A layered approach

Privacy & Security

Bodily Truth is designed to collect less, restrict access, and place multiple safeguards between client information and unauthorized use.

Last updated

Collect with purpose

Information is requested for a defined service, communication, consent, eligibility, payment, or recordkeeping purpose—not simply because it might be useful later.

Protect in layers

Encrypted connections, browser protections, server-side validation, access restrictions, and provider safeguards work together rather than relying on one control.

Retain deliberately

Records are assigned retention periods and deletion procedures instead of being kept indefinitely without a documented reason.

Review and improve

Security settings, access, alerts, errors, retention jobs, and vendors are subject to recurring operational review.

Data minimization comes first

Bodily Truth limits each workflow to information needed for that interaction. The contact form is used to respond to an inquiry and manage related communications. Its complete message is routed to the protected Bodily Truth mailbox and does not enter the client-form record systems. The acknowledgement service receives limited delivery details rather than the complete message.

Appointment, intake, return, and dream workflows use defined field allowlists. Information removed from an active workflow is not retained merely for compatibility. Operational notification emails are also minimized so submitted health or dream details do not need to appear in the mailbox notification itself.

Cloudflare Web Analytics is disabled, and the site is not configured with advertising pixels. Security services, embedded providers, and ordinary web infrastructure may still process limited technical information as described in the Privacy Policy and any applicable cookie notice.

Form submissions are treated as service requests, not ordinary page traffic

  • Server-verified human checks. Cloudflare Turnstile responses are verified on the server for the expected hostname and the specific form action.
  • Narrow request boundaries. Form services check the expected host, path, origin, request method, and applicable country restriction before processing a submission.
  • Bounded and validated input. Requests must use JSON, total request size is limited while streaming, and individual fields are validated before storage or delivery.
  • Neutral responses. Public errors avoid returning storage keys, provider details, submitted text, or internal configuration names.
  • No-store responses. Form API responses tell browsers and intermediary caches not to retain the response.
  • Abuse controls. Cloudflare protections, endpoint rate limiting, geographic rules, and service-level validation provide overlapping defenses.

Website and browser safeguards

Secure connections

HTTP is redirected to HTTPS. The site requires modern transport security, publishes HSTS for the main domain and subdomains, and uses DNSSEC to help protect DNS integrity.

Strict script policy

An enforced Content Security Policy restricts where scripts and embedded frames may load from. Executable inline JavaScript and HTML event-handler scripts are prohibited.

Framing protection

Pages cannot be placed inside another site’s frame, reducing clickjacking risk.

Limited browser capabilities

The site denies unused camera, microphone, geolocation, payment, and USB browser permissions.

Safer content handling

MIME-sniffing protection and a restrictive referrer policy reduce unintended interpretation or disclosure of response information.

Edge protection

Cloudflare provides managed security filtering, DDoS mitigation, encrypted delivery, and network-error visibility at the site edge.

Storage, vendors, and access

Depending on the service used, Bodily Truth relies on specialized providers for website delivery, form storage, scheduling, payment, email, operational records, and video. Current providers include Cloudflare, Boost.space, Cal.com, Stripe, Zoho, Resend, and Gumlet. Each provider has a limited role; no single provider is treated as the only security boundary.

Administrative access is limited to the owner. Two-factor authentication is enabled on documented core infrastructure and mail systems. Credentials are kept out of the public website repository, and Cloudflare access tokens are created only for a defined task with narrow permissions and then revoked when no longer needed.

Form records use defined retention deadlines. Automated expiration or scheduled deletion is used where supported, backed by review procedures and operational alerts. Confidential execution settings reduce exposure of form payloads in ordinary automation histories, and failed bundles are not intentionally retained in an incomplete-execution queue.

For details about the categories of information processed, purposes of processing, sharing, retention, and privacy rights, see the Privacy Policy.

Security is maintained as an ongoing process

The technical controls are supported by operational procedures, including:

  • recurring account, audit-log, deployment, Worker-error, certificate, DNS, and security-event reviews;
  • notifications for material Cloudflare incidents, deployment events, certificate issues, DDoS events, account insights, and credential-leak findings;
  • scheduled retention checks and record-free internal failure alerts;
  • vendor and configuration review after material changes;
  • privacy-request, deletion, incident-response, and legal-hold procedures; and
  • automated tests for form boundaries, security headers, routing, content security, storage behavior, and accidental secret exposure before deployment.

How you can reduce what you share

  • Provide only information relevant to the service or question.
  • Use the designated intake or dream form when Bodily Truth asks for service information.
  • Avoid sending medication details, extensive health histories, identification documents, passwords, or payment-card information by ordinary email.
  • Use Stripe’s hosted payment page for payment information; do not place card details in a Bodily Truth form or email.
  • For a privacy request, contact [email protected].

Report a security concern

If you believe you have found a vulnerability affecting Bodily Truth, email [email protected]. The standardized reporting details are also published in security.txt.

Please describe the affected address, the behavior observed, and a safe way to reproduce it. Do not include another person’s information, access data beyond what is necessary to demonstrate the issue, disrupt the service, or use a security report for ordinary client or privacy correspondence.