Legal
Security & Data Handling
Last updated: September 2026. A plain description of how this website handles the information you send it.
This website is deliberately non-clinical
This website is not HIPAA compliant and is not covered by a business associate agreement. We therefore designed it to never need protected health information. Our contact form asks for your name, contact details, a reason, a short note, and how you heard about us. Nothing clinical is requested. Anything medical or insurance-related is collected afterwards through a secure channel. See the Privacy Policy.
How enquiries are stored
- Submitted over HTTPS and written by our own server-side code
- Stored in a database with row-level security that grants no read or write access to the public website or to browser sessions
- Validated on the server as well as in your browser
- Protected by a hidden spam field, a minimum submit time, and per-address rate limiting
- IP addresses stored only as a one-way hash, never in readable form
Transport and browser protections
Every page is served over HTTPS with HSTS, a Content Security Policy, frame protection, a strict referrer policy, MIME sniffing protection, and a permissions policy that blocks camera, microphone, geolocation, and payment access.
One honest limitation: because this site's pages are server-rendered by a bundler that emits an inline hydration script, our Content Security Policy still allows inline scripts rather than using per-request nonces. We consider that a hardening item, not a claim of full coverage.
Secrets and third parties
No API keys or credentials are present in the code your browser downloads. Server keys live only in the server environment. We do not load advertising or social tracking scripts, and analytics load only after you accept optional cookies.
Reporting a security concern
Email hello@thewellinyou.com with the words “security report” in the subject, or call (904) 555-0142. Please do not include patient details in your report.