Privacy

Your data

The free Diagnostic runs in your browser. Core adds an encrypted server-side profile when you subscribe.

Free Diagnostic (no account)

When you complete the Diagnostic, your answers and computed results are saved in localStorage on this device under keys prefixed with iamunbreakable-diagnostic-. They persist between sessions on the same browser until you clear site data or use a private window. We do not receive Diagnostic answers unless you choose to import them at Core signup.

Core subscription

Core uses passwordless email sign-in and stores your profile on our API (Render) in Neon Postgres (EU region). Profile data is encrypted at application level for special-category health fields. Core protocols are served from the API only — they are not bundled in the public site.

  • Processors: Render (API hosting), Neon (database), Stripe (payments), Resend (magic-link email)
  • Health data: explicit consent required before health special-category fields are written; DPIA completed before live health data flows
  • Your rights (UK GDPR): export your profile JSON via GET /api/profile/export when signed in; delete your account via DELETE /api/profile (cancels subscription and erases your row)

What is not collected

  • No analytics or engagement telemetry in v1
  • No third-party trackers in the Diagnostic flow
  • No passwords — magic-link only

Fonts

Typography is bundled with the site (Fraunces, Schibsted Grotesk, IBM Plex Mono). No separate font request goes to a third party when you load pages.