Privacy Policy

Your answers never leave your device.

The Wholeness Path was built for people who have good reason to distrust data collection. This page explains exactly what happens to your information, in plain language first and technical detail after.

Last updated July 2026

What we have, and what we don't.

The free Doorway tier collects nothing about you as an individual, and nothing you answer. Your assessment runs entirely in your browser. Your answers are stored only on your device and are never transmitted. No answer, score, or identity ever reaches a C.U.R.E. server.

We use one privacy-respecting, cookieless analytics service to count aggregate visits and completions, so that we can tell funders and partners how many people the platform reaches. Those counts identify no one. We have no record that any particular person used the platform.

Future paid tiers will collect the minimum necessary and nothing more. When the Companion and Path tiers launch, they will require an email and password for your account, billing details handled by Stripe rather than stored by us, and any optional content you choose to save, encrypted and accessible only to you.

We never sell user data. We never share it without your consent. We never use it to train AI models. We never share it with advertisers. These commitments are structural rather than promotional. The architecture of the platform is what makes them enforceable.

You can leave at any time, take your data with you, and delete it from our records once paid tiers exist.

How the free Doorway tier works.

Architecture

The free Doorway tier, including the 9-domain assessment, the personalized regimen, the Daily Companion, and Lighthouse Lite, runs entirely in your browser.

When you visit mendme.org and complete the assessment, the items, your answers, the scoring, and the results are all processed locally on your device. Your responses do not travel to any C.U.R.E. server. They do not leave your device.

If you save your assessment to resume later, that data is held in your browser's local storage, a feature browsers provide so websites can remember information between visits. It sits on your device. It does not sit on ours.

What this means in practice

If a researcher asks how many people have completed the assessment, we can give an aggregate count and nothing more. We cannot say who any of them were.

If a journalist asks for the average score across our users, we do not know. Scores are never transmitted.

If a court subpoenas us for a specific user's responses, there are no records to provide. Privacy here is structural, not a policy we promise to follow.

The trade-off is real. We can see that sessions started and finished, but nothing about what anyone answered, scored, or wrote. We cannot tune the platform on response content because we never receive response content. We accept that trade-off because the people this platform serves, including targeted parents in active legal cases, survivors of abuse, and communities with deep and earned institutional distrust, need this architecture more than we need the analytics.

What is stored on your device

Your browser may hold the following, on your own hardware:

You can clear all of it at any time by clearing your browser's local storage for mendme.org, or through your browser's privacy controls.

Hosting logs

Like virtually every website, our host (Netlify) records standard technical request logs: approximate IP address used to operate the infrastructure, browser type, pages requested, and country or region-level location. These logs are operational rather than analytical. They contain no assessment responses, no user-entered text, and no identifying information beyond what any browser sends automatically. C.U.R.E. does not analyze them except for technical troubleshooting, and they are retained only per Netlify's standard policies.

What we measure, and how.

The platform uses Plausible Analytics to count aggregate usage. Plausible is cookieless and sets no advertising profile. It stores no IP addresses, does not fingerprint browsers, and cannot identify an individual or follow anyone between visits. It is open-source, hosted in the EU, and built to GDPR and CCPA standards. It is not advertiser-funded and does not sell data.

We use analytics at all because foundation funders and institutional partners reasonably need to know how many people the platform is reaching. We use Plausible specifically because it answers that question without compromising the architecture that protects you.

Everything sent to Plausible
EventWhat it records
AssessmentStartedThat a Wholeness Path session began
AssessmentCompletedThat a session reached the end
Lighthouse StartedThat a Lighthouse Lite check-in began
Question AnsweredThat a question was answered. A count only. Not which question, and not what was chosen
Lighthouse CompletedThat a check-in reached the end
Result Path ClickedThat an onward link was clicked from a results screen

Six events, and no others. Each is a bare count. Alongside them, Plausible records standard anonymous page views and the coarse context every analytics tool receives: browser, device type, and country or city-level region, none of it tied to a person or kept as a profile.

Why each event is a count and not a container

In Plausible, a custom property is the mechanism by which extra data can be attached to an event. Our account has none configured. There is no field in which an answer, a score, or an identifier could travel, even accidentally.

What is never sent, here or anywhere

This is not a promise about intent. It is a description of the code. There is no event in the platform that carries answer content, and a technical reviewer inspecting network traffic in browser developer tools will find none.

Verified. The list above was checked on July 23, 2026 against the platform's complete analytics record for all time. The six events named are the only events the platform has ever transmitted. We will re-check and re-date this section whenever the instrumentation changes.

The platform sets no cookies for tracking or profiling, and uses no Google Analytics, no Facebook Pixel, and no advertising tracker of any kind. It may use a minimal session cookie for technical operation only, such as remembering that you accepted the platform's introductory framing during a single visit.

C.U.R.E. does not know who you are. C.U.R.E. does not know what you answered. C.U.R.E. knows only that, in a given month, the door opened a certain number of times.

Institutional deployments.

When the platform is deployed inside a school, youth-serving organization, workplace, or clinical practice, the data flow is designed differently from individual consumer use. Individual responses are processed in the user's browser exactly as in the free tier. Aggregate metrics are shared with the institution at cohort level only.

Partners receive cohort engagement figures, aggregate response patterns across domains, pre and post measurement within properly consented research contexts, and facilitator-reported observations.

Partners do not receive individual responses, individual identifying information, the text of any journal entry or reflection, or anything that would let them identify a specific person.

Crisis flagging follows the same rule. An institution learns that someone in a cohort flagged concern, never who. Identification happens through the facilitator's existing human relationship and engagement protocols, not through the platform's data.

For schools, the privacy-first architecture is structurally FERPA-compatible, with specific documentation prepared per district before deployment. For clinical practices, Business Associate Agreement frameworks are prepared before any deployment; the architecture limits the scope of HIPAA exposure without eliminating it, and specialized counsel reviews any clinical deployment. For workplaces, employee privacy considerations vary by state and by employer, and C.U.R.E. integrates with the employer's existing framework.

Your rights as a user.

In the free Doorway tier

Once paid tiers launch

The right to ask what we have

At any time you can write to martincasares@mendme.org and ask what data we hold about you, when you last engaged, or whether anything about you has ever been shared. We will answer truthfully. For free Doorway tier users, the truthful answer is that we have no data about you as an individual and no way to create any. Aggregate usage counts exist, and they identify no one.

Breach notification.

In the event of a security incident affecting user data, we commit to investigation within 72 hours of detection, notification to affected users within 7 days of confirmation, public notification if more than 500 users are affected, honest disclosure of what was and was not affected including what we do not yet know, concrete remediation steps for those affected, and documented lessons carried into ongoing practice.

These commitments apply once paid tiers launch and user data exists to be breached. In the free Doorway tier there is no user data at the platform level to breach.

Children's privacy.

The Wholeness Path is designed for adults. The free Doorway tier does not collect age and cannot verify it.

An adolescent-adapted assessment is planned only for institutional partnerships, with parental notice and consent handled by the institution. C.U.R.E. does not collect information directly from minors outside those contexts.

If we learn that someone under 18 has used the consumer platform without parental consent, we will retain no identifiable information about them in any future paid-tier system, provide guidance toward involving a trusted adult, and point to age-appropriate resources including school counselors and Crisis Text Line.

Changes to this policy.

We may update this policy to reflect operational changes such as new infrastructure, legal changes such as new privacy regulation, platform changes affecting privacy, or the evolution of best practice.

When we do, the date at the top of this page changes, material changes are flagged in a notice on the platform, existing paid-tier users are notified directly by email where applicable, and the previous version is archived and available on request.

We will not reduce privacy protections retroactively. Anyone using the platform at the time of a reduction keeps the previous protections for their account.

Questions and concerns.

For anything about this policy, your particular situation, or privacy generally, write to martincasares@mendme.org. We respond within 5 business days for ordinary questions and within 24 hours for breach reports or urgent privacy concerns.

You may also raise privacy complaints with the State of Michigan Attorney General's Consumer Protection Division, the Federal Trade Commission, or your own state's privacy authority.

Why this matters here

Privacy is not a marketing claim or a compliance checklist. It is the precondition for the people this platform serves to engage with it at all.

A targeted parent in an active custody case cannot risk their assessment appearing in court. A survivor cannot risk their reflections being subpoenaed. A student cannot risk cohort data being used against them. An employee cannot risk their employer learning what they shared in a private moment.

These users do not engage with platforms that collect their data. They engage with platforms that structurally cannot. The Wholeness Path is built to be the second kind.

This page explains how. The platform's behavior is the proof.