Legal
Privacy Policy
Last updated: August 19, 2026
People bring Pneumanos things they have told nobody else. That imposes an obligation, and this page sets out how it is met — what is collected, what is encrypted, who can see it, how long it is kept, and how to get it all back or have it destroyed.
The short version
- We collect the minimum needed to run a booking: an email address, whatever you choose to put on your profile, and what you write about each session.
- What you write about a session is encrypted in the database and read only by the practitioner.
- Nothing is ever sold, and nothing is used to train machine-learning systems.
- There is no advertising, no tracking pixel, and no third-party analytics.
- We never see your card details — Stripe handles those on its own pages.
- You can ask for a complete copy of everything, or erase it entirely, at any time.
1. Who is responsible
Pneumanos, an independent spiritual discernment and consulting practice operating at pneumanos.com, is the data controller for the information described here. Contact: hello@pneumanos.com.
Pneumanos is not a healthcare provider and is not affiliated with any religious organisation. Your information is therefore not held under healthcare privacy regimes such as HIPAA, and it is never shared with any church, denomination, or spiritual body — there is none to share it with. See the Scope of Practice.
2. What we collect
Information you give us
- Your email address. Required — it is your identity here, since there are no passwords.
- A recovery email address, if you choose to set one.
- Your profile: your name, what you would like to be called, your pronouns, the religious or spiritual traditions you select, and anything you write in the "about you" field. Every one of these is optional.
- What you write about a session: your description of what you would like to bring to it, and a phone number if you choose a telephone session.
- Messages you send us through the support form.
Some of this — religious or spiritual affiliation in particular — is a special category of personal data under laws such as the GDPR. It is collected only because you chose to enter it, only for the purpose of the conversations you book, and it can be removed at any moment by clearing the field on your profile.
Information collected automatically
- Sign-in records: the date, your IP address, your browser's user-agent string, and an approximate city-level location derived from the IP. This exists so you can see where your account has been signed in from and sign out a device you do not recognise.
- Referral source: the host of the site that linked you here (for example "google.com"), and any campaign tag in the URL. The full referring URL is never stored, because it can contain the words you searched for.
- A session cookie and a CSRF cookie. Both are strictly necessary to keep you signed in and to make writes safe. There are no advertising, analytics, or tracking cookies of any kind.
Information we deliberately do not collect
- Card numbers, expiry dates, or security codes. These are entered on Stripe's own pages and never reach this site.
- Recordings. Sessions are not recorded or transcribed.
- Any information from third-party data brokers, advertising networks, or social platforms.
3. Encryption of what you write
Your description of what you want to bring to a session — and any phone number attached to it — is encrypted before it is written to the database, using authenticated symmetric encryption (Fernet: AES-128-CBC with HMAC-SHA256). Anyone who obtained a copy of the database, a backup, or a stray dump would find ciphertext where those fields should be.
It is decrypted in exactly three places: when it is shown back to you, when the practitioner reads it to prepare for your session, and when you request a copy of your own data. Traffic between your browser and this site is protected in transit by TLS.
4. Why we hold it, and on what legal basis
| What | Why | Basis (GDPR) |
|---|---|---|
| Email address | Sign-in; sending confirmations and reminders | Performance of a contract |
| Profile, including traditions | So sessions begin from who you are | Explicit consent (Art. 9(2)(a)) |
| Session descriptions | Preparing for and delivering the session | Performance of a contract |
| Payment records | Taking payment; accounting and tax | Contract; legal obligation |
| Sign-in records | Account security; showing you your own sessions | Legitimate interests |
| Referral host | Knowing how people find the practice | Legitimate interests |
5. Who can see your information
The practitioner. Your profile, your bookings, and what you wrote about them. Nobody else at Pneumanos, because there is nobody else.
Other members: never. There are no public profiles, no directories, no reviews, and no way for one member to discover another. Nothing you enter here is published anywhere.
A small number of service providers, each of which sees only what it needs to do its job and none of which may use it for their own purposes:
- Stripe — payment processing. Receives your email address and the amount. Handles your card details directly, under its own privacy policy.
- Our email provider — delivering confirmations, reminders, and one-time codes. Sees the address and the contents of those emails, which include your session's date, time, and your own description of it.
- Our hosting provider — running the server and its database.
- ip-api.com — turning an IP address into an approximate city for the sign-in history. Receives the IP address alone; no other information about you.
We never sell your information, share it for anyone's advertising, or use it to train machine-learning systems. We may disclose it where the law compels us — see the next section.
6. The limits of confidentiality
Confidentiality here is a professional commitment. Because Pneumanos is not a licensed healthcare provider, it is not legal privilege, and it cannot be absolute. Information may be disclosed where:
- there is a credible and immediate risk of serious harm to you or to another identifiable person;
- there is reason to believe a child or vulnerable adult is at risk of harm;
- we receive a subpoena, court order, or other lawful demand we cannot refuse;
- it is necessary to establish, exercise, or defend a legal claim.
Where disclosure is required, we disclose the minimum necessary and, where we are permitted to do so, tell you first.
7. How long we keep it
- Your account and profile — until you close the account.
- Bookings and what you wrote about them — until you close the account, or until you ask for them to be erased sooner.
- Payment records — up to 7 years after the payment, because tax and accounting law requires it. These contain no card data and no session content.
- Sign-in records — deleted when you close your account; older entries are pruned routinely.
- One-time codes — deleted within a day of expiring.
- Support messages — up to 2 years after they are resolved.
When you close your account, everything above is deleted or irreversibly anonymised. A single permanent identifier — a random UUID with your name, email, and content stripped from it — is retained so the account cannot be silently recreated and so historical records remain consistent. It cannot be used to identify you.
8. Your rights
Wherever you live, you may:
- Get a copy of everything we hold about you, decrypted and complete, emailed as a single file — from the Your Data page. No forms, no waiting period.
- Correct anything wrong, from your profile page or by writing to us.
- Erase everything, by closing your account in settings.
- Withdraw consent for the special-category data by clearing the traditions field. That does not affect anything done while consent was in place.
- Object to or restrict processing based on legitimate interests.
- Take your data elsewhere — the JSON export is machine-readable for exactly this.
- Complain to your local data-protection authority. In the EU/EEA and UK this is your national supervisory authority. Please consider telling us first — we would rather fix it.
Requests are answered within 30 days, and usually the same day. We never charge for them.
California residents: the rights to know, delete, correct, and opt out of "sale" or "sharing" are covered by the above. Pneumanos does not sell or share personal information as those terms are defined by the CCPA/CPRA, and does not discriminate against anyone for exercising a privacy right.
9. International transfers
Our servers and service providers are located in the United States. If you are in the EU/EEA, the UK, or elsewhere, using this site involves transferring your information there. Where required, those transfers rely on Standard Contractual Clauses or an equivalent safeguard.
10. Children
This service is for adults. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, write to us and it will be deleted.
11. Security
TLS in transit; authenticated encryption at rest for what you write about sessions; passwordless sign-in with short-lived one-time codes; CSRF protection on every write; session records you can inspect and revoke yourself; and no card data on our systems at all. No system is perfectly secure, but the design assumes that and limits what a breach could expose.
12. Changes to this policy
The "last updated" date above always reflects the current version. Material changes are notified by email to account holders before they take effect.
13. Contact
Any question about your data, or any request under this policy: hello@pneumanos.com.