CORE7 Index
All legal documents

Privacy Policy

What we collect, why we hold it, and the rights you have over it.

Version 2026-07-pre-launch

Placeholder text, not yet reviewed

This document is scaffolding. It has not been drafted or reviewed by counsel and it does not state the actual terms of the CORE7 Index. Do not rely on it. The headings below mark the sections the finished document needs to cover.

What we collect

To draft: Account details, scan responses, report output, payment records held by our payment processor, and technical logs. Call out that scan responses are personal and health-adjacent, since the instrument includes retirement-health and mental-health items, and that this raises the sensitivity of the whole record.

Why we hold it

To draft: Producing your report, giving you access to your history and retest comparison, supporting the coaching relationship you have opted into, taking payment, and keeping the service running and secure.

Who can see your responses

To draft: Access is scoped by role. Set out what you see, what a CORE7 Trusted Guide sees and only after you are rostered to them, and what a group administrator sees. Group reporting is aggregate only and is fully suppressed below a threshold of ten participants, so no individual is identifiable from it.

Service providers

To draft: Confirm the list below is complete at the time of drafting, and state that we do not sell personal information.

  • Vercel: application hosting
  • Supabase: database and storage
  • Clerk: accounts and authentication
  • Stripe: payments and practitioner payouts
  • Resend: transactional email
  • Sentry: error monitoring

How long we keep it

To draft: The proposed starting point, which needs sign-off before it is published: individual responses and reports are retained while the account or coaching relationship is active; data from an account inactive for 36 months is anonymized or purged; anonymized data may be kept for aggregate reporting and instrument validation; backups roll off on a 30 to 90 day cycle.

Your rights over your data

To draft: Access, export, correction and deletion, plus the rights that apply under state privacy law and the GDPR where relevant. This section must describe a working mechanism rather than an invitation to email us, and it needs to name the response window we commit to.

Cookies and analytics

To draft: What is set and by whom. Today that is the session cookie our identity provider needs and the error monitoring described above. If any non-essential analytics is added, this section and a consent mechanism have to land with it.

How we protect it

To draft: Encryption in transit and at rest, role-scoped database access enforced at the row level, and how we handle a breach.

Children

To draft: The Youth vertical means minors may hold records. State the parental consent position and align it with the eligibility section of the Terms of Use.

Contact

To draft: Who to write to about privacy, and how to escalate.

You can exercise these rights yourself. From Data and privacy in your account you can download a full copy of your data or permanently delete your account.