Privacy Policy
What we collect, why we hold it, and the rights you have over it.
Version 2026-07-pre-launch
Placeholder text, not yet reviewed
This document is scaffolding. It has not been drafted or reviewed by counsel and it does not state the actual terms of the CORE7 Index. Do not rely on it. The headings below mark the sections the finished document needs to cover.
What we collect
To draft: Account details, scan responses, report output, payment records held by our payment processor, and technical logs. Call out that scan responses are personal and health-adjacent, since the instrument includes retirement-health and mental-health items, and that this raises the sensitivity of the whole record.
Why we hold it
To draft: Producing your report, giving you access to your history and retest comparison, supporting the coaching relationship you have opted into, taking payment, and keeping the service running and secure.
Who can see your responses
To draft: Access is scoped by role. Set out what you see, what a CORE7 Trusted Guide sees and only after you are rostered to them, and what a group administrator sees. Group reporting is aggregate only and is fully suppressed below a threshold of ten participants, so no individual is identifiable from it.
Service providers
To draft: Confirm the list below is complete at the time of drafting, and state that we do not sell personal information.
- Vercel: application hosting
- Supabase: database and storage
- Clerk: accounts and authentication
- Stripe: payments and practitioner payouts
- Resend: transactional email
- Sentry: error monitoring
How long we keep it
To draft: The proposed starting point, which needs sign-off before it is published: individual responses and reports are retained while the account or coaching relationship is active; data from an account inactive for 36 months is anonymized or purged; anonymized data may be kept for aggregate reporting and instrument validation; backups roll off on a 30 to 90 day cycle.
Your rights over your data
To draft: Access, export, correction and deletion, plus the rights that apply under state privacy law and the GDPR where relevant. This section must describe a working mechanism rather than an invitation to email us, and it needs to name the response window we commit to.
Cookies and analytics
To draft: What is set and by whom. Today that is the session cookie our identity provider needs and the error monitoring described above. If any non-essential analytics is added, this section and a consent mechanism have to land with it.
How we protect it
To draft: Encryption in transit and at rest, role-scoped database access enforced at the row level, and how we handle a breach.
Children
To draft: The Youth vertical means minors may hold records. State the parental consent position and align it with the eligibility section of the Terms of Use.
Contact
To draft: Who to write to about privacy, and how to escalate.
You can exercise these rights yourself. From Data and privacy in your account you can download a full copy of your data or permanently delete your account.

