← Back to Assessment
Privacy Policy
Last Updated: March 6, 2026
Privacy-First Approach: Assessment responses are transmitted securely to our
server-side scoring engine, processed, and returned as your personalized results. No scoring
algorithms are stored in your browser. We only collect your email and assessment responses when
you voluntarily submit them to receive your personalized report.
1. Information We Collect
When You Complete the Assessment:
- Email Address: To send your stress profile and 7-day intervention sequence
- Assessment Responses: Your answers to stress-related questions
- Calculated Results: Stress scores, multiplier, top patterns, and recommended protocols
- Assessment Date: When you completed the assessment
- Device Information: Browser type and operating system (for compatibility purposes)
Automatically Collected:
- Browser Session Data: Stored locally in your browser to preserve progress
- Analytics: Anonymous usage statistics (pages viewed, time spent, completion rate)
2. How We Use Your Information
We use your data solely for the following purposes:
- Personalized Results: Generate your stress profile and protocol recommendations
- Email Communication: Send your assessment PDF and 7-day stress relief email sequence
via MailerLite
- Improvement: Analyze anonymous aggregated data to improve assessment quality
- Programme Updates: Share information about relevant workshops, retreats, and programmes
that may address your assessment results
We will NEVER:
- Sell your data to third parties
- Share your individual stress assessment with anyone without explicit consent
- Use your responses for purposes beyond improving this tool
- Send spam or unrelated marketing emails
3. Data Storage and Security
Where Your Data Lives:
- Supabase (PostgreSQL): Secure cloud database hosted in AWS (encrypted at rest and in
transit)
- MailerLite: Email marketing platform (GDPR-compliant, used for sending emails only)
- Your Browser: Session storage for preserving progress during assessment (automatically
cleared when you close the tab)
Security Measures:
- End-to-end HTTPS encryption for all data transmission
- Row-level security policies in database (access controls)
- Regular security audits and updates
- No storing of sensitive health data beyond self-reported stress levels
4. Third-Party Services
We use the following trusted services:
MailerLite (Email Delivery):
Supabase (Data Storage):
- Open-source backend infrastructure
- AWS-hosted PostgreSQL database
- Privacy Policy: supabase.com/privacy
Analytics (Optional Usage Tracking):
- Privacy-friendly analytics (no cookies, no personal data)
- Tracks page views and performance metrics only
5. Your Rights (GDPR & CCPA Compliance)
You have the following rights regarding your data:
- Access: Request a copy of all data we have about you
- Correction: Update inaccurate information
- Deletion: Request complete removal of your data ("Right to be Forgotten")
- Portability: Receive your data in a machine-readable format (JSON)
- Opt-Out: Unsubscribe from emails at any time (link in every email)
- Objection: Object to specific data processing activities
To Exercise Your Rights:
Email us at: xavier@inflowmotions.com
We will respond within 30 days.
6. Data Retention
- Assessment Data: Retained for 3 years from your last interaction, then deleted
automatically. You may request earlier deletion at any time.
- Email Lists: Until you unsubscribe (automatic removal from MailerLite)
- Session Data: Cleared when you close your browser tab
- Analytics: Anonymous data aggregated and retained for 12 months
7. Children's Privacy
This assessment is not intended for individuals under 18 years old. We do not knowingly collect data from
minors. If you believe we have inadvertently collected information from a minor, please contact us
immediately.
8. International Data Transfers
Your data may be processed in:
- European Union: Supabase servers (GDPR-compliant)
- United States: MailerLite servers
All transfers comply with GDPR Standard Contractual Clauses.
9. Cookies and Tracking
We use minimal tracking:
- Session Storage: Temporary browser storage (no cookies)
- Analytics Cookies: Optional, privacy-friendly analytics (no personal identifiers)
We do NOT use:
- Advertising cookies
- Third-party tracking pixels
- Social media trackers
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify
you by:
- Updating the "Last Updated" date at the top of this page
- Sending an email notification for significant changes (if you're subscribed)
Continued use of the tool after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy questions, data requests, or concerns:
12. Legal Basis for Processing (GDPR)
We process your data based on:
- Consent: You voluntarily submit your email to receive results
- Legitimate Interest: Improving the tool and providing personalized interventions
- Contractual Necessity: Delivering the service you requested (assessment results)
You may withdraw consent at any time by emailing us or unsubscribing from emails.
© 2026 Stress Assessment Tool. All rights reserved.
Terms of Service | Privacy Policy | Take Assessment