Skip to main content

Legal

Privacy Policy

Last updated August 18, 2026

1. What I collect

When you take the Structural Test, submit an application, book a call, or become a client, I collect the information you provide directly: name, email, assessment answers, intake responses, bloodwork results you upload, and session notes. I also collect basic analytics (pages visited, referral source) through privacy-respecting first-party tracking.

2. How I use it

I use your data to deliver the engagement you signed up for: interpreting your assessment, building your protocol, running sessions, tracking progress, and sending relevant follow-up. I do not sell your data to anyone. I do not share it with third parties for advertising.

3. Where it lives

Your data is stored in a Supabase database hosted in the United States. Bloodwork panels and biomarker data are stored in the same encrypted database. Payment information is processed by Stripe and is never stored on my servers.

4. Who can see it

Only Erik Warner has access to your data. No contractors, no virtual assistants, no third-party analysts. The database is protected by row-level security policies that restrict access to authenticated admin sessions only.

5. Email communication

When you take the Structural Test or submit an application, you will receive follow-up emails from me. You can unsubscribe at any time using the link in every email or at /unsubscribe. I will never send you email from a third party on my behalf.

6. Your rights

You can request a full export of your data at any time. You can request deletion of your data at any time, with the exception of records I am legally required to retain (signed agreements, payment records). To exercise either right, email erik@erikwarner.com or use the in-portal data deletion tool.

7. Data retention

For active clients, data is retained for the duration of the engagement plus three years. For leads who take the Structural Test but do not apply, assessment data is retained for 12 months. For applicants who are not accepted, application data is retained for 6 months. After these periods, data is permanently deleted.

8. Security

The database uses row-level security, encrypted connections (TLS), and scoped access policies. Admin access requires authenticated sessions. Bloodwork files are stored in access-controlled storage buckets. No system is perfectly secure, but the architecture follows least-privilege principles throughout.

9. Changes to this policy

If this policy changes, the updated date above will reflect the most recent revision. Material changes will be communicated by email to active clients and leads at least 30 days before taking effect.

10. Contact

Questions about this policy: erik@erikwarner.com.