A layered approach

Privacy & Security

Bodily Truth limits collection, restricts access, and maintains layered safeguards appropriate to the information it handles.

Last updated

Collect with purpose

Information is requested for a defined service, communication, consent, eligibility, payment, or recordkeeping purpose—not simply because it might be useful later.

Protect in layers

Technical, administrative, and provider safeguards operate together to reduce unauthorized access, use, or disclosure.

Retain deliberately

Records are assigned retention periods and deletion procedures instead of being kept indefinitely without a documented reason.

Review and improve

Security, access, retention, incidents, and service providers are subject to recurring review.

Data minimization comes first

Bodily Truth limits collection and use to information reasonably necessary for the applicable service, communication, transaction, security, legal, or recordkeeping purpose.

Service communications and administrative records are limited where practicable so sensitive form content is not duplicated unnecessarily.

The Bodily Truth website is not configured to use optional site analytics, advertising pixels, or behavioral advertising. Necessary technical information may be processed as described in the Privacy Policy and Cookie and Similar Technologies Notice.

Protected form processing

  • Submission verification. Protected forms use server-side verification and abuse controls before accepting information.
  • Input limits. Form submissions are subject to content, size, and format validation.
  • Request restrictions. Submission services accept only authorized requests within the applicable service and geographic boundaries.
  • Limited responses. Public error messages and responses are designed to avoid unnecessary disclosure of submitted or internal information.
  • Cache restrictions. Form responses are designated against storage by browsers and intermediary caches.

Website and browser safeguards

Secure connections

The website uses encrypted connections and measures intended to protect transport and domain integrity.

Restricted resource loading

Browser policies restrict the sources from which scripts, frames, styles, fonts, and other resources may load.

Framing protection

Pages cannot be placed inside another site’s frame, reducing clickjacking risk.

Limited browser capabilities

Unused browser capabilities are restricted.

Safer content handling

Browser response and referral controls reduce unintended interpretation or disclosure of information.

Edge protection

Managed filtering, denial-of-service mitigation, encrypted delivery, and diagnostic controls protect the website boundary.

Storage, vendors, and access

Bodily Truth uses specialized providers for website delivery, storage, scheduling, payment, communications, and related service functions. Provider access is limited to the applicable function and is not treated as the sole security boundary.

Administrative access is limited to authorized persons. Account authentication, credential controls, and access review protect administrative systems.

Identified client, appointment, form, dream, and practitioner-note information is protected during transmission and storage. Access to sensitive content is restricted and subject to accountability controls.

Records are assigned retention periods, and deletion may be suspended when a legal hold or other lawful exception applies.

For the categories, purposes, recipients, retention, consent, and rights that apply to health-related information, see the Consumer Health Data Privacy Policy. The Privacy Policy covers the broader personal-information practices.

Security is maintained as an ongoing process

The technical controls are supported by operational procedures, including:

  • recurring account, access, deployment, certificate, domain, and security-event reviews;
  • notification and escalation procedures for material operational or security events;
  • scheduled retention checks and internal failure alerts;
  • service-provider and configuration review after material changes;
  • privacy-request, deletion, incident-response, and legal-hold procedures; and
  • testing for access boundaries, website security, storage behavior, and accidental secret exposure.

How you can reduce what you share

  • Provide only information relevant to the service or question.
  • Use the designated intake or dream form when Bodily Truth asks for service information.
  • Avoid sending medication details, extensive health histories, identification documents, passwords, or payment-card information by ordinary email.
  • Use the designated payment service for payment information; do not place card details in a Bodily Truth form or email.
  • For a privacy request, contact [email protected].

Report a security concern

If you believe you have found a vulnerability affecting Bodily Truth, email [email protected]. The standardized reporting details are also published in security.txt.

A report should identify the affected address, observed behavior, and a safe reproduction method. A reporter must not include another person's information, access data beyond what is necessary to demonstrate the issue, disrupt the service, or use the reporting channel for ordinary client or privacy correspondence.