01
Data minimization comes first
Bodily Truth limits collection and use to information reasonably necessary for the applicable service, communication, transaction, security, legal, or recordkeeping purpose.
Service communications and administrative records are limited where practicable so sensitive form content is not duplicated unnecessarily.
The Bodily Truth website is not configured to use optional site analytics, advertising pixels, or behavioral advertising. Necessary technical information may be processed as described in the Privacy Policy and Cookie and Similar Technologies Notice.
02
Protected form processing
Protected forms use verification, abuse-prevention, validation, access limitations, response controls, and measures intended to reduce unintended storage or disclosure.
03
Website and browser safeguards
Secure connections
The website uses encrypted connections and measures intended to protect delivery and domain integrity.
Browser safeguards
Browser protections limit resource loading, framing, unnecessary capabilities, and unintended information disclosure.
Website boundary
Filtering, abuse mitigation, delivery, and diagnostic safeguards help protect the website and its services.
04
Storage, vendors, and access
Bodily Truth uses specialized providers for website delivery, storage, scheduling, payment, communications, and related service functions. Provider access is limited to the applicable function and is not treated as the sole security boundary.
Administrative access is limited to authorized persons. Account authentication, credential controls, and access review protect administrative systems.
Identified client, appointment, form, dream, and practitioner-note information is protected during transmission and storage. Access to sensitive content is restricted and subject to accountability controls.
Records are assigned retention periods, and deletion may be suspended when a legal hold or other lawful exception applies.
For the categories, purposes, recipients, retention, consent, and rights that apply to health-related information, see the Consumer Health Data Privacy Policy. The Privacy Policy covers the broader personal-information practices.
05
Security is maintained as an ongoing process
Technical safeguards are supported by procedures for access review, security events, retention, service-provider changes, privacy requests, incident response, and testing.
06
How you can reduce what you share
- Provide only information relevant to the service or question.
- Use the designated intake or dream form when Bodily Truth asks for service information.
- Avoid sending medication details, extensive health histories, identification documents, passwords, or payment-card information by ordinary email.
- Use the designated payment service for payment information; do not place card details in a Bodily Truth form or email.
- For a privacy request, contact privacy@bodilytruth.com.
07
Report a security concern
If you believe you have found a vulnerability affecting Bodily Truth, email security@bodilytruth.com. The standardized reporting details are also published in security.txt.
A report should identify the affected address, observed behavior, and a safe reproduction method. A reporter must not include another person's information, access data beyond what is necessary to demonstrate the issue, disrupt the service, or use the reporting channel for ordinary client or privacy correspondence.