Privacy notice

Last updated 16 August 2026

Who we are

Lantern is a record-keeping service for UK counselling trainees, their supervisors and their placements, run by Oscar Giles in the United Kingdom. For the information described here, Lantern is the data controller. We are registered with the Information Commissioner's Office, registration number 00014826466, and our postal address is available on the ICO's public register or on request. Contact us about anything on this page at hello@my-lantern.app.

What Lantern stores

Your account details (name, email address, password held only as a secure hash, your role as trainee, supervisor or placement provider, professional body, optional member number, optional course name and qualification date); your training ledger (session dates, durations, pseudonymous client codes, modality, age group, placement name, optional therapeutic approach); supervision records, including the supervisor's name as you type it and any brief topic themes you add; the links between trainees and supervisors; supervision session proposals while they are open; submissions, sign-off attestations, amendments and countersigned circumstances notes; documents you upload to your vault; invoices supervisors create; placement organisations (their name, settings, registered email domains and member list); feedback you send us; email preferences; the secret tokens behind your calendar feed and unsubscribe links; a Stripe customer reference once card payment is enabled; and an audit trail of actions taken in the app.

If you ask your placement to confirm your client hours, we also store the contact name and email address you give us for your placement, the summary they were asked to confirm (monthly totals plus each session's date, duration and format, never client codes), the month-by-month outcome, and the name and role the confirmer types when they respond. Their confirmation becomes part of your training evidence.

We do not ask for or store special category data, and we never see or store card details: if and when card payment is enabled, it is handled entirely by Stripe.

No client-identifying data, by design

Client sessions are recorded against short pseudonymous codes. Client session records deliberately have no free-text fields, so names or identifying details of clients cannot be stored on them. Supervision entries can carry short topic themes and circumstances notes are about your own circumstances; in both places the app instructs you never to include client details. You remain responsible for choosing client codes that do not identify anyone and for keeping client details out of the few free-text fields that exist.

Why we use it, and our lawful basis

  • To provide the service (your account, ledger, compliance checks, sign-off, exports, vault, invoicing) and to take payment: performance of our contract with you.
  • Service emails (supervision invitations, submission and return notices, placement confirmation requests and responses, organisation notices, trial notices, invoices a supervisor sends you): performance of our contract. Account holders can switch every category off under Account; whatever an email would have told you still appears inside the service. Only account security emails (password reset, email change confirmation) always deliver.
  • Optional recurring emails (your monthly summary, unsigned-month reminders, a warning from the 21st of a month with client hours whose supervision minimum is not yet met, the supervisor digest): our legitimate interest in helping you keep your record current. Every one carries a one-click unsubscribe, and you can switch them off under Account.
  • Security, audit trail, backups and fraud prevention: our legitimate interest in keeping a compliance record trustworthy and available, and in some cases our legal obligation to keep information secure.
  • Anonymous visit counts and product statistics: our legitimate interest in understanding whether the service is useful. These counts contain no personal data.

Where we rely on legitimate interests you can object at any time (see Your rights). We do not use your information for advertising, and we do not sell it.

Who can see what

Your supervisor sees the months you submit to them, your compliance standing, your course name if you add one, the supervision sessions you log against your link with them (including any topic themes), and notes you ask them to countersign. Each supervisee has a record page on the supervisor's side showing the months they signed with you, with today's totals, and supervisors can download a summary of the months they have signed. They cannot browse your open client ledger. Documents in your vault are private to you and are not shared with your supervisor. Beyond the people described in this section, nobody sees your records, though as the service's operator we can access them where necessary to run, support and secure the service.

Anyone you give a signed evidence pack or signature sheet to can check it on our public verification page. That check shows the trainee's name, the month, the supervisor who signed, the date, and whether the record is unchanged. Nothing can be looked up without the 64-character fingerprint printed on the document itself, so the page tells the holder nothing they did not already have.

If you ask your placement to confirm your client hours, the person at the email address you give receives a one-time link showing your name, your placement, monthly session totals and each session's date, duration and format, so they can check the record against their own; client codes are never shared. They can confirm month by month, and any months they query are recorded as queried, never as confirmed. If a request goes unanswered we send that person one reminder after 14 days (unless they hold a Lantern account and have switched placement confirmation emails off; the request still sits in their in-app queue), and unanswered links expire after 90 days. Their typed name, role and response date are stored with your record and appear in your evidence pack. If that person holds a Lantern placement account with the same email address, the request also appears in their in-app queue, and their response is recorded against their account. Placement accounts sharing an organisational email domain can see each other's name and email address, and how many requests are waiting with each of them (a count only, not the requests themselves); accounts on personal email domains (gmail and similar) are never listed to anyone.

A placement account can also keep short roster details about each trainee who has sent it a request: cohort, course, placement start and end dates, and a brief internal note. These are the placement's own working records. They never appear on your evidence documents, they are included in your data export so you can see what is held about you, and they are deleted when either account is deleted.

Placement accounts can join together as an organisation with a shared request queue. Members of an organisation see each other's names and email addresses and, while the organisation's queue pooling is on, the requests addressed to each other (the same summaries described above) — joining makes your queue visible to the organisation, and the join screen says so. Whoever responds, the response is recorded in that individual's name. Organisation names appear only inside Lantern, never on evidence documents.

If you turn on the optional calendar feed, anyone holding that secret link can see your session dates, durations and client codes, and the supervisor name on your supervision entries. Share it only with software you trust, and regenerate it from Account if it leaks.

Who processes data for us

We use a small number of suppliers, each under a data processing agreement and each acting only on our instructions:

  • Supabase — database, sign-in and file storage. Your data is held in their London region.
  • Vercel — hosting. The application runs in their London region.
  • Resend — email delivery. Emails we send you, including their content, pass through and are retained briefly by this provider, which is based in the United States.
  • GitHub — storage of our nightly backups. Backups are encrypted before they leave our control, so the provider holds only ciphertext.
  • Stripe — card payments, once card payment is switched on. Stripe handles the payment itself and tells us only that a subscription is active and until when.

Where a supplier processes data outside the UK, that transfer is covered by the UK's approved safeguards (an International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses). We may also disclose information if the law requires it.

Cookies and local storage

Lantern uses strictly necessary cookies to keep you signed in. There are no advertising, profiling or third-party tracking cookies, which is why you never see a cookie banner. Small per-device preferences are kept in your browser's own storage and never leave your device: your chosen colour theme, view choices such as cards versus table, and dismissals of in-app notices.

Our public pages keep anonymous visit counts: which page, on which day, and the referring site, added up in aggregate. No cookie is used for this, and no IP address, device detail or identity is recorded. Visits by signed-in people are not counted at all. If you would rather your visits were not counted, add ?notrack=1to any page address once: that stores a single opt-out marker in your browser's local storage, and ?notrack=0 removes it.

Automated checks, not automated decisions

Lantern automatically evaluates each month against your professional body's published requirements and shows a verdict. This is information for you and your supervisor, not a decision about you: it produces no legal or similarly significant effect, nothing is reported to anyone, and a human supervisor decides whether to sign a month.

How long we keep it

  • Your account and records: for as long as your account exists. A training record is evidence you may need years later, so we do not delete it on a timer.
  • After you delete your account: removed or anonymised immediately, as described below.
  • Encrypted backups: kept on a rolling 30-day cycle, so deleted information can persist in backups for up to 30 days before ageing out.
  • Audit trail: the log of actions is append-only by design (so a compliance record cannot be quietly rewritten) and is retained after account deletion. By then its entries point at an internal identifier rather than a person, though a small number of entries can carry operational details such as an email address a request or invoice was addressed to. We rely on legitimate interests to keep this trail intact.
  • Anonymous visit counts: kept indefinitely. They contain no personal data.

Deleting your account

You can delete your account yourself from Account, without asking us. Where nothing else depends on your records, everything is erased outright. Otherwise your user record is anonymised: your name and email are removed, your sign-in is deleted, your vault files and personal records are deleted, and your supervision links are ended. If you have signed months as a supervisor, the attestation name you typed stays on those trainees' signed months, because it is part of their professional evidence and is covered by the record's fingerprint.

Signed records

When a supervisor signs a month it becomes immutable, and a SHA-256 fingerprint of its content is stored so tampering is detectable. Amendments to signed months are recorded separately and visibly; the original record never changes. This means a signed month cannot be edited or erased on request while the account exists, since the record's value to you depends on it being unalterable. Deleting your account still removes or anonymises it as described above.

How we protect it

Data is encrypted in transit and at rest. Direct database access is locked down so that records can only be reached through the application, which checks on every request that you are entitled to what you asked for. Downloads from the vault use short-lived private links. Backups are encrypted with a key we hold separately. Administrative accounts use two-factor authentication. If a breach ever puts your rights at risk, we will tell the ICO within 72 hours and tell you without undue delay.

Your rights

Under UK data protection law you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable form. Two of these are built in and need no request: “Download my data” in Account gives you everything we hold as JSON (plus PDF and CSV exports of your record at any time), and account deletion is a button. For anything else, email hello@my-lantern.app and we will respond within one month.

If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

Children

Lantern is for adults working towards or supervising a counselling qualification. It is not intended for anyone under 18, and we do not knowingly hold data about children.

Changes to this notice

When we change this notice we update the date at the top. If a change materially affects how we use your information, we will tell account holders in the app and by email before it takes effect; notices we are required to give you deliver regardless of your email preferences.

Contact

Questions and data requests: hello@my-lantern.app. See also the terms of service.