transaction, registration or attendance information. We do not treat that information as your permission for a new use. Where required, we will tell you about information obtained from another source, including its source and purpose, subject to lawful restrictions protecting other people’s rights.
| Information | Purpose |
|---|---|
| Sign-in and account details, admission requests, profile information, language and membership status | Identify you, protect access, review admission and provide the service you select. Sign-in currently uses verified email. |
| Agreement versions, acknowledgments, permissions and withdrawals | Establish which terms you reviewed and which uses or sharing you permitted, and respect later changes. |
| Journal and practice entries, progress, Idea Vault drafts and submitted versions | Save and retrieve your work, maintain the versions you submit and provide the sharing you choose. |
| Messages, mentoring requests and check-ins, agreed contact and reports of received help | Deliver the interaction to its intended participants and record whether proposed help was accepted, delivered or withdrawn. |
| Bookings, attendance, access requests and meeting participation choices | Reserve places, arrange access, manage scheduled services and resolve delivery problems. |
| Purchases, accepted offers, payment-provider references, credits, cancellations and refunds | Provide paid access, reconcile charges and fulfill accounting, dispute and recovery obligations. The payment provider handles the payment details requested by its checkout. |
| Uploaded files, selected publications, program or contest entries and separate reuse permissions | Carry out the particular contribution or activity you requested, with its stated audience and rights. |
| Reports, selected evidence, moderation decisions, appeals and necessary audit records | Review concerns, protect participants, apply rules fairly and account for decisions. |
| Technical and security information, such as request details, network address, device/browser information and errors | Operate and protect the site, investigate misuse and troubleshoot failures. |
Required fields are identified in the relevant form. Without information needed for a booking, payment or identity check, we may be unable to provide that particular service. You can still use the public information that does not require an account.
Your personal reflections
Write only what you are comfortable storing and what is useful for your chosen purpose. We do not require a medical history, a diagnosis, a religious declaration or someone else’s identifying details to take part. Reflections can nevertheless reveal sensitive information, including health or beliefs. Consider removing names and details that are unnecessary, especially before sharing with a group or provider.
Private drafts are not community posts. Idea Vault submissions retain the version you submit; later edits to a private draft do not change that submitted record. Named sharing exposes the selected version to its permitted recipient, not your private progress fields. Members see the profile information used by the community features; the member directory does not disclose your sign-in email.
The public support worksheet keeps its entries and prompt choices in the current page only. Those controls do not send that text to StormTamers or save it in browser storage. Leaving or reloading the page can lose the text. Ordinary page requests and visits to external resource links still involve the site’s or provider’s normal data handling. Saved account practice uses a separate, stored workflow.
Who can receive information
Other members receive information you contribute to a shared space or expressly share with them. A group or mentoring conversation is visible to its authorized participants. Sharing within a group is not public publication, but participants can see what you post and may remember or copy it. Community rules prohibit unauthorized copying; no online service can guarantee another person’s conduct.
Authorized operators and reviewers access the information their role needs to provide support, review a case, administer the service or meet a legal obligation. An ordinary member cannot browse your private drafts. Privacy from other members does not mean your stored information is inaccessible to every authorized operator or service provider. A report supplies selected evidence; it does not open an entire private conversation to the assigned reviewer.
Service providers process information needed for hosting, storage, sign-in, communications, payments and the optional features you choose. StormTamers uses Microsoft Azure infrastructure. A Teams event can send Microsoft the attendee and registration details needed for that event. Payment providers receive the details needed to process and reconcile the purchase. Optional AI involves the provider identified for that feature. Review the provider information presented with a connected service before using it.
We may disclose limited information where law requires it, to respond to a valid legal process, or when necessary to protect people or establish, exercise or defend legal rights. We assess the request and its scope. Membership does not give us permission to sell your personal reflections or use them in advertising. Testimonials, marketing and other publication require the separate permissions described for those activities.
Recordings and optional AI
Support circles prohibit recording, transcription and AI use. In other eligible events, recording choices identify the segment, intended use, retention conditions and alternative participation route. Joining the community or paying for an event does not supply that permission. Hosts supervise meeting admission and the provider’s controls; participants must also respect the rules on their own devices.
If you withdraw an eligible recording or reuse permission, future permitted access and distribution are reviewed and stopped as applicable. Copies already received, provider-controlled files and material subject to a valid retention requirement need separate handling. Moving a file into a recycle bin is not permanent deletion. The request status must distinguish those actions and any remaining provider copies.
For optional AI reflection or facilitation, review the selected input before submitting it. Authorized case reviewers can separately request assistance with eligible selected evidence; gathering incident reports are excluded. AI can make mistakes, and decisions remain human. Do not send unnecessary sensitive information. Withdrawing a request cannot recall information already transmitted to a provider. Membership acknowledgment does not consent to unrestricted AI processing of your journal or conversations.
The reasons we process information
For processing covered by European or UK data-protection rules, the purposes above use these bases:
| Purpose | Legal basis |
|---|---|
| Open and operate your account; store and retrieve your chosen work; deliver bookings and purchases | Steps you request before a contract and performance of that contract, limited to information necessary for the service. |
| Meet applicable tax, accounting, disclosure and privacy-request duties | The legal obligation that applies to the particular record or request. |
| Protect accounts, investigate misuse, resolve service disputes and maintain necessary security records | Legitimate interests in a secure, reliable service and fair dispute handling, balanced against your rights. |
| Optional public reuse, testimonials, eligible recordings and other uses presented as consent-based | Your separate consent to the identified purpose. Declining an optional use does not remove unrelated membership access. |
You can ask about a specific basis or object to processing based on legitimate interests. Where we rely on consent, you may withdraw it using the relevant control or by contacting us. Withdrawal does not change the lawfulness of processing before it. Other applicable laws may require consent or another condition even where the table describes a contract or legitimate interest.
Sensitive information may require an additional legal condition. General membership acceptance is not blanket consent to process sensitive information or to use it for new purposes. We must establish the applicable condition before carrying out processing that needs one. Ask us if you need details about the basis for a particular use or wish to object to it.
In particular, saving a private reflection does not make sensitive information public or give permission to use it for advertising, health profiling or unrelated AI training. Any processing that needs explicit consent must identify the information and purpose before asking for that consent. You can use non-sensitive examples and the public worksheet without providing a personal health history.
Cookies and saved preferences
Sign-in and security features use necessary browser storage to maintain access and protect requests. Choosing a light or dark appearance saves that preference in your browser until you clear it or select the system setting. That preference does not contain your journal. Blocking necessary storage can prevent sign-in or other requested functions from working. The site legal notice explains applicable site-wide storage and choices; an external provider controls storage on its own service.
How long information stays
We keep information for its stated purpose and any applicable legal need, rather than treating every category as permanent. Ending paid access and deleting information are separate actions.
| Information | Retention and removal |
|---|---|
| Account details and your saved work | Retained while needed for your continuing account and chosen saved work. You can request eligible content removal or account closure. Canceling a subscription alone does not erase it. |
| Sharing and publication records | Access follows the permission’s scope and expiry. Withdrawal stops future authorized use; necessary permission, withdrawal and dispute records can remain after the shared content is removed. |
| Mentoring and participation history | Ending a session or the seven-day mentoring follow-up window ends the relevant participation rights, not the history. Owned-content withdrawal and account privacy requests remain available. |
| Prepared account exports | Available to download for seven days after they become ready, with the expiry shown in Account. Expiry ends download access; removal from storage is a separate cleanup step. Request a new export if needed. |
| Payment, tax and dispute records | Limited records remain for applicable accounting or legal requirements and unresolved payments, refunds or disputes. The relevant obligation determines the period. They are not retained as a substitute journal. |
| Recurring-payment agreement evidence | Keep the limited evidence of billing authorization for the legally required period, including after cancellation where required. This does not justify keeping unrelated reflections. |
| Reports, evidence and safety records | Retained only while needed for a specific case, appeal, safety or legal purpose. A justified hold has its own review and expiry; it is not permission to retain unrelated material indefinitely. |
| Recordings and provider copies | Governed by the recording’s separately reviewed conditions and provider obligations. Withdrawal and removal require follow-up for each affected copy. |
| Operational records and backups | Kept for the documented operational or recovery purpose and applicable retention cycle. Removing active data does not instantly remove all backup or provider copies. Restoration must respect previously completed removal requests. |
Current technical logging settings retain local web request logs for three days and Microsoft Application Insights monitoring records for 90 days. These periods apply to those log systems. Saved work, financial records and evidence retained for a specific case follow the separate rules above.
As checked on October 2, 2026, the community database uses a seven-day recovery window. Microsoft can retain older backup files needed to restore a point within that window. Seven days therefore does not promise complete erasure of every copy. Separately connected services follow their own reviewed retention conditions.
Account closure stops participation and sharing before all removal work finishes. Outstanding export files, documented retention holds, recurring-payment cancellation or unresolved financial obligations can delay final completion. A review date is not a promised deletion date. We will explain remaining work or a retention reason where permitted and keep the request status distinct from completed removal. Ask us for the applicable retention criteria or status of a particular record.
Your choices and privacy requests
Account provides controls for eligible export, content removal, sharing withdrawal and closure. Exports reflect a particular snapshot; request another for later changes. They do not entitle you to someone else’s private material. Removing a draft does not remove a separately submitted version, so identify the material you want removed. Contact us if the available controls do not cover your request.
Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of information; restrict or object to a use; withdraw consent; or make choices about sale, sharing or sensitive information. We assess the rights and exceptions that apply and respond within the applicable legal time limit. We may need proportionate identity verification; do not send a password or unnecessary identity documents by email. An authorized representative may contact us, subject to appropriate verification.
We will explain a refusal or limitation where permitted, including a review route. You may complain to the relevant privacy authority. Exercising a privacy right does not itself result in unfair treatment; a requested deletion or withdrawal can, however, make a service that needs the information unavailable.
Requests are normally free. If a law permits an exceptional fee or refusal, we will explain the basis before charging or refusing. You do not need a lawyer or particular legal wording to contact us. A statutory request is not limited to the fields available in Account.
Response times and complaints
The deadline depends on the right and law involved. European and UK data-protection requests normally have a one-month response period; permitted extensions or identity checks have their own conditions. Canadian access requests under PIPEDA normally require a response within 30 days. Where California’s CCPA applies, requests to know, correct or delete normally have a 45-day period. We will explain any permitted extension and its reason within the required time. These examples do not replace a shorter deadline or another applicable local right.
You can complain to your competent data-protection authority, including an EU/EEA authority, the UK’s ICO, Canada’s Office of the Privacy Commissioner or the applicable provincial authority, Australia’s OAIC, or the appropriate US state authority. You can ask us which route applies. Contacting us does not waive a right to approach an authority or court, and we will explain any required preliminary complaint step.
International handling and security
The community database and its private file storage are hosted in Microsoft’s Azure West US 3 region in the United States, as verified on October 2, 2026. Connected services, including sign-in, payments and Teams, can process information in other locations. Where the law requires a transfer safeguard, we must establish it before the transfer. Contact us for the safeguards and locations applicable to your information. The regions where membership is offered do not establish where data is stored.
We use access controls and other technical and organizational measures to protect information. No system is free from risk. If a breach requires notification, we will notify affected people and authorities as required. This service is intended for adults. Contact us if you believe a child has supplied personal information so we can review and address it.
Changes to this notice
Published versions will identify their effective date. We will notify members of material changes and seek separate permission when a new use requires it. Changing this notice does not create consent or retroactively change the terms of an accepted purchase. Privacy questions can always be sent to legal@virtuamerica.com.
Accessibility
We want everyone to be able to use this site. Our accessibility target is WCAG 2.2 Level AA.
An evaluation of every page and connected service has not yet been completed.
To report a barrier or request assistance, include the page address and the task you were trying to complete. Please do not send passwords or sensitive personal information. Contact: legal@virtuamerica.com.
Contact VirtuAmerica LLC
VirtuAmerica LLC7533 S Center View Ct #8067
West Jordan, UT 84084, USA
legal@virtuamerica.com