Privacy
Your data
The free Diagnostic runs in your browser. Core adds an encrypted server-side profile when you subscribe.
Free Diagnostic (no account)
When you complete the Diagnostic, your answers and computed results are saved in localStorage on this device under keys prefixed with iamunbreakable-diagnostic-. They persist between sessions on the same browser until you clear site data or use a private window. We do not receive Diagnostic answers unless you choose to import them at Core signup.
Core subscription
Core uses passwordless email sign-in and stores your profile on our API (Render) in Neon Postgres (EU region). Profile data is encrypted at application level for special-category health fields. Core protocols are served from the API only — they are not bundled in the public site.
- Processors: Render (API hosting), Neon (database), Stripe (payments), Resend (magic-link email)
- Health data: explicit consent required before health special-category fields are written; DPIA completed before live health data flows
- Your rights (UK GDPR): export your profile JSON via
GET /api/profile/exportwhen signed in; delete your account viaDELETE /api/profile(cancels subscription and erases your row)
What is not collected
- No analytics or engagement telemetry in v1
- No third-party trackers in the Diagnostic flow
- No passwords — magic-link only
Fonts
Typography is bundled with the site (Fraunces, Schibsted Grotesk, IBM Plex Mono). No separate font request goes to a third party when you load pages.