Privacy and Consumer Health Data Policy
How Theraphea collects, uses, stores, protects, shares, and deletes ordinary data and sensitive psychometric test information.
Consumer Health Data Privacy PolicyThis document serves as both the general Privacy Policy and the consumer health data notice. Theraphea does not sell data or send test answers, scores, or result links to advertising platforms.
Controller and scope
MIRACLE CO., registration number 7268792, 100 Elgar Pl Ste 17F, Bronx, NY 10475, USA is the controller of data for theraphea.com unless a feature expressly identifies another controller.
This Policy applies to the site, psychometric tests, results, accounts, contact forms, articles, and related administrative operations. It does not govern independent third-party sites.
Data we receive
- Test data: selected test, answers, sex where required by scoring, start and completion times, calculated scores, levels, subscales, crisis indicators, and result.
- Consent evidence: notice version, time, 18+ confirmation, purpose, method, locale, and attempt or result identifier.
- Account and profile: email, name, telephone, city, year of birth, biography, avatar, and sign-in data within enabled features.
- Technical data: infrastructure and rate limiting process IP addresses during a request; we may receive browser, device, locale, path, referrer without query/hash, security logs, random identifiers, and pseudonymous hashes.
- Requests and support: selected contact method, message, result UUID, and form choices.
- Browser settings: locale, theme, interface state, unfinished test, submission outbox, and temporary local result.
- Article analytics after opt-in: translation ID, article path, minimised referrer, date, bot signal, and an HMAC hash of a random viewer ID/user agent.
- Administrative events: result access, grants and revocations, privacy requests, incident handling, and staff actions.
Sources
The main source is you: answers, profile, forms, settings, and actions. Technical data comes from the browser, Vercel, Supabase, and an enabled sign-in provider. A person holding a unique link may initiate an access event for the permitted part of a result.
We do not connect an electronic health record, insurer, pharmacy profile, wearable, or another independent medical source without separate notice and legal review.
Purposes and legal bases
Where the GDPR or UK GDPR applies, explicit consent under Article 9(2)(a) is the additional condition for sensitive data; performance of a contract alone does not authorise special-category processing.
- Provide the requested self-assessment and score, store, and display the result: performance of your request or contract for ordinary data and explicit consent for sensitive mental-health information.
- Create an account and provide sign-in, recovery, and profile management: performance of your request or contract.
- Protect the service, prevent abuse, investigate errors, and retain necessary audit records: legitimate interests and/or legal obligation, subject to data minimisation.
- Respond to contact or privacy requests: your request, pre-contractual steps, consent, legitimate interests, or legal obligation depending on the circumstances.
- Count views of public articles: separate optional analytics consent.
- Comply with law and court orders and protect rights: legal obligation and legitimate interests.
Consumer health data
Consumer health data includes answers, scores, severity levels, crisis indicators, inferences, and technical identifiers that may reveal an interest in or condition of mental health.
We collect it directly from you for the specific purposes of conducting the selected test, calculating, storing, and showing the result, managing access, and maintaining security. Before collection, the categories, purpose, main recipient categories, and withdrawal method are presented.
Recipient categories are Vercel and Supabase as infrastructure, authorised personnel or contractors on a need-to-know basis, and a person to whom you deliberately grant a valid link with selected permissions. Optional sharing, a new purpose, an AI provider, research, or advertising would require a separate basis and consent where required.
We do not sell consumer health data or share it for cross-context behavioural advertising. Google Ads, GTM, and advertising pixels are not loaded.
Automated scoring
A result is calculated automatically under the versioned test definition and scoring rules. This is profiling for informational self-assessment, not a decision about treatment, insurance, employment, credit, access to a service, or another legal or similarly significant decision.
A result may be wrong because of the limits of the instrument, context, submitted answers, or software error. You may ask for an explanation, correction of a technical error, or deletion.
Data stored in the browser
Unfinished answers are stored in this origin’s localStorage until completion, restart, or browser-data deletion. The submission outbox and temporary result have a TTL of up to 24 hours and are removed at the next expiry check.
The application does not encrypt localStorage, and any script able to execute on theraphea.com can access it. Do not take a test on a shared or public device; clear site data after use.
Retention
Where no exact period is stated, we consider the purpose, sensitivity, risk, account activity, ability to aggregate, mandatory periods, and defence of claims. Data is deleted, de-identified, or isolated when the purpose ends.
- New server_v1 results are generally retained for no more than 365 days unless you delete them sooner or law requires longer retention. Legacy records may temporarily remain on an earlier schedule pending migration.
- Unfinished tests remain until completion, restart, or browser clearing; the outbox and local result remain for up to 24 hours with lazy expiry.
- Accounts and profiles remain while active and for a limited deletion, abuse-prevention, and legal-compliance period afterwards.
- Consent, privacy requests, grants, and security audit records remain as reasonably necessary to prove choices, maintain security, resolve disputes, and meet recordkeeping duties.
- Messages remain until a request is completed and for a limited period afterwards for quality, legal defence, and compliance.
- Article analytics remain until the operational or legal need ends; the viewer cookie lasts up to 180 days after consent and is deleted on opt-out.
- Vendor backups and logs are deleted under their cycles, contractual commitments, and applicable law.
Recipients and vendors
We require processors to maintain confidentiality, purpose limitation, security, rights assistance, and deletion to the extent required by contract and law. You may request the current subprocessor list by email.
- Vercel: hosting, CDN, server functions, and technical logs; the result-storage function is configured for the dub1 region in Dublin.
- Supabase: database, authentication, RPC, and profile/result storage; the production region and backup/log retention must match the live project configuration.
- Enabled OAuth or OTP providers: only if you choose the corresponding sign-in method.
- OpenAI: embeddings of editorial blog material; test answers and results are not sent.
- Professional advisers, auditors, security providers, and public authorities where necessary under contract or law.
Analytics, cookies, and advertising
Necessary and user-requested functional technologies operate without optional opt-in. Internal article analytics and TGTrack on advertising landing pages run only after consent in Cookie Settings.
Analytics does not run on answers and does not receive scores, severity, result UUID/URL, email, or account ID. TGTrack is used on advertising landing pages only to identify the source of a visit to Telegram and is not loaded on sensitive routes.
Google Ads, Google Tag Manager, remarketing, enhanced conversions, Customer Match, and advertising pixels are disabled in the current application. Any future change would require an updated policy, consent flow, and technical review before loading on sensitive routes.
International processing
The controller is in the United States, and vendors may process data in the United States, EEA, United Kingdom, and other countries. Protection may differ from that in your country.
Where required, we use contractual and organisational safeguards such as Standard Contractual Clauses, the UK Addendum, transfer assessments, and access restrictions. General consent is not used as a permanent substitute for required transfer safeguards.
The precise flow depends on the live Supabase region, logs, subprocessors, and enabled authentication features and must be confirmed before targeting a particular jurisdiction.
Security
No system can promise absolute security. For an incident, we will contain, investigate, and notify vendors, regulators, and affected people within time limits imposed by applicable law.
- HTTPS in transit, server boundaries, strict attempt validation, and size limits.
- Raw results are not directly readable by public database roles; reads pass through server-side checks.
- Owner and share secrets are stored as cryptographic hashes, and grants can be limited and revoked.
- Rate limiting processes an IP address during the request and stores an HMAC scope rather than the raw address; buckets expire.
- Access and administrative actions are logged, and personnel receive least-privilege access.
Your rights and requests
Send a request to info@deeppsysolutions.com. To protect a result, we may verify an account or owner session, control of an email address, or another valid access right. Do not send a password or full secret in an open email.
We respond within the period set by applicable law; US state-law requests are generally answered within 45 days, subject to a permitted extension. If we refuse, we explain why and the available appeal route.
Withdrawal does not make earlier processing unlawful. We stop future processing based on that consent and delete or isolate the data unless another mandatory basis applies.
- Ask whether we process your data and obtain access or a copy.
- Correct inaccurate data and complete incomplete data.
- Delete data, withdraw consent, and stop future consent-based processing.
- Restrict processing, object, request portability, and appeal a refusal where applicable.
- Opt out of sale or targeted advertising and use Global Privacy Control. We state that we do not sell data or use it for such advertising.
- Complain to a supervisory authority where you live or work or where an alleged violation occurred.
Additional US state rights
Residents of Washington, Nevada, Connecticut, and other states with consumer health privacy laws receive the more specific definitions and rights where those laws apply.
Before collection, we disclose the categories, purpose, recipient categories, and withdrawal method. Optional sharing requires separate consent. You may request access, withdraw consent, and request deletion, including processor instructions where required.
We do not discriminate against a person for exercising a right in good faith. Mandatory exceptions for security, a requested service, legal defence, and compliance remain available.
EEA and United Kingdom
Where the GDPR or UK GDPR applies, MIRACLE CO. acts as controller. The legal bases and special-category condition appear above. You also have rights to complain, portability, restriction, and withdrawal.
Theraphea does not use a result for a legal or similarly significant decision. If such a function were introduced, it would require a separate assessment, information about logic, human review, and a challenge route.
An EEA or UK representative and DPO are not identified in this Policy. If targeted offering or the scale and nature of processing creates an appointment duty, it must be completed before that launch; policy wording cannot replace the appointment.
Russian-language access
The Russian translation is provided for convenience. It does not mean that foreign infrastructure automatically satisfies Russian requirements for initial recording of Russian citizens’ personal data in Russia or written consent for health data.
The current checkbox records an explicit electronic action but is not represented as an electronic signature where written consent is legally required. Policy language cannot cure that requirement.
Targeted launch for Russian citizens requires separate confirmation of localisation, notifications, cross-border transfer, and an appropriate e-signature or OTP process.
Children
The service is intended for people aged 18 or older. We do not knowingly collect children’s data. If we learn that a minor submitted data contrary to this rule, we will take reasonable steps to stop processing and delete it.
Opening the service to minors would require age assurance, parental consent, safeguarding, retention controls, and a child-specific risk assessment before launch.
Changes and contact
We update the version and date when purposes, categories, vendors, or rights materially change. A new optional purpose is not applied to previously collected sensitive data without any required new consent.
Controller: MIRACLE CO., registration number 7268792, 100 Elgar Pl Ste 17F, Bronx, NY 10475, USA. Privacy and consumer health data requests: info@deeppsysolutions.com.