Privacy
What we hold, and what stops anyone else holding it
Health-adjacent information deserves a plainer answer than a privacy policy usually gives.
What we collect
The account details you give us, the bookings you make, the messages you send through the platform, and the technical records a web service needs to run. No advertising trackers, and nothing sold to anybody.
Who can see it
The practitioner you book, and the staff who need it to run the service. One practitioner cannot reach another practitioner’s records: the database enforces that boundary itself rather than trusting the application to remember it.
How it is protected
Encrypted in transit everywhere. Session notes, identity documents and bank details are encrypted at rest with keys held outside the code. Passwords are hashed, never stored or logged in a readable form, and never returned by the API.
Payment details
Card and bank details are held by Stripe. Wellbeing4me™ never receives them, so they cannot leak from us.
How long we keep it
Chat messages are destroyed 30 days after they are sent. Anything you created is soft-deleted rather than erased on request, so statutory retention duties for health-adjacent records can be honoured, and then removed at the end of that period.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to us and we will tell you what we hold, what we must keep, and for how long.
See also our terms. To ask for a copy of your data or its deletion: hello@wellbeing4me.com.