Legal

Privacy Policy

Last updated

We built Inner Child Coach with your privacy at its core. This policy explains plainly what we collect, why, and how it is protected — so you can reflect with full confidence that your answers stay yours.

1. Overview

Inner Child Coach (innerchild.coach, "we", "us") is a self-reflection tool grounded in Schema Therapy, CBT, and EFT. We are not a healthcare provider and the quiz does not constitute medical advice, diagnosis, or treatment.

We respect your privacy. We do not sell, rent, or share your personal data with third parties for marketing purposes, and we never will.

2. What we collect

a. Quiz responses

When you complete the quiz your answers (numerical Likert ratings, one per question) and computed belief scores are stored in our database alongside a randomly generated session ID. This session ID is created fresh in your browser each time you start the quiz and is not linked to your name, email address, or any other identifying information.

b. Optional reflection text

The results screen may invite you to write a short personal reflection. Any text you choose to submit is stored with your quiz result under the same anonymous session ID. You are never required to submit this text.

c. Technical information

Our hosting infrastructure may automatically log standard server data such as your IP address, browser type, and page requests for security and performance monitoring. These logs are retained for a maximum of 30 days and are not linked to quiz results.

d. Cookies & local storage

We do not use advertising or tracking cookies. We may store a lightweight session token in your browser's sessionStorage solely to prevent duplicate submissions during a single visit. This is cleared when you close your browser tab.

3. How we use your data

  • To return your personalised results immediately after quiz completion.
  • To de-duplicate submissions within a single session.
  • To generate aggregate, fully anonymised statistics that help us improve the quiz (for example, understanding which questions are unclear).

We do not use your responses to profile, target, or identify you.

4. Data storage & security

Quiz results are stored in a Supabase-managed PostgreSQL database hosted on AWS infrastructure in the EU (eu-west-1) region. Access is restricted via Row Level Security (RLS) policies — only the insert operation is permitted from public clients, and only when a valid session ID is present.

All data is transmitted over TLS 1.2+. Database backups are encrypted at rest. No employee has routine access to individual quiz results.

5. Data retention

Anonymous quiz results are retained for up to 24 months to support longitudinal aggregate research. After this period results are permanently deleted. Because results are not linked to any personal identifier, we are unable to locate or delete a specific individual's submission on request — there is simply nothing to look up. If you prefer no record to persist, please do not submit the quiz.

6. Third-party services

We use a small number of carefully chosen infrastructure providers:

  • Supabase — database hosting and API. Data is processed under Supabase's DPA in compliance with GDPR.
  • Google Fonts — font files are loaded from Google's CDN. Google may log the request; no quiz data is shared. You can review Google's privacy policy.

We do not use Google Analytics, Meta Pixel, or any other behavioural tracking tools.

7. Children's privacy

This service is intended for adults (18+). We do not knowingly collect data from children. If you believe a child has submitted data, please contact us and we will take appropriate steps.

8. Your rights

Depending on your jurisdiction you may have rights including access, rectification, erasure, restriction, portability, and objection. Because our data is fully anonymous and not linked to any personal identifier, these rights cannot practically be exercised on quiz results. For any other data concerns, contact us at the address below and we will respond within 30 days.

9. Changes to this policy

We may update this policy from time to time. Material changes will be noted at the top of this page with a revised date. Continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact

For any questions about this policy or our data practices, please write to us at privacy@innerchild.coach.