PRIVACY

Privacy

This page explains how That Upgrade Feeling handles personal data and browser information across public browsing, Premium purchases, Customer Access, licensing, reviews, and site security.

Current site state

That Upgrade Feeling (“TUF”) is designed to collect only the information reasonably needed to operate the site, deliver digital products, protect access, maintain purchase and licensing records, handle reviews and refund/download states, and keep the service secure.

The current site does not provide public TUF member accounts and does not currently run behavioral advertising, advertising cookies, or cross-site tracking pixels. TUF does operate a privacy-minimized first-party analytics system for aggregate site measurement. Newsletter signup is not yet treated as active public functionality and will be covered by an updated notice before launch if it is enabled.

Information processed during normal browsing

Like any website, page requests require technical information to be processed by the hosting and security infrastructure. This may include the requested URL, IP address, browser or user-agent information, request time, response status, and limited security-event information.

TUF uses this information for delivery, troubleshooting, abuse prevention, security controls, and operational reliability rather than to build a behavioral advertising profile.

First-party site analytics

TUF uses its own first-party analytics system to understand aggregate site use and improve content and products. The analytics system can record page views, a normalized traffic source, a two-letter country code when a trusted server or edge signal is available, a coarse device class (Desktop, Mobile, Tablet or Unknown), normalized external destination domains for outbound clicks, accepted internal search terms, and the approved campaign fields utm_source, utm_medium, utm_campaign and utm_content when present.

A random first-party session token is used for a 30-minute session. Only a SHA-256 hash of that token is stored in the analytics database. TUF Analytics does not store raw IP addresses, raw User-Agent strings, browser fingerprints, full outbound URLs, destination query strings or fragments, anchor text, full internal-search query strings, keystroke streams, utm_term or advertising click IDs.

Country classification is accepted only from an allowlisted server or edge signal; TUF Analytics does not perform an IP-geolocation fallback. Device classification is derived transiently on the server and only the coarse device class is stored. Analytics reporting is read-only aggregation over the minimized session and event records.

Premium purchase, access and licensing data

For Premium digital products, TUF may process information needed to identify and support a purchase and its licensed access. Depending on the transaction and product, this can include the purchaser name, email address, product, order or transaction reference, Paddle transaction identifier, License ID, access activation and expiry state, download state, voluntary-refund state, and limited security/session information used to protect Customer Access and the Full Reader.

Some customer-delivered Premium files may be personalized with purchaser identity and a License ID for licensing and anti-sharing purposes.

Payment checkout is hosted by Paddle. TUF does not collect full payment-card details through an on-site TUF payment form. Paddle’s own terms and privacy practices apply to information processed through its hosted checkout and Merchant of Record services.

Verified reviews

A verified purchaser may submit a product review from protected Customer Access. TUF may store the review display name, rating, review text, verification state, related product and purchase/access reference needed to enforce one verified review per eligible purchase. The purchase email used for verification is kept internal and is not displayed publicly as part of the review.

Cookies and browser storage

TUF uses limited browser storage and may use strictly necessary first-party cookies for functionality and security. This can include remembering the selected visual style, maintaining authorized Premium Customer Access, protecting Full Reader browser access, and supporting browser verification when security protection modes require it.

These mechanisms are used for service functionality, access control and security. They are not currently used for behavioral advertising or cross-site tracking. More detail is provided on the Cookies & Local Storage page.

Service providers and disclosures

TUF may disclose or make data available only as reasonably necessary to providers that help operate the service, such as managed website hosting and security infrastructure, and to Paddle for payment, transaction, refund and Merchant of Record functions when checkout is used.

Providers may process information in locations outside Saudi Arabia depending on their infrastructure and service arrangements. Any processing or transfer remains subject to applicable legal requirements and the provider’s contractual and privacy obligations.

TUF may also disclose information when required by applicable law, a lawful request, or when reasonably necessary to establish, exercise or defend legal rights.

Retention and deletion

TUF keeps personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing purchased access, maintaining licensing and transaction evidence, handling support, refunds and disputes, preventing abuse, and meeting applicable legal, accounting or regulatory obligations.

A final category-by-category retention schedule will be published before the public commercial launch. When data is no longer required for its purpose or a lawful retention requirement, it should be deleted, anonymized or otherwise securely disposed of as appropriate.

Security

TUF uses technical and organizational safeguards intended to reduce unauthorized access, disclosure, alteration or loss. Access to administrative purchase and license records is restricted, access credentials are protected rather than intentionally exposed as public data, and security controls are designed to avoid logging passwords, raw authentication tokens or full sensitive request payloads.

No online service can guarantee absolute security.

Your privacy rights

Where the Saudi Personal Data Protection Law or another applicable law applies, individuals may have rights relating to their personal data, including rights to be informed, to request access or a copy, to request correction or completion, and to request destruction in circumstances provided by law. Additional rights may apply depending on the legal basis and circumstances of processing.

Requests may require reasonable identity verification so that personal data is not disclosed or changed for the wrong person.

Privacy requests

A dedicated public privacy/support contact channel will be published before TUF’s public commercial launch. Until that channel is published, this site remains in pre-launch preparation and visitors should not send sensitive personal information through TUF’s public social-media accounts.

Changes to this notice

This notice may be updated when TUF activates new features or materially changes how personal data is processed. The public page should describe the active service rather than planned or inactive functionality.

Last updated: August 21, 2026.