PNEUMANOS

Legal

Privacy Policy

Last updated: August 19, 2026

People bring Pneumanos things they have told nobody else. That imposes an obligation, and this page sets out how it is met — what is collected, what is encrypted, who can see it, how long it is kept, and how to get it all back or have it destroyed.

The short version

1. Who is responsible

Pneumanos, an independent spiritual discernment and consulting practice operating at pneumanos.com, is the data controller for the information described here. Contact: hello@pneumanos.com.

Pneumanos is not a healthcare provider and is not affiliated with any religious organisation. Your information is therefore not held under healthcare privacy regimes such as HIPAA, and it is never shared with any church, denomination, or spiritual body — there is none to share it with. See the Scope of Practice.

2. What we collect

Information you give us

Some of this — religious or spiritual affiliation in particular — is a special category of personal data under laws such as the GDPR. It is collected only because you chose to enter it, only for the purpose of the conversations you book, and it can be removed at any moment by clearing the field on your profile.

Information collected automatically

Information we deliberately do not collect

3. Encryption of what you write

Your description of what you want to bring to a session — and any phone number attached to it — is encrypted before it is written to the database, using authenticated symmetric encryption (Fernet: AES-128-CBC with HMAC-SHA256). Anyone who obtained a copy of the database, a backup, or a stray dump would find ciphertext where those fields should be.

It is decrypted in exactly three places: when it is shown back to you, when the practitioner reads it to prepare for your session, and when you request a copy of your own data. Traffic between your browser and this site is protected in transit by TLS.

4. Why we hold it, and on what legal basis

What Why Basis (GDPR)
Email address Sign-in; sending confirmations and reminders Performance of a contract
Profile, including traditions So sessions begin from who you are Explicit consent (Art. 9(2)(a))
Session descriptions Preparing for and delivering the session Performance of a contract
Payment records Taking payment; accounting and tax Contract; legal obligation
Sign-in records Account security; showing you your own sessions Legitimate interests
Referral host Knowing how people find the practice Legitimate interests

5. Who can see your information

The practitioner. Your profile, your bookings, and what you wrote about them. Nobody else at Pneumanos, because there is nobody else.

Other members: never. There are no public profiles, no directories, no reviews, and no way for one member to discover another. Nothing you enter here is published anywhere.

A small number of service providers, each of which sees only what it needs to do its job and none of which may use it for their own purposes:

We never sell your information, share it for anyone's advertising, or use it to train machine-learning systems. We may disclose it where the law compels us — see the next section.

6. The limits of confidentiality

Confidentiality here is a professional commitment. Because Pneumanos is not a licensed healthcare provider, it is not legal privilege, and it cannot be absolute. Information may be disclosed where:

Where disclosure is required, we disclose the minimum necessary and, where we are permitted to do so, tell you first.

7. How long we keep it

When you close your account, everything above is deleted or irreversibly anonymised. A single permanent identifier — a random UUID with your name, email, and content stripped from it — is retained so the account cannot be silently recreated and so historical records remain consistent. It cannot be used to identify you.

8. Your rights

Wherever you live, you may:

Requests are answered within 30 days, and usually the same day. We never charge for them.

California residents: the rights to know, delete, correct, and opt out of "sale" or "sharing" are covered by the above. Pneumanos does not sell or share personal information as those terms are defined by the CCPA/CPRA, and does not discriminate against anyone for exercising a privacy right.

9. International transfers

Our servers and service providers are located in the United States. If you are in the EU/EEA, the UK, or elsewhere, using this site involves transferring your information there. Where required, those transfers rely on Standard Contractual Clauses or an equivalent safeguard.

10. Children

This service is for adults. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, write to us and it will be deleted.

11. Security

TLS in transit; authenticated encryption at rest for what you write about sessions; passwordless sign-in with short-lived one-time codes; CSRF protection on every write; session records you can inspect and revoke yourself; and no card data on our systems at all. No system is perfectly secure, but the design assumes that and limits what a breach could expose.

12. Changes to this policy

The "last updated" date above always reflects the current version. Material changes are notified by email to account holders before they take effect.

13. Contact

Any question about your data, or any request under this policy: hello@pneumanos.com.