Privacy Policy
How we collect, use, and protect your personal information
1. Introduction
Welcome to jimrohn.com (the “Platform”), operated by SUCCESS Enterprises, LLC (“SUCCESS Enterprises,” “we,” “us,” or “our”). We are committed to protecting the privacy of everyone who visits and uses our Platform, including visitors, registered members, and subscribers.
This Privacy Policy explains what personal information we collect, how we use and share it, the choices you have regarding your information, and how we protect it. This policy applies to all information collected through the Platform, including the jimrohn.com website, our membership portal, AI coaching features, e-commerce store, email communications, and any related services.
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Platform.
2. Information We Collect
We collect information in several ways depending on how you interact with the Platform. Below is a detailed breakdown of the categories of information we collect.
2.1 Account Data
When you create an account on jimrohn.com, we collect the following information through our authentication provider (Supabase Auth):
- Email address — used as your primary account identifier and for communications
- Full name — used for personalization and display within the Platform
- Password — securely hashed and stored; we never have access to your plaintext password
- Profile information — any additional details you voluntarily provide, such as a profile photo, biography, or personal development goals
- Social login data — if you choose to sign in with a third-party provider (such as Google), we receive your name, email address, and profile photo from that provider
2.2 Payment Data
When you make a purchase or subscribe to a membership, payment processing is handled entirely by Stripe, our third-party payment processor. We want to be clear about what we do and do not store:
- We never store your full credit card number, CVV, or complete bank account details on our servers
- Stripe processes and stores your payment information in compliance with PCI DSS (Payment Card Industry Data Security Standard)
- We do receive and store limited payment metadata from Stripe, including: the last four digits of your card, card brand (e.g., Visa, Mastercard), billing address, transaction amounts, transaction dates, subscription status, and a Stripe customer ID that links your account to your payment history
2.3 Usage Data
We automatically collect certain information about how you interact with the Platform, including:
- Pages and content viewed — which articles, quotes, videos, and journey modules you access
- Features used — interactions with the AI coach, daily practice check-ins, journey progress, and community features
- Device information — browser type and version, operating system, screen resolution, and device type
- Log data — IP address, access times, referring URLs, and pages visited before and after using our Platform
- Performance data — page load times, errors encountered, and interaction patterns that help us improve the user experience
2.4 AI Coaching Data
Our Platform includes an AI coaching feature powered by Anthropic's Claude technology that provides personalized guidance based on Jim Rohn's philosophy and teachings. When you use this feature, we collect:
- Conversation history — the messages you send to and receive from the AI coach, stored to provide continuity and personalized coaching over time
- Coaching preferences — your selected topics of interest, personal development goals, and areas of focus
- Reflection and journal entries — responses you provide during guided reflections, daily check-ins, and journey module exercises
- Transformation metrics — progress data, completed milestones, and self-assessments used to track your personal development journey
Important: Your AI coaching conversations are private to your account. We do not use the content of your individual coaching conversations to train AI models. Conversation data is sent to Anthropic for processing in real time but is not retained by Anthropic for model training purposes, in accordance with Anthropic's commercial data usage policies.
2.5 Communication Data
We collect information related to our email communications with you, processed through our email service provider, Resend:
- Email interactions — whether you open emails, click links within them, and which content you engage with
- Communication preferences — your subscription status, email frequency preferences, and opt-in or opt-out choices
- Support communications — messages you send to our support team and the content of those interactions
2.6 Cookie Data
We use cookies and similar tracking technologies to operate the Platform, remember your preferences, and understand how you use our services. For detailed information about the specific cookies we use, their purposes, and how to manage your cookie preferences, please see our Cookie Policy.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery
- Creating and managing your account
- Processing payments and managing subscriptions
- Providing access to content, journeys, and member features based on your membership tier
- Delivering digital products you have purchased
- Responding to your support inquiries and requests
3.2 Personalization
- Customizing your experience based on your interests and activity
- Recommending relevant content, journeys, and resources
- Adapting the Platform interface to your preferences
- Tailoring your daily practice and check-in experiences
3.3 AI Coaching
- Providing personalized coaching conversations based on Jim Rohn's teachings
- Tracking your progress through transformation journeys
- Generating insights and recommendations based on your reflections and goals
- Maintaining coaching continuity across sessions by referencing past conversations
3.4 Marketing Communications
- Sending newsletters, product updates, and educational content (with your consent)
- Notifying you of new content, features, or membership benefits
- Providing personalized recommendations for products and content you may find valuable
- Sending transactional emails related to your account, purchases, and subscriptions
You can opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email or by updating your communication preferences in your account settings. Transactional emails (such as purchase receipts and account security notifications) are not subject to opt-out.
3.5 Analytics and Improvement
- Understanding how users interact with the Platform to improve functionality and design
- Analyzing content performance to deliver more of what our members value
- Measuring the effectiveness of our features and services
- Conducting aggregate statistical analysis (which does not identify individual users)
3.6 Security and Fraud Prevention
- Detecting, investigating, and preventing fraudulent transactions and unauthorized access
- Enforcing our Terms of Service and other policies
- Protecting the security and integrity of the Platform
- Complying with legal obligations and responding to lawful requests from authorities
4. Information Sharing
We never sell your personal data. We do not and will not sell, rent, or trade your personal information to third parties for their marketing purposes.
We share your information only with the following categories of service providers who help us operate the Platform, and only to the extent necessary for them to provide their services:
- Stripe (payments) — processes your payment transactions securely. Stripe receives your payment information directly and is a PCI DSS Level 1 certified service provider. See Stripe's Privacy Policy.
- Supabase (database and authentication) — hosts our database and manages user authentication. Your account data and Platform content are stored on Supabase's infrastructure. See Supabase's Privacy Policy.
- Anthropic / Claude (AI coaching) — powers our AI coaching feature. Your coaching conversation content is sent to Anthropic for real-time processing. Anthropic does not use commercial API data to train its models. See Anthropic's Privacy Policy.
- Resend (email delivery) — sends transactional and marketing emails on our behalf. Resend receives your email address and email interaction data. See Resend's Privacy Policy.
- Vercel (hosting) — hosts the Platform and may process server logs that include IP addresses and request data. See Vercel's Privacy Policy.
- Bunny.net (video hosting) — delivers video content through their content delivery network. Bunny.net may collect usage data related to video playback. See Bunny.net's Privacy Policy.
- Meta / Facebook (advertising, planned) — we may implement Meta tracking pixels in the future for advertising measurement and audience targeting. If implemented, this will be disclosed in an update to this policy and managed through our cookie consent preferences.
- Analytics providers — we may use analytics services to understand Platform usage in aggregate. Any analytics data shared with third parties is anonymized or aggregated so that it does not identify individual users.
We may also disclose your information in the following limited circumstances:
- Legal requirements — when required by law, subpoena, court order, or other legal process
- Protection of rights — when necessary to protect the rights, property, or safety of SUCCESS Enterprises, our users, or the public
- Business transfers — in connection with a merger, acquisition, reorganization, or sale of assets, in which case your information may be transferred to the successor entity
- With your consent — when you explicitly authorize us to share your information for a specific purpose
5. Cookies and Tracking Technologies
We use cookies and similar technologies (such as local storage and session storage) to operate the Platform, maintain your session, remember your preferences, and understand how our services are used.
The types of cookies we use include:
- Essential cookies — required for the Platform to function properly, including authentication and security
- Functional cookies — remember your preferences and settings to enhance your experience
- Analytics cookies — help us understand how users interact with the Platform so we can improve it
- Marketing cookies — used to deliver relevant advertising and measure campaign effectiveness (if applicable)
You can manage your cookie preferences at any time through our cookie consent banner or by visiting our Cookie Policy, which provides full details on each cookie we use, its purpose, and how to opt out.
6. Your Privacy Rights
Depending on where you are located, you may have specific rights regarding your personal information. We are committed to honoring these rights regardless of where you reside, to the extent practicable.
6.1 Rights for EU/EEA Residents (GDPR)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of access — you have the right to request a copy of the personal data we hold about you
- Right to rectification — you have the right to request that we correct any inaccurate or incomplete personal data
- Right to erasure (“right to be forgotten”) — you have the right to request that we delete your personal data, subject to certain legal exceptions
- Right to data portability — you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller
- Right to restrict processing — you have the right to request that we limit how we use your personal data in certain circumstances
- Right to object — you have the right to object to the processing of your personal data for direct marketing purposes or when processing is based on our legitimate interests
- Right to withdraw consent — where we rely on your consent to process personal data, you have the right to withdraw that consent at any time
- Right to lodge a complaint — you have the right to file a complaint with your local data protection authority if you believe we have violated your privacy rights
Our legal basis for processing your personal data under the GDPR includes: performance of a contract (providing our services to you), legitimate interests (improving our Platform and communicating with you), consent (marketing communications and certain cookies), and compliance with legal obligations.
6.2 Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know — you have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which we collected it, our purposes for collecting it, and the categories of third parties with whom we share it
- Right to delete — you have the right to request that we delete personal information we have collected from you, subject to certain legal exceptions
- Right to correct — you have the right to request that we correct inaccurate personal information we maintain about you
- Right to opt out of sale or sharing — you have the right to opt out of the “sale” or “sharing” of your personal information. As stated above, we do not sell your personal information. If we implement advertising pixels that constitute “sharing” under the CCPA, we will provide a clear opt-out mechanism.
- Right to limit use of sensitive personal information — you have the right to limit the use and disclosure of sensitive personal information to what is necessary to provide our services
- Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different pricing, quality of service, or access to features because you exercise your privacy rights.
6.3 How to Exercise Your Rights
To exercise any of the rights described above, you may:
- Email us at privacy@jimrohn.com with the subject line “Privacy Rights Request”
- Use your account settings to update, correct, or delete certain information directly
- Use the unsubscribe link in any marketing email to opt out of marketing communications
We will respond to all verified requests within 30 days (or within the timeframe required by applicable law). To verify your identity, we may ask you to confirm certain account details. If we need additional time, we will notify you of the extension and the reason for it.
You may also designate an authorized agent to make a request on your behalf by providing written authorization to the agent and contacting us to verify the arrangement.
7. Data Security
We take the security of your personal information seriously and implement appropriate technical and organizational measures to protect it. These measures include:
- Encryption in transit — all data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security) / HTTPS
- Encryption at rest — personal data stored in our database is encrypted at rest using industry-standard encryption protocols
- Access controls — access to personal data is restricted to authorized personnel on a need-to-know basis, with role-based permissions and multi-factor authentication
- Secure authentication — passwords are hashed using strong, one-way cryptographic algorithms and are never stored in plaintext
- Infrastructure security — our hosting providers (Vercel and Supabase) maintain SOC 2 Type II compliance and undergo regular security audits
- Payment security — all payment processing is handled by Stripe, which is PCI DSS Level 1 certified, the highest level of payment security certification
- Regular security reviews — we conduct periodic security assessments and update our practices in response to evolving threats
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and notifying affected users as required by applicable law.
8. Data Retention
We retain your personal information in accordance with the following guidelines:
- Active accounts — your personal data is retained for as long as your account remains active and you continue to use the Platform
- Closed or inactive accounts — if you close your account or your account becomes inactive, we will retain your data for up to 24 months following account closure or last activity, after which it will be permanently deleted or anonymized
- Payment records — transaction records may be retained for up to 7 years as required by tax and financial regulations
- AI coaching data — conversation history and coaching data are retained for the duration of your active account. Upon account deletion, coaching data is permanently removed within the 24-month retention period described above
- Marketing data — if you unsubscribe from marketing communications, we retain your email address on our suppression list to ensure we honor your opt-out preference
- Legal requirements — we may retain certain data beyond these periods if required by law, regulation, or to resolve disputes or enforce our agreements
Early deletion: You can request deletion of your personal data at any time by contacting us at privacy@jimrohn.com. We will process your request within 30 days, subject to any legal obligations that require us to retain certain information.
9. Children's Privacy
The Platform is intended for users who are 18 years of age or older. We do not knowingly collect, use, or disclose personal information from children under the age of 18. If you are under 18, please do not create an account or provide any personal information through the Platform.
If we become aware that we have inadvertently collected personal information from a child under 18, we will take immediate steps to delete that information from our systems. If you believe that a child under 18 has provided us with personal information, please contact us at privacy@jimrohn.com so we can take appropriate action.
10. International Users
The Platform is operated from and our data is primarily stored in the United States. If you are accessing the Platform from outside the United States, please be aware that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your country of residence.
For EU/EEA residents: We are committed to GDPR compliance. When we transfer your personal data outside the EU/EEA, we rely on appropriate legal mechanisms to ensure adequate protection, including:
- Standard Contractual Clauses (SCCs) — approved by the European Commission, these contractual safeguards ensure that your data receives equivalent protection when transferred internationally
- Adequacy decisions — where applicable, we transfer data to countries that the European Commission has determined provide an adequate level of data protection
- Service provider commitments — our key service providers (including Supabase, Stripe, and Vercel) maintain their own GDPR compliance programs and data processing agreements
By using the Platform, you consent to the transfer of your information to the United States and other jurisdictions where our service providers operate, subject to the safeguards described in this policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make changes:
- Material changes — for significant changes that affect how we collect, use, or share your personal information, we will notify you via email (sent to the address associated with your account) and/or by posting a prominent notice on the Platform at least 30 days before the changes take effect
- Minor changes — for non-material updates (such as formatting or clarification), we will update the “Last Updated” date at the top of this page
Your continued use of the Platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with any changes, you should discontinue your use of the Platform and may request deletion of your account and personal data.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
- Email: privacy@jimrohn.com
- Mail:
SUCCESS Enterprises, LLC
Attn: Privacy Team
Dallas, TX
For data protection inquiries from EU/EEA residents, you may also contact your local data protection authority. A list of EU data protection authorities is available on the European Data Protection Board website.
We aim to respond to all privacy-related inquiries within 30 days of receipt.