Trust
How we handle your data
Last updated: September 2026. Plain language, and every claim below matches how the site actually works — not how we'd like it to sound.
The short version
Your report text is processed for a few seconds to generate your explanation, then discarded. We never store it, so we can't sell it, leak it, or hand it over — we don't have it. That's not a policy promise; it's how the code is built.
1. Your report text: never stored
When you paste a report and run an explanation:
- The text is sent to our server only to run the explanation — the same code path every time, free or premium.
- It is never written to any database, log, or cache. Once your explanation is generated and sent back to your browser, the text is gone.
- Rate-limiting and abuse checks look at how many requests come from an address, never at what those requests contain.
This is deliberate. Storing medical text would make us a target and a liability; not storing it means there's nothing to breach.
2. Share pages: scrubbed before anything is saved
If you create a shareable page for one of your explanations, the server refuses raw report text outright. It only accepts structured, condition-level findings — the short parsed terms the app extracted (for example "disc bulge", "spinal stenosis").
- Anything that reads like sentences or pasted prose is rejected by an automated check (long phrases, sentence punctuation).
- Only four small fields per finding are kept: the term, a plain-English phrase, severity, and location — each length-capped.
- Share pages expire automatically after 90 days.
So a share page can describe what was found, but never your full report or anything that could identify you.
3. What's logged: counts, not content
To keep the service running and know whether it's working, we keep aggregate counters only:
- Counts of page views, explanations run, emails captured, checkouts started, payments completed, shares created.
- Daily rollups of those same counts — never per-person records.
- Anonymous A/B test tallies (which headline or price variant was shown, and how many checkouts each produced).
- Error reports: a short error message, the page it happened on, and a timestamp. Browser error reports never include your report text.
None of this can be traced back to your report or your identity.
4. Things you choose to give us
- Email address (optional). Only if you ask for email updates or a summary by email. Used solely to send what you asked for; every message has an unsubscribe link, and unsubscribing is permanent.
- Testimonials (optional). Only what you write into the share-your-story form, published only if you choose to share it.
- Payment details. Handled entirely by Stripe, our checkout provider. Card numbers never touch our servers — we only learn that a payment succeeded and which plan it was for.
- Push notification subscriptions (optional). Your browser's push endpoint is stored so we can send you the alerts you opted into, and deleted when you unsubscribe.
5. Third parties that touch any data
- Cloudflare — hosts the site and its storage. Sees the same network traffic any host would.
- Stripe — processes payments. Sees your payment details; we don't.
- Resend — sends the emails you asked for. Sees recipient addresses and message content you opted into.
- Cloudflare Web Analytics — the only analytics on the site, and it doesn't use cookies. No ad trackers, no social-media pixels, no cross-site profiling.
We don't sell data to anyone, because the valuable part — your report text — never exists on our side long enough to sell.
6. Security basics
- All traffic is encrypted in transit (HTTPS).
- Payment webhooks are verified by cryptographic signature; unsigned requests are rejected and counted.
- Admin and operational pages require a secret token that is never published or linked from the public site.
Questions or deletion requests
Since we don't store report text, there's usually nothing to delete — but if you gave us your email or a testimonial and want it removed, email thesaggars@gmail.com and we'll take care of it.
For the formal version, see our privacy policy.