Effective Date: 2026-04-19 · Last Updated: 2026-05-22
This Privacy Policy describes how CWDS OÜ (“NerveWindow,” “we,” “us,” or “our”) handles personal data in connection with:
alexzah.com and any subdomain or product page (the “Websites”);We are the data controller for the personal data we handle in connection with the Service. You can contact us at the address in Section 16.
The short version. The Application is designed so that your state check-ins, session history, scores, and notes stay on your device. We do not collect them as app content. Currently live sales pages, checkout, the new account-flow customer journey, and current V2/account app pages do use standard analytics and advertising tools — and this Policy explains exactly what they are and how to control them. Purchases pass through a small set of named third parties. We do not sell personal data.
We process different categories of data in different contexts. This Section separates them by surface (App vs. Websites).
The Application is designed to operate without sending your in-app content to us. We receive the following limited categories of data from, or on behalf of, App users:
When you visit a Website, read a sales page, open a marketing email, begin a checkout or account-flow page, or use a current V2/account app page, we and our processors may receive:
If you contact us by email, via a support form, or by replying to a marketing email, we receive the contents of that communication and your email address. We use this to respond and keep a record of the conversation.
We want to be explicit about what we do not collect, because the brand promise of the Application depends on it.
We do not collect, store on our servers, or transmit to any third party:
We do not:
For currently live sales pages, account-flow pages, and current V2/account app pages, third-party browser tools can still record page views, button clicks, and, for Clarity, masked session recordings as described in Section 6. Those tools are separate from our server-side storage of your personal app content.
Currently live sales pages, checkout and account-flow pages, and current V2/account app pages use the third-party browser tools listed below. This tracking applies to the new account-flow customer journey starting 2026-05-22. Legacy buyers’ original direct-app experience is unchanged; the frozen legacy app pages are not retroactively changed by this disclosure.
These tools may collect page views, button clicks, checkout or conversion events, referring URL, UTM/campaign parameters, browser and device data, approximate location derived from IP address, cookie identifiers, and, for Microsoft Clarity, session recordings and heatmaps. Free-text fields on current account app pages are masked where they exist.
| Tool | ID | What It Collects | Provider Privacy | Opt-out / Control |
|---|---|---|---|---|
| Meta Pixel + Conversions API (CAPI) | 338326925788695 | Page views, button clicks, checkout/conversion events, campaign/referrer data, cookie identifiers, IP address, and browser/device data. For purchases, CAPI may send the server-side purchase event described below. | Meta Privacy Policy | Reject marketing cookies in the consent banner; use Meta’s activity off Meta technologies and Ad Preferences controls. |
| Google Tag Manager (GTM) | GTM-M52SWDT3 | Loads and manages the other tags; may process page URL, referrer, consent state, and tag-firing data. | Google Privacy Policy; GTM Use Policy | Controlled by the consent banner and by the individual tags it loads. |
| Google Analytics 4 (GA4) | G-EXJH3VMV3F | Page views, events such as button clicks, UTM parameters, browser/device data, approximate location, and pseudonymous identifiers. | Google Privacy Policy | Reject analytics cookies in the consent banner; use the Google Analytics opt-out browser add-on or Google Ads Settings. |
| Microsoft Clarity | vxpxhd7ljj | Page views, clicks/taps, scrolls, heatmaps, browser/device data, and session recordings. Input fields are masked on current account app pages where they exist. | Microsoft Privacy Statement; Clarity Terms | Reject analytics cookies in the consent banner; opt out through the Digital Advertising Alliance by selecting Microsoft at optout.aboutads.info; use Global Privacy Control where supported. |
| TikTok Pixel + Events API | D92NO6RC77U49J865M20 | Page views and purchase-funnel events (with marketing consent); for purchases, the server-side event described in Section 6.1.2. | TikTok Privacy Policy | Reject marketing cookies in the consent banner; TikTok in-app ad settings. |
| X (Twitter) Ads Pixel | ogz03 | Page views and purchase-funnel events (with marketing consent); server-side conversion events may follow (Section 6.1.3). | X Privacy Policy | Reject marketing cookies in the consent banner; X ads preferences. |
| Google Ads | AW-16663440143 | Conversion measurement; click IDs (gclid/gbraid/wbraid) stored up to 90 days; with marketing consent, hashed email for Enhanced Conversions (Section 6.1.4). | Google Privacy Policy | Reject marketing cookies in the consent banner; Google Ads Settings. |
In addition to the browser-based Meta Pixel, after a successful purchase we send a small server-to-server message to Meta’s Conversions API (CAPI) so that Meta can measure ad effectiveness even when browsers block tracking pixels.
This server message contains: the event type, order amount, currency, and product identifiers; SHA-256-hashed versions of your email address, first and last name, city, region, postal code, and country, plus an internal customer reference — sent on the basis of our legitimate interest in measuring our own advertising (hashing means Meta receives a scrambled fingerprint it can only match against data it already holds; we never send these details in plain text). Only if you accepted marketing cookies, the message additionally includes your IP address, your browser user-agent, and the _fbp/_fbc cookie values Meta set in your browser.
The banner is shown to visitors from the EU/EEA, the United Kingdom, Switzerland, and California; elsewhere, these tools may run by default where local law permits, and you can still limit them through your browser or platform settings.
You can object at any time to our processing based on legitimate interest — see Section 11 for your rights, including the right to object.
The same event_id is attached to both the browser pixel event and the server-side event so that Meta deduplicates them and counts the purchase only once.
Before purchase, if you have accepted marketing cookies, we also send server-side copies of key funnel events (page view, add-to-cart, checkout started) to Meta and TikTok so measurement keeps working when browsers block pixels. These events carry an anonymous first-party visitor ID (stored on your device as nw_ext_id for up to 1 year), your IP address, and your browser user-agent — but not your name or email. If you decline marketing cookies, these events are not sent and the ID is not used.
We use TikTok advertising tools to measure which TikTok ads lead to visits and purchases. With your marketing consent, the TikTok pixel records page views and purchase-funnel events in your browser. After a purchase, we also send a server-to-server event to TikTok containing the order details, a SHA-256-hashed version of your email address, and an internal visitor reference — sent on the basis of our legitimate interest in measuring our own advertising; we never send your email in plain text. Only if you accepted marketing cookies, this server event additionally includes your IP address, your browser user-agent, and — where present — the TikTok click ID (ttclid) and _ttp cookie value from the ad you clicked. Provider: TikTok Technology Limited (Ireland) / TikTok Inc. (US); transfers are covered by Standard Contractual Clauses.
We use X advertising tools to measure which X (Twitter) ads lead to visits and purchases. With your marketing consent, the X pixel records page views and purchase-funnel events in your browser; if you decline marketing cookies, the pixel does not run. We may also send server-side conversion events to X containing order details, a SHA-256-hashed version of your email address, and — where present — the X click ID (twclid) from the ad you clicked; we never send your email in plain text. Provider: X Corp. (United States); transfers are covered by Standard Contractual Clauses.
We use Google Ads conversion measurement to know which Google ad led to a purchase. When you arrive from a Google ad, the click ID (gclid/gbraid/wbraid) is stored in your browser for up to 90 days. On purchase, we report the order value (and any later refund adjustments) to Google, and — only with your marketing consent — a SHA-256-hashed version of your email address (“Enhanced Conversions”) so Google can attribute the sale to the ad more accurately. We also send Google Consent Mode signals reflecting your banner choices, so Google’s tags behave according to your consent.
The Websites use:
You can clear cookies at any time through your browser settings, and you can change your consent choices at any time through the consent banner or the Cookie settings link on the Websites.
Key cookies and stored identifiers: nervewindow_cookie_consent_v1 — your consent choices, stored in your browser’s local storage (12 months); _fbp, _fbc — Meta attribution (3 months); _ttp / ttclid — TikTok attribution (13 months); _ga, _ga_* — Google Analytics (up to 24 months); gclid/gbraid/wbraid — Google click IDs in localStorage (90 days); twclid — X (Twitter) click ID captured with our first-party attribution records; nw_ext_id — anonymous visitor ID for server-side measurement (12 months); Clarity cookies (_clck, _clsk) — session analytics (up to 12 months); Stripe cookies (__stripe_mid, __stripe_sid) — fraud prevention during checkout (strictly necessary). Exact names and durations may vary slightly by tool version.
We currently do not respond to “Do Not Track” browser signals because there is no consensus on how to interpret them. We do honour the Global Privacy Control (GPC) signal where applicable law requires it.
Our own attribution records. When you land on our pages from an ad, we record the ad-click reference from the URL (such as fbclid, gclid, ttclid, or twclid) and campaign tags together with your order in our own systems (including Stripe order metadata). We do this on the basis of our legitimate interest in knowing which advertising pays for itself. Before you give marketing consent, this information stays in our systems only — it is not sent to any advertising platform. We also keep a record of pages visited on our own sites, linked to a random identifier (not your name or email), for up to 180 days, so we can understand which ads and pages lead to purchases.
Separate from core on-device operation, the Application may make limited network requests when one of the following happens:
Information that you intentionally submit through these flows, and the minimum metadata required to complete them, may be transmitted for that specific purpose. These operational requests do not convert the Application into a cloud service and do not transmit your state check-ins, session history, or notes for any analytic purpose.
We use a small set of named third parties to run the Service. Each of them has its own privacy policy, and each processes personal data only on our instructions, under a data-processing agreement or a Controller-to-Controller arrangement as appropriate.
| Provider | Role | Data Shared | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processor | Payment, buyer email, order metadata | US + local |
| GetResponse S.A. | Email marketing and transactional email | Email address, opt-in source, open/click activity, buyer tags | Poland (EU) |
| Apple, Inc. | Platform store & payments (App Store) | Order reference, product, App Store receipt | US + Ireland (EU) |
| Google LLC | Platform store, tag management, analytics (Play Store, GTM, GA4) | Order reference, page views, button-click events, UTM/campaign parameters, browser/device data, approximate location, pseudonymous identifiers | US + local |
| Meta Platforms, Inc. | Ad attribution and retargeting (Meta Pixel + Conversions API) | Page views, button clicks, checkout/conversion events, campaign/referrer data, cookie identifiers, IP address, browser/device data (browser tools, per consent); for purchases, server-side events including order amount, currency, product IDs, SHA-256-hashed contact details (email, name, city, region, postal code, country) and a customer reference (legitimate interest), plus — with marketing consent — IP address, browser user-agent, and _fbp/_fbc cookies | US + Ireland (EU) |
| TikTok Technology Limited / TikTok Inc. | Ad attribution (TikTok Pixel + Events API) | Page views and funnel events (browser, with consent); for purchases, server-side events with order details, SHA-256-hashed email, and a visitor reference (legitimate interest), plus — with marketing consent — IP address, user-agent, and TikTok click ID | Ireland (EU) + US |
| X Corp. | Ad attribution (X Ads pixel; server conversion events may follow) | Page views and funnel events (browser, with consent); server-side purchase events may include order details, SHA-256-hashed email, and the X click ID | US |
| Microsoft Corporation | Session analytics (Microsoft Clarity) | Page views, clicks/taps, scrolls, heatmaps, browser/device data, and masked session recordings | US |
| DigitalOcean LLC (via Cloudways Ltd.) | Web hosting for the Websites | Server logs, IP address | EU + US regions |
| Cloudflare, Inc. | Content delivery and security | IP address, request metadata | US + edge locations |
We do not share personal data with third parties for any purpose other than those described in this Policy, or as required by law.
Several of the providers above are located in the United States or operate globally. When we transfer personal data of EU/EEA, UK, or Swiss residents outside those regions, we rely on the following safeguards, as appropriate:
You may request a copy of the safeguards in place for a specific provider by contacting us at the address in Section 16.
When the EU General Data Protection Regulation (GDPR) or the UK GDPR applies, we rely on the following lawful bases:
If you are in the EU, EEA, UK, or Switzerland, you have the right, subject to the conditions and limits in the applicable law, to:
To exercise any of these rights, contact us at the address in Section 16. We will respond within one month, or within two months for complex or numerous requests, as permitted by law.
If you are a California resident, you have the right to:
Residents of other regions may have additional rights under applicable local law. We honour any non-waivable statutory right you have where you live.
We retain personal data only for as long as we need it for the purpose for which it was collected, and for periods required by applicable law. Indicative retention windows:
| Category | Retention |
|---|---|
| Order and license records | For the operational life of the Service, plus the period required by tax, accounting, and consumer-protection law (typically 7 years under Estonian accounting law). |
| Support and bug-report conversations | Up to 3 years after the conversation, for troubleshooting and dispute resolution. |
| Marketing email activity | For as long as you remain subscribed, plus a limited period after unsubscribe to honour your opt-out request. |
| Website analytics (GA4, Clarity, Meta Pixel) | Subject to the retention settings of each tool; GA4 is configured to the shortest retention option compatible with the product. |
| Payment records via Stripe | Governed by Stripe’s retention policy and applicable financial-services law. |
When retention periods expire, we delete or anonymise the data.
We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including:
No security measure is perfect. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority as required by law, and we will notify affected users where applicable law so requires.
The Service is intended for adults. As stated in our Terms of Use, you must be at least 18 years old to use the Service. We do not knowingly collect personal data from anyone under 18. If we learn that we have received personal data of a minor, we will delete it promptly.
If you believe a minor has submitted personal data to us, please contact us at the address in Section 16 so that we can take appropriate action.
We may update this Policy to reflect changes in the Service, applicable law, or our practices. When we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, give additional notice inside the Application, on our Websites, or by email.
If we materially expand collection beyond the page-level, click, conversion, and masked session analytics described in Section 6, we will update this Policy, update the relevant in-app or website disclosures, and where required by applicable law, obtain your consent before the change takes effect for you.
For privacy questions, data-subject requests, or complaints:
CWDS OÜ
Attention: Privacy
Kotkapoja tn 2a-10, Kristiine, 10615 Tallinn, Harju maakond, Estonia
Email: alex@alexzah.com
Support: alex@alexzah.com
If you are in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data-protection supervisory authority. If you are in Estonia, that is the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) — aki.ee.
© 2026 CWDS OÜ. All rights reserved.