Community observations, not medical advice.Always speak with a qualified healthcare professional.

Data Protection

How we protect your health data under UK GDPR Article 9.

Summary: Health data is special category data under UK GDPR (Article 9). We only process it with your explicit consent. We use row-level security, pseudonymous identities, and aggregation thresholds. You can delete your data at any time.

Our lawful basis

We process special category health data under Article 9(2)(a) — explicit consent. You must actively opt in by checking the consent box before submitting any outcome or creating a stack. We never bundle this consent with other terms.

For standard personal data (email, display name), our lawful basis is Article 6(1)(b) — contract (providing the service you requested) and Article 6(1)(f) — legitimate interests (preventing abuse, maintaining service security).

Technical security measures

  • Row-Level Security (RLS): Database-level policies ensure users can only read/write their own data. Even if an API bug exposed a query, RLS prevents cross-user data leakage.
  • Aggregation threshold: We never display outcomes for a compound × condition pair with fewer than 3 data points. This prevents reverse-engineering individual identities from small samples.
  • Encryption in transit: All traffic uses TLS 1.3.
  • Encryption at rest: Database encrypted with AES-256.
  • No third-party trackers on any page that displays or collects health data.
  • Pseudonymous by default: Display names only. Real names are never required or displayed.
  • Session-scoped consent: Article 9 consent is re-asked each session, not stored indefinitely.

Data minimisation

We collect the minimum data needed to provide the service:

  • We DO collect: Display name, email (for login), compounds, conditions, outcomes, doses, duration, side effects
  • We DON'T collect: Real name (optional), precise location, IP addresses (not stored), browsing history, advertising identifiers

Your rights

Access

Request all data we hold about you

Rectification

Correct inaccurate data

Erasure

Delete your account and all data

Portability

Export your data in JSON

Object

Stop specific processing

Withdraw consent

Revoke consent at any time

To exercise any right, email privacy@works-for-us.app. We respond within 30 days.

DPIA (Data Protection Impact Assessment)

Because we process special category health data at scale, a DPIA is required under UK GDPR Article 35. Our DPIA documents the processing, assesses risks, and records mitigations. It is reviewed annually or whenever processing changes materially.

Status: DPIA to be completed before public launch. Current draft available on request.

Data retention

Data typeRetention period
Individual outcomes + stack dataUntil account deletion (max 30 days after request)
Account (email + display name)Until account deletion
Aggregated, de-identified dataPermanent (can no longer be linked to you)
Consent logs6 years (Article 7(1) evidence)

International transfers

Our infrastructure (Vercel + Supabase) may process data in the US. We rely on the UK-US Data Bridge (UK GDPR Art 46) for lawful transfers. All data is encrypted in transit and at rest regardless of location.