Last updated October 9, 2026
Privacy
What I know about you, why I have it, who else touches it, and how to make me delete it. Short, because there isn't much. This page covers all of webblabs.ai: the homepage, the free guides, and the courses.
The short version
I keep your email address and a record that you bought a course. That's the whole list. No passwords (there aren't any), no card numbers (Stripe keeps those), no tracking you around the internet. One cookie, and only so you stay signed in.
What I collect and why
| What | Why |
|---|---|
| Your email | It's your login and where the course link, receipt, and lesson updates go. |
| Your name, if you give it at checkout | So the email says hi properly. Optional. |
| Purchase record | What you bought, when, and how much. Stripe keeps the card details; I see that you paid, not your card number. |
| Sign-in links and one cookie | The link we email you works once and expires. The cookie keeps you signed in for about 90 days. It's strictly necessary; the course won't work without it. |
| Emails I send you | Receipt, your course link, lesson updates, and replies when you write to me. |
That's it. I don't buy data about you, and I don't sell yours. Ever.
Who else touches it
- Stripe runs the checkout. Your card, Apple Pay, Google Pay, Link, or Klarna details go to Stripe, not to me. Stripe's privacy policy covers what they keep.
- Cloudflare hosts the site, plays the lesson videos, and sends the transactional emails (your receipt and course link). Their servers are in the US. Like any host, Cloudflare sees your IP address when you load a page and keeps short-lived logs of it for security. I don't look at them.
- Beehiiv runs the newsletter signup box on the homepage and sends the newsletter, but only if you sign up for it there. Buying a course doesn't put you on the newsletter. When you use that box, Beehiiv sets its own cookies under its own privacy policy.
- Skool, if you join the 30-Day Challenge or the Lab. That's a separate account under Skool's privacy policy.
- Instagram and ManyChat, if you DM me a comment word. Those messages live on those platforms under their rules, not here. The first reply you get is automated.
- Higgsfield, only if you click the referral link in the Higgsfield guide. Their site then sets a cookie that tells them you came from me, which is how I'd earn a commission if you subscribe. I never see who clicked.
Nobody else. No ad networks, no tracking pixels.
Cookies
One of mine. It's the sign-in cookie for the course pages, set after you tap your email link, and it does nothing but remember that it's you. No cookie banner because there's nothing to opt out of: without it, there's no course. (The Beehiiv signup box and the Higgsfield link set their own, as above, and only when you use them.)
"Do Not Track" and similar browser signals: I don't track you across sites, so there's nothing for that signal to switch off. The site behaves the same with it on or off.
Where it lives
In the US, on Cloudflare and Stripe. If you're buying from outside the US, your email and purchase record travel here. That's the only way the course works.
If you're in the UK or the EU: I'm a US business and I hold your data because you bought something from me (a contract) and to run the site (my legitimate interest). You have every right listed below, plus the right to complain to your local data authority if I get it wrong. I'd rather you emailed me first.
How long I keep it
Your email and course access stay until you ask me to delete them. Purchase records stay as long as tax law makes me keep records of sales, even after you ask for deletion, because I'm not allowed to throw out a sales record. Sign-in links expire on their own, and the cookie clears when it expires or you sign out.
Your rights
Email [email protected] and you can:
- See it. I'll send you everything I have on you.
- Fix it. Wrong email, typo in your name, whatever. I'll change it.
- Delete it. I'll remove your account and your email from my systems and tell you when it's done. The sales record stays for tax purposes, and that's the only exception.
No forms, no "verify your identity" runaround beyond writing from the email you bought with. These rights apply to everyone, wherever you live.
Keeping it safe
There are no passwords to leak. Sign-in links work once and then they're dead, and I store them scrambled, so even a copy of my database wouldn't let someone in. Videos play through signed links that can't be forwarded. If anything ever goes wrong with your data, I'll email you and tell you plainly what happened.
Kids
The courses are for adults, or for a parent and child doing them together. I don't knowingly collect anything from anyone under 13, and I don't sell to anyone under 18 without a parent. For the kids' game course, the parent buys it and the parent's email is the only thing on file; there's no account, form, or upload for the child. If a kid has ended up in my system, email me and I'll remove them.
Changes
If this page changes in a way that matters, the date at the top changes and I'll email you about it. Small wording fixes just get the new date.
Questions, or want your data gone?
Email [email protected]. Webb Labs, operated by Kaleb Webb, Mesa, Arizona. Trouble using the site for any reason? Same address, and I'll fix it.