Privacy Policy
We take your privacy seriously and are committed to keeping your information safe
Felt — Privacy Policy
Effective date: July 17, 2026 Last updated: July 17, 2026
Felt is operated by Felt LLC, a sole proprietor located in Utah, United States ("Felt," "we," "us," "our").
This policy explains what we collect, why, how long we keep it, and what control you have. Felt handles information about your mental health, so we've tried to write this plainly rather than defensively.
Contact: privacy@felt-emdr.com · 1771 Oakridge Dr, Lehi, UT 84043, United States
1. The short version
- Felt is a self-guided EMDR and trauma-processing practice tool. What you write in a session — the memory you're working on, your beliefs about it, your distress ratings — is the most sensitive data in the product, and we treat it as health data.
- We do not run analytics, advertising, or third-party tracking on Felt. No ad pixels, no marketing SDKs, no session replay.
- We do not sell your personal information and do not share it for cross-context behavioral advertising.
- Your session data is isolated at the database level so that only your account can read it.
- You can delete your account and all session data yourself, at any time, from Settings → Delete.
- Felt is for adults only (18+).
2. What we collect
2.1 Account and identity
We use Supabase Auth to sign you in. Depending on the method you choose:
- Email + password — your email address and a hashed (never plaintext) password.
- Google sign-in — your Google account email, name, profile picture, and Google account identifier, shared with us by Google when you consent.
We also store your unique user ID, sign-up and sign-in timestamps, email-confirmation status, and an authentication session token in a browser cookie.
Anonymous trial accounts. You can start a session at /trial without signing up. We create an anonymous account behind the scenes to hold that session's data. If you later create a real account, the anonymous account is upgraded in place and your trial data carries over. If you don't, the account and its data are deleted automatically (see §6).
2.2 Profile
- Disclaimer acknowledgement — the timestamp when you accepted the in-app safety disclaimer.
- Screening responses (
risk_flags) — your answers to the pre-session safety questionnaire. This is health information. We use it to determine whether and how you proceed. - Preferences — app and interface settings.
2.3 Session content — the sensitive core
Each session you run stores:
- A title you provide, which may reference a memory or event.
- The session type (e.g. EMDR).
- Distress and belief ratings you enter before, during, and after the session.
- Session content — your free-text and structured answers, including intake notes, the target memory or image you're processing, and the associated negative and positive beliefs.
- Your flower drawing (stored as vector stroke data).
- Start and completion timestamps.
We also keep point-in-time backups of sessions — JSON snapshots containing the same content — so that an interrupted session can be recovered.
2.4 Waitlist
If you join the waitlist, we store your email address and the date you signed up.
2.5 Contact form
Your name, email address, and message, which are emailed to our support inbox.
2.6 Stored on your device
- Cookies — your Supabase authentication session, which keeps you signed in. This cookie is strictly necessary to operate the service. We do not use advertising or analytics cookies.
- localStorage — your color theme and interface preferences only. No personal or health data.
2.7 Collected automatically by our host
Our hosting provider (Vercel) processes standard server and CDN logs, which include your IP address and request metadata, in the course of serving the site. These are ordinary infrastructure logs, not a behavioral profile.
3. How we use your information
| Purpose | Data used |
|---|---|
| Authenticate you and keep you signed in | Account, auth cookie |
| Run sessions; save and restore progress | Session content, backups |
| Show your meadow and session history | Session content, flower drawings |
| Safety gating — deciding whether and how you proceed | Screening responses, disclaimer acknowledgement |
| Reply to you | Contact-form submissions |
| Waitlist and product-update email | Waitlist email address |
| Keep the service secure and operational | IP and request logs |
We do not use your session content to train machine-learning models. We do not use it for advertising. We do not profile you or make automated decisions with legal or similarly significant effects about you.
4. Legal bases (GDPR / UK GDPR)
If you are in the EEA, UK, or Switzerland, our legal bases are:
- Contract (Art. 6(1)(b)) — creating your account, running sessions, storing your history, responding to you.
- Consent (Art. 6(1)(a)) — marketing and product-update email. Withdraw at any time via the unsubscribe link.
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and keeping the service running.
- Explicit consent (Art. 9(2)(a)) — for special-category health data. Your session content and screening responses reveal information about your mental health. We process them only on the basis of your explicit consent, given when you accept the in-app disclaimer and begin a session. You can withdraw that consent by deleting your account, which erases the underlying data.
5. Who we share it with
We share personal data only with the service providers below, each acting as our processor under contract. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
| Provider | Purpose | What they receive |
|---|---|---|
| Supabase | Authentication and database hosting | All account, profile, session, backup, and waitlist data |
| OAuth sign-in | Email, name, profile picture, Google ID — only if you choose Google sign-in | |
| Resend | Transactional and marketing email | Recipient email address; contact-form name and message |
| Vercel | App hosting, edge compute, CDN | All traffic in transit; IP address and request metadata in logs |
We may also disclose information if legally required (subpoena, court order, or law enforcement demand we're compelled to honor), or to protect against imminent harm. Given the sensitivity of session content, we will resist overbroad requests and, where lawfully permitted, notify you before disclosing.
If Felt is ever acquired or transferred, your data may transfer with it. You will be notified beforehand and given the opportunity to delete your account first.
6. Retention and deletion
- Anonymous trial accounts are deleted automatically after 7 days of inactivity — no sign-in and no session activity in that window. A scheduled daily job performs the deletion, which cascades to that account's sessions, profile, and backups. We keep an internal log of each run (timestamp and number of accounts deleted; no personal data). Registered accounts are never touched by this job.
- Registered accounts — your profile, sessions, and backups persist until you delete your account.
[TODO — define a concrete inactivity-based retention period for registered accounts and state it here.] - Self-serve deletion — signed-in users can permanently delete their account at Settings → Delete. This deletes your auth user and cascades to your sessions, profile, and backups, then signs you out. This is irreversible.
- Waitlist entries persist until removed. Contact-form messages persist in our support inbox. Neither is removed by account deletion — email privacy@felt-emdr.com to have them deleted.
[TODO — confirm whether these should be wired into the deletion path.] - Backups and logs held by our providers may persist for a short additional period in their routine backup cycles before being overwritten.
7. Security
- All data is encrypted in transit (TLS) and at rest.
- Every user table enforces Postgres Row Level Security: a signed-in user can read and write only their own rows. This is enforced by the database itself, not just application code.
- Passwords are hashed; we never see them.
- Deleting an auth user cascades automatically to their profile, sessions, and backups.
No system is perfectly secure. If a breach affects your unsecured health information, we will notify you and, where required, the FTC and applicable regulators, consistent with the FTC Health Breach Notification Rule and other applicable breach-notification laws.
8. International transfers
Felt is operated from the United States and your data is stored and processed there. If you access Felt from outside the US, you are transferring your data to the US. For EEA/UK/Swiss users, transfers to our providers rely on the EU Standard Contractual Clauses and the UK Addendum, or on an applicable adequacy decision, together with supplementary measures where appropriate.
9. Your rights
Regardless of where you live, you can:
- Access and export your data — email privacy@felt-emdr.com and we will provide a machine-readable copy of your account, profile, sessions, and drawings.
- Correct inaccurate information.
- Delete your account and all session data — instantly, yourself, at Settings → Delete.
- Opt out of marketing email — unsubscribe link in every message.
If you're in the EEA, UK, or Switzerland, you also have the rights to restriction, objection, portability, withdrawal of consent, and to lodge a complaint with your supervisory authority.
If you're in California, you have the rights to know, delete, correct, and to limit use of sensitive personal information under the CCPA/CPRA. Felt does not sell or share personal information, so there is no opt-out to exercise. Sensitive personal information (your health data) is used only to provide the service you requested — never for inferring characteristics about you. We will not discriminate against you for exercising any right.
If you're in Utah, Colorado, Connecticut, Virginia, Texas, or another state with a comprehensive privacy law, you have equivalent rights of access, deletion, correction, and portability, and — where your state provides one — a right to appeal a denied request by replying to our response.
If you're in Canada, you have rights of access and correction under PIPEDA and may complain to the Office of the Privacy Commissioner.
We respond to requests within 30 days (45 where permitted). We may need to verify your identity, usually by confirming control of your account email. Authorized agents may submit requests on your behalf with written proof.
10. Children
Felt is not for anyone under 18. We do not knowingly collect data from minors. If we learn that a minor has created an account, we will delete it. If you believe a minor is using Felt, contact privacy@felt-emdr.com.
11. Not a medical service
Felt is a self-guided wellness practice tool. It is not a medical device, does not provide diagnosis or treatment, and does not create a clinician–patient relationship. We are not currently a HIPAA covered entity or business associate, and we do not share your data with clinicians. That does not lower our standard of care for this information — it is health data and we treat it as such.
If you are in crisis, contact a licensed professional or call or text 988 (US Suicide & Crisis Lifeline).
12. Changes to this policy
We will post any changes here with an updated date. For material changes to how we handle session content, we will notify you by email and, where the change requires it, ask for your consent again before it takes effect.
13. Contact
Felt LLC · 1771 Oakridge Dr, Lehi, UT 84043, United States, Utah, USA privacy@felt-emdr.com