Consumer Health Data Privacy Policy
This policy supplements the Bodily Truth Privacy Policy and explains how consumer health data is collected, used, disclosed, retained, and protected.
Effective and last updated:
1. Scope and Meaning of Consumer Health Data
This policy applies to Bryan True, operating as Bodily Truth, and to consumer health data handled through Bodily Truth's contact, appointment, intake, return, and multi-dream services.
“Consumer health data” is used broadly. It may include information linked or reasonably linkable to a person that identifies or reveals physical or mental health status, bodily functions, symptoms, medication use or change status, health-related services sought or received, or an inference drawn from those details. Information can fall within this definition even when it is not a medical record and even though Bodily Truth provides educational, nonmedical services.
Bodily Truth is not representing that it is a HIPAA-covered health care provider. HIPAA is not the basis for this policy.
2. Categories We Collect
Depending on the requested interaction, Bodily Truth may collect:
- Identity and contact information linked to a service: name, email address, and communications.
- Appointment and service-seeking information: service type, booking status, date and time, timezone, and eligibility confirmations.
- Long-term bodily observations: self-reported tendencies involving temperature, hydration, digestion, energy, sweating, recovery, discomfort, movement, and related patterns.
- Current bodily observations: recent energy, sleep, stress response, recovery, daily functioning, bowel and urinary patterns, food response, swelling, sweating, environmental sensitivity, and subjective state.
- Diet and product-use context: diet type or changes, allergies, supplements or herbal products, medication-taking status, and whether medication use has changed. Bodily Truth forms instruct users not to provide medication names or dosages.
- Free-text context: current challenges, subjective reports, or a brief health-related contact inquiry.
- Dream information: dream narratives, approximate dates or times, and optional general physical or emotional context.
- Derived educational information: a provisional constitutional label, scores, candidate ordering, and review status produced from the long-term intake answers.
- Consent and eligibility evidence: affirmative choices, policy and presentation versions, and server-generated timestamps.
- Technical and security information: request and security signals needed to deliver, protect, and troubleshoot the relevant form or service.
Some fields are optional, and certain questions allow “prefer not to answer.” A user may include information outside the requested categories in free text. Please provide only what is relevant and do not include medication names or dosages, medical records, payment-card details, government identifiers, credentials, or emergency information.
3. Sources of Consumer Health Data
We collect consumer health data directly from you through Bodily Truth forms and communications; from Cal.com when you schedule, reschedule, or cancel an appointment; and from Stripe only to the limited extent a transaction or fulfillment status identifies purchase of a Bodily Truth service. We also derive the limited provisional intake result described above.
Technical information comes from your browser, device, network request, Cloudflare, and Turnstile when those services protect or deliver the interaction.
4. Why We Collect and Use It
We collect and use these categories only to:
- respond to a brief health-related inquiry and manage related communication;
- confirm adult and U.S. service eligibility;
- schedule, administer, prepare for, reschedule, or cancel an appointment;
- provide the requested educational appointment or multi-dream interpretation;
- compare current observations with earlier observations and maintain continuity between requested services;
- create the provisional educational intake result for practitioner review;
- maintain the client, appointment, form, dream, and practitioner-note record;
- send appointment links, receipts, and minimized administrative notifications;
- process a payment, refund, dispute, or required accounting record;
- protect the service, prevent abuse, troubleshoot failure, and respond to incidents;
- honor privacy rights, processing restrictions, appeals, and legal holds; and
- comply with law and establish, exercise, or defend legal claims.
The Worker-generated provisional result is not a medical diagnosis, current organ-state determination, treatment recommendation, or automated decision with legal or similarly significant effect. Dream interpretation is not a psychological or medical diagnosis.
5. Consent
Before a contact, intake, return, or multi-dream form can be submitted, Bodily Truth presents a separate consumer-health-data consent. The presentation identifies the applicable categories, purposes, service-provider recipient categories, and withdrawal method. The consent is separate from agreement to the Terms of Service, Disclaimer, and Refund Policy.
The system records the affirmative choice, the Consumer Health Data Privacy Policy version, the consent-presentation version, and a server-generated timestamp. If the policy or presentation version changes after a form loads, the Worker rejects the stale submission before security verification, storage, or email delivery and requires the user to review the current version.
Consent may be withdrawn for future collection or use by emailing [email protected]. Withdrawal does not invalidate processing completed before the request and is not itself a request to delete existing records. If the information is necessary to provide the service you requested, withdrawal may prevent that service from continuing.
6. Processors, Recipients, and Categories Disclosed
For transparency, the following providers may process limited categories according to their function:
| Provider or recipient | Categories and purpose |
|---|---|
| Cloudflare | Form and service-record information in Workers and encrypted D1 content; contact delivery; technical and security information through Pages, Turnstile, and protective services. |
| Cal.com | Identity, contact, service type, scheduling, timezone, booking status, and its own eligibility or policy evidence for booking and attendee notifications. |
| Stripe | Identity, payment, transaction, refund, dispute, and limited service-fulfillment context. Stripe does not receive Bodily Truth intake answers or dream narratives from Bodily Truth. |
| Resend | Name, email, appointment or submission type, administrative time or identifier, and delivery content needed for appointment links, receipts, or acknowledgements. It does not receive health answers, dream narratives, or the contact-message body. |
| Zoho Mail | The complete contact message; minimized form notifications; appointment correspondence, replies, privacy requests, and operational records. |
| Your email or calendar provider | Appointment invitation and calendar information generated through Cal.com and ordinary messages addressed to you. |
These disclosures support services you request or provider processing on Bodily Truth's behalf. Whether a particular disclosure is legally defined as “sharing” depends on the applicable law and provider role. Bodily Truth does not use these disclosures to sell consumer health data or target advertising.
Information may also be disclosed when reasonably necessary to a professional adviser under an appropriate duty, to an authority as required or permitted by law, or to a successor in a legitimate transaction that assumes the applicable obligations.
7. Categories Shared or Sold
Bodily Truth does not sell consumer health data and does not use it for targeted or behavioral advertising. It does not provide consumer health data to advertising platforms or data brokers.
Bodily Truth does not currently disclose consumer health data to an affiliate. There is no affiliate to list. The necessary provider disclosures described in Section 6 may include identity and service-seeking information, appointment information, transaction context, the complete contact message, or encrypted service records according to the recipient's limited function. No provider is represented as receiving every category.
If a future use, recipient, or category requires a separate sharing consent under applicable law, Bodily Truth will present that consent before the disclosure. The current form consent is not an authorization to sell consumer health data.
8. Practices We Do Not Use
- We do not sell consumer health data.
- We do not use it for targeted or behavioral advertising.
- We do not use client submissions to train an OpenAI or other generative-AI model.
- We do not use a health-facility geofence to identify, track, collect from, or send health-related messages to visitors.
- We do not collect medication names or dosages through the active service forms.
- We do not operate an organizer-side Google Calendar integration.
9. Storage, Access, and Security
Identified client, appointment, form, dream-order, and practitioner-note records are maintained in Cloudflare D1. Direct identity and substantive record content are encrypted at the application layer. Exact-email lookup uses a keyed pseudonymous value rather than a readable client directory. The owner-only administrative dashboard is protected by Cloudflare Access and a separate exact-owner check. Decryption of selected form or note content creates a content-free audit event.
Form requests use HTTPS, required JSON media types, body and field limits, server-side validation, exact route and origin controls, U.S. service boundaries, and form-specific Turnstile verification. Administrative email notifications omit health answers and dream narratives.
More information appears on the Privacy & Security page. No security control can guarantee complete protection.
10. Retention and Deletion
Identified client, appointment, form, dream-order, and practitioner-note records have a seven-calendar-year active retention target tied to the applicable appointment, submission, order, or record date. Scheduled deletion runs daily in bounded batches and respects active legal holds. An eligible record may remain until the next successful run.
After deletion from active D1 tables, Cloudflare D1 Time Travel may preserve recoverable database state for up to seven additional days under the current plan. Administrative form notifications have a 90-day mailbox target. Contact and ordinary reply correspondence generally have a one-year target, while privacy, incident, dispute, accounting, and legal-hold records follow their documented category-specific periods.
Cal.com, Stripe, email/calendar providers, and infrastructure services control some of their own records and recovery systems. A request will be propagated where applicable, but Bodily Truth does not promise immediate erasure from every provider backup. A legal hold or other legal duty may delay or limit deletion, and the reason will be documented.
11. Your Consumer Health Data Rights
Depending on applicable law, you may have the right to:
- confirm whether Bodily Truth collects, shares, or sells consumer health data about you;
- access, correct, or delete that data;
- withdraw consent from future collection, use, or sharing;
- receive a list of relevant recipients and a way to contact them when required;
- receive a portable copy where applicable;
- use an authorized agent where applicable;
- exercise rights without unlawful discrimination; and
- appeal a refusal to act.
Bodily Truth does not sell consumer health data, so there is no sale authorization to revoke.
12. How to Make a Request or Appeal
Email [email protected] with the right you want to exercise and the email address or service involved, or write to the postal address below. Use the same method to withdraw consent or appeal a decision, and label an appeal as “Privacy Appeal.”
We use a proportionate verification process that generally confirms control of the relevant email address and matches limited information already held. We do not require creation of a new account. If a request cannot be authenticated using commercially reasonable efforts, we may request only the additional information reasonably necessary to verify it.
We aim to respond within 45 days. When legally permitted and reasonably necessary, that period may be extended once by 45 days, with notice and an explanation during the initial period. If an appeal is denied, we will provide the applicable attorney-general complaint method when required.
13. Course Information
The public course is currently unpublished. Under its current design, browser progress and a pseudonymous completion record are not connected by Bodily Truth to a name, email, appointment, or health-form record. Visiting or completing educational material may still be treated broadly under some laws as seeking a health-related service. To the extent course information legally qualifies as consumer health data, the protections and rights in this policy apply.
14. Changes to Categories, Purposes, or Recipients
Bodily Truth will update this policy before collecting, using, or disclosing consumer health data in a materially new category or for a materially new purpose. When affirmative consent is required, it will be obtained before the new collection or disclosure. Historical policy and consent versions are preserved in a private release archive.
15. Contact Information
Send consumer-health-data questions, requests, consent withdrawals, or appeals to [email protected] or:
Bryan True, operating as Bodily Truth500 Westover Dr #37430
Sanford, NC 27330
United States